{
  "data": {
    "a": {
      "slug": "dropbox-sign",
      "name": "Dropbox Sign",
      "vendor": "Dropbox, Inc.",
      "vendorUrl": "https://sign.dropbox.com",
      "kind": "http-api",
      "category": "e-signatures",
      "summary": "Dropbox Sign (formerly HelloSign) is Dropbox's e-signature service. Its REST API sends documents or templates for signature, embeds signing in an iframe, reports status by webhook and returns signed PDFs with an audit trail.",
      "url": "https://www.anchorterminal.com/tools/dropbox-sign",
      "markdownUrl": "https://www.anchorterminal.com/tools/dropbox-sign.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dropbox-sign.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json",
      "repo": "https://github.com/hellosign/hellosign-openapi",
      "license": "Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.hellosign.com/v3",
      "packages": [
        {
          "registry": "npm",
          "name": "@dropbox/sign"
        },
        {
          "registry": "pypi",
          "name": "dropbox-sign"
        }
      ],
      "auth": "mixed",
      "authNotes": "A self-serve API key from the account's API settings page, sent as the HTTP Basic username with an empty password. Each account can hold up to four keys for rotation, and every key has full access to the account. OAuth 2.0 access tokens (Bearer) act on behalf of other users with seven scopes across two billing models, and OAuth apps need approval by Dropbox Sign support before production. Embedded apps can be self-published in the web app.",
      "pricing": "paid",
      "pricingNotes": "Production signature requests need a paid API plan, and the API answers 402 without one. Essentials is $900 a year ($75 a month) from 50 requests a month, Standard $3,000 a year ($250 a month) from 100, and Premium is quoted by sales. Test mode is free on every endpoint from a free account, so an agent can build and test without a contract (checked 2026-10-07).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 22,
        "npmWeekly": 149738,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.hellosign.com",
      "llmsTxt": "https://developers.hellosign.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/hellosign/hellosign-openapi/main/openapi.yaml",
      "capabilities": [
        "esign.send",
        "esign.templates",
        "esign.embed",
        "esign.status"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "api-key",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "python",
        "typescript",
        "java",
        "php",
        "ruby",
        "dotnet",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-10",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.9,
        "grade": "B",
        "agentReady": false,
        "rank": 171,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 85,
          "payments": 25,
          "reliability": 75,
          "schema": 88,
          "security": 65,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation.",
        "bestFor": "An agent that sends a prepared PDF or a saved template for signature from one company account and tracks it to completion by webhook or polling, with the signed PDF and audit trail at the end.",
        "strengths": [
          "Public OpenAPI 3.0.3 spec with 74 operations, plus llms.txt and a Markdown copy of every docs page",
          "Free test mode works on every endpoint from a free account, with watermarked, non-binding requests that don't count against quota",
          "Error catalogue of 20 HTTP error names with cause, remediation and a retryable flag, also embedded in the spec as `x-error-codes`",
          "Rate limits published with numbers (100 a minute standard, 25 on higher-tier endpoints, 10 in test mode) and returned in response headers",
          "Official SDKs in six languages at version 1.13.0, released 10 September 2026, with semantic versioning"
        ],
        "weaknesses": [
          "No idempotency keys found in the docs or the spec, so a retried send can create a second signature request",
          "An API key grants full access to the account, with no scoped or read-only keys. Scopes exist only on OAuth tokens",
          "OAuth apps need manual approval by Dropbox Sign support before production use",
          "The terms supply the service as is, and no SLA was found. A major outage on 2 January 2026 lasted 3 hours 12 minutes",
          "Embedded signing and bulk send need the Standard plan ($3,000 a year), and embedded templates need Premium, priced by quote"
        ],
        "agentNotes": [
          "Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute",
          "Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created",
          "Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form",
          "Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL",
          "Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.9
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 85,
          "payments": 25,
          "reliability": 75,
          "schema": 88,
          "security": 65,
          "transparency": 51
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "npm install @dropbox/sign",
