> ## Documentation Index
> Fetch the complete documentation index at: https://docs.spitshake.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a public document link

> Mints a signed link that downloads this document without an API token. Anyone holding the link can open it until it expires, the account turns links off, or an admin revokes all links. Requires public document links to be on for the account.



## OpenAPI

````yaml POST /api/submissions/{submission_id}/documents/{id}/link
openapi: 3.0.3
info:
  title: SpitShake API
  version: 1.0.0
  description: >
    SpitShake is a document signing and e-signature platform. This API allows
    you to

    manage templates, send documents for signing, track submissions, and
    integrate

    document signing into your applications.


    ## Authentication


    SpitShake supports the tenant authentication methods below plus an isolated
    partner credential:


    ### API Token (Recommended)

    Pass your API token in the `X-Auth-Token` header or as `Authorization:
    Bearer <token>`.

    Generate tokens at **Settings > API** with granular scopes.


    ```

    curl -H "X-Auth-Token: YOUR_TOKEN" https://your-instance.com/api/templates

    ```


    ### OAuth 2.1 (Authorization Code + PKCE)

    For connector directories and third-party agents. Discover endpoints at

    `GET /.well-known/oauth-authorization-server`. PKCE is mandatory.


    ### Session Cookie

    Automatically set when logged into the web application. Used by the
    frontend.


    ### JWT Bearer Token (Embed API only)

    For embedded forms and builders. Generate via `POST /api/embed/token`.


    ```

    curl -H "Authorization: Bearer JWT_TOKEN"
    https://your-instance.com/api/embed/submission/123

    ```


    ### Partner Bearer Key (`/api/partner/v1` only)

    Operator-issued `spk_` keys authenticate the reseller control plane. Partner
    keys and tenant

    credentials are mutually non-acceptable.


    ## Idempotency

    Create and send operations accept an `Idempotency-Key` header. A repeated

    request with the same key and body replays the original response without

    creating a duplicate. Keys expire after 24 hours.


    ## Versioning

    Tenant API responses include an `X-API-Version: v1` header. The tenant API
    is available

    at both `/api/*` and `/api/v1/*` (explicit pin). Partner responses include

    `X-API-Version: partner-v1`, and that control plane is separately pinned at

    `/api/partner/v1/*`.


    ## Pagination


    List endpoints use cursor-based pagination:


    | Parameter | Type | Description |

    |-----------|------|-------------|

    | `limit` | integer | Items per page (1-100, default 10) |

    | `after` | integer | Return items after this ID |

    | `before` | integer | Return items before this ID |


    Response includes a `pagination` object:

    ```json

    {
      "data": [...],
      "pagination": {
        "count": 10,
        "next": 456,
        "prev": 123
      }
    }

    ```


    Use `pagination.next` as the `after` parameter to get the next page.


    ## Rate Limits


    API requests are limited to 120 requests per minute per API token.

    Partner API requests are limited to 100 requests per minute per partner key.


    ## Errors


    All errors return a JSON object with an `error` field:


    ```json

    { "error": "Not found" }

    ```


    | Status | Meaning |

    |--------|---------|

    | 400 | Bad request - invalid parameters |

    | 401 | Unauthorized - invalid or missing authentication |

    | 403 | Forbidden - insufficient permissions or plan limits exceeded |

    | 404 | Not found |

    | 422 | Unprocessable entity - validation errors |

    | 500 | Internal server error (includes `detail` field with exception
    message for debugging) |


    ## Plan Limits


    Some endpoints require specific subscription plans. If your plan doesn't
    support an endpoint,

    you'll receive a 403 response with an `upgrade_url` field.
  contact:
    name: SpitShake Support
    url: https://spitshake.io
  license:
    name: Proprietary
servers:
  - url: https://spitshake.io
    description: Production
  - url: /
    description: >-
      Current instance (relative — only correct when the spec is served by the
      API host itself)
security:
  - ApiToken: []
  - SessionCookie: []
tags:
  - name: Templates
    description: Manage document templates with fields, submitters, and documents
  - name: Submissions
    description: Create and manage document signing submissions
  - name: Submitters
    description: Manage individual submitters (signers) within submissions
  - name: Users
    description: Manage account users and team members
  - name: Access Tokens
    description: Manage API tokens for programmatic access (requires Pro plan)
  - name: Webhooks
    description: Configure webhook endpoints for event notifications (requires Pro plan)
  - name: Settings
    description: Account settings, SMTP, storage, certificates, and email configuration
  - name: Audit Events
    description: View audit log of account activities (requires Pro plan)
  - name: Subscriptions
    description: View current plan, usage, and manage billing
  - name: Plans
    description: List available subscription plans (public)
  - name: Payments
    description: Process payments within signing flows via Stripe
  - name: Verification
    description: SMS OTP phone verification for signing sessions
  - name: KBA
    description: Knowledge-Based Authentication for identity verification
  - name: AI
    description: AI-powered document analysis and field detection
  - name: Embed
    description: Embed signing forms and template builders in your application
  - name: Custom Domains
    description: >-
      Manage custom signing domains, with DNS verification and automatic TLS
      certificates
  - name: Brands
    description: >-
      Named brands for accounts that sign on behalf of more than one brand
      (admin only)
  - name: Teams
    description: Team management and template access control
  - name: Health
    description: System health check endpoints (public)
  - name: MFA
    description: Multi-Factor Authentication setup, management, and verification
  - name: BAA
    description: Business Associate Agreement acceptance and management (HIPAA)
  - name: Security Events
    description: Security event monitoring and breach detection dashboard (admin only)
  - name: Thumbnails
    description: Template document thumbnail generation and retrieval
  - name: Partner API
    description: >-
      Versioned reseller control plane for provisioning and metering isolated
      tenant accounts
paths:
  /api/submissions/{submission_id}/documents/{id}/link:
    post:
      tags:
        - Submissions
      summary: Create a public document link
      description: >-
        Mints a signed link that downloads this document without an API token.
        Anyone holding the link can open it until it expires, the account turns
        links off, or an admin revokes all links. Requires public document links
        to be on for the account.
      operationId: createSubmissionDocumentLink
      parameters:
        - name: submission_id
          in: path
          required: true
          schema:
            type: integer
        - name: id
          in: path
          required: true
          schema:
            type: integer
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                expires_in_days:
                  type: integer
                  minimum: 1
                  maximum: 3650
                  nullable: true
                  description: >-
                    Days until the link expires. Omit to use the account
                    setting; null for a link that never expires.
      responses:
        '201':
          description: Link created
          content:
            application/json:
              schema:
                type: object
                properties:
                  url:
                    type: string
                    format: uri
                  expires_at:
                    type: string
                    format: date-time
                    nullable: true
        '403':
          description: Public document links are turned off for this account
        '404':
          description: Submission or document not found
        '422':
          description: Invalid expires_in_days
components:
  securitySchemes:
    ApiToken:
      type: apiKey
      in: header
      name: X-Auth-Token
      description: API token generated at Settings > API
    SessionCookie:
      type: apiKey
      in: cookie
      name: _spitshake_session
      description: Session cookie (automatic when logged in)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.