embed
Put document filling inside your product.
Not every customer should leave your app to fill a form. Embed a Mezdoc form with one iframe. It loads only on the domains you allow, and when the user is done your page gets a message with the submission id and a link to the PDF.
Fill the embed. Watch your app get the result.
// waiting for the user to submitA simulation in your browser. Nothing you type leaves this page.
Three steps to go live.
- step 1
Create an embed link
Pick a template, set the link to embed, and list the sites allowed to show it. Email code, expiry and uses work the same as a hosted link.
- step 2
Paste the iframe
Drop the tag where the form belongs in your page. You choose the width and height.
Embed the form<iframe src="https://app.mezdoc.com/embed/t/7Hq2xVb9Lw..." width="100%" height="800" style="border:0" ></iframe> - step 3
Listen for the result
Check the origin, then read the message. Keep the submissionId: your server can fetch the PDF again any time.
Listen for messageswindow.addEventListener("message", (event) => { if (event.origin !== "https://app.mezdoc.com") return; const msg = event.data; if (msg.type === "completed") { // msg.submissionId, msg.url (valid for an hour) saveCertificate(msg.submissionId, msg.url); } if (msg.type === "error") showError(msg.message); });Later: fetch the PDF from your servercurl https://api.mezdoc.com/api/v1/submissions/sub_8Kq2mR4tVx/pdf \ -H "Authorization: Bearer sk_live_..." -o certificate.pdf
What the embed supports.
- Only on your domainsEach embed link lists the sites allowed to show it. Browsers refuse to show the form anywhere else, and a link with no list is shown nowhere.
- Three messages to your page
processingwhen the user submits, thencompletedwith thesubmissionIdand aurlthat works for an hour, orerrorwith a message. - An email code, if you want oneThe form asks for a 6-digit code sent to the user before it opens, right inside your page.
- The same link settingsExpiry, a limit on uses, revoking at any time, and following the live template version or a pinned one.
- Fields, checks and signaturesMezdoc renders the fields, checks each answer before submit, and takes a drawn, typed or uploaded signature.
- Your server hears it tooA signed
submission.completedwebhook reaches your backend as well, retried with backoff if your server is down.
Questions about embedding.
- How does my app know the user finished?
The embed posts a message to your page. Listen for message events and check that event.origin is the Mezdoc app. A processing message arrives when the user submits, then completed with the submissionId and a download url, or error with a message.
- Can I control which sites are allowed to embed?
Yes. Each embed link carries a list of allowed origins. The form only renders inside a site on that list, so your link cannot be embedded on a site you do not control.
- What will my users see?
A clean form with your template's fields. It carries the Mezdoc logo and "Powered by Mezdoc", and sits in your page at the width and height you give the iframe.
- How long does the download link work?
The url in the completed message is signed and works for an hour. Keep the submissionId and your server can fetch the PDF again at any time through the API.
- Is it the same template as the API and the web form?
Yes. One template, one data model. Whether the data arrives by API, a hosted link or an embed, you get the same PDF.
Embed your first form.
Free plan, no card