{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/signnow.json",
        "name": "airSlate SignNow",
        "score": 68.5,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status",
          "contracts.generate"
        ],
        "slug": "signnow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/pandadoc.json",
        "name": "PandaDoc",
        "score": 63.1,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status",
          "contracts.generate"
        ],
        "slug": "pandadoc"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/dropbox-sign.json",
        "name": "Dropbox Sign",
        "score": 68.9,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status"
        ],
        "slug": "dropbox-sign"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/documenso.json",
        "name": "Documenso",
        "score": 62.8,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.status",
          "esign.embed"
        ],
        "slug": "documenso"
      }
    ],
    "tool": {
      "slug": "docusign",
      "name": "Docusign",
      "vendor": "Docusign, Inc.",
      "vendorUrl": "https://www.docusign.com",
      "kind": "http-api",
      "category": "e-signatures",
      "summary": "Docusign is an e-signature and agreement management service. Its eSignature REST API creates envelopes from documents or templates, sends them to signers, embeds signing in an app and reports status. A hosted MCP server exposes a subset as tools.",
      "url": "https://www.anchorterminal.com/tools/docusign",
      "markdownUrl": "https://www.anchorterminal.com/tools/docusign.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/docusign.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/docusign.json",
      "repo": "https://github.com/docusign/OpenAPI-Specifications",
      "license": "Proprietary service under Docusign's Master Services Agreement. The OpenAPI specifications repository and the eSignature SDKs on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.docusign.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "docusign-esign"
        },
        {
          "registry": "pypi",
          "name": "docusign-esign"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 access tokens only, sent as a Bearer header. A developer creates an integration key in a free developer account and chooses authorisation code grant (with a secret or PKCE), JWT Grant for a service that impersonates a consenting user, or Implicit Grant. Moving to production means a Go-Live review of the key's API activity, a paid account and an administrator. Public integrations must join the partner programme. Since 30 September 2026, a production integration key used with the MCP server also needs Docusign's approval through a form.",
      "pricing": "paid",
      "pricingNotes": "Developer API plans start at $50 a month billed annually (Starter, from 40 envelopes a month), then $300 (Intermediate) and $480 (Advanced), with larger plans through sales. A free developer account with no time limit lets an agent build and test in the demo environment without a contract, but envelopes sent there aren't legally binding. Workflow Builder and Agreement Manager need an IAM subscription (checked 2026-10-07).",
      "priceSummary": "$50 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the spec files or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 42,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 542682,
        "pypiWeekly": 305902,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.docusign.com",
      "openapi": "https://raw.githubusercontent.com/docusign/OpenAPI-Specifications/master/esignature.rest.swagger-v2.1.json",
      "capabilities": [
        "esign.send",
        "esign.templates",
        "esign.embed",
        "esign.status",
        "contracts.generate"
      ],
      "tags": [
        "hosted",
        "paid",
        "sandbox",
        "oauth",
        "mcp",
        "openapi",
        "webhooks",
        "node",
        "python",
        "java",
        "csharp",
        "php",
        "ruby",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.5,
        "grade": "B",
        "agentReady": false,
        "rank": 301,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 81,
          "payments": 30,
          "reliability": 57,
          "schema": 70,
          "security": 64,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 57,
            "points": 11.4,
            "reason": "Read with the hosted lines and scored on the eSignature REST API, with the MCP server noted. health.docusign.com is Docusign's own status centre with incidents by site and a history (20). Its feed lists 34 incidents since 9 July 2026. Docusign's post-mortems call two of them service disruptions, document viewing and signing failures on NA4 on 30 July (18:52 to 20:51 UTC) and failed or delayed email notifications, signing requests among them, from 25 to 30 September. Send and sign also had elevated latency and errors across NA1 to NA4 on 9 September (00:42 to 03:12 UTC). That is several majors (0). Limits have numbers, 3,000 requests an hour per account and 500 per 30 seconds in production (15). The docs describe `X-RateLimit-Reset` and burst headers, tell apps to stop until the reset, and return 429 for limit errors. `transactionId` lets a sender check whether an envelope was created after a lost response, valid for seven days, but there's no general idempotency key (12 of 15). No SLA was found in the Master Services Agreement or the terms index. The service schedules weren't readable (0). The eSignature API v2.1 is generally available, and the docs give 30 September 2026 as the MCP server's general availability date (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "Spec files for eSignature v2.1 (Swagger 2.0, 213 paths, 414 operations) and ten other APIs are public under MIT in docusign/OpenAPI-Specifications. The MCP tool schemas sit behind sign-in, so the API carries this line (25). developers.docusign.com/llms.txt and www.docusign.com/llms.txt return 404, and no Markdown copy of the docs was found (0). Operation descriptions are long and say what a call is for (the median is 179 characters and Envelopes:create explains drafts, templates and required fields), though 43 of 414 are under 40 characters (15 of 20). The eSignature spec has no `enum` and no `required` list on any schema, and no security definitions. Valid values are listed in prose (6 of 15). How-to guides and code in six languages, an error-code page and a troubleshooting page exist, but the spec documents only a 400 with `errorCode` and `message` for most operations (12 of 15). The API is versioned (v2.1, builds such as 26.2.01.01), the SDK changelogs are dated, and the developer changelog mixes product changes with blog posts (12 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "Envelope listing takes `count` (up to 1,000) and an `include` parameter to add recipients, folders and other detail, but there's no field selection and envelope objects are large. The MCP server lists 42 tools with no toolsets or read-only subset (15 of 25). `count`, `start_position`, `nextUri`, and filters by date, status, folder, user and search text (20). Errors carry an upper-case `errorCode` and a message, with a published code list and troubleshooting page. The docs say some errors return HTML or an empty body (15 of 20). `transactionId` guards envelope creation for seven days. There's no general idempotency key, and we couldn't see whether the MCP tools carry readOnlyHint or destructiveHint (8 of 20). Official SDKs in C#, Java, Node.js, PHP, Python and Ruby. A first call still needs the account ID and base URI from /oauth/userinfo, and an envelope definition is verbose (12 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 64,
            "points": 11.2,
            "reason": "OAuth 2.0 with scopes, authorisation code grant with PKCE or a secret, and JWT Grant with an RSA key pair and one-hour tokens. Consent can be revoked. The `signature` scope covers most of the eSignature API, and a JWT integration can impersonate any consenting user (26 of 30). There's no read-only eSignature scope. The MCP limitations page says admins can only switch MCP access on or off, with no control over read and write tools. Envelopes can be created as drafts before sending, and production MCP keys need Docusign's approval (8 of 20). Envelope and agreement content reaches the model, and no prompt-injection guidance was found in the MCP docs. The AI attachment asks customers to review AI output (3 of 15). Each envelope has an audit_events endpoint, Connect has failure logs, a Monitor API exists, and MCP calls land in the eSignature API audit logs (15). ISO 27001:2022, SOC 1 and SOC 2 Type 2, PCI DSS, C5 and IRAP on the compliance page. security.txt returns 404, and no bug bounty or vulnerability disclosure policy was found on the trust pages. We didn't search NVD (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public without login, $50, $300 and $480 a month billed annually with a starting envelope allowance, and no per-envelope or overage price is shown (10). The developer account is free with no time limit and most capabilities enabled, on a demo environment where envelopes aren't legally binding. We didn't run the sign-up form to confirm no card is asked for (20). A person signs up in a browser, creates the integration key and grants consent, and production adds a Go-Live review (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 81,