        "http": "curl \"https://api.hellosign.com/v3/template/list\" \\\n    -u \"${API_KEY}:\""
      },
      "letme": {
        "capability": "https://letme.dev/esign.send",
        "tool": "https://letme.dev/dropbox-sign"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Dropbox, Inc.",
        "domain": "hellosign.com",
        "domainRegistered": "2004-03-05",
        "endpointOnVendorDomain": true,
        "terms": "https://sign.dropbox.com/about/terms",
        "privacy": "https://sign.dropbox.com/about/privacy",
        "statusPage": "https://status.hellosign.com",
        "changelog": "https://developers.hellosign.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Dropbox Sign terms (effective 7 January 2025) put the agreement with Dropbox, Inc. for customers in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere.",
          "The API host is api.hellosign.com and the docs are at developers.hellosign.com. The marketing site is sign.dropbox.com. RDAP gives 2004-03-05 for hellosign.com and 1995-06-28 for dropbox.com.",
          "sign.dropbox.com/.well-known/security.txt and api.hellosign.com/.well-known/security.txt return 404. www.dropbox.com/.well-known/security.txt serves a plain-text file that names the Intigriti bug bounty and disclosure programmes without the standard Contact and Expires fields.",
          "The privacy policy is dated 14 January 2025. The data processing agreement at assets.dropbox.com is dated 25 October 2021.",
          "The sub-processor list at www.dropbox.com/privacy/subprocessor/sign returned only its title to our reader."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/dropbox-sign.json",
      "live": {
        "slug": "dropbox-sign",
        "probe": {
          "target": "https://api.hellosign.com/v3",
          "method": "get",
          "lastAt": "2026-10-08T23:26:30.061385274Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 138,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 138,
          "p95ms24h": 382,
          "samples24h": 87,
          "samples30d": 87,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 87,
              "ok": 87
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hellosign.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T23:23:55.056091933Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@dropbox/sign",
            "version": "1.13.0",
            "seenAt": "2026-10-08T16:09:21.702754102Z"
          },
          {
            "registry": "pypi",
            "name": "dropbox-sign",
            "version": "1.13.0",
            "released": "2026-09-10",
            "seenAt": "2026-10-08T16:09:25.156865046Z"
          }
        ],
        "githubStars": 22,
        "npmWeekly": 149738,
        "pypiWeekly": 73874,
        "securityTxt": {
          "url": "https://hellosign.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:08.009752876Z"
        },
        "pages": [
          {
            "url": "https://developers.hellosign.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:43.499814076Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df5ec179b075"
          },
          {
            "url": "https://sign.dropbox.com/about/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:17.794548551Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "30f2bccc1007"
          },
          {
            "url": "https://sign.dropbox.com/about/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:19.844597175Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "daf78169f086"
          }
        ],
        "updatedAt": "2026-10-08T23:26:30.061385274Z"
      }
    },
    "answer": "Dropbox Sign scores 68.9 (B) on agent readiness against PandaDoc's 63.1 (B), and leads in 6 of 7 scored categories. PandaDoc leads on payments \u0026 pricing.",
    "b": {
      "slug": "pandadoc",
      "name": "PandaDoc",
      "vendor": "PandaDoc",
      "vendorUrl": "https://www.pandadoc.com",
      "kind": "http-api",
      "category": "e-signatures",
      "summary": "PandaDoc is a document platform for proposals, quotes, contracts and e-signatures. Its REST API and hosted MCP server create documents from templates, send them for signature, embed signing sessions and report status through webhooks.",
      "url": "https://www.anchorterminal.com/tools/pandadoc",
      "markdownUrl": "https://www.anchorterminal.com/tools/pandadoc.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pandadoc.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pandadoc.json",
      "repo": "https://github.com/PandaDoc/pandadoc-openapi-specification",
      "license": "Proprietary service under PandaDoc's Master Services Agreement. The OpenAPI specification, the API client SDKs and the MCP server guide on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.pandadoc.com/public/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "pandadoc-node-client"
        },
        {
          "registry": "pypi",
          "name": "pandadoc-python-client"
        }
      ],
      "auth": "mixed",
