An MCP server
Connect Claude, ChatGPT (developer mode) or Cursor to https://seal.nightroll.app/mcp and sign in with OAuth. Agents search envelopes, read document text, suggest fields, draft envelopes and request sends: 14 tools.
Beta Invite-only for now. Try it without an account.
Send documents for signature from the web app, the REST API, or an MCP client such as Claude, ChatGPT or Cursor. Agents draft and ask; nothing goes out until a person approves it with a passkey. Signers need no account, and every finished document is sealed with a timestamped signature anyone can check.
A private sample workspace for 24 hours: nothing is emailed. Have an invite? Sign up. Or read the docs.
Claude asks to send
“Mutual NDA, Acme and Northwind”
A PDF, or a photo or scan that Seal turns into one. Seal suggests fields from form widgets and from labels like “Signature” and “Date”.
Add signers, approvers, viewers, cc and in-person signers, in order, in parallel or both. Place signatures, initials, dates, text, checkboxes, choices, attachments and formulas, with rules and conditions.
Each recipient gets an email link, plus an emailed code if you ask for one. No account and no app, on any phone or computer.
Recipients agree to sign electronically, read the documents, fill in their fields and sign by drawing, typing or uploading. Or decline, with a reason.
When the last person finishes, Seal flattens the fields, seals the PDF with a timestamped certification signature and emails everyone a copy and a certificate of completion.
Connect Claude, ChatGPT (developer mode) or Cursor to https://seal.nightroll.app/mcp and sign in with OAuth. Agents search envelopes, read document text, suggest fields, draft envelopes and request sends: 14 tools.
A request returns an approval link. You see exactly what will happen and approve with Face ID, Touch ID or a security key. The approval is bound to that draft: any edit cancels it. It works once and expires after 30 minutes.
No agent gets a sign tool or an approve tool. Signing happens only in the signer’s own browser, and approving needs a person’s passkey.
The assistant summarizes documents, lists key terms with page and quote citations, suggests fields and drafts reminders. Your Anthropic, OpenAI or OpenRouter key stays encrypted in your browser. Seal’s server never sees it and never calls a model.
Seal compares what each page shows with the text it contains and flags hidden text to senders and signers. It strips control and bidi characters, marks document text as untrusted data for agents, and never fetches links found in documents.
Each capability is defined once and becomes a REST endpoint (OpenAPI 3.1), an MCP tool, a CLI command and an assistant tool, with the same permissions and limits. llms.txt describes it for models.
Every completed PDF carries a certification signature from Seal’s document-sealing certificate and an RFC 3161 timestamp from a public timestamp authority. Acrobat shows it as signed and unmodified.
Document hashes before and after sealing; each recipient’s authentication, consent time, IP address and browser; the hash-chained audit trail; and which agent asked, through which tool, and who approved how.
Every send, signature and decline is stored in object storage before Seal confirms it. If the server stops mid-request, a signature it confirmed is never lost.
Verify checks a sealed PDF in your browser without uploading it. Evidence sits in write-once storage: 1 year on Free, 7 years on Workspace.
Beta: paid plans aren’t on sale yet and nothing is billed. An invite code gives your workspace the Workspace plan free while the beta lasts.
$0
$12 a month
What counts as an envelope: one send to up to 10 recipients and up to 10 MB of documents. Each further started block of 10 recipients or 10 MB counts as one more. Envelopes count when they are sent, never at completion; drafts, agent drafts and test envelopes never count. Signers never pay.
No. Signers open the emailed link on any phone or computer, agree to sign electronically and sign. They never need an account and never pay.
In the US, the ESIGN Act and UETA give electronic signatures the same effect as handwritten ones for most documents; a few kinds, such as wills, still need paper. In the EU, Seal’s signatures are simple electronic signatures under eIDAS, which can’t be refused as evidence just for being electronic. Seal doesn’t offer qualified signatures. This is not legal advice.
Agents can draft envelopes and ask to send, void or correct them. A person approves each request with a passkey. No tool can sign: only the signer can, in their own browser. A workspace admin can let one specific agent key send without approval up to a daily cap; signing still needs the signers.
Open it on the verify page (checked in your browser, nothing uploaded) or in Adobe Acrobat, which shows it as signed and unmodified. Acrobat warns that it doesn’t know Seal’s certificate; add the root certificate from /pki to trust it.
Documents and evidence are stored in Cloudflare R2, through short-lived links signed by Seal. The service runs on Cloudflare Workers with Durable Objects, whose databases can be restored to any minute of the last 30 days; an encrypted export is also made every night.
Seal works end to end, but it is new and run by a small team. Expect rough edges and the occasional maintenance window, and expect limits and features to change. Evidence of envelopes you send stays for its full retention term.
Beta codes can carry an end date. When it passes, the workspace moves to the Free plan. Nothing is charged automatically, and your documents and evidence stay.
Yes. The web app and the REST API cover everything: uploads, templates, fields, sending, reminders, voids, embedded signing and sending, bulk send and webhooks. Personal API keys can send directly.
Open a sample workspace for 24 hours. No account, and nothing is emailed.