contract_id.GET /contracts/{id} until contract.status becomes signed
(or all parties have signed_at set).signed_download.php?token=....
Recipients open a tokenized URL:
https://firmato.eu/sign/public/sign.php?token=...
The signing UI enforces OTP and (if configured) handwritten signature capture, storing events and evidence in the existing DB tables.
Once fully signed, the platform generates a stamped PDF (with report/audit trail) via:
https://firmato.eu/sign/public/signed_download.php?token=...
This endpoint returns HTTP 403 if the document is not fully signed yet.