ESIGN Consent Disclosure
Under the ESIGN Act section 101(c), consumers must consent to receiving records electronically before an electronic signature can be captured. SpitShake collects that consent from every signer, in one of two styles chosen per template:
Either way consent is recorded server-side before the signature is accepted — the submit endpoint refuses a signature without it. For B2B transactions the consent step can be removed entirely (see Disabling for B2B templates).
Inline became the default on 2026-09-23. Templates that never chose a style switched from the pop-up to the consent line; set
"esign_disclosure_style": "modal" to keep the pop-up.How it works
- A signer opens their signing link (
/s/:slug). - Inline: they go straight to the form (or the quick-sign carousel). The consent line sits under the final button, linking to the full disclosure — paper alternative, withdrawal rights, hardware requirements, what the consent covers. Modal: they see that disclosure first and click I Agree & Continue.
- When the signer clicks the final button (inline) or I Agree & Continue (modal), consent is recorded in the submitter’s encrypted metadata: timestamp, IP address, user agent,
esign_disclosure_style, and — for inline —esign_disclosure_consent_text, the exact sentence shown under the button. That sentence is composed by the server from the template, never taken from the browser. - An immutable audit entry of type
esign_disclosure.acceptedis written, carrying the style and (inline) the sentence. - Only then is the signature submitted.
Configuration
Template preferences
The consent modal is controlled by thesetemplate.preferences keys:
Customizing the modal copy
Override the title, body, or button text via the API:\n\n for paragraph breaks (rendered with whitespace-pre-line). When a custom body is set, it replaces the default federally-compliant copy entirely. The “Full disclosure” link to /legal/esignature-disclosure is always shown regardless of custom body.
Disabling for B2B templates
For pure B2B transactions where both parties are businesses (not consumers), the ESIGN section 101(c) consumer consent requirement does not apply. You can disable the modal:esign_disclosure_bypass_acknowledged: true alongside esign_disclosure_enabled: false — setting the disable flag alone without the acknowledgment has no effect (the modal still shows).
When the modal is disabled:
- The signer lands directly on the start screen or first field.
- The server auto-stamps acceptance metadata with
esign_disclosure_bypassed_by_template: trueandesign_disclosure_bypass_reason: "template_preference". - An immutable audit entry of type
esign_disclosure.bypassed_by_templateis written.
Re-enabling
Setesign_disclosure_enabled back to true (or remove it from preferences):
Builder UI
The consent modal can also be configured in the template Builder:- Open a template in the Builder (
/templates/:id/edit). - Open the template settings panel.
- Find the Electronic Signature Disclosure section.
- Toggle Show ESIGN consumer consent disclosure to enable or disable.
- When enabled: choose How signers give consent — A line under the sign button (default) or A pop-up before the document opens — and fill in optional custom title, body, and agree button text.
- When disabled: an amber warning appears with a B2B acknowledgment checkbox that must be checked.
- Changes auto-save after 3 seconds.
Audit trail
ESIGN consent events are recorded in the immutable audit trail:
Audit entry example (inline consent, the default):
metadata is { "style": "modal", "disclosure_title": "…" }.
Submitter metadata after acceptance (inline):
Submission gate
The consent disclosure is enforced as a server-side gate. If a signer attempts to submit (POST /s/:slug/submit) without prior acceptance, the server returns:
The consent disclosure applies to all submitters on the template. If you need different consent behavior per role, create separate templates for each role.

