{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "dropbox-sign",
    "name": "Dropbox Sign",
    "vendor": "Dropbox, Inc.",
    "vendorUrl": "https://sign.dropbox.com",
    "kind": "http-api",
    "category": "e-signatures",
    "summary": "Dropbox Sign (formerly HelloSign) is Dropbox's e-signature service. Its REST API sends documents or templates for signature, embeds signing in an iframe, reports status by webhook and returns signed PDFs with an audit trail.",
    "url": "https://www.anchorterminal.com/tools/dropbox-sign",
    "markdownUrl": "https://www.anchorterminal.com/tools/dropbox-sign.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dropbox-sign.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json",
    "repo": "https://github.com/hellosign/hellosign-openapi",
    "license": "Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.hellosign.com/v3",
    "packages": [
      {
        "registry": "npm",
        "name": "@dropbox/sign"
      },
      {
        "registry": "pypi",
        "name": "dropbox-sign"
      }
    ],
    "auth": "mixed",
    "authNotes": "A self-serve API key from the account's API settings page, sent as the HTTP Basic username with an empty password. Each account can hold up to four keys for rotation, and every key has full access to the account. OAuth 2.0 access tokens (Bearer) act on behalf of other users with seven scopes across two billing models, and OAuth apps need approval by Dropbox Sign support before production. Embedded apps can be self-published in the web app.",
    "pricing": "paid",
    "pricingNotes": "Production signature requests need a paid API plan, and the API answers 402 without one. Essentials is $900 a year ($75 a month) from 50 requests a month, Standard $3,000 a year ($250 a month) from 100, and Premium is quoted by sales. Test mode is free on every endpoint from a free account, so an agent can build and test without a contract (checked 2026-10-07).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 22,
      "npmWeekly": 149738,
      "pypiWeekly": null,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://developers.hellosign.com",
    "llmsTxt": "https://developers.hellosign.com/llms.txt",
    "openapi": "https://raw.githubusercontent.com/hellosign/hellosign-openapi/main/openapi.yaml",
    "capabilities": [
      "esign.send",
      "esign.templates",
      "esign.embed",
      "esign.status"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "api-key",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "sandbox",
      "python",
      "typescript",
      "java",
      "php",
      "ruby",
      "dotnet",
      "status-page",
      "bug-bounty",
      "soc2"
    ],
    "lastRelease": "2026-09-10",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.9,
      "grade": "B",
      "agentReady": false,
      "rank": 161,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 85,
        "payments": 25,
        "reliability": 75,
        "schema": 88,
        "security": 65,
        "transparency": 68
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 75,
          "points": 15,
          "reason": "Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. status.hellosign.com on Statuspage lists 13 components in four groups with incident history (20). Two incidents in the 90 days to 7 October 2026, both marked minor, a Salesforce integration fault on 21 August (6 h 43 min) and file upload problems on 31 August (54 min). The last major incident was an outage on 2 January 2026 (3 h 12 min), outside the window (20 of 30). Rate limits with numbers, 100 requests a minute standard, 25 on 17 higher-tier endpoints and 10 in test mode, although the header table describes the limit as hourly (15). The docs describe 429 with `X-Ratelimit` headers, tell clients to respect Retry-After and back off, and the error catalogue marks each error retryable or not. No idempotency keys or safe-retry guidance for sends were found (10 of 15). The terms supply the service as is and as available, and no SLA was found (0). The API is at v3 and generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 88,
          "points": 14.3,
          "reason": "One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SDKs (25). llms.txt at developers.hellosign.com, a Markdown copy of each page by appending .md, and scoped llms-full.txt files by section and language (10). Operation descriptions average about 220 characters and several state consequences, such as cancel being irreversible and asynchronous. A glossary written for models covers core objects, signers, fields and workflows. Few descriptions say when not to use an endpoint (14 of 20). 