            "points": 7.09,
            "reason": "The MCP server's general availability on 30 September 2026 is the latest dated change found (30). Dated entries in the last 90 days include the Node SDK 10.0.0 on 16 July, the Slackbot MCP connector guide on 23 July, a Data IO update on 19 August and the MCP release, alongside nine blog posts (20). Closed service with a public changelog, a support centre and a developer support page. We didn't test a support channel (10 of 15). Official SDKs in six languages. The Node SDK tracks eSignature v2.1-26.2.01.01, while the stable Python package is 6.1.0 from 13 March 2026 with only release candidates since (15). The Node SDK repository has integration tests and a dated changelog, no CI workflow is visible in it, and the spec repository's last commit is 3 July 2026 (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "note": "editorial 59, provenance 85",
            "reason": "The service is closed under a Master Services Agreement dated 14 November 2022. The spec files and SDKs are MIT (15). The data protection attachment of 4 September 2024 promises prompt deletion after termination without a number of days, and the privacy notice gives no retention periods. The privacy notice says systems are designed to avoid training models on customers' personal information without consent, and the AI attachment of 8 July 2026 takes that consent for AI improvement data with an opt-out toggle (20 of 30). No written deprecation policy was found. Changes are announced in dated posts, such as the 23 June 2026 notice of status-code changes rolling out to production in July (6 of 20). The sub-processor list was updated on 18 September 2026 and has an RSS feed, the attachment gives 30 days' notice of new sub-processors, and the privacy notice names Australia, the United States, the European Union and Canada as storage locations (18 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Envelope listing takes `count` (up to 1,000) and an `include` parameter to add recipients, folders and other detail, but there's no field selection and envelope objects are large. The MCP server lists 42 tools with no toolsets or read-only subset (15 of 25). `count`, `start_position`, `nextUri`, and filters by date, status, folder, user and search text (20). Errors carry an upper-case `errorCode` and a message, with a published code list and troubleshooting page. The docs say some errors return HTML or an empty body (15 of 20). `transactionId` guards envelope creation for seven days. There's no general idempotency key, and we couldn't see whether the MCP tools carry readOnlyHint or destructiveHint (8 of 20). Official SDKs in C#, Java, Node.js, PHP, Python and Ruby. A first call still needs the account ID and base URI from /oauth/userinfo, and an envelope definition is verbose (12 of 15).",
            "maintenance": "The MCP server's general availability on 30 September 2026 is the latest dated change found (30). Dated entries in the last 90 days include the Node SDK 10.0.0 on 16 July, the Slackbot MCP connector guide on 23 July, a Data IO update on 19 August and the MCP release, alongside nine blog posts (20). Closed service with a public changelog, a support centre and a developer support page. We didn't test a support channel (10 of 15). Official SDKs in six languages. The Node SDK tracks eSignature v2.1-26.2.01.01, while the stable Python package is 6.1.0 from 13 March 2026 with only release candidates since (15). The Node SDK repository has integration tests and a dated changelog, no CI workflow is visible in it, and the spec repository's last commit is 3 July 2026 (6 of 10).",
            "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public without login, $50, $300 and $480 a month billed annually with a starting envelope allowance, and no per-envelope or overage price is shown (10). The developer account is free with no time limit and most capabilities enabled, on a demo environment where envelopes aren't legally binding. We didn't run the sign-up form to confirm no card is asked for (20). A person signs up in a browser, creates the integration key and grants consent, and production adds a Go-Live review (0).",
            "reliability": "Read with the hosted lines and scored on the eSignature REST API, with the MCP server noted. health.docusign.com is Docusign's own status centre with incidents by site and a history (20). Its feed lists 34 incidents since 9 July 2026. Docusign's post-mortems call two of them service disruptions, document viewing and signing failures on NA4 on 30 July (18:52 to 20:51 UTC) and failed or delayed email notifications, signing requests among them, from 25 to 30 September. Send and sign also had elevated latency and errors across NA1 to NA4 on 9 September (00:42 to 03:12 UTC). That is several majors (0). Limits have numbers, 3,000 requests an hour per account and 500 per 30 seconds in production (15). The docs describe `X-RateLimit-Reset` and burst headers, tell apps to stop until the reset, and return 429 for limit errors. `transactionId` lets a sender check whether an envelope was created after a lost response, valid for seven days, but there's no general idempotency key (12 of 15). No SLA was found in the Master Services Agreement or the terms index. The service schedules weren't readable (0). The eSignature API v2.1 is generally available, and the docs give 30 September 2026 as the MCP server's general availability date (10).",
            "schema": "Spec files for eSignature v2.1 (Swagger 2.0, 213 paths, 414 operations) and ten other APIs are public under MIT in docusign/OpenAPI-Specifications. The MCP tool schemas sit behind sign-in, so the API carries this line (25). developers.docusign.com/llms.txt and www.docusign.com/llms.txt return 404, and no Markdown copy of the docs was found (0). Operation descriptions are long and say what a call is for (the median is 179 characters and Envelopes:create explains drafts, templates and required fields), though 43 of 414 are under 40 characters (15 of 20). The eSignature spec has no `enum` and no `required` list on any schema, and no security definitions. Valid values are listed in prose (6 of 15). How-to guides and code in six languages, an error-code page and a troubleshooting page exist, but the spec documents only a 400 with `errorCode` and `message` for most operations (12 of 15). The API is versioned (v2.1, builds such as 26.2.01.01), the SDK changelogs are dated, and the developer changelog mixes product changes with blog posts (12 of 15).",
            "security": "OAuth 2.0 with scopes, authorisation code grant with PKCE or a secret, and JWT Grant with an RSA key pair and one-hour tokens. Consent can be revoked. The `signature` scope covers most of the eSignature API, and a JWT integration can impersonate any consenting user (26 of 30). There's no read-only eSignature scope. The MCP limitations page says admins can only switch MCP access on or off, with no control over read and write tools. Envelopes can be created as drafts before sending, and production MCP keys need Docusign's approval (8 of 20). Envelope and agreement content reaches the model, and no prompt-injection guidance was found in the MCP docs. The AI attachment asks customers to review AI output (3 of 15). Each envelope has an audit_events endpoint, Connect has failure logs, a Monitor API exists, and MCP calls land in the eSignature API audit logs (15). ISO 27001:2022, SOC 1 and SOC 2 Type 2, PCI DSS, C5 and IRAP on the compliance page. security.txt returns 404, and no bug bounty or vulnerability disclosure policy was found on the trust pages. We didn't search NVD (12 of 20).",
            "transparency": "The service is closed under a Master Services Agreement dated 14 November 2022. The spec files and SDKs are MIT (15). The data protection attachment of 4 September 2024 promises prompt deletion after termination without a number of days, and the privacy notice gives no retention periods. The privacy notice says systems are designed to avoid training models on customers' personal information without consent, and the AI attachment of 8 July 2026 takes that consent for AI improvement data with an opt-out toggle (20 of 30). No written deprecation policy was found. Changes are announced in dated posts, such as the 23 June 2026 notice of status-code changes rolling out to production in July (6 of 20). The sub-processor list was updated on 18 September 2026 and has an RSS feed, the attachment gives 30 days' notice of new sub-processors, and the privacy notice names Australia, the United States, the European Union and Canada as storage locations (18 of 20)."