      "authNotes": "OAuth 2.0 authorisation code is the recommended method for the REST API, with `read` and `write` scopes and a Bearer token. Registering an OAuth application needs production API access, which is in the API Developer plan and a paid add-on on Business and Enterprise. API keys (`Authorization: API-Key ...`) are labelled legacy. A key belongs to one workspace and carries its owner's role, a sandbox key is self-serve from the developer centre, and a production key needs approval from Sales. The MCP server takes OAuth only, with PKCE and dynamic client registration, and scopes `read`, `write`, `documents:read`, `documents:edit` and `documents:send`. A person signs in and approves each connection.",
      "pricing": "freemium",
      "pricingNotes": "Free eSign plan at $0 with API and MCP access, capped at 25 documents created through the API and 5 documents sent a month. Starter is $19 a user a month billed annually ($35 monthly) and Business $49 ($65 monthly). Enterprise is priced by Sales. Each document created with a production credential uses one usage credit. Starter gets a one-time grant of 25 and Business 50, then credits are bought as packs on the billing page, with no public pack price found. Sandbox keys aren't charged, and the 14-day trial asks for a card only to change plan. Prices are from the help centre, because www.pandadoc.com/pricing answered our reader with a browser check (checked 2026-10-07).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 found in the developer docs, the OpenAPI spec or the help centre's billing articles (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 49684,
        "pypiWeekly": 11543,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.pandadoc.com",
      "llmsTxt": "https://developers.pandadoc.com/llms.txt",
      "openapi": "https://openapi.pandadoc.com/_build/openapi.yaml",
      "registryName": "com.pandadoc.mcp/mcp",
      "capabilities": [
        "esign.send",
        "esign.templates",
        "esign.embed",
        "esign.status",
        "contracts.generate"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "python",
        "typescript",
        "java",
        "php",
        "status-page",
        "eu-region"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.1,
        "grade": "B",
        "agentReady": false,
        "rank": 319,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 58,
          "schema": 87,
          "security": 61,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": 0,
        "verdict": "The public OpenAPI spec lists 133 operations and reached version 8.21.0 on 2 October 2026, and the hosted MCP server, with OAuth and dynamic client registration, is open to every plan including Free. The status page records three incidents affecting document creation, sending or the API between 15 July and 6 September 2026, and writes have no idempotency keys.",
        "bestFor": "Suited to agents that prepare a proposal, quote or contract from a template, send it for signature and track it, for a team that already works in PandaDoc.",
        "strengths": [
          "Public OpenAPI 3.0.3 spec with 133 operations, version 8.21.0 on 2 October 2026, plus llms.txt and a Markdown copy of each docs page",
          "Hosted MCP server in the official MCP registry as com.pandadoc.mcp/mcp, with OAuth, PKCE and dynamic client registration",
          "API and MCP access on every plan including Free, and a sandbox key that isn't charged",
          "Rate limits published per endpoint, from 100 to 2,000 requests a minute on production keys",
          "API request logs and a per-document audit trail are readable through the API"
        ],
        "weaknesses": [
          "Three incidents hit document creation, sending or the API between 15 July and 6 September 2026, the longest about 3.5 hours",
          "No idempotency keys, and each document created with a production credential uses one usage credit",
          "Production API keys need approval from Sales, and usage credit pack prices sit on the in-app billing page",
          "Webhook deliveries aren't retried automatically, and a subscription failing for 7 days is deactivated",
          "The Python SDK was last released in April 2024 and the Node SDK's 7.0.0 line has been a release candidate since January 2026"
        ],
        "agentNotes": [
          "Wait for `document.draft` before sending. Creation is asynchronous and a new document stays in `document.uploaded` for a few seconds",
          "Match the region. Accounts on app.pandadoc.eu use api.pandadoc.eu and mcp.pandadoc.eu, and the global hosts reject them",
          "Check for an existing document before retrying a create. There's no idempotency key and each production create uses a usage credit",
          "Retry 409 after a pause and back off on 429. A sandbox key allows 10 requests a minute per endpoint",
          "Don't rely on webhooks alone. Failed deliveries aren't retried, so poll the status endpoint as a fallback"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.1
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 77,
          "payments": 30,
          "reliability": 58,
          "schema": 87,
          "security": 61,
          "transparency": 33
        },
        "provenanceScore": 84
      },
      "connect": {