67 enums, 239 required lists and about 80 length or range constraints. Sends are multipart forms with indexed keys, and `metadata` and `custom_fields` are loosely typed (11 of 15). Request and response examples with SDK samples in six languages, and a catalogue of 20 HTTP error names with cause, remediation and a retryable flag, embedded in the spec as `x-error-codes` (15). The path carries v3 and a dated changelog has 48 entries since November 2022. No written API versioning policy was found beyond the SDK one (13 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks stay small. No field selection was found (15 of 25). Page-number pagination with totals in `list_info`, and a `query` search language over title, signer, sender, dates, completion state and metadata. The docs warn of a short indexing delay after creation (18 of 20). Errors carry `error_name` and `error_msg`, with 20 documented names, a remediation line each and a retryable flag, plus warnings in successful responses (20). No idempotency keys in the docs or spec, so a retried send can create a duplicate. Cancel returns 200 when queued and confirms by event. The retryable flags are the only safe-retry aid (4 of 20). A template send needs only `template_ids` and `signers`, `test_mode` is a single flag, and official SDKs cover six languages (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 65,
          "points": 11.38,
          "reason": "API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. OAuth 2.0 tokens carry seven scopes but serve apps acting for other users and need support approval. Scored between plain revocable keys and scoped OAuth (25), less 5 because the docs show the key inside the URL as `https://KEY:@api.hellosign.com`, a judgement call since that is URL userinfo, not a query string (20 of 30). The limited OAuth scopes and test mode narrow what a call can do, but there is no read-only key and no confirmation step on cancel, remove or template delete (9 of 20). Responses can carry signer-entered field values and decline reasons, and no injection guidance was found (5 of 15). The API Dashboard records the account's API requests, responses and callbacks, live and test, and each completed document carries an audit trail with timestamps, IP addresses and a SHA-256 hash (13 of 15). SOC 2 Type II, ISO 27001 and ISO 27018 at trust.dropbox.com, a bug bounty and disclosure programme on Intigriti, and webhook HMAC verification. No standard security.txt on the Sign hosts (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, Essentials at $900 a year from 50 requests a month and Standard at $3,000 a year from 100, with larger volumes on a selector and Premium by quote. That is plan pricing, not a per-request price (10 of 20). Test mode is free on every endpoint from a free account, but its requests aren't legally binding, and the pages we read don't say whether signup needs a card (15 of 20). A person has to create the account and copy the key from the web app, and production needs a paid plan (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 85,
          "points": 7.44,
          "reason": "SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, among them a new Document Field Detection endpoint (30). Dated changelog entries on 31 July, 19 August and 3 September 2026, plus SDK 1.12.0 and 1.13.0 on 10 September (20). A closed service with a public changelog, an API support address (apisupport@hellosign.com), a help centre and public GitHub issues, nine open on the spec repository. We didn't test response times (11 of 15). Current official SDKs for Python, Node, PHP, Java, Ruby and .NET, all pushed in September 2026 (15). CI in the spec repository builds the spec and each SDK and fails on uncommitted generated code, and Node dependencies were upgraded on 6 October (9 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "note": "editorial 51, provenance 85",
          "reason": "The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). The terms let Dropbox delete customer data any time after 30 days from termination. The data processing agreement, dated 25 October 2021, promises deletion within a commercially reasonable period on request and still points to a hellosign.com sub-processor address. The privacy policy of 14 January 2025 gives no retention period. The documents agree but stay vague (18 of 30). Prior SDK major versions are patched for 12 months and the API returns a `deprecated_parameter` warning, but no API deprecation policy with notice periods was found (8 of 20). The privacy policy links a Sign sub-processor list and the agreement promises advance notice of new sub-processors with a 60-day objection window. The list itself returned only its title to our reader, so names and locations are unconfirmed. Data residency is a Premium option (10 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks stay small. No field selection was found (15 of 25). Page-number pagination with totals in `list_info`, and a `query` search language over title, signer, sender, dates, completion state and metadata. The docs warn of a short indexing delay after creation (18 of 20). Errors carry `error_name` and `error_msg`, with 20 documented names, a remediation line each and a retryable flag, plus warnings in successful responses (20). No idempotency keys in the docs or spec, so a retried send can create a duplicate. Cancel returns 200 when queued and confirms by event. The retryable flags are the only safe-retry aid (4 of 20). A template send needs only `template_ids` and `signers`, `test_mode` is a single flag, and official SDKs cover six languages (15).",