          },
          "sources": [
            {
              "what": "APIs overview",
              "url": "https://www.docusign.com/products/apis",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server docs and tool list",
              "url": "https://developers.docusign.com/platform/mcp-server/",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP limitations and general availability notice",
              "url": "https://developers.docusign.com/platform/mcp-server/limitations-workarounds/",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://mcp.docusign.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-07"
            },
            {
              "what": "API resource limits",
              "url": "https://developers.docusign.com/platform/resource-limits/",
              "seen": "2026-10-07"
            },
            {
              "what": "eSignature rules and limits",
              "url": "https://developers.docusign.com/docs/esign-rest-api/esign101/rules-and-limits/",
              "seen": "2026-10-07"
            },
            {
              "what": "API guidelines",
              "url": "https://developers.docusign.com/platform/api-guidelines/",
              "seen": "2026-10-07"
            },
            {
              "what": "error codes",
              "url": "https://developers.docusign.com/docs/esign-rest-api/esign101/error-codes/",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication scopes",
              "url": "https://developers.docusign.com/platform/auth/reference/scopes/",
              "seen": "2026-10-07"
            },
            {
              "what": "JWT Grant",
              "url": "https://developers.docusign.com/platform/auth/jwt/",
              "seen": "2026-10-07"
            },
            {
              "what": "Go-Live",
              "url": "https://developers.docusign.com/platform/go-live/",
              "seen": "2026-10-07"
            },
            {
              "what": "base paths",
              "url": "https://developers.docusign.com/platform/api-endpoint-base-paths/",
              "seen": "2026-10-07"
            },
            {
              "what": "spec repository (cloned)",
              "url": "https://github.com/docusign/OpenAPI-Specifications",
              "seen": "2026-10-07"
            },
            {
              "what": "Node SDK repository (cloned)",
              "url": "https://github.com/docusign/docusign-esign-node-client",
              "seen": "2026-10-07"
            },
            {
              "what": "npm package",
              "url": "https://registry.npmjs.org/docusign-esign/latest",
              "seen": "2026-10-07"
            },
            {
              "what": "PyPI package",
              "url": "https://pypi.org/pypi/docusign-esign/json",
              "seen": "2026-10-07"
            },
            {
              "what": "developer plans and prices",
              "url": "https://ecom.docusign.com/en-US/plans-and-pricing/developer",
              "seen": "2026-10-07"
            },
            {
              "what": "status incident feed",
              "url": "https://health.docusign.com/production/1ds/ssg/apps/health/dynamic/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "developer changelog",
              "url": "https://developers.docusign.com/changelog/",
              "seen": "2026-10-07"
            },
            {
              "what": "status-code change post",
              "url": "https://www.docusign.com/blog/developers/clearer-docusign-api-error-message-and-status-code-improvements",
              "seen": "2026-10-07"
            },
            {
              "what": "compliance",
              "url": "https://www.docusign.com/trust/compliance",
              "seen": "2026-10-07"
            },
            {
              "what": "sub-processors",
              "url": "https://www.docusign.com/trust/privacy/subprocessors-list",
              "seen": "2026-10-07"
            },
            {
              "what": "Master Services Agreement",
              "url": "https://www.docusign.com/legal/terms-and-conditions/msa",
              "seen": "2026-10-07"
            },
            {
              "what": "data protection attachment",
              "url": "https://www.docusign.com/legal/terms-and-conditions/data-protection-attachment",
              "seen": "2026-10-07"
            },
            {
              "what": "AI attachment",
              "url": "https://www.docusign.com/legal/terms-and-conditions/ai-attachment-docusign-services",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy notice",
              "url": "https://www.docusign.com/privacy",
              "seen": "2026-10-07"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.verisign.com/com/v1/domain/docusign.com",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the service schedules linked from the terms index, so whether a paid tier has an SLA with a figure is not established",
            "unchecked: the MCP server's live tool definitions and annotations, which need a signed-in session (an unauthenticated initialise call returned 403)",
            "unchecked: whether the developer account sign-up asks for a card",
            "unchecked: NVD and any vulnerability disclosure or bug bounty page outside docusign.com/trust",
            "unchecked: per-envelope overage prices and what happens when a plan's envelope allowance runs out",
            "The APIs marketing page says the MCP server is in open beta while the developer docs give 30 September 2026 as its general availability date",
            "The JWT Grant page gives a one-hour access token while the MCP page says JWT tokens expire after eight hours"
          ]
        },
        "negative": 0,
        "verdict": "The eSignature REST API has public Swagger and OpenAPI files on GitHub, OAuth 2.0, a free developer sandbox and Connect webhooks, and the MCP server reached general availability on 30 September 2026. Production needs a paid plan from $50 a month and a Go-Live review, and the status site lists 34 incidents since 9 July 2026.",
        "bestFor": "Teams whose company already uses Docusign and needs an agent to send envelopes from templates, embed signing and track status with a full audit trail.",
        "strengths": [
          "Public Spec files under MIT on GitHub for eSignature v2.1 (213 paths, 414 operations) and ten other APIs",
          "Free developer account with no time limit, on a separate demo environment (demo.docusign.net, mcp-d.docusign.com)",
          "Rate limits published with numbers (3,000 calls an hour per account, 500 per 30 seconds in production) and returned in response headers",
          "Each envelope has an audit_events endpoint, and Connect webhooks support HMAC signatures, OAuth and mutual TLS",
          "Sub-processor list updated 18 September 2026 with an RSS feed, and 30 days' notice of new sub-processors in the data protection attachment"
        ],
        "weaknesses": [
          "health.docusign.com lists 34 incidents since 9 July 2026, including a two-hour NA4 disruption on 30 July and email notification failures from 25 to 30 September",
          "Production access needs a paid account, an admin and a Go-Live review, and MCP integration keys need Docusign's approval since 30 September 2026",
          "The eSignature spec is Swagger 2.0 with no enums, no required lists and no security definitions. Valid values sit in prose",
          "The `signature` scope covers most of the eSignature API, and MCP admins can only switch access on or off, with no read or write tool control",
          "No llms.txt, no security.txt, and no bug bounty, written deprecation policy or SLA found in the pages reviewed"
        ],
        "agentNotes": [
          "Call /oauth/userinfo once after sign-in, cache `base_uri` and the account ID, and send every eSignature call to that host under /restapi/v2.1",
