---
title: "E-signatures (credentials)"
canonical: "https://support.appfire.com/space/CDMC/2192903044/E-signatures%20(credentials)"
format: markdown
---
> Macro (aura-html)

## Overview

In a workflow, you can require your reviewers to provide an electronic signature when approving or rejecting a document. This adds an extra layer of identity verification using a one-time signing token generated by an authenticator app. An e-signature can be enabled separately for each approval.

E-signatures are commonly used in regulated environments where document approvals require verified identity, for example, quality management systems, legal reviews, or compliance-driven content workflows.

## Enable e-signature for approval

To require e-signature authentication for an approval, set the **Authentication Method** to **E-signature** under *General Settings* in the approval configuration.

![Approval configuration showing the Authentication Method field set to E-signature.](media://d38d5f7c-8687-454a-a5ee-0e7c14436c14)

See [Approvals](https://appfire.atlassian.net/wiki/spaces/CDMC/pages/2193195490) for detailed steps on configuring an approval.

## Set up a signing token

Reviewers must set up a signing token the first time they encounter an approval that requires e-signature authentication.

**Prerequisites:**

Download and install a two-factor authentication (2FA) app on your smart device. Supported apps include:

- [Authy](https://play.google.com/store/apps/details?id=com.authy.authy)
- [Google Authenticator](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2)
- [1Password](https://play.google.com/store/apps/details?id=com.agilebits.onepassword)
- [Microsoft Authenticator](https://apps.apple.com/gb/app/microsoft-authenticator/id983156458)

This token is specific to Comala Document Management approvals and is separate from any 2FA token used for Confluence login.

**To set up your signing token,**

1. In the *Workflow State* dialog, click **Configure your e-signature**.
2. A validation email is sent to your address. The link in the email is valid for 15 minutes.
3. Open the email and click **Go to approval signing token settings**.
  
4. A QR code is displayed. Scan it with your authenticator app to create an authentication account linked to your email and Confluence instance. A manual setup key is provided if you can't scan the QR code. The QR code is valid for 30 minutes.
5. Enter the 6-digit signing token from your authenticator app.

## Sign a document with an e-signature

Once your signing token is set up, you can use it to approve or reject documents that require e-signature authentication.

1. Open the *Workflow State Dialog* on your Confluence page.
2. Enter the** OTP token** from your authenticator app. The token renews every 30 seconds.
3. Click **Approve **or** Reject**.


> ℹ️ Each reviewer must use their own signing token. Navigating away from the dialog may require entering a new token.

## Token administration

Global administrators can manage signing tokens for all reviewers in the instance from the *E-Signatures* tab under global settings.

![Global E-Signatures settings page showing reviewer signing tokens.](media://352e6c6e-3ac4-4009-b09a-9f7504aca82e)

Administrators can:

- View all set up tokens and their expiry dates.
- Remove a signing token, requiring the reviewer to re-authenticate.
- Set an expiry date for each token.

> ℹ️ - The e-signature feature doesn't work if your site uses single sign-on (SSO) through Atlassian Access.
> ℹ️ - Email addresses and signing tokens are sent securely through the Comala server and aren't stored.

### **Related topics**

- [Approvals](https://appfire.atlassian.net/wiki/spaces/CDMC/pages/2193195490)
- [Workflow state dialog](https://appfire.atlassian.net/wiki/spaces/CDMC/pages/2193129918)