          "maintenance": "SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, among them a new Document Field Detection endpoint (30). Dated changelog entries on 31 July, 19 August and 3 September 2026, plus SDK 1.12.0 and 1.13.0 on 10 September (20). A closed service with a public changelog, an API support address (apisupport@hellosign.com), a help centre and public GitHub issues, nine open on the spec repository. We didn't test response times (11 of 15). Current official SDKs for Python, Node, PHP, Java, Ruby and .NET, all pushed in September 2026 (15). CI in the spec repository builds the spec and each SDK and fails on uncommitted generated code, and Node dependencies were upgraded on 6 October (9 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, Essentials at $900 a year from 50 requests a month and Standard at $3,000 a year from 100, with larger volumes on a selector and Premium by quote. That is plan pricing, not a per-request price (10 of 20). Test mode is free on every endpoint from a free account, but its requests aren't legally binding, and the pages we read don't say whether signup needs a card (15 of 20). A person has to create the account and copy the key from the web app, and production needs a paid plan (0).",
          "reliability": "Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. status.hellosign.com on Statuspage lists 13 components in four groups with incident history (20). Two incidents in the 90 days to 7 October 2026, both marked minor, a Salesforce integration fault on 21 August (6 h 43 min) and file upload problems on 31 August (54 min). The last major incident was an outage on 2 January 2026 (3 h 12 min), outside the window (20 of 30). Rate limits with numbers, 100 requests a minute standard, 25 on 17 higher-tier endpoints and 10 in test mode, although the header table describes the limit as hourly (15). The docs describe 429 with `X-Ratelimit` headers, tell clients to respect Retry-After and back off, and the error catalogue marks each error retryable or not. No idempotency keys or safe-retry guidance for sends were found (10 of 15). The terms supply the service as is and as available, and no SLA was found (0). The API is at v3 and generally available (10).",
          "schema": "One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SDKs (25). llms.txt at developers.hellosign.com, a Markdown copy of each page by appending .md, and scoped llms-full.txt files by section and language (10). Operation descriptions average about 220 characters and several state consequences, such as cancel being irreversible and asynchronous. A glossary written for models covers core objects, signers, fields and workflows. Few descriptions say when not to use an endpoint (14 of 20). 67 enums, 239 required lists and about 80 length or range constraints. Sends are multipart forms with indexed keys, and `metadata` and `custom_fields` are loosely typed (11 of 15). Request and response examples with SDK samples in six languages, and a catalogue of 20 HTTP error names with cause, remediation and a retryable flag, embedded in the spec as `x-error-codes` (15). The path carries v3 and a dated changelog has 48 entries since November 2022. No written API versioning policy was found beyond the SDK one (13 of 15).",
          "security": "API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. OAuth 2.0 tokens carry seven scopes but serve apps acting for other users and need support approval. Scored between plain revocable keys and scoped OAuth (25), less 5 because the docs show the key inside the URL as `https://KEY:@api.hellosign.com`, a judgement call since that is URL userinfo, not a query string (20 of 30). The limited OAuth scopes and test mode narrow what a call can do, but there is no read-only key and no confirmation step on cancel, remove or template delete (9 of 20). Responses can carry signer-entered field values and decline reasons, and no injection guidance was found (5 of 15). The API Dashboard records the account's API requests, responses and callbacks, live and test, and each completed document carries an audit trail with timestamps, IP addresses and a SHA-256 hash (13 of 15). SOC 2 Type II, ISO 27001 and ISO 27018 at trust.dropbox.com, a bug bounty and disclosure programme on Intigriti, and webhook HMAC verification. No standard security.txt on the Sign hosts (18 of 20).",
          "transparency": "The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). The terms let Dropbox delete customer data any time after 30 days from termination. The data processing agreement, dated 25 October 2021, promises deletion within a commercially reasonable period on request and still points to a hellosign.com sub-processor address. The privacy policy of 14 January 2025 gives no retention period. The documents agree but stay vague (18 of 30). Prior SDK major versions are patched for 12 months and the API returns a `deprecated_parameter` warning, but no API deprecation policy with notice periods was found (8 of 20). The privacy policy links a Sign sub-processor list and the agreement promises advance notice of new sub-processors with a 60-day objection window. The list itself returned only its title to our reader, so names and locations are unconfirmed. Data residency is a Premium option (10 of 20)."