          "Create and send an envelope in one Envelopes:create call with `status` set to `sent`. Docusign asks for five calls or fewer per envelope",
          "Subscribe to Connect or set `eventNotification` for status. Polling one envelope more than once every 15 minutes is flagged and can fail the Go-Live review",
          "Set `transactionId` on envelope creation so a retry after a lost response can find the envelope. The ID is valid for seven days",
          "Read `X-RateLimit-Reset` and `X-BurstLimit-Remaining`, and stop calling until the reset after a 429"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.5
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 81,
          "payments": 30,
          "reliability": 57,
          "schema": 70,
          "security": 64,
          "transparency": 59
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "npm install docusign-esign -save"
      },
      "letme": {
        "capability": "https://letme.dev/esign.send",
        "tool": "https://letme.dev/docusign"
      },
      "notable": [
        "The docs say the MCP server reached general availability on 30 September 2026, and that production integration keys with no MCP calls from 1 to 30 September were disabled until Docusign approves them (https://developers.docusign.com/platform/mcp-server/limitations-workarounds/)",
        "The APIs page still describes the MCP server as in open beta (https://www.docusign.com/products/apis)",
        "The MCP docs list 42 tools for the demo environment and 29 for production. The descriptions of sendReminder and updateEnvelopeRecipients appear to be swapped in the table (https://developers.docusign.com/platform/mcp-server/)",
        "A blog post of 23 June 2026 moved hourly, burst and polling limit errors from HTTP 400 to 429 and changed 16 error messages, with the production rollout expected in July 2026 (https://www.docusign.com/blog/developers/clearer-docusign-api-error-message-and-status-code-improvements)",
        "An app may request the status of one envelope once every 15 minutes. More frequent polling doesn't fail but is flagged and can fail the Go-Live review (https://developers.docusign.com/platform/resource-limits/)",
        "The status feed holds 111 incidents since 3 December 2025, nine with a post-mortem (https://health.docusign.com/production/1ds/ssg/apps/health/dynamic/incidents.json)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "eSignature REST API v2.1, with the hosted MCP server noted alongside. Other APIs include Workflow Builder, Agreement Manager, Web Forms, Connected Fields, Click, Admin, Monitor and Rooms"
        },
        {
          "label": "Base URLs",
          "value": "Demo https://demo.docusign.net/restapi/v2.1/, production https://{server}.docusign.net/restapi/v2.1/ where {server} is the account's data centre (for example NA2, CA or EU). Newer APIs at https://api.docusign.com/v1/. Auth at account-d.docusign.com (demo) and account.docusign.com"
        },
        {
          "label": "MCP server",
          "value": "Streamable HTTP at https://mcp.docusign.com/mcp (production) and https://mcp-d.docusign.com/mcp (demo). General availability on 30 September 2026 per the docs. 42 tools listed for demo, 29 of them in production. OAuth metadata shows authorisation code with PKCE (S256) and no registration endpoint"
        },
        {
          "label": "MCP tools",
          "value": "createEnvelope, createEnvelopeWithDocuments, getEnvelope, getEnvelopes, listRecipients, updateEnvelope, updateEnvelopeRecipients, sendReminder, getTemplates, getAccount, getUser, getUsers, getUserInfo, eight Workflow Builder tools, three CLM workflow tools, getAllAgreements and getAgreementDetails. Workflow Builder and Agreement Manager tools need an IAM subscription"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 only. authorisation code grant (confidential, or public with PKCE), JWT Grant for service integrations (RSA key pair, one-hour access token, no refresh token) and Implicit Grant, which the docs advise against. Refresh tokens typically last 30 days. Each app has an integration key"
        },
        {
          "label": "Go-Live",
          "value": "An integration key is built in the developer account, then promoted after a review of its API activity. Production needs a paid account and an administrator. Manual reviews typically take 24 to 48 hours. Public integrations must join the partner programme"
        },
        {
          "label": "Rate limits",
          "value": "3,000 requests an hour per account across all apps, reset on the hour. Burst limit of 500 calls per 30 seconds in production and 200 in the developer environment. One status GET per envelope per 15 minutes. /oauth/userinfo 25,000 an hour per user and 50,000 per integration key"
        },
        {
          "label": "Errors",
          "value": "JSON body with `errorCode` (upper-case constant) and `message`. 429 for hourly, burst and polling limits since a change announced on 23 June 2026. Multi-item calls return 200 or 201 with `errorDetails` per failed item"
        },
        {
          "label": "Webhooks",
          "value": "Connect at account or organisation level, or `eventNotification` per envelope. JSON SIM event model (Connect 2.0), HMAC signatures, OAuth, mutual TLS, a retry queue and failure logs. Listeners should answer 200 within five seconds"
        },
        {
          "label": "Audit trail",
          "value": "GET /envelopes/{envelopeId}/audit_events returns an envelope's history. MCP calls are recorded in the existing eSignature API audit logs, with no MCP-specific log"
        },
        {
          "label": "Pricing",
          "value": "Developer API plans on ecom.docusign.com (US page). Starter $50 a month ($600 billed annually) from 40 envelopes a month, Intermediate $300 ($3,600) from 100, Advanced $480 ($5,760) with PowerForms, Bulk Send and Connect. Enhanced plans through sales with a five-user minimum"
        },
        {
          "label": "SDKs",
          "value": "C#, Java, Node.js, PHP, Python and Ruby. npm docusign-esign 10.0.0 (16 July 2026, eSignature v2.1-26.2.01.01), PyPI docusign-esign 6.1.0 (13 March 2026) with release candidates up to 10.0.0rc1 in June. MIT"
        },
        {
          "label": "Specs",
          "value": "github.com/docusign/OpenAPI-Specifications, MIT, last commit 3 July 2026. eSignature v2.1 and v2 as Swagger 2.0, Agreement Manager and Workflow Builder as OpenAPI 3.0.3, plus Admin, Click, Monitor, Navigator, Rooms, Web Forms, Workspaces, Maestro and the Connect schema"
        },
        {
          "label": "Certifications",
          "value": "ISO 27001:2022, SOC 1 Type 2, SOC 2 Type 2, PCI DSS, C5 and IRAP, with HIPAA and 21 CFR Part 11 support stated, per docusign.com/trust/compliance"
        },
        {
          "label": "Status",
          "value": "health.docusign.com, Docusign's own status centre, with incidents by site (NA1 to NA4, EU, AU, CA, JP1, DEMO and others) and post-mortems on some. 111 incidents in the feed since 3 December 2025"
        },
        {
          "label": "Data handling",
          "value": "Data protection attachment of 4 September 2024, privacy notice effective 9 October 2025, AI attachment of 8 July 2026. Customer data stored in Australia, the United States, the European Union or Canada per the privacy notice"
        }
      ],
      "unitPrices": [
        {
          "item": "Starter plan",
          "unit": "month",
          "usd": 50,
          "note": "Starting amount of 40 envelopes a month, $600 billed annually"
        },
        {
          "item": "Intermediate plan",
          "unit": "month",
          "usd": 300,
          "note": "Starting amount of 100 envelopes a month, $3,600 billed annually"
        },
        {
          "item": "Advanced plan",
          "unit": "month",
          "usd": 480,
          "note": "Adds PowerForms, Bulk Send, signer attachments and Connect, $5,760 billed annually"
        }
      ],
      "provenance": {
        "legalEntity": "Docusign, Inc.",
