Void Signature Envelope
signature_void_envelopeVoidSignatureEnvelope voids an envelope (owner-gated, ownership checked like SignAsCompany): writes a terminal DOCUMENT_VOIDED status + voided_at and appends a hash-chained document_voided event. Voiding a completed (executed) envelope requires a reason. Voided envelopes are excluded from the pipeline Signed derivation, so the investor reverts to Committed and can be re-sent. Exposed as the counterpart to opening an envelope: a caller that can send one should be able to cancel one. The destructive case is guarded in the domain rather than by obscurity — ownership is checked, the row is never deleted, and voiding an executed envelope requires a reason. The destructive annotation is what makes a client confirm before calling it. One consequence of exposing it: ip_address, user_agent and geo_location on VoidSignatureEnvelopeRequest are caller-supplied and land verbatim in the hash-chained document_voided event. The chain stays tamper-evident, but on a rescission of an executed agreement those three fields are now written by whatever an MCP client sends rather than by a browser route reading the real request. Server-deriving them at the handler would fix it; not done here.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| reason | No | ||
| ipAddress | No | ||
| userAgent | No | ||
| envelopeId | No | ||
| geoLocation | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| status | No |