        },
        "sources": [
          {
            "what": "API product page",
            "url": "https://sign.dropbox.com/features/api",
            "seen": "2026-10-07"
          },
          {
            "what": "API pricing",
            "url": "https://sign.dropbox.com/products/dropbox-sign-api/pricing",
            "seen": "2026-10-07"
          },
          {
            "what": "llms.txt and docs index",
            "url": "https://developers.hellosign.com/llms.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "docs overview, test mode, plans by endpoint and rate limits",
            "url": "https://developers.hellosign.com/docs/overview",
            "seen": "2026-10-07"
          },
          {
            "what": "authentication and key rotation",
            "url": "https://developers.hellosign.com/api/api-reference-authentication",
            "seen": "2026-10-07"
          },
          {
            "what": "OAuth overview and scopes",
            "url": "https://developers.hellosign.com/docs/guides/o-auth/overview",
            "seen": "2026-10-07"
          },
          {
            "what": "app approval",
            "url": "https://developers.hellosign.com/docs/guides/app-approval/overview",
            "seen": "2026-10-07"
          },
          {
            "what": "self-publishing API apps",
            "url": "https://developers.hellosign.com/docs/guides/app-approval/self-publish",
            "seen": "2026-10-07"
          },
          {
            "what": "warnings and errors",
            "url": "https://developers.hellosign.com/api/manual-reference-pages/warnings-and-errors",
            "seen": "2026-10-07"
          },
          {
            "what": "events walkthrough, verification and retries",
            "url": "https://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough",
            "seen": "2026-10-07"
          },
          {
            "what": "security and compliance glossary, audit trail and quotas",
            "url": "https://developers.hellosign.com/api/manual-reference-pages/glossary/security-compliance",
            "seen": "2026-10-07"
          },
          {
            "what": "search on list endpoints",
            "url": "https://developers.hellosign.com/api/manual-reference-pages/search",
            "seen": "2026-10-07"
          },
          {
            "what": "API Dashboard guide",
            "url": "https://developers.hellosign.com/docs/guides/api-dashboard",
            "seen": "2026-10-07"
          },
          {
            "what": "SDK overview",
            "url": "https://developers.hellosign.com/docs/sdks/overview",
            "seen": "2026-10-07"
          },
          {
            "what": "SDK versioning policy",
            "url": "https://developers.hellosign.com/docs/sdks/versioning-policy",
            "seen": "2026-10-07"
          },
          {
            "what": "changelog",
            "url": "https://developers.hellosign.com/changelog",
            "seen": "2026-10-07"
          },
          {
            "what": "quickstart",
            "url": "https://developers.hellosign.com/api/api-quickstart",
            "seen": "2026-10-07"
          },
          {
            "what": "docs MCP server (initialize and tools/list)",
            "url": "https://developers.hellosign.com/_mcp/server",
            "seen": "2026-10-07"
          },
          {
            "what": "OpenAPI spec and SDK source repository",
            "url": "https://github.com/hellosign/hellosign-openapi",
            "seen": "2026-10-07"
          },
          {