        "domain": "docusign.com",
        "domainRegistered": "1999-06-14",
        "endpointOnVendorDomain": true,
        "terms": "https://www.docusign.com/legal/terms-and-conditions/msa",
        "privacy": "https://www.docusign.com/privacy",
        "statusPage": "https://health.docusign.com",
        "changelog": "https://developers.docusign.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Master Services Agreement names Docusign, Inc., a Delaware corporation, and is dated 14 November 2022. The privacy notice (effective 9 October 2025) gives 221 Main Street, Suite 800, San Francisco, CA 94105.",
          "The eSignature API answers at docusign.net hosts, auth at account.docusign.com and the MCP server at mcp.docusign.com. We did not look up the registration of docusign.net.",
          "www.docusign.com/.well-known/security.txt and developers.docusign.com/.well-known/security.txt return 404.",
          "status.docusign.com redirects to health.docusign.com, which loads its incidents from a JSON feed on the same host.",
          "RDAP for docusign.com gives a registration date of 1999-06-14 and MarkMonitor Inc. as registrar."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Docusign, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "docusign.com, registered 1999-06-14 (27 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "mcp.docusign.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 4 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 5.4,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "health.docusign.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.docusign.com/legal/terms-and-conditions/msa",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 8561,
            "points": 5.4,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Agreement and any disputes or claims arising out of or in connection with it or its subject matter or formation (including, without limitation, non-contractual disputes or claims) are governed by and construed in accordance with the law of the Republic of Ireland.",
                "says": "The law of the Republic of Ireland"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…OF EACH PARTY (AND THEIR RESPECTIVE AFFILIATES) ARISING OUT OF OR RELATED TO THE AGREEMENT WILL BE LIMITED TO THE AMOUNTS PAID BY CUSTOMER FOR THE DOCUSIGN SERVICE(S) DURING THE TWELVE (12) MONTH PERIOD PRECEDING THE FIRST EVENT GIVING RISE TO LIABILITY.",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Docusign may suspend any use of the Docusign Services or remove or disable any Account or content that Docusign reasonably and in good faith believes violates Section 2.2 above."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Customer shall not, and shall not permit its Authorized Users or others under its control to, do the following with respect to the Docusign Services:"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(c) access or use the Docusign Services or Documentation for the purpose of: (i) developing or operating products or services intended to be offered to third parties in competition with the Docusign Services, or (ii) allowing access to its Account by a direct competitor of Docusign;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "An Authorized User must be one individual natural person registered by the customer, and two or more persons may not share one.",
                "quote": "“Authorized User” means one individual natural person, whether an employee, business partner, contractor, or agent of Customer or its Affiliates who is registered by Customer in Customer’s Account to use the Docusign Services."
              },
              {
                "date": "2026-10-08",
                "text": "The customer may not use machine-learning output from the services to train, calibrate or validate other systems without Docusign's written consent.",
                "quote": "use the machine-learning algorithm output generated from the Docusign Services to train, calibrate, or validate, in whole or in part, any other systems, programs or platforms, or for benchmarking, software-development, or other competitive purposes"
              },
              {
                "date": "2026-10-08",
                "text": "After termination, help retrieving remaining Customer Data and other transition assistance is set out in a Statement of Work at the then-current rates of Docusign.",
                "quote": "retrieving Customer Data and completed eDocuments still remaining in the Docusign Services, and/or (b) other reasonable transition assistance, the details of which will be set forth in a mutually agreed upon Statement of Work between the Parties at Docusign's then-current rates for such services."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.docusign.com/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-09",
            "words": 8859,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Version Date: October 9, 2025",
                "says": "Last updated 2025-10-09"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We recommend that you read this Notice in full to ensure you are fully informed about the way we collect, use, store, or otherwise process your personal information as well as your privacy rights."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We keep your personal information for no longer than necessary for the purposes for which it is processed."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Examples of third-party sources include marketers, partners, researchers, affiliates (companies under common ownership or control of Docusign), service providers, and others where they are legally allowed to share your personal information with us."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Right to Opt-Out of Sales of Personal Information and Processing of Personal Information for Targeted Advertising Purposes."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If you have any questions or concerns about how personal information is processed in these cases, including how to exercise your rights as a data subject, you should contact the customer (either your employer or the individual or entity requesting your signature)."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "For questions or complaints regarding our use of your personal information or this Notice, please contact us at privacy@docusign.com or by sending a letter to Docusign Inc., Attention: Privacy Team, 221 Main Street, Suite 800, San Francisco, CA 94105.",
                "says": "privacy@docusign.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Transfers outside the Docusign group are only made to organizations that agree to adhere to the standards in our Binding Corporate Rules or use another valid alternative (such as EU Standard Contractual Clauses) under data protection law.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training.optout",
                "label": "Says it may use customer content to train or improve models, and gives an opt-out",
                "found": true,
                "quote": "Building, training and maintaining our artificial intelligence models through machine learning that power certain of our Services using de-identified Customer Data (with customer consent)"
              },
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "This disclosure of information may be considered a “sale” or “processing of your personal information for targeted advertising purposes” under applicable laws."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Docusign says it places no third-party advertising cookies in customer products such as eSignature and does not disclose customer data to advertising and marketing partners.",
                "quote": "Note that we do not deploy third-party advertising cookies in our products used by customers, such as eSignature, Contact Lifecycle, and Identify or disclose customer data to advertising and marketing partners."
