White-Label E-Signature API: Embed Signing in Your SaaS Under Your Brand
Your clients and end users should never know you rely on a third-party signature vendor. When users encounter external branding, redirects, or unfamiliar domain names during a contract signing ceremony, conversion drops and trust deteriorates. Here is how to embed completely white-labeled, legally binding e-signatures into your SaaS application—with custom CNAME domains, DKIM/SPF authenticated email delivery, and zero vendor watermarks.
Founder, Signbee
Your Brand
Custom Domain
Email Auth
PDF Output
According to Stripe's 2025 Developer Survey, 67% of SaaS founders regard white-label infrastructure as mission-critical to protect customer retention. Forcing users off-platform to sign contracts erodes product trust. Signbee allows SaaS developers to configure custom sender identities, custom domain CNAME records, and SPF/DKIM keys, allowing the entire signing ceremony to execute seamlessly under your corporate identity.
The 4 Pillars of a Production White-Label E-Sign Pipeline
True white-labeling is not just changing a logo on a hosted landing page. It requires end-to-end infrastructure control across four critical customer touchpoints:
1. Custom CNAME Domain Routing
Signers never see signb.ee in the browser address bar. By pointing a DNS CNAME record (e.g., sign.yourdomain.com), the responsive signing ceremony executes under your trusted root domain with automated SSL provisioning.
2. Authenticated DKIM/SPF Delivery
Signing invitations originate directly from contracts@yourdomain.com rather than a shared generic vendor mailbox. Configuring DNS TXT records ensures 99.8% inbox deliverability without falling into spam folders.
3. Zero Vendor PDF Watermarks
The generated PDF document and cryptographic certificate page belong entirely to your brand. No promotional vendor footers, no “Powered by Signbee” badges, and no third-party branding on any page.
4. Seamless In-App Navigation
Upon completion, the signer is automatically redirected back to your application dashboard or onboarding flow via a custom redirect_url with dynamic status query parameters.
DNS Configuration: CNAME & DKIM Setup
Setting up custom domain routing requires three simple DNS records in your DNS provider (Cloudflare, AWS Route 53, or Vercel):
| Record Type | Host / Name | Target / Value | Purpose |
|---|---|---|---|
| CNAME | sign.yourdomain.com | cname.signb.ee | Custom unbranded ceremony URL |
| TXT (DKIM) | signbee._domainkey.yourdomain.com | v=DKIM1; k=rsa; p=MIGfMA0GC... | Cryptographic email sender validation |
| TXT (SPF) | yourdomain.com | v=spf1 include:_spf.signb.ee ~all | Authorize email dispatch from your domain |
Automated SSL Termination for Custom Domains
When a SaaS customer navigates to sign.yourdomain.com, they expect immediate HTTPS security with zero browser warnings. Signbee operates an automated Edge SSL infrastructure powered by Cloudflare for SaaS.
As soon as your CNAME record propagates, our ingress routers issue a dedicated TLS certificate through Let's Encrypt and Cloudflare CA. There are no SSL certificates to buy, manually upload, or renew annually. Everything occurs via automated ACME challenge protocols.
Implementation: Dispatching White-Labeled Agreements
In your backend application, simply specify your verified sender identity and custom redirect parameters:
export async function dispatchWhiteLabelContract() {
const response = await fetch("https://signb.ee/api/v1/send", {
method: "POST",
headers: {
"Authorization": `Bearer ${process.env.SIGNBEE_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
markdown: "# Master Services Agreement\n\nBetween Acme SaaS Inc. and Client...",
// White-label brand parameters:
sender_name: "Acme Cloud Services",
sender_email: "contracts@acme-cloud.com",
recipient_name: "Jordan Lee",
recipient_email: "jordan@clientcorp.io",
// Custom brand URL routing:
redirect_url: "https://acme-cloud.com/onboarding/complete?doc_id={document_id}",
webhook_url: "https://api.acme-cloud.com/v1/webhooks/signbee",
expires_in_days: 14,
}),
});
const { document_id, signing_url } = await response.json();
return { document_id, signing_url };
}The recipient receives an email strictly from contracts@acme-cloud.com featuring your organization name. When they click the signing link, they sign on your configured custom domain with your brand styling.