            "what": "vendor repositories",
            "url": "https://api.github.com/orgs/hellosign/repos?per_page=100\u0026sort=pushed",
            "seen": "2026-10-07"
          },
          {
            "what": "npm package",
            "url": "https://registry.npmjs.org/@dropbox/sign",
            "seen": "2026-10-07"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@dropbox/sign",
            "seen": "2026-10-07"
          },
          {
            "what": "PyPI package",
            "url": "https://pypi.org/pypi/dropbox-sign/json",
            "seen": "2026-10-07"
          },
          {
            "what": "status page summary",
            "url": "https://status.hellosign.com/api/v2/summary.json",
            "seen": "2026-10-07"
          },
          {
            "what": "status incident history",
            "url": "https://status.hellosign.com/api/v2/incidents.json",
            "seen": "2026-10-07"
          },
          {
            "what": "trust page",
            "url": "https://sign.dropbox.com/trust",
            "seen": "2026-10-07"
          },
          {
            "what": "trust centre",
            "url": "https://trust.dropbox.com/?product=dropboxsign",
            "seen": "2026-10-07"
          },
          {
            "what": "terms of service",
            "url": "https://sign.dropbox.com/about/terms",
            "seen": "2026-10-07"
          },
          {
            "what": "privacy policy",
            "url": "https://sign.dropbox.com/about/privacy",
            "seen": "2026-10-07"
          },
          {
            "what": "data processing agreement",
            "url": "https://assets.dropbox.com/documents/en/legal/hs-data-processing-agreement.pdf",
            "seen": "2026-10-07"
          },
          {
            "what": "security.txt on the Sign host (404)",
            "url": "https://sign.dropbox.com/.well-known/security.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "security.txt on dropbox.com",
            "url": "https://www.dropbox.com/.well-known/security.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=dropbox",
            "seen": "2026-10-07"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/hellosign.com",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: the Sign sub-processor list at www.dropbox.com/privacy/subprocessor/sign, which returned only its title to our reader, so names and locations are unconfirmed.",
          "unchecked: PyPI weekly downloads for dropbox-sign. pypistats.org refused us for a rate limit.",
          "unchecked: whether creating a free account for test mode needs a card. The docs and pricing page don't say and we didn't sign up.",
          "unchecked: prices at the 250, 500 and 750+ steps of the pricing selector, and the month-to-month price. The static page showed $75 and $250 a month beside $900 and $3,000 a year.",
          "unchecked: documents in the trust centre beyond the public summary, such as the SOC 2 report and penetration test summary.",
          "The rate-limit docs give per-minute limits, describe `X-Ratelimit-Limit` as hourly and show an example message of 2,000 an hour. Which window applies wasn't established.",
          "The glossary says 429 responses carry Retry-After, while the main rate-limit section lists only the `X-Ratelimit` headers. We didn't trigger a 429 to confirm.",
          "No SLA was found for any plan in the terms or on the pricing page. A Premium contract may include one.",
          "No vendor MCP server for signing was found. The registry entry io.usefulapi/dropbox-sign is third-party and wasn't graded."
