# SignPlus for Confluence

Sign a Confluence page, and prove later which version was signed.

SignPlus renders a Confluence page to PDF inside Atlassian's runtime, sends it to Dokobit for signing with each signer's own eID, and attaches the signed document back to the page. Signed with a qualified eID such as Smart-ID or an ID card, it is a qualified electronic signature, which eIDAS gives the legal effect of a handwritten one. The page is hashed with its version number, so a signature is tied to the text that was actually in front of the signers.

- **Host:** Confluence Cloud
- **Version:** v12.0.0
- **Documentation:** https://oktul.com/docs/plugins/signplus/overview/

## A signed PDF and the page it came from usually stop being the same document

Getting a Confluence page signed normally means exporting it by hand, sending the file somewhere, and filing the result. The signed PDF ends up in an inbox or a drive, and the page carries no record that it was signed at all.

The page also keeps moving. Confluence is built for editing, so the text a signer agreed to can be rewritten the same afternoon, and nothing in the signed file says which version it was.

SignPlus keeps both ends attached. The signing starts from the page, the signed document comes back as an attachment on that page, and the identity that was signed is a hash of the space, the page and its version number, so a later edit does not quietly inherit the signature.

## What it does inside Confluence

Each one is a module in the app's Forge manifest rather than a description of intent.

### Start a signing without leaving the page

Sign this page, in the byline, opens the signing panel. Choose the signers, set a deadline and start the signing. The same byline later says whether the page has changed since it was signed.

### Groups, sent in the background

Add a Confluence group as signers and every member is invited, up to 25,000 people on one signing. SignPlus sends it in the background, so closing the page does not stop it, and the signing details list who has not signed yet.

### No one has to go and fetch it

Dokobit calls the app when a signer acts or the status changes. Once the signed document has been downloaded from Dokobit, the app attaches it to the page it came from.

### A document in your company's style

Panels, status lozenges, Jira work items tables, Oktul Work Item Selector fields and Jira Assets tables print the way the page draws them, with your font, logo, first page, header and footer.

### Site settings, with per-space overrides where allowed

A site administrator sets the signing mode, the formats, the signing methods and what happens to the page while it is signed. A space administrator changes only what the site has opened to spaces, so a space cannot quietly point signing somewhere else.

### Start signings from flows and other systems

Two Jira automation actions, a REST API authenticated with an Atlassian service account, and webhooks that tell another system when a signing completes or a signed page is edited.

## Installation runs through the product you already administer

1. **Choose the signing mode** A new installation signs in Dokobit's test environment, where documents come back watermarked. Switch to your own Dokobit token before the first real signing.
2. **Decide what each space may change** Every setting carries its own switch. Leave them off if signing must be identical everywhere.
3. **Open a page and select Sign this page under the title** Add people or a group, choose the options, start the signing.
4. **Collect the signed PDF from the page** It arrives as an attachment when the last signer has finished. Nothing has to be downloaded from Dokobit by hand.

## Host platform and compatibility

- **Host product:** Confluence Cloud
- **Surfaces:** Byline item and panel, Your signings page, site and space settings, Jira automation actions, REST API
- **Rendering:** Forge native, UI Kit 2
- **Runtime:** Node.js 24 on Forge
- **Signing provider:** Dokobit
- **Jira:** Optional. Adds the automation actions, Assets tables and Work Item Selector cards
- **Licence:** Enforced by the app on every entry point

## Page content leaves Atlassian, and here is exactly where it goes

SignPlus cannot do its job inside Atlassian alone: a qualified electronic signature is produced by a trust service provider. Dokobit is declared in the app's Forge manifest, which is the file Atlassian reviews, and a webhook address reaches nothing until your administrator approves it in Atlassian's own dialog, so neither is a matter of trust in this page.

- **Does page content leave Atlassian?:** Yes, to Dokobit. This application declares egress, unlike Work Item Selector.
- **To which services?:** *.dokobit.com, and any webhook address your administrator approves
- **What is sent to Dokobit?:** The page rendered as a PDF, and each participant's name and email address.
- **Where is the PDF made?:** Inside Atlassian's runtime. No third party renders it.
- **What else does it reach?:** Only Atlassian's own hosts, and they receive nothing: your site and the avatar service for images, Atlassian's image library at dam-cdn.atl.orangelogic.com for the pictures in Atlassian's page templates, and api.atlassian.com to check a REST API caller's token.
- **What is stored in Forge?:** One record per signing: the page's identity and hash, the Dokobit document token, the request's name and deadline and the page's prior restrictions, and one record per participant. A signing being sent is held as a job for 7 days. Never the document itself.
- **How is the signed version identified?:** SHA-256 of the space, the page and its version number.
- **Who makes the signature?:** The signer, on Dokobit's page, with their own eID. A qualified eID gives a qualified electronic signature (QES) under eIDAS, equal in law to a handwritten one across the EU. Oktul never sees a personal code or PIN.
- **Is Dokobit a qualified trust service provider?:** Yes, for validating electronic signatures and seals. Dokobit states that it is supervised by Lithuania's Communications Regulatory Authority and listed on the EU Trusted List. Its compliance page at dokobit.com/compliance carries the certificates.
- **Where does Dokobit keep the data?:** In the EU/EEA, mirrored in two locations, encrypted with TLS and AES-256, under ISO/IEC 27001 and 27018 certification audited by DNV, by Dokobit's own statement. The provider is Dokobit, UAB (registry code 301549834).