              },
              {
                "date": "2026-10-08",
                "text": "Third-party integrations a customer connects may use, transfer or store Customer Data outside the services, and Docusign accepts no responsibility for that.",
                "quote": "Certain features of third party integrations may use, transfer, and/or store Your Customer Data or information outside of the Services, and Docusign is not responsible for any such use, transfer, or storage."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/docusign.json",
      "live": {
        "slug": "docusign",
        "probe": {
          "target": "https://mcp.docusign.com/mcp",
          "method": "get",
          "lastAt": "2026-10-08T17:36:34.836578872Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 69,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 86,
          "p95ms24h": 276,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://health.docusign.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:36:38.349966743Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "docusign/OpenAPI-Specifications",
            "version": "20.1.00",
            "released": "2020-04-17",
            "seenAt": "2026-10-08T16:09:01.313876796Z"
          },
          {
            "registry": "npm",
            "name": "docusign-esign",
            "version": "10.0.0",
            "seenAt": "2026-10-08T16:08:57.83420854Z"
          },
          {
            "registry": "pypi",
            "name": "docusign-esign",
            "version": "6.1.0",
            "released": "2026-03-13",
            "seenAt": "2026-10-08T16:09:01.102662485Z"
          }
        ],
        "githubStars": 24,
        "npmWeekly": 542682,
        "pypiWeekly": 298433,
        "securityTxt": {
          "url": "https://docusign.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:29.983479591Z"
        },
        "updatedAt": "2026-10-08T17:36:34.836578872Z"
      }
    },
    "verify": {
      "accepts": "a page on docusign.com or one of its subdomains, or the README of github.com/docusign/OpenAPI-Specifications",
      "badgeUrl": "https://www.anchorterminal.com/badges/docusign.svg",
      "body": {
        "slug": "docusign",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/docusign",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/docusign\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/docusign.svg\" alt=\"Docusign on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Docusign on Anchor Terminal](https://www.anchorterminal.com/badges/docusign.svg)](https://www.anchorterminal.com/tools/docusign)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/docusign\"\u003eDocusign on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/docusign",
    "json": "https://www.anchorterminal.com/tools/docusign.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/docusign.md",
    "slim": "https://www.anchorterminal.com/tools/docusign.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62.5/100 · rank #301 of 629 · #5 in Contracts, proposals \u0026 e-signatures · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe eSignature REST API has public Swagger and OpenAPI files on GitHub, OAuth 2.0, a free developer sandbox and Connect webhooks, and the MCP server reached general availability on 30 September 2026. Production needs a paid plan from $50 a month and a Go-Live review, and the status site lists 34 incidents since 9 July 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Docusign, Inc. (https://www.docusign.com) |\n| Kind | HTTP API |\n| Category | Contracts, proposals \u0026 e-signatures (https://www.anchorterminal.com/categories/e-signatures) |\n| Transport | HTTP |\n| Endpoint | `https://mcp.docusign.com/mcp` |\n| Auth | OAuth · OAuth 2.0 access tokens only, sent as a Bearer header. A developer creates an integration key in a free developer account and chooses authorisation code grant (with a secret or PKCE), JWT Grant for a service that impersonates a consenting user, or Implicit Grant. Moving to production means a Go-Live review of the key's API activity, a paid account and an administrator. Public integrations must join the partner programme. Since 30 September 2026, a production integration key used with the MCP server also needs Docusign's approval through a form. |\n| Pricing | Paid ($50 / mo) · Developer API plans start at $50 a month billed annually (Starter, from 40 envelopes a month), then $300 (Intermediate) and $480 (Advanced), with larger plans through sales. A free developer account with no time limit lets an agent build and test in the demo environment without a contract, but envelopes sent there aren't legally binding. Workflow Builder and Agreement Manager need an IAM subscription (checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the spec files or the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under Docusign's Master Services Agreement. The OpenAPI specifications repository and the eSignature SDKs on GitHub are MIT |\n| Tools exposed | 42 |\n| Packages | npm: `docusign-esign`; pypi: `docusign-esign` |\n| Source | https://github.com/docusign/OpenAPI-Specifications |\n| Docs | https://developers.docusign.com |\n| llms.txt | not found |\n| Last release | 2026-09-30 |\n| npm downloads / week | 542,682 |\n| PyPI downloads / week | 305,902 |\n| Surface graded | eSignature REST API v2.1, with the hosted MCP server noted alongside. Other APIs include Workflow Builder, Agreement Manager, Web Forms, Connected Fields, Click, Admin, Monitor and Rooms |\n| Base URLs | Demo https://demo.docusign.net/restapi/v2.1/, production https://{server}.docusign.net/restapi/v2.1/ where {server} is the account's data centre (for example NA2, CA or EU). Newer APIs at https://api.docusign.com/v1/. Auth at account-d.docusign.com (demo) and account.docusign.com |\n| MCP server | Streamable HTTP at https://mcp.docusign.com/mcp (production) and https://mcp-d.docusign.com/mcp (demo). General availability on 30 September 2026 per the docs. 42 tools listed for demo, 29 of them in production. OAuth metadata shows authorisation code with PKCE (S256) and no registration endpoint |\n| MCP tools | createEnvelope, createEnvelopeWithDocuments, getEnvelope, getEnvelopes, listRecipients, updateEnvelope, updateEnvelopeRecipients, sendReminder, getTemplates, getAccount, getUser, getUsers, getUserInfo, eight Workflow Builder tools, three CLM workflow tools, getAllAgreements and getAgreementDetails. Workflow Builder and Agreement Manager tools need an IAM subscription |\n| Credentials | OAuth 2.0 only. authorisation code grant (confidential, or public with PKCE), JWT Grant for service integrations (RSA key pair, one-hour access token, no refresh token) and Implicit Grant, which the docs advise against. Refresh tokens typically last 30 days. Each app has an integration key |\n| Go-Live | An integration key is built in the developer account, then promoted after a review of its API activity. Production needs a paid account and an administrator. Manual reviews typically take 24 to 48 hours. Public integrations must join the partner programme |\n| Rate limits | 3,000 requests an hour per account across all apps, reset on the hour. Burst limit of 500 calls per 30 seconds in production and 200 in the developer environment. One status GET per envelope per 15 minutes. /oauth/userinfo 25,000 an hour per user and 50,000 per integration key |\n| Errors | JSON body with `errorCode` (upper-case constant) and `message`. 