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation.",
      "bestFor": "An agent that sends a prepared PDF or a saved template for signature from one company account and tracks it to completion by webhook or polling, with the signed PDF and audit trail at the end.",
      "strengths": [
        "Public OpenAPI 3.0.3 spec with 74 operations, plus llms.txt and a Markdown copy of every docs page",
        "Free test mode works on every endpoint from a free account, with watermarked, non-binding requests that don't count against quota",
        "Error catalogue of 20 HTTP error names with cause, remediation and a retryable flag, also embedded in the spec as `x-error-codes`",
        "Rate limits published with numbers (100 a minute standard, 25 on higher-tier endpoints, 10 in test mode) and returned in response headers",
        "Official SDKs in six languages at version 1.13.0, released 10 September 2026, with semantic versioning"
      ],
      "weaknesses": [
        "No idempotency keys found in the docs or the spec, so a retried send can create a second signature request",
        "An API key grants full access to the account, with no scoped or read-only keys. Scopes exist only on OAuth tokens",
        "OAuth apps need manual approval by Dropbox Sign support before production use",
        "The terms supply the service as is, and no SLA was found. A major outage on 2 January 2026 lasted 3 hours 12 minutes",
        "Embedded signing and bulk send need the Standard plan ($3,000 a year), and embedded templates need Premium, priced by quote"
      ],
      "agentNotes": [
        "Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute",
        "Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created",
        "Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form",
        "Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL",
        "Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.9
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 85,
        "payments": 25,
        "reliability": 75,
        "schema": 88,
        "security": 65,
        "transparency": 51
      },
      "provenanceScore": 85
    },
    "connect": {
      "install": "npm install @dropbox/sign",
      "http": "curl \"https://api.hellosign.com/v3/template/list\" \\\n    -u \"${API_KEY}:\""
    },
    "letme": {
      "capability": "https://letme.dev/esign.send",
      "tool": "https://letme.dev/dropbox-sign"
    },
    "notable": [
      "The API answers at https://api.hellosign.com/v3 and is described by one OpenAPI 3.0.3 spec with 68 paths and 74 operations, covering signature requests, templates, embedded URLs, unclaimed drafts, bulk send, teams, API apps, reports and fax (https://github.com/hellosign/hellosign-openapi)",
      "Test mode works on every endpoint from a free account. Test requests are watermarked, not legally binding and don't count against quota (https://developers.hellosign.com/docs/overview)",
      "Rate limits are 100 requests a minute for standard calls, 25 a minute for 17 higher-tier endpoints such as send and file download, and 10 a minute in test mode (https://developers.hellosign.com/docs/overview)",
      "Webhooks cover 23 event types, carry an HMAC-SHA256 `event_hash` keyed on the primary API key, retry up to six times and clear the callback URL after ten consecutive failures (https://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough)",
      "The docs site runs an MCP server at https://developers.hellosign.com/_mcp/server with one read-only tool, searchDocs. It searches documentation and can't send or read signature requests (https://developers.hellosign.com/llms.txt)",
      "No vendor MCP server for the signing product was found. The official MCP registry lists io.usefulapi/dropbox-sign, a third-party server (https://registry.modelcontextprotocol.io/v0/servers?search=dropbox)",
      "The completed PDF carries an audit trail with timestamps, signer IP addresses and a SHA-256 document hash (https://developers.hellosign.com/api/manual-reference-pages/glossary/security-compliance)",
      "status.hellosign.com lists two minor incidents in the last 90 days, a Salesforce integration fault on 21 August 2026 and file upload problems on 31 August 2026 (https://status.hellosign.com/history)"
    ],
    "area": "business",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.hellosign.com/v3, OpenAPI 3.0.3, 68 paths and 74 operations. Signature Request 20, Template 11, Team 10, Fax Line 7, API App 5, Fax 5, Account 4, Unclaimed Draft 4, and others"
      },
      {
        "label": "Credentials",
        "value": "API key over HTTP Basic, up to four keys an account, full account access. OAuth 2.0 Bearer tokens with scopes basic_account_info and request_signature (app owner billed) or account_access, signature_request_access, template_access, team_access and api_app_access (user billed)"
      },
      {
        "label": "Going to production",
        "value": "Non-embedded sending needs only a paid plan. Embedded apps are self-published in the web app (up to 10 apps). OAuth apps need review by support"
      },
      {
        "label": "Test mode",
        "value": "`test_mode=true` on any endpoint, free, watermarked and not legally binding, 10 requests a minute, not counted against quota"
      },
      {
        "label": "Plans",
        "value": "Essentials $900 a year from 50 requests a month, 5 templates. Standard $3,000 a year from 100 requests a month, 15 templates, adds bulk send and embedded signing and requesting. Premium by quote, adds embedded templates, data residency and multiple domains (https://sign.dropbox.com/products/dropbox-sign-api/pricing)"
      },
      {
        "label": "Rate limits",
        "value": "100 requests a minute standard, 25 a minute on 17 higher-tier endpoints, 10 a minute in test mode. `X-Ratelimit-Limit`, `X-Ratelimit-Limit-Remaining` and `X-Ratelimit-Reset` headers. 429 with error name `exceeded_rate`"