        "http": "curl \"https://api.pandadoc.com/public/v1/documents?count=5\" \\\n  -H \"Authorization: API-Key $PANDADOC_API_KEY\"",
        "claudeCode": "claude mcp add pandadoc --transport http https://mcp.pandadoc.com/v1/mcp",
        "config": {
          "mcpServers": {
            "pandadoc": {
              "url": "https://mcp.pandadoc.com/v1/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/esign.send",
        "tool": "https://letme.dev/pandadoc"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "PandaDoc",
        "domain": "pandadoc.com",
        "domainRegistered": "2013-03-07",
        "endpointOnVendorDomain": true,
        "terms": "https://www.pandadoc.com/master-services-agreement/",
        "privacy": "https://www.pandadoc.com/legal/privacy-notice/",
        "statusPage": "https://status.pandadoc.com",
        "changelog": "https://developers.pandadoc.com/changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-07",
        "notes": [
          "www.pandadoc.com answered every request from our reader with a Vercel browser check (HTTP 429), so the terms, privacy notice, security page, sub-processor list and security.txt on that host were not read. The terms URL is the one named in the OpenAPI spec and the privacy URL the one linked from PandaDoc/mcp-server-guide.",
          "The registered company name was not confirmed first-hand. The MIT licence files on GitHub read \"Copyright (c) 2021 PandaDoc\".",
          "The API answers at api.pandadoc.com and api.pandadoc.eu, and the MCP server at mcp.pandadoc.com and mcp.pandadoc.eu.",
          "app.pandadoc.com and api.pandadoc.com return 404 for /.well-known/security.txt.",
          "RDAP for pandadoc.com gives a registration date of 2013-03-07 and expiry on 2028-03-07."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pandadoc.json",
      "live": {
        "slug": "pandadoc",
        "probe": {
          "target": "https://api.pandadoc.com/public/v1",
          "method": "get",
          "lastAt": "2026-10-08T23:26:39.857761262Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 186,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 200,
          "p95ms24h": 527,
          "samples24h": 87,
          "samples30d": 87,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 87,
              "ok": 87
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.pandadoc.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T23:24:13.433981808Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "PandaDoc/pandadoc-openapi-specification",
            "version": "v7.27.1",
            "released": "2026-05-18",
            "seenAt": "2026-10-08T16:24:38.986435339Z"
          },
          {
            "registry": "npm",
            "name": "pandadoc-node-client",
            "version": "6.2.0",
            "seenAt": "2026-10-08T16:24:37.971551567Z"
          },
          {
            "registry": "pypi",
            "name": "pandadoc-python-client",
            "version": "6.2.0",
            "released": "2024-04-08",
            "seenAt": "2026-10-08T16:24:38.801559871Z"
          }
        ],
        "githubStars": 6,
        "npmWeekly": 49684,
        "pypiWeekly": 10927,
        "securityTxt": {
          "url": "https://pandadoc.com/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:38.152830762Z"
        },
        "pages": [
          {
            "url": "https://developers.pandadoc.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:55.997591832Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e7cd0cb1a50c"
          },
          {
            "url": "https://www.pandadoc.com/legal/privacy-notice/",
            "kind": "privacy",
            "status": 429,
            "checkedAt": "2026-10-08T18:29:33.711832356Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.pandadoc.com/master-services-agreement/",
            "kind": "terms",
            "status": 429,
            "checkedAt": "2026-10-08T18:29:35.722967757Z",
            "changedAt": "0001-01-01T00:00:00Z"
          }
        ],
        "updatedAt": "2026-10-08T23:26:39.857761262Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Dropbox, Inc.",
        "b": "PandaDoc",
        "name": "Vendor"
      },
      {
        "a": "https://api.hellosign.com/v3",
        "b": "https://api.pandadoc.com/public/v1",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT",
        "b": "Proprietary service under PandaDoc's Master Services Agreement. The OpenAPI specification, the API client SDKs and the MCP server guide on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.pandadoc.mcp/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-09-10",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "2025-01-07",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2025-01-14",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "22 stars, 150k npm/wk",
        "b": "50k npm/wk, 12k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Dropbox Sign scores 68.9 (B) on agent readiness against PandaDoc's 63.1 (B), and leads in 6 of 7 scored categories. PandaDoc leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Dropbox Sign or PandaDoc?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Dropbox Sign and PandaDoc need an API key?"