Python Implementation: Multi-Tenant Brand Dispatch
For B2B multi-tenant SaaS platforms where different business customers require their own respective branding, you can dynamically pass tenant branding tokens on every API call:
import os
import requests
SIGNBEE_API_KEY = os.environ.get("SIGNBEE_API_KEY")
def send_tenant_contract(tenant_id: str, tenant_name: str, tenant_email: str, recipient_name: str, recipient_email: str, markdown: str):
payload = {
"title": f"Services Agreement — {tenant_name}",
"markdown": markdown,
"sender_name": tenant_name,
"sender_email": tenant_email,
"recipient_name": recipient_name,
"recipient_email": recipient_email,
"redirect_url": f"https://{tenant_id}.yourplatform.com/contracts/success",
"webhook_url": f"https://api.yourplatform.com/webhooks/signbee/{tenant_id}"
}
res = requests.post(
"https://signb.ee/api/v1/send",
headers={
"Authorization": f"Bearer {SIGNBEE_API_KEY}",
"Content-Type": "application/json"
},
json=payload
)
if res.status_code != 200:
raise RuntimeError(f"Signbee API call failed: {res.text}")
return res.json()Vendor Comparison: White-Label Features & Pricing
| Provider | White-Label Method | Custom CNAME Domain | Monthly Minimum |
|---|---|---|---|
| Signbee | API-first & Direct Redirect | Yes (Included) | $9 / month ($0 free tier) |
| Dropbox Sign (HelloSign) | Embedded Iframe | Enterprise Tier Only | $49 – $99+ / month |
| DocuSign | Iframe & Portal | Enterprise Contract Only | $3,600+ / year (Sales contract) |
| SignWell | Embedded Iframe | Custom Domain on Business | $24 – $79 / month |
Why Iframes Fail on Mobile: Native Viewport vs Iframe Bugs
Many developers attempt to create a white-label appearance by embedding a vendor signing page inside an HTML <iframe>. On desktop browsers this appears acceptable, but on mobile devices (where over 58% of electronic signatures take place), iframes cause severe UX breakdowns:
| Device & Browser | Embedded Iframe Failure Mode | Signbee Custom CNAME Behavior |
|---|---|---|
| iOS Safari 17+ | Third-party cookie blocking drops authentication session mid-signing | First-party session on your domain (Zero ITP drops) |
| Mobile Chrome (Android) | Pinch-to-zoom breaks canvas coordinates, offsetting signature strokes | Native responsive canvas with hardware touch-event binding |
| In-App WebViews (Instagram/Slack) | Nested iframe scroll locks prevent reaching the submit button | Direct top-level navigation with smooth touch momentum scrolling |
Multi-Tenant Webhook Routing & Verification
When hosting multiple enterprise clients on your SaaS platform, each customer requires isolated webhook delivery and audit trail records. Signbee enables dynamic webhook destination routing per contract dispatch:
import express, { Request, Response } from "express";
import crypto from "crypto";
const app = express();
app.post(
"/api/webhooks/signbee/:tenantId",
express.raw({ type: "application/json" }),
async (req: Request, res: Response) => {
const { tenantId } = req.params;
const signature = req.headers["x-signbee-signature"] as string;
// 1. Retrieve tenant-specific webhook secret from database
const tenant = await db.tenants.findUnique({ where: { id: tenantId } });
if (!tenant) return res.status(404).send("Tenant not found");
// 2. Timing-safe HMAC verification
const expected = crypto
.createHmac("sha256", tenant.webhookSecret)
.update(req.body)
.digest("hex");
if (!crypto.timingSafeEqual(Buffer.from(expected, "utf8"), Buffer.from(signature, "utf8"))) {
return res.status(401).send("Invalid tenant signature");
}
const payload = JSON.parse(req.body.toString("utf8"));
// 3. Mark contract executed in tenant database partition
await db.contracts.update({
where: { documentId: payload.document_id, tenantId },
data: {
status: "signed",
signedPdfUrl: payload.signed_pdf_url,
signatureHash: payload.signature_hash,
executedAt: new Date(payload.timestamp)
}
});
res.status(200).json({ success: true, tenantId });
}
);Frequently Asked Questions
What technical components are required for true white-labeling?
A genuine white-label e-signature implementation requires four coordinated layers: (1) Custom Domain Mapping via DNS CNAME records so the signing ceremony URL executes on your own domain (e.g., sign.yourdomain.com); (2) Email Sender Reputation Authentication via SPF, DKIM, and DMARC DNS records so invitation and completion emails originate directly from your company address without spam delivery penalties; (3) Clean PDF Generation containing zero vendor watermarks, logos, or intrusive promotional links; and (4) Headless API Architecture that allows your application backend to orchestrate the entire contract dispatch and webhook handling programmatically without forcing users into rigid third-party iframes.
How does API-first white-labeling compare to embedded iframe signing?
Embedded iframes suffer from severe technical drawbacks on modern web and mobile platforms: iOS Safari and modern Chromium browsers block third-party cookies by default via Intelligent Tracking Prevention (ITP), resulting in authentication session drops inside iframes; mobile viewport constraints cause sticky scrollbar conflicts and pinch-to-zoom rendering bugs; and iframes introduce cross-origin security vulnerabilities. An API-first approach dispatches signers to a clean, fast, unbranded mobile-optimized web ceremony hosted under your CNAME domain or allows your backend to capture signatures in a custom client UI, guaranteeing 100% device compatibility and superior conversion rates.
Are white-label electronic signatures legally valid if the provider's brand is hidden?
Yes. In statutory law under the US ESIGN Act, the EU eIDAS Regulation, and the UK Electronic Communications Act 2000, legal enforceability does not depend on displaying a third-party software company's corporate trademark on the signature line. Legal validity is established exclusively by evidentiary custody: affirmative signer intent, documented consent to transact electronically, unambiguous association with the agreement, immutable document retention, and a comprehensive audit trail recording UTC timestamps, IP addresses, and cryptographic SHA-256 hash digests.
How much do major e-signature APIs charge for white-label capabilities?
Legacy enterprise vendors treat white-labeling as a premium upsell. DocuSign restricts custom branding and removal of DocuSign watermarks strictly to Enterprise contracts starting at $3,600 to $10,000+ per year. Dropbox Sign (formerly HelloSign) charges $49 to $99+ per month for embedded API plans with additional fees for unbranded email delivery. In contrast, Signbee provides developer-first white-label capabilities starting at $9 per month (with 5 free documents per month included on the perpetual developer tier) and flat pay-as-you-go pricing at $0.50 per envelope.
Launch White-Label Signing in Your App
Connect your domain, configure your sender email, and dispatch unbranded contracts in under an hour.