      },
      {
        "label": "Errors",
        "value": "20 HTTP error names with status, cause, remediation and a retryable flag (yes, no or conditional), 10 OAuth error names and 5 asynchronous error events, in the docs and in the spec as `x-error-codes`, `x-oauth-error-codes` and `x-error-events`"
      },
      {
        "label": "Webhooks",
        "value": "Account and app callbacks, 23 event types, multipart POST. The receiver answers 200 with `Hello API Event Received`. HMAC-SHA256 `event_hash`, a published IP range file, six retries, 30-second timeout, callback URL cleared after ten consecutive failures"
      },
      {
        "label": "Lists",
        "value": "`page` and `page_size` (1 to 100, default 20) with a `query` search language over fields such as title, to, from, created, complete, declined and metadata"
      },
      {
        "label": "SDKs",
        "value": "Python dropbox-sign, Node @dropbox/sign, PHP, Java, Ruby and .NET, generated from the OpenAPI spec, version 1.13.0 on 10 September 2026, MIT. Prior major versions patched for 12 months"
      },
      {
        "label": "Docs MCP",
        "value": "https://developers.hellosign.com/_mcp/server (fern-docs-mcp-server 1.0.0), one tool, searchDocs, marked readOnlyHint. Documentation search only"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II, SOC 3, ISO 27001, ISO 27018, HIPAA, PCI DSS and eIDAS listed at trust.dropbox.com. Bug bounty and disclosure programme on Intigriti"
      },
      {
        "label": "Status",
        "value": "status.hellosign.com on Statuspage, 13 components in four groups (Core, Web, API, Integrations) with incident history"
      }
    ],
    "provenance": {
      "legalEntity": "Dropbox, Inc.",
      "domain": "hellosign.com",
      "domainRegistered": "2004-03-05",
      "endpointOnVendorDomain": true,
      "terms": "https://sign.dropbox.com/about/terms",
      "privacy": "https://sign.dropbox.com/about/privacy",
      "statusPage": "https://status.hellosign.com",
      "changelog": "https://developers.hellosign.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-07",
      "notes": [
        "The Dropbox Sign terms (effective 7 January 2025) put the agreement with Dropbox, Inc. for customers in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere.",
        "The API host is api.hellosign.com and the docs are at developers.hellosign.com. The marketing site is sign.dropbox.com. RDAP gives 2004-03-05 for hellosign.com and 1995-06-28 for dropbox.com.",
        "sign.dropbox.com/.well-known/security.txt and api.hellosign.com/.well-known/security.txt return 404. www.dropbox.com/.well-known/security.txt serves a plain-text file that names the Intigriti bug bounty and disclosure programmes without the standard Contact and Expires fields.",
        "The privacy policy is dated 14 January 2025. The data processing agreement at assets.dropbox.com is dated 25 October 2021.",
        "The sub-processor list at www.dropbox.com/privacy/subprocessor/sign returned only its title to our reader."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Dropbox, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "hellosign.com, registered 2004-03-05 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.hellosign.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.hellosign.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://sign.dropbox.com/about/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-01-07",
          "words": 7791,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Posted: January 7, 2025",
              "says": "Last updated 2025-01-07"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These terms will be interpreted, construed, and enforced in all respects in accordance with the local laws of the State of California, U.S.A., without reference to its choice of law rules to the contrary.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "DROPBOX’S AND ITS SUPPLIERS’ TOTAL LIABILITY WILL NOT EXCEED IN AGGREGATE THE AMOUNT ACTUALLY PAID BY CUSTOMER TO DROPBOX FOR THE APPLICABLE DROPBOX SIGN SERVICES OR RELATED SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Dropbox may terminate Customer’s right to use any Free Access Subscriptions or Beta Releases at any time for any reason or no reason in Dropbox’s sole discretion, without liability."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You must have the authority to bind that organization to these terms, otherwise you must not sign up for the Dropbox Sign Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Nevertheless, and without limiting the other disclaimers and limitations in these Terms, CUSTOMER AGREES THAT ANY FREE ACCESS SUBSCRIPTION OR BETA RELEASES ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS WITHOUT ANY WARRANTY, SUPPORT, MAINTENANCE, STORAGE, SLA, OR INDEMNITY OBLIGATIONS OF ANY KIND."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "access the Dropbox Sign Services for the purpose of building a competitive product or service or copying its features or user interface;",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We reserve the right to change the prices, features, or options included in a particular Subscription Plan without notice, provided that such changes shall not take effect until your next applicable Subscription Term (as defined below).‍",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "WAIVER OF CLASS ACTIONS."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "After termination the customer loses access to Customer Data, and Dropbox may delete it at any time after 30 days.",
              "quote": "Customer’s right to access any Customer Data in the applicable Dropbox Sign Services will cease and Dropbox may delete the Customer Data at any time after 30 days from the date of termination."