      },
      {
        "answer": "Yes. Dropbox Sign has a hosted endpoint at https://api.hellosign.com/v3 and PandaDoc at https://api.pandadoc.com/public/v1.",
        "question": "Can an agent call Dropbox Sign and PandaDoc without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 75 against 58",
          "Maintenance \u0026 community, 85 against 77",
          "Transparency \u0026 trust, 68 against 59"
        ],
        "also": null,
        "goodFor": "An agent that sends a prepared PDF or a saved template for signature from one company account and tracks it to completion by webhook or polling, with the signed PDF and audit trail at the end.",
        "slug": "dropbox-sign",
        "watchFor": "No idempotency keys found in the docs or the spec, so a retried send can create a second signature request"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 30 against 25"
        ],
        "also": null,
        "goodFor": "Suited to agents that prepare a proposal, quote or contract from a template, send it for signature and track it, for a team that already works in PandaDoc.",
        "slug": "pandadoc",
        "watchFor": "Three incidents hit document creation, sending or the API between 15 July and 6 September 2026, the longest about 3.5 hours"
      }
    ],
    "job": {
      "capability": "esign.send",
      "name": "Esign send"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/documenso-vs-dropbox-sign.json",
        "title": "Documenso vs Dropbox Sign",
        "url": "https://www.anchorterminal.com/compare/documenso-vs-dropbox-sign"
      },
      {
        "json": "https://www.anchorterminal.com/compare/documenso-vs-pandadoc.json",
        "title": "Documenso vs PandaDoc",
        "url": "https://www.anchorterminal.com/compare/documenso-vs-pandadoc"
      },
      {
        "json": "https://www.anchorterminal.com/compare/docusign-vs-dropbox-sign.json",
        "title": "Docusign vs Dropbox Sign",
        "url": "https://www.anchorterminal.com/compare/docusign-vs-dropbox-sign"
      },
      {
        "json": "https://www.anchorterminal.com/compare/docusign-vs-pandadoc.json",
        "title": "Docusign vs PandaDoc",
        "url": "https://www.anchorterminal.com/compare/docusign-vs-pandadoc"
      },
      {
        "json": "https://www.anchorterminal.com/compare/dropbox-sign-vs-signnow.json",
        "title": "Dropbox Sign vs airSlate SignNow",
        "url": "https://www.anchorterminal.com/compare/dropbox-sign-vs-signnow"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pandadoc-vs-signnow.json",
        "title": "PandaDoc vs airSlate SignNow",
        "url": "https://www.anchorterminal.com/compare/pandadoc-vs-signnow"
      }
    ],
    "scores": [
      {
        "by": 17,
        "dropbox-sign": 75,
        "edge": "dropbox-sign",
        "key": "reliability",
        "name": "Reliability",
        "pandadoc": 58,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "dropbox-sign": 88,
        "edge": "dropbox-sign",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "pandadoc": 87,
        "weight": 13
      },
      {
        "by": 4,
        "dropbox-sign": 72,
        "edge": "dropbox-sign",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "pandadoc": 68,
        "weight": 13
      },
      {
        "by": 4,
        "dropbox-sign": 65,
        "edge": "dropbox-sign",
        "key": "security",
        "name": "Security \u0026 auth",
        "pandadoc": 61,
        "weight": 14
      },
      {
        "by": 5,
        "dropbox-sign": 25,
        "edge": "pandadoc",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "pandadoc": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 8,
        "dropbox-sign": 85,
        "edge": "dropbox-sign",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "pandadoc": 77,
        "weight": 7
      },
      {
        "by": 9,
        "dropbox-sign": 68,
        "edge": "dropbox-sign",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "pandadoc": 59,