**Scope / What it is for**

- `read:page:confluence` — Read the page being signed or exported.
- `read:confluence-content.all` — Read the page body in order to render it.
- `read:confluence-content.summary` — Receive the page-edited event, so a signed page that changes can be reported.
- `write:confluence-content` — Record the signing against the page, and set and lift its restrictions.
- `read:confluence-content.permission` — Check the reader may act on the page before offering to sign it.
- `read:space:confluence` — Resolve the space a signing belongs to, and apply space settings.
- `readonly:content.attachment:confluence` — List existing attachments on the page.
- `read:attachment:confluence` — Read an attachment so it can be included in the document.
- `write:confluence-file` — Attach the signed PDF back to the page.
- `read:confluence-user` — Show who initiated a signing, and who the signers are.
- `read:email-address:confluence` — Dokobit identifies a signer by email address, so the address of a signer you choose is read and sent.
- `read:cmdb-object:jira` — Read the objects behind a Jira Assets table on a page, so they are in the document. Needs Jira connected.
- `read:content-details:confluence` — Match a signer named by email address to their Confluence account.
- `read:confluence-groups` — Offer your groups as signers, and list a group's members when the signing is sent.
- `search:confluence` — Search a space's pages by title in the automation actions' page picker.
- `read:jira-work` — Read the work items in an Oktul Work Item Selector field, so they print as cards. Needs Jira connected.
- `storage:app` — Store the signing records and the settings.

## The tests every release has to pass

- **Automated tests:** 1359. Counted on the current build, including authorisation, injection and logging suites.
- **Test suites:** 68. Rendering, permissions, the REST API, automation, webhooks and licensing.
- **People per signing:** 25000. After groups are expanded. Enforced on the page, in automation and in the REST API alike.

## The questions other administrators ask most

### Is a SignPlus signature legally binding?

Signed with a qualified eID, such as Smart-ID or an Estonian, Latvian, Lithuanian, Finnish or Belgian ID card, it is a qualified electronic signature, which Article 25(2) of eIDAS gives the legal effect of a handwritten signature in every EU member state. Dokobit's list of eIDs on dokobit.com says which methods produce one. Set E-signature levels to QES only to refuse the rest. A signing in test mode has no legal effect.

### Who holds the relationship with the signing provider?

You do. Real signing runs on your own Dokobit account, with the token you enter in SignPlus. Test mode runs on Oktul's Dokobit sandbox so you can try SignPlus first, and what it signs is watermarked and binds nobody.

### What happens if a signer never signs?

The signing keeps its status until everyone has signed or the deadline passes, and a strict deadline cancels it then. The signed document is attached to the page only once it exists.

### Who can delete a finished signing?

A Confluence administrator, by default. The site can add space administrators, page editors or the person who started it. Deleting removes SignPlus's record; the signed file stays attached to the page.

### Can a space administrator point signing somewhere else?

No. The signing mode is set for the whole site, and a space changes only the settings the site administrator has opened to spaces.

### Does a lapsed licence stop a signing in progress?

No. New signings stop, but a signing already out for signature still completes, and its signed document is attached to the page.

### Is this application in the Runs on Atlassian programme?

No, and it cannot be. That programme is for applications that keep all data inside Atlassian, and this one sends page content to a signing provider by design. Oktul Work Item Selector for Jira carries the badge; this application states its egress instead.

---

## Published by

- Oktul OÜ
- Oktul OÜ · Reg. nr 17589681 · Tallinn, Harjumaa, Estonia
- Email: hello@oktul.com
- Web: https://oktul.com/
- Atlassian Marketplace: https://marketplace.atlassian.com/vendors/534484195
- LinkedIn: https://www.linkedin.com/company/oktul
- YouTube: https://www.youtube.com/@OktulDevelopment
- Estonian: https://oktul.com/et/