429 for hourly, burst and polling limits since a change announced on 23 June 2026. Multi-item calls return 200 or 201 with `errorDetails` per failed item |\n| Webhooks | Connect at account or organisation level, or `eventNotification` per envelope. JSON SIM event model (Connect 2.0), HMAC signatures, OAuth, mutual TLS, a retry queue and failure logs. Listeners should answer 200 within five seconds |\n| Audit trail | GET /envelopes/{envelopeId}/audit_events returns an envelope's history. MCP calls are recorded in the existing eSignature API audit logs, with no MCP-specific log |\n| Pricing | Developer API plans on ecom.docusign.com (US page). Starter $50 a month ($600 billed annually) from 40 envelopes a month, Intermediate $300 ($3,600) from 100, Advanced $480 ($5,760) with PowerForms, Bulk Send and Connect. Enhanced plans through sales with a five-user minimum |\n| SDKs | C#, Java, Node.js, PHP, Python and Ruby. npm docusign-esign 10.0.0 (16 July 2026, eSignature v2.1-26.2.01.01), PyPI docusign-esign 6.1.0 (13 March 2026) with release candidates up to 10.0.0rc1 in June. MIT |\n| Specs | github.com/docusign/OpenAPI-Specifications, MIT, last commit 3 July 2026. eSignature v2.1 and v2 as Swagger 2.0, Agreement Manager and Workflow Builder as OpenAPI 3.0.3, plus Admin, Click, Monitor, Navigator, Rooms, Web Forms, Workspaces, Maestro and the Connect schema |\n| Certifications | ISO 27001:2022, SOC 1 Type 2, SOC 2 Type 2, PCI DSS, C5 and IRAP, with HIPAA and 21 CFR Part 11 support stated, per docusign.com/trust/compliance |\n| Status | health.docusign.com, Docusign's own status centre, with incidents by site (NA1 to NA4, EU, AU, CA, JP1, DEMO and others) and post-mortems on some. 111 incidents in the feed since 3 December 2025 |\n| Data handling | Data protection attachment of 4 September 2024, privacy notice effective 9 October 2025, AI attachment of 8 July 2026. Customer data stored in Australia, the United States, the European Union or Canada per the privacy notice |\n| Capabilities | esign.send, esign.templates, esign.embed, esign.status, contracts.generate |\n| Tags | hosted, paid, sandbox, oauth, mcp, openapi, webhooks, node, python, java, csharp, php, ruby, status-page, soc2, iso27001 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/docusign.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 57 | 11.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 70 | 11.4 |\n| Agent ergonomics | 13% | 16.2 | 70 | 11.4 |\n| Security \u0026 auth | 14% | 17.5 | 64 | 11.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 81 | 7.1 |\n| Transparency \u0026 trust (editorial 59, provenance 85) | 7% | 8.8 | 72 | 6.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **62.5 → B** |\n\n### Why each score\n\n- Reliability 57: Read with the hosted lines and scored on the eSignature REST API, with the MCP server noted. health.docusign.com is Docusign's own status centre with incidents by site and a history (20). Its feed lists 34 incidents since 9 July 2026. Docusign's post-mortems call two of them service disruptions, document viewing and signing failures on NA4 on 30 July (18:52 to 20:51 UTC) and failed or delayed email notifications, signing requests among them, from 25 to 30 September. Send and sign also had elevated latency and errors across NA1 to NA4 on 9 September (00:42 to 03:12 UTC). That is several majors (0). Limits have numbers, 3,000 requests an hour per account and 500 per 30 seconds in production (15). The docs describe `X-RateLimit-Reset` and burst headers, tell apps to stop until the reset, and return 429 for limit errors. `transactionId` lets a sender check whether an envelope was created after a lost response, valid for seven days, but there's no general idempotency key (12 of 15). No SLA was found in the Master Services Agreement or the terms index. The service schedules weren't readable (0). The eSignature API v2.1 is generally available, and the docs give 30 September 2026 as the MCP server's general availability date (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 70: Spec files for eSignature v2.1 (Swagger 2.0, 213 paths, 414 operations) and ten other APIs are public under MIT in docusign/OpenAPI-Specifications. The MCP tool schemas sit behind sign-in, so the API carries this line (25). developers.docusign.com/llms.txt and www.docusign.com/llms.txt return 404, and no Markdown copy of the docs was found (0). Operation descriptions are long and say what a call is for (the median is 179 characters and Envelopes:create explains drafts, templates and required fields), though 43 of 414 are under 40 characters (15 of 20). The eSignature spec has no `enum` and no `required` list on any schema, and no security definitions. Valid values are listed in prose (6 of 15). How-to guides and code in six languages, an error-code page and a troubleshooting page exist, but the spec documents only a 400 with `errorCode` and `message` for most operations (12 of 15). The API is versioned (v2.1, builds such as 26.2.01.01), the SDK changelogs are dated, and the developer changelog mixes product changes with blog posts (12 of 15).\n- Agent ergonomics 70: Envelope listing takes `count` (up to 1,000) and an `include` parameter to add recipients, folders and other detail, but there's no field selection and envelope objects are large. The MCP server lists 42 tools with no toolsets or read-only subset (15 of 25). `count`, `start_position`, `nextUri`, and filters by date, status, folder, user and search text (20). Errors carry an upper-case `errorCode` and a message, with a published code list and troubleshooting page. The docs say some errors return HTML or an empty body (15 of 20). `transactionId` guards envelope creation for seven days. There's no general idempotency key, and we couldn't see whether the MCP tools carry readOnlyHint or destructiveHint (8 of 20). Official SDKs in C#, Java, Node.js, PHP, Python and Ruby. A first call still needs the account ID and base URI from /oauth/userinfo, and an envelope definition is verbose (12 of 15).\n- Security \u0026 auth 64: OAuth 2.0 with scopes, authorisation code grant with PKCE or a secret, and JWT Grant with an RSA key pair and one-hour tokens. Consent can be revoked. The `signature` scope covers most of the eSignature API, and a JWT integration can impersonate any consenting user (26 of 30). There's no read-only eSignature scope. The MCP limitations page says admins can only switch MCP access on or off, with no control over read and write tools. Envelopes can be created as drafts before sending, and production MCP keys need Docusign's approval (8 of 20). Envelope and agreement content reaches the model, and no prompt-injection guidance was found in the MCP docs. The AI attachment asks customers to review AI output (3 of 15). Each envelope has an audit_events endpoint, Connect has failure logs, a Monitor API exists, and MCP calls land in the eSignature API audit logs (15). ISO 27001:2022, SOC 1 and SOC 2 Type 2, PCI DSS, C5 and IRAP on the compliance page. security.txt returns 404, and no bug bounty or vulnerability disclosure policy was found on the trust pages. We didn't search NVD (12 of 20).\n- Payments \u0026 pricing 30: Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public without login, $50, $300 and $480 a month billed annually with a starting envelope allowance, and no per-envelope or overage price is shown (10). The developer account is free with no time limit and most capabilities enabled, on a demo environment where envelopes aren't legally binding. We didn't run the sign-up form to confirm no card is asked for (20). A person signs up in a browser, creates the integration key and grants consent, and production adds a Go-Live review (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 81: The MCP server's general availability on 30 September 2026 is the latest dated change found (30). Dated entries in the last 90 days include the Node SDK 10.0.0 on 16 July, the Slackbot MCP connector guide on 23 July, a Data IO update on 19 August and the MCP release, alongside nine blog posts (20). Closed service with a public changelog, a support centre and a developer support page. We didn't test a support channel (10 of 15). Official SDKs in six languages. The Node SDK tracks eSignature v2.1-26.2.01.01, while the stable Python package is 6.1.0 from 13 March 2026 with only release candidates since (15). The Node SDK repository has integration tests and a dated changelog, no CI workflow is visible in it, and the spec repository's last commit is 3 July 2026 (6 of 10).