            },
            {
              "date": "2026-10-08",
              "text": "A customer that exceeds its plan's usage limits is upgraded automatically to the next highest plan and must pay for it.",
              "quote": "If Customer exceeds their Subscription Plan’s usage limits, Customer will be automatically upgraded into the next highest Subscription Plan and Customer expressly acknowledges and agrees that it will pay for the upgraded Subscription Plan."
            },
            {
              "date": "2026-10-08",
              "text": "Renewals are priced at Dropbox's rates in force at the time of renewal.",
              "quote": "Pricing for any Subscription Term renewal, new order form, or order form changes will be at Dropbox’s then-applicable rates."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://sign.dropbox.com/about/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-01-14",
          "words": 3675,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Posted: January 14, 2025",
              "says": "Last updated 2025-01-14"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "When registering for or using the Dropbox Sign Services we collect personal information provided by you."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will retain your personal information for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law, for legal, tax or regulatory reasons, or other lawful purposes."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share and/or collect additional information about you from third parties primarily to assist us in understanding how we can maintain and improve the services we offer to better serve you."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "If you wish to opt out of interest-based advertising, click www.aboutads.info/choices [or if located in the European Union click www.youronlinechoices.eu]."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Dropbox acknowledges that you have the right to access your personal information."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions about the security of your personal information, you can contact us at privacy@dropbox.com.‍",
              "says": "privacy@dropbox.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "When transferring data from the European Union, the European Economic Area, the United Kingdom, and Switzerland, Dropbox relies upon a variety of legal mechanisms, such as contracts with our customers and affiliates, Standard Contractual Clauses, the EU-U.S.",
              "says": "Relies on standard contractual clauses"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/dropbox-sign.json",
    "live": {
      "slug": "dropbox-sign",
      "probe": {
        "target": "https://api.hellosign.com/v3",
        "method": "get",
        "lastAt": "2026-10-08T18:20:29.156505354Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 132,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 142,
        "p95ms24h": 306,
        "samples24h": 33,
        "samples30d": 33,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 33,
            "ok": 33
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.hellosign.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T18:21:56.962032231Z"
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@dropbox/sign",
          "version": "1.13.0",
          "seenAt": "2026-10-08T16:09:21.702754102Z"
        },
        {
          "registry": "pypi",
          "name": "dropbox-sign",
          "version": "1.13.0",
          "released": "2026-09-10",
          "seenAt": "2026-10-08T16:09:25.156865046Z"
        }
      ],
      "githubStars": 22,
      "npmWeekly": 149738,
      "pypiWeekly": 73874,
      "securityTxt": {
        "url": "https://hellosign.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:39:08.009752876Z"
      },
      "pages": [
        {
          "url": "https://developers.hellosign.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:43.499814076Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "df5ec179b075"
        },
        {
          "url": "https://sign.dropbox.com/about/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:17.794548551Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "30f2bccc1007"
        },
        {
          "url": "https://sign.dropbox.com/about/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:19.844597175Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "daf78169f086"
        }
      ],
      "updatedAt": "2026-10-08T18:24:19.844597175Z"
    }
  }
}