        "weight": 7
      }
    ],
    "summary": "Dropbox Sign scores 68.9 (B) on agent readiness against PandaDoc's 63.1 (B), and leads in 6 of 7 scored categories. PandaDoc leads on payments \u0026 pricing. Both do esign send.",
    "verdicts": {
      "dropbox-sign": "A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation.",
      "pandadoc": "The public OpenAPI spec lists 133 operations and reached version 8.21.0 on 2 October 2026, and the hosted MCP server, with OAuth and dynamic client registration, is open to every plan including Free. The status page records three incidents affecting document creation, sending or the API between 15 July and 6 September 2026, and writes have no idempotency keys."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc",
    "json": "https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.md",
    "slim": "https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.min.md"
  },
  "markdown": "Dropbox Sign scores 68.9 (B) on agent readiness against PandaDoc's 63.1 (B), and leads in 6 of 7 scored categories. PandaDoc leads on payments \u0026 pricing. Both do esign send.\n\n- Dropbox Sign: grade B, 68.9/100, rank #171 of 722. Markdown https://www.anchorterminal.com/tools/dropbox-sign.md · JSON https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json\n- PandaDoc: grade B, 63.1/100, rank #319 of 722. Markdown https://www.anchorterminal.com/tools/pandadoc.md · JSON https://www.anchorterminal.com/api/v1/tools/pandadoc.json\n\n## Which one, for what\n\n### Dropbox Sign (B)\n\nGood for: An agent that sends a prepared PDF or a saved template for signature from one company account and tracks it to completion by webhook or polling, with the signed PDF and audit trail at the end.\n\nAhead on:\n- Reliability, 75 against 58\n- Maintenance \u0026 community, 85 against 77\n- Transparency \u0026 trust, 68 against 59\n\nWatch for: No idempotency keys found in the docs or the spec, so a retried send can create a second signature request\n\n### PandaDoc (B)\n\nGood for: Suited to agents that prepare a proposal, quote or contract from a template, send it for signature and track it, for a team that already works in PandaDoc.\n\nAhead on:\n- Payments \u0026 pricing, 30 against 25\n\nWatch for: Three incidents hit document creation, sending or the API between 15 July and 6 September 2026, the longest about 3.5 hours\n\n\n## Score by category\n\n| Category | Weight | Dropbox Sign | PandaDoc | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 75 | 58 | Dropbox Sign +17 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 87 | Dropbox Sign +1 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 68 | Dropbox Sign +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 61 | Dropbox Sign +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 30 | PandaDoc +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 77 | Dropbox Sign +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 68 | 59 | Dropbox Sign +9 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **68.9 · B** | **63.1 · B** | |\n\n## Facts side by side\n\n| Fact | Dropbox Sign | PandaDoc |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Dropbox, Inc. | PandaDoc |\n| Hosted endpoint | `https://api.hellosign.com/v3` | `https://api.pandadoc.com/public/v1` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT | Proprietary service under PandaDoc's Master Services Agreement. The OpenAPI specification, the API client SDKs and the MCP server guide on GitHub are MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `com.pandadoc.mcp/mcp` |\n| Last release | 2026-09-10 | 2026-10-02 |\n| Terms last updated | 2025-01-07 | couldn't be read |\n| Privacy policy last updated | 2025-01-14 | couldn't be read |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | yes | couldn't be read |\n| Terms or service can change without notice | yes | couldn't be read |\n| Arbitration or class-action waiver | yes | couldn't be read |\n| Popularity | 22 stars, 150k npm/wk | 50k npm/wk, 12k PyPI/wk |\n\n## Verdicts\n\n**Dropbox Sign.