All notable changes to this project will be documented in this file.

[0.9.0] - 2026-07-13

Added

  • Boldsign.TextTag — typed builders for BoldSign text-tag form-field definitions: signature/2, initial/2, date_signed/2, text_box/2, checkbox/2, plus build/3 as an escape hatch for any field type. Callers get the correct BoldSign type strings ("Signature", "DateSigned", ...) and sensible default sizes instead of hand-writing the textTagDefinitions payload. Place a {{definition_id}} placeholder in the document, pass the built definitions as textTagDefinitions with useTextTags: true, and BoldSign replaces the placeholder with the typed field.

[0.8.1] - 2026-07-03

Fixed

  • Boldsign.WebhookPlug now acknowledges BoldSign's endpoint-verification ping (X-BoldSign-Event: Verification) with 200 OK before signature validation. The ping is sent before any webhook signing secret exists, so it can never carry a valid signature; previously the plug rejected it with 401 and BoldSign's dashboard "Verify" button always failed.

[0.8.0] - 2026-06-30

Changed

  • Bumped the package version to 0.8.0.
  • Replaced Bypass-backed tests with a small Bandit-backed local test server.
  • Multipart uploads now use raw request bodies to avoid creating atoms from dynamic BoldSign form field names.

Fixed

  • Empty multipart list fields now encode as "[]" instead of being omitted.
  • Multipart field names and filenames now percent-escape ", CR, and LF in content disposition headers.
  • Webhook signature parsing now handles BoldSign headers with a space after the comma, such as t=TIMESTAMP, s0=SIGNATURE.

Tests

  • Added regression coverage for empty list multipart encoding, raw multipart request encoding, multipart content disposition escaping, and spaced webhook signature headers.

[0.7.0] - 2026-06-28

Added

Changed

  • Bumped the package version to 0.7.0.
  • Refreshed the README and LiveBook embedded signing example for the current API surface, current regional endpoints, API-key or OAuth auth, and hosted-PDF usage.
  • Expanded request handling so document and template operations can automatically switch between JSON and multipart payloads where the official BoldSign API allows file uploads.
  • Updated the default regional base URLs to match the current official BoldSign endpoints, including CA and AU regions.

Fixed

  • Added compatibility with req 0.6 by converting multipart form-part names to atoms at the request boundary while preserving the exact BoldSign wire field names.
  • Corrected several HTTP verb and query-parameter mismatches in existing document, template, team, user, and identity verification wrappers.
  • Aligned identity verification requests with the current official API contract.

Tests

  • Added extensive local HTTP server coverage across client auth, documents, templates, contacts, contact groups, custom fields, users, teams, identity verification, plan APIs, and multipart encoding.
  • Added multipart regression coverage for Req-compatible atom part names, including bracketed/dotted BoldSign field names.

[0.5.2] - 2026-04-12

Fixed

  • Send document requests now stay on JSON by default and only switch to multipart when files are actually present.
  • Multipart form encoding now follows the official BoldSign SDK pattern for file uploads plus JSON-encoded complex fields such as signers and textTagDefinitions.

[0.5.0] - 2026-04-10

Added