> ## Documentation Index
> Fetch the complete documentation index at: https://developers.myhero.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign a signature block

> Signs one signature block.

The server captures the caller's IP address, user agent and its own clock, hashes the document, writes an append-only audit record, and then applies the signature into the collaborative document.

Callers only need read access — signing does not require edit rights.

Signing is idempotent per block: a second call returns the existing record.

Rejected once the document is fully signed and locked.



## OpenAPI

````yaml post /signature/{documentId}/{nodeId}/sign
openapi: 3.1.0
info:
  title: HERO API
  version: current
  description: |-
    The HERO REST API.

    See https://developers.myhero.so for the rendered docs.
servers:
  - url: https://app.myhero.so
security: []
paths:
  /signature/{documentId}/{nodeId}/sign:
    post:
      tags:
        - Signatures
      summary: Sign a signature block
      description: >-
        Signs one signature block.


        The server captures the caller's IP address, user agent and its own
        clock, hashes the document, writes an append-only audit record, and then
        applies the signature into the collaborative document.


        Callers only need read access — signing does not require edit rights.


        Signing is idempotent per block: a second call returns the existing
        record.


        Rejected once the document is fully signed and locked.
      operationId: signDocumentBlock
      parameters:
        - schema:
            type: string
            minLength: 1
          required: true
          name: documentId
          in: path
        - schema:
            type: string
            minLength: 1
          required: true
          name: nodeId
          in: path
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                company:
                  type: string
                title:
                  type: string
                clientReportedAt:
                  type: number
                signatureId:
                  type:
                    - string
                    - 'null'
                customPayload: {}
              required:
                - name
      responses:
        '201':
          description: 201 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      _id:
                        type: string
                      documentId:
                        type: string
                      nodeId:
                        type: string
                      signer:
                        type: object
                        properties:
                          userId:
                            type: string
                          email:
                            type: string
                          displayName:
                            type: string
                          authProvider:
                            type: string
                        required:
                          - userId
                          - email
                          - displayName
                          - authProvider
                      signatory:
                        type: object
                        properties:
                          name:
                            type: string
                          company:
                            type: string
                          title:
                            type: string
                        required:
                          - name
                      terms:
                        type: string
                      termsHash:
                        type: string
                      ipAddress:
                        type: string
                      userAgent:
                        type: string
                      signedAt:
                        type: number
                      clientReportedAt:
                        type: number
                      hashAlgorithm:
                        type: string
                        enum:
                          - sha256
                      contentHash:
                        type: string
                      resolvedContentHash:
                        type: string
                      documentHash:
                        type: string
                      previousAuditId:
                        type:
                          - string
                          - 'null'
                      chainHash:
                        type: string
                      voidedAt:
                        type: number
                      voidedBy:
                        type: string
                      restoredAt:
                        type: number
                    required:
                      - _id
                      - documentId
                      - nodeId
                      - signer
                      - signatory
                      - terms
                      - termsHash
                      - ipAddress
                      - userAgent
                      - signedAt
                      - hashAlgorithm
                      - contentHash
                      - documentHash
                      - previousAuditId
                      - chainHash
                required:
                  - data
        '400':
          description: 400 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: |-
                      Error class name (e.g.

                      ValidationError, NotFound)
                  message:
                    type: string
                    description: Human-readable error message
                  details:
                    type: array
                    items: {}
                required:
                  - error
                  - message
        '403':
          description: 403 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: |-
                      Error class name (e.g.

                      ValidationError, NotFound)
                  message:
                    type: string
                    description: Human-readable error message
                  details:
                    type: array
                    items: {}
                required:
                  - error
                  - message
        '409':
          description: 409 response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: |-
                      Error class name (e.g.

                      ValidationError, NotFound)
                  message:
                    type: string
                    description: Human-readable error message
                  details:
                    type: array
                    items: {}
                required:
                  - error
                  - message
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: HERO personal access token

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.