** A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation.\n\n**PandaDoc.** The public OpenAPI spec lists 133 operations and reached version 8.21.0 on 2 October 2026, and the hosted MCP server, with OAuth and dynamic client registration, is open to every plan including Free. The status page records three incidents affecting document creation, sending or the API between 15 July and 6 September 2026, and writes have no idempotency keys.\n\n## Before you call either\n\n### Dropbox Sign\n\n1. Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute\n2. Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created\n3. Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form\n4. Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL\n5. Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event\n\n### PandaDoc\n\n1. Wait for `document.draft` before sending. Creation is asynchronous and a new document stays in `document.uploaded` for a few seconds\n2. Match the region. Accounts on app.pandadoc.eu use api.pandadoc.eu and mcp.pandadoc.eu, and the global hosts reject them\n3. Check for an existing document before retrying a create. There's no idempotency key and each production create uses a usage credit\n4. Retry 409 after a pause and back off on 429. A sandbox key allows 10 requests a minute per endpoint\n5. Don't rely on webhooks alone. Failed deliveries aren't retried, so poll the status endpoint as a fallback\n\n## Questions\n\n### Which is better for AI agents, Dropbox Sign or PandaDoc?\n\nDropbox Sign scores 68.9 (B) on agent readiness against PandaDoc's 63.1 (B), and leads in 6 of 7 scored categories. PandaDoc leads on payments \u0026 pricing.\n\n### Do Dropbox Sign and PandaDoc need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Dropbox Sign and PandaDoc without installing anything?\n\nYes. Dropbox Sign has a hosted endpoint at https://api.hellosign.com/v3 and PandaDoc at https://api.pandadoc.com/public/v1.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.json, and with the fewest tokens: https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"dropbox-sign\", \"b\": \"pandadoc\"}`. From a terminal: `anchor compare dropbox-sign pandadoc`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json and https://www.anchorterminal.com/api/v1/tools/pandadoc.json\n\n## Other comparisons with Dropbox Sign or PandaDoc\n\n- [Documenso vs Dropbox Sign](https://www.anchorterminal.com/compare/documenso-vs-dropbox-sign.md)\n- [Documenso vs PandaDoc](https://www.anchorterminal.com/compare/documenso-vs-pandadoc.md)\n- [Docusign vs Dropbox Sign](https://www.anchorterminal.com/compare/docusign-vs-dropbox-sign.md)\n- [Docusign vs PandaDoc](https://www.anchorterminal.com/compare/docusign-vs-pandadoc.md)\n- [Dropbox Sign vs airSlate SignNow](https://www.anchorterminal.com/compare/dropbox-sign-vs-signnow.md)\n- [PandaDoc vs airSlate SignNow](https://www.anchorterminal.com/compare/pandadoc-vs-signnow.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Dropbox Sign vs PandaDoc",
        "url": ""
      }
    ],
    "description": "Dropbox Sign scores 68.9 (B) on agent readiness against PandaDoc's 63.1 (B), and leads in 6 of 7 scored categories. PandaDoc leads on payments \u0026 pricing. Both do esign send. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Dropbox Sign B 68.9",
      "PandaDoc B 63.1",
      "scores"
    ],
    "h1": "Dropbox Sign vs PandaDoc",
    "image": "https://www.anchorterminal.com/assets/og/compare-dropbox-sign-vs-pandadoc.png",
    "path": "/compare/dropbox-sign-vs-pandadoc",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Dropbox Sign vs PandaDoc for AI agents, B 68.9 vs B 63.1",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc"
  },
  "tokens": {
    "markdown": 2000,
    "slim": 730
  },
  "version": 1
}
