PDF Digital Document Signing API with PAdES Standards - n8n Workflow

Use this robust n8n workflow to create a secure PDF Digital Signature API. It supports PAdES baseline levels (B, T, LT, LTA), visible/invisible signatures, and manages dependencies automatically.

Workflow Preview

Ready to automate?

Download this n8n workflow template and start using it instantly.

Who is this best for?


  • Technical teams and developers needing a compliant PDF signing service.

  • Organizations requiring automated PAdES (B, T, LT, LTA) compliant document archives.

  • Users running self-hosted n8n instances who manage sensitive document processing.

  • Developers looking for a detailed n8n workflow example involving external binaries and shell scripting.

Overview

Digitally signing documents according to established standards like PAdES is often complex, requiring specialized libraries, secure certificate handling, and environment management. This highly technical n8n workflow solves this by providing a complete, self-contained API endpoint for secure PDF signing. This n8n template handles the secure upload of the PDF and PFX certificate, automatically installs required dependencies (like Java JRE), extracts certificate components, executes the signing process using the open-pdf-sign.jar utility, and manages temporary file cleanup. It supports both visible and invisible signatures and allows selection of all PAdES baseline levels (B, T, LT, LTA), ensuring your output is compliant. Implementing this robust n8n node sequence simplifies a critical compliance task.

How it Works

The entire process starts with a specialized n8n trigger.


  1. Incoming Request (Webhook n8n trigger): The process is initiated by a POST request to the /pdf-sign webhook, receiving the input PDF, PFX certificate file, certificate password, and desired signing parameters (level and visibility).

  2. File Staging: The uploaded PDF, PFX, and optional logo are immediately written to temporary locations (/tmp/) using Read/Write File n8n node operations. This ensures secure, isolated processing.

  3. Environment Check: The n8n workflow first checks if Java is installed using the Check Java n8n node. If missing, it downloads and executes a script to install necessary dependencies.

  4. Certificate Preparation: The certificate password and a unique timestamp are extracted. A shell script (pfx-split.sh) is run via an Execute Command n8n node to securely split the PFX file into separate PEM certificate and private key files.

  5. Visibility Routing: An If n8n node determines if the signature should be visible (adding visual parameters) or invisible (no visual mark).

  6. Signature Level Routing: A Switch n8n node routes the flow based on the requested PAdES level (B, T, LT, LTA), setting the corresponding signing parameter.

  7. Execution (Sign PDF): The Sign PDF Execute Command n8n node executes the main signing script (processpdf.sh), passing all input and temporary file paths, along with the visibility and PAdES level parameters.

  8. Response: The resulting signed PDF file is read from the temporary output path and returned to the client using the Respond To Webhook n8n node with the correct PDF MIME type.

  9. Cleanup: Finally, a cleanup script is executed via another Execute Command n8n node to delete all temporary input, output, and certificate files for security.

Installation Guide


  1. Import: Copy the provided n8n workflow JSON and import it into your n8n instance.

  2. Activate: Ensure the workflow is active. Note that this n8n template contains multiple Webhook nodes. The main signing endpoint is /pdf-sign.

  3. Dependencies (Self-Hosted n8n): This n8n workflow requires a server environment that permits the installation of packages (like Java JRE) via the Execute Command n8n node. If you are using a Dockerized n8n installation, ensure the container has permissions to run shell commands and write to temporary directories.

  4. Initial Setup: The workflow automatically checks and installs Java and the signing JAR file upon the first run if they are not detected. No manual external setup is required beyond basic OS shell access.

  5. Testing: Use the provided landing page webhooks (e.g., /en/signpage) or the CURL examples referenced in the sticky notes to test the /pdf-sign endpoint. Credentials are not required for internal nodes but proper PFX certificate and password must be provided in the input payload.

Node Details

This complex n8n workflow relies on powerful file and command line manipulation:

Webhook (n8n trigger): The primary entry point (/pdf-sign) accepting multipart form data including the PDF file, PFX certificate, and required parameters like pfxPassword and signLevel.
Execute Command (n8n node): Used extensively for dependency management (Check Java, Install Dependencies), certificate extraction (Run Cert Script), and the core signing process (Sign PDF). It interfaces directly with shell scripts and the Java signing library.
Read/Write File (n8n node): Crucial for securely handling uploaded binaries. It writes input files (Write Files : PDF, Write PFX) and reads the final result (Read Signed PDF) from the server's temporary file system.
If (Java Missing?): Checks the exit code of the which keytool command. If Java is not found, the n8n workflow branches to download and install required dependencies.
If (Without Visible?): Checks the input parameter isVisible. Determines whether to include parameters for creating a visible signature mark on the PDF document.
Switch (Switch Sign Visible): Routes the execution path based on the user-defined signLevel (B, T, LT, LTA), ensuring the correct PAdES standard parameter is used for the digital signing process.


  • Set (Extract Password): Extracts and saves the certificate password and generates a unique timestamp, used across subsequent n8n node steps for secure, temporary file naming.

Related n8n Workflows

Free

Nodes: 10 Nodes
Updated: December 26 2025
View all
Created by
Vigh Sandor
Vigh Sandor

I'm a DevOps engineer and automation enthusiast who builds smart, practical workflows using n8n.io. I focus on creating reliable, open-source solutions that connect tools and simplify everyday operations — whether it’s infrastructure management, workflow automation, or integrating AI into existing systems.

Featured*