---
title: "E-Signature"
canonical: "https://support.appfire.com/space/CDML/649757622/E-Signature"
format: markdown
---
> Macro (aura-html)


## Overview

Each individual approval in the workflow can be configured to require [reviewer identity authentication](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649890845).

This adds a [credentials prompt](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649595003) for a reviewer to the workflow state dialog box.

![image](media://30103bfb-a698-42d0-8b11-d913d4b136fb)

[Global administrators can choose the authentication method](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650347320) to be used for the approvals in the workflow.

The required credentials for authentication can be configured to be one of the following:

- <span style="color: #172b4d">Confluence username and password</span>
- time-based signing token

## <span style="color: #172b4d">Confluence username and password</span>

<span style="color: #172b4d">E-signature for an approval can be set by global admin to require a reviewer to authenticate their identity by entering their Confluence username and password.</span>

<span style="color: #172b4d">The approval decision buttons are disabled until the reviewer adds the requested credentials to the workflow popup.</span>

<span style="color: #172b4d">This can be:</span>

- <span style="color: #172b4d">the Confluence password for each user approval decision</span>

![image](media://4ab131d9-00c4-409f-ba32-b366c6f6af0e)

- <span style="color: #172b4d">the Confluence username and a password for each user approval decision</span>

![image](media://5a3c3923-264f-4a1a-8bd9-5d1fc93b1fb7)

Entering the credentials will activate the **Approve** and **Reject** decision buttons. The credentials are validated when the reviewer makes their approval decision.

## Signing token

Global administration can set an e-signature for an approval to require a reviewer to <span style="color: #172b4d">[authenticate their identity by entering their Confluence username and a time-based signing token](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889506)</span>.

<span style="color: #172b4d">The signing token is a time-based one-time password generated by a third-party app. The user must set up the app for the instance.</span>

<span style="color: #172b4d">The approval decision buttons are inactive until the reviewer adds the requested credentials to the workflow state dialog box. This can be:</span>

- <span style="color: #172b4d">the time-based token for each user approval decision</span>

![image](media://e24b7903-42a3-47da-874c-b07023c12eac)

- <span style="color: #172b4d">The Confluence username and the time-based token for each user approval decision</span>

![image](media://365fd34c-e709-44f3-88df-8b8b00dc392d)

Entering the username and token will activate the **Approve** and **Reject** decision buttons. The credentials are validated when the reviewer makes their approval decision.

Each reviewer needs to [set up their own personal code for the instance](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649760336) using their Confluence login email address. The code is then used to set up a [third-party app ](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649693211)to generate the signing token for each review.

## Setting up a signing token

The workflow state dialog box for the approval displays a prompt to set up a personal code for a user if:

- The approval requires reviewer authentication, ***AND***
- The global e-signature configuration is set to require the use of a signing token

![image](media://95fab8bd-cf90-4a6c-9351-dd760372eb2a)

If the user has already set up a personal code, the workflow state dialog box only displaysdialog box the credentials prompt for the username and a signing token.

To be able to electronically sign using a signing token, a reviewer needs:

- <span style="color: #172b4d">A device with a </span><span style="color: #172b4d">[2 Factor Authentication (2FA) app](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649693211)</span><span style="color: #172b4d"> such as </span><span style="color: #172b4d">[Authy](https://play.google.com/store/apps/details?id=com.authy.authy&hl=en_GB)</span><span style="color: #172b4d">, </span><span style="color: #172b4d">[Google Authenticator](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en_GB)</span><span style="color: #172b4d">, or </span><span style="color: #172b4d">[1Password](https://play.google.com/store/apps/details?id=com.agilebits.onepassword&hl=en_GB)</span>
- <span style="color: #172b4d">The username that they use to log in to Confluence.</span>

<span style="color: #172b4d">The user can then set up an account on the app to generate a time-based signing token. </span>The authentication app requires the signing token each time the user needs to approves a page that requires an e-signature.

![image](media://e60d6149-0859-49b7-b20f-2676170c843d)

Once a user sets up the code with the third-party app, the workflow dialog box prompts for a signing token generated by the app to initialize the app to the user and the instance:

- Adding the token makes the approval decision buttons active
- The token is validated when the user makes the approval decision

The authenticator app generates a new, valid numeric signing token every 30 seconds. If the user navigates away from the content without undertaking the approval, the next time they view the content, a new time-based signing token is required to activate the approval buttons.

## Global administrator user token reset

<span style="color: #172b4d">Global administrators can reset existing valid setup codes for a user by choosing to </span><span style="color: #172b4d">**Remove**</span><span style="color: #172b4d"> the user signing token in the </span><span style="color: #172b4d">[Comala Document Management e-signatures configuration screen](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650347320)</span>

Global admins can also amend the signing token setup expiry date for a user’s signing token.

If the expiry date for the user signing token expires or the global administrator removes it, the user needs to reset their personal code for the instance using the third-party authentication app. 

## Related pages

- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649890845](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649890845)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649693211](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649693211)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649760336](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649760336)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889506](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889506)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/650347320](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650347320)