Open a request link (recipient view)
get
https://api.expiryedge.com/v1/getCollectionRequestPublicPublic - no API key60/min
Request
curl 'https://api.expiryedge.com/v1/getCollectionRequestPublic?token=3f9a1c7e5b2d4f6a8c0e1b3d5f7a9c2e4b6d8f0a1c3e5b7d9f2a4c6e8b0d1f3a'Response
{
"request": {
"status": "viewed",
"expires_at": "2026-10-31T23:59:59.000Z",
"recipient_name": "Dana Whitfield",
"expiry_linked": true
},
"review": null,
"template": {
"name": "New client onboarding - Northwind Dental",
"description": "Documents we need before the first engagement.",
"pages": [
{
"id": "p_company",
"title": "Company details",
"order": 0,
"description_html": "<p>Tell us about your practice.</p>",
"sections": [
{
"id": "s_basics",
"title": "Basics",
"order": 0,
"description_html": "",
"fields": [
{
"id": "fld_company_name",
"type": "short_text",
"label": "Legal company name",
"required": true,
"help_text": ""
},
{
"id": "fld_entity",
"type": "dropdown",
"label": "Entity type",
"required": true,
"help_text": "",
"options": [
"LLC",
"Corporation",
"Sole proprietor"
]
},
{
"id": "fld_insurance",
"type": "file_upload",
"label": "Liability insurance certificate",
"required": true,
"help_text": "PDF or image, current policy year.",
"allowed_types": [
"pdf",
"jpg",
"png"
],
"max_size_bytes": 26214400,
"reference_file": {
"original_filename": "sample-certificate.pdf",
"content_type": "application/pdf",
"size_bytes": 120331
}
}
]
}
]
}
]
},
"organization": {
"name": "Contoso Legal",
"logo_url": null
},
"draft": {
"responses": {
"fld_company_name": "Northwind Dental LLC"
},
"files": {},
"last_page_id": "p_company"
}
}Returns what the fill page needs and marks a pending request viewed. review is set when the sender requested changes (only the rejected fields need answers). The handler does not check the HTTP method; token may also be sent in a JSON body.
tokenstringrequiredThe 64-character hex token from the request link (/collect/{token}).pattern: ^[a-f0-9]{64}$passwordstringDeprecatedLegacy: request password in the query string (ends up in logs). Use theX-Collection-Passwordheader instead.
X-Collection-PasswordstringRequest password, when the sender set one. Preferred over thepasswordbody field / query parameter.
200
Recipient view.
requestobjectrequiredtemplateobjectrequiredTemplate without its id. Reference files omitstorage_path; fetch them with getCollectionTemplateReferenceFile.organizationobjectrequireddraftobjectrequiredAutosaved progress (empty objects when none).reviewobject | nullSet when the sender requested changes; only fields rejected infield_reviewsneed new answers.
400 | Malformed token ( Invalid link) or invalid input. |
401 | The request has a password and it is missing ( {"requiresPassword": true}) or wrong. |
403 | The sender paused this request. |
404 | Unknown token (link rotated, deleted or mistyped), or the template no longer exists. |
410 | The request was cancelled, already completed ( alreadySubmitted: true) or has expired. |
429 | Password locked out after 5 wrong attempts (15 minutes, per request). |
500 | Unexpected server error. |