\n- Transparency \u0026 trust 72: The service is closed under a Master Services Agreement dated 14 November 2022. The spec files and SDKs are MIT (15). The data protection attachment of 4 September 2024 promises prompt deletion after termination without a number of days, and the privacy notice gives no retention periods. The privacy notice says systems are designed to avoid training models on customers' personal information without consent, and the AI attachment of 8 July 2026 takes that consent for AI improvement data with an opt-out toggle (20 of 30). No written deprecation policy was found. Changes are announced in dated posts, such as the 23 June 2026 notice of status-code changes rolling out to production in July (6 of 20). The sub-processor list was updated on 18 September 2026 and has an RSS feed, the attachment gives 30 days' notice of new sub-processors, and the privacy notice names Australia, the United States, the European Union and Canada as storage locations (18 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/docusign.md (JSON https://www.anchorterminal.com/fixes/docusign.json)\n\n### What we couldn't check\n\n- unchecked: the service schedules linked from the terms index, so whether a paid tier has an SLA with a figure is not established\n- unchecked: the MCP server's live tool definitions and annotations, which need a signed-in session (an unauthenticated initialise call returned 403)\n- unchecked: whether the developer account sign-up asks for a card\n- unchecked: NVD and any vulnerability disclosure or bug bounty page outside docusign.com/trust\n- unchecked: per-envelope overage prices and what happens when a plan's envelope allowance runs out\n- The APIs marketing page says the MCP server is in open beta while the developer docs give 30 September 2026 as its general availability date\n- The JWT Grant page gives a one-hour access token while the MCP page says JWT tokens expire after eight hours\n\n### Sources\n\n- APIs overview: \u003chttps://www.docusign.com/products/apis\u003e (seen 2026-10-07)\n- MCP server docs and tool list: \u003chttps://developers.docusign.com/platform/mcp-server/\u003e (seen 2026-10-07)\n- MCP limitations and general availability notice: \u003chttps://developers.docusign.com/platform/mcp-server/limitations-workarounds/\u003e (seen 2026-10-07)\n- MCP OAuth metadata: \u003chttps://mcp.docusign.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-07)\n- API resource limits: \u003chttps://developers.docusign.com/platform/resource-limits/\u003e (seen 2026-10-07)\n- eSignature rules and limits: \u003chttps://developers.docusign.com/docs/esign-rest-api/esign101/rules-and-limits/\u003e (seen 2026-10-07)\n- API guidelines: \u003chttps://developers.docusign.com/platform/api-guidelines/\u003e (seen 2026-10-07)\n- error codes: \u003chttps://developers.docusign.com/docs/esign-rest-api/esign101/error-codes/\u003e (seen 2026-10-07)\n- authentication scopes: \u003chttps://developers.docusign.com/platform/auth/reference/scopes/\u003e (seen 2026-10-07)\n- JWT Grant: \u003chttps://developers.docusign.com/platform/auth/jwt/\u003e (seen 2026-10-07)\n- Go-Live: \u003chttps://developers.docusign.com/platform/go-live/\u003e (seen 2026-10-07)\n- base paths: \u003chttps://developers.docusign.com/platform/api-endpoint-base-paths/\u003e (seen 2026-10-07)\n- spec repository (cloned): \u003chttps://github.com/docusign/OpenAPI-Specifications\u003e (seen 2026-10-07)\n- Node SDK repository (cloned): \u003chttps://github.com/docusign/docusign-esign-node-client\u003e (seen 2026-10-07)\n- npm package: \u003chttps://registry.npmjs.org/docusign-esign/latest\u003e (seen 2026-10-07)\n- PyPI package: \u003chttps://pypi.org/pypi/docusign-esign/json\u003e (seen 2026-10-07)\n- developer plans and prices: \u003chttps://ecom.docusign.com/en-US/plans-and-pricing/developer\u003e (seen 2026-10-07)\n- status incident feed: \u003chttps://health.docusign.com/production/1ds/ssg/apps/health/dynamic/incidents.json\u003e (seen 2026-10-07)\n- developer changelog: \u003chttps://developers.docusign.com/changelog/\u003e (seen 2026-10-07)\n- status-code change post: \u003chttps://www.docusign.com/blog/developers/clearer-docusign-api-error-message-and-status-code-improvements\u003e (seen 2026-10-07)\n- compliance: \u003chttps://www.docusign.com/trust/compliance\u003e (seen 2026-10-07)\n- sub-processors: \u003chttps://www.docusign.com/trust/privacy/subprocessors-list\u003e (seen 2026-10-07)\n- Master Services Agreement: \u003chttps://www.docusign.com/legal/terms-and-conditions/msa\u003e (seen 2026-10-07)\n- data protection attachment: \u003chttps://www.docusign.com/legal/terms-and-conditions/data-protection-attachment\u003e (seen 2026-10-07)\n- AI attachment: \u003chttps://www.docusign.com/legal/terms-and-conditions/ai-attachment-docusign-services\u003e (seen 2026-10-07)\n- privacy notice: \u003chttps://www.docusign.com/privacy\u003e (seen 2026-10-07)\n- domain registration: \u003chttps://rdap.verisign.com/com/v1/domain/docusign.com\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 85/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Docusign, Inc. | 20/20 |\n| Domain age | docusign.com, registered 1999-06-14 (27 years) | 15/15 |\n| Endpoint on the vendor's domain | mcp.docusign.com | 15/15 |\n| Terms of service | read, states 4 of the 7 things a reader expects, and has 1 clause that costs points | 5.4/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | health.docusign.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Master Services Agreement names Docusign, Inc., a Delaware corporation, and is dated 14 November 2022. The privacy notice (effective 9 October 2025) gives 221 Main Street, Suite 800, San Francisco, CA 94105.\n\nThe eSignature API answers at docusign.net hosts, auth at account.docusign.com and the MCP server at mcp.docusign.com. We did not look up the registration of docusign.net.\n\nwww.docusign.com/.well-known/security.txt and developers.docusign.com/.well-known/security.txt return 404.\n\nstatus.docusign.com redirects to health.docusign.com, which loads its incidents from a JSON feed on the same host.\n\nRDAP for docusign.com gives a registration date of 1999-06-14 and MarkMonitor Inc. as registrar.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.docusign.com/legal/terms-and-conditions/msa), read 2026-10-08, gives no date, states 4 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"(c) access or use the Docusign Services or Documentation for the purpose of: (i) developing or operating products or services intended to be offered to third parties in competition with the Docusign Services, or (ii) allowing access to its Account by a direct competitor of Docusign;\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the Republic of Ireland.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Not found in the text. Says how changes to the terms are announced.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). An Authorized User must be one individual natural person registered by the customer, and two or more persons may not share one. \"“Authorized User” means one individual natural person, whether an employee, business partner, contractor, or agent of Customer or its Affiliates who is registered by Customer in Customer’s Account to use the Docusign Services.\"\n- Also in the text (2026-10-08). The customer may not use machine-learning output from the services to train, calibrate or validate other systems without Docusign's written consent. \"use the machine-learning algorithm output generated from the Docusign Services to train, calibrate, or validate, in whole or in part, any other systems, programs or platforms, or for benchmarking, software-development, or other competitive purposes\"\n- Also in the text (2026-10-08). After termination, help retrieving remaining Customer Data and other transition assistance is set out in a Statement of Work at the then-current rates of Docusign. \"retrieving Customer Data and completed eDocuments still remaining in the Docusign Services, and/or (b) other reasonable transition assistance, the details of which will be set forth in a mutually agreed upon Statement of Work between the Parties at Docusign's then-current rates for such services.\"\n\n**Privacy policy** (https://www.docusign.com/privacy), read 2026-10-08, dated 2025-10-09, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and gives an opt-out. \"Building, training and maintaining our artificial intelligence models through machine learning that power certain of our Services using de-identified Customer Data (with customer consent)\"\n- To know. Says it sells personal data or shares it for advertising. \"This disclosure of information may be considered a “sale” or “processing of your personal information for targeted advertising purposes” under applicable laws.\"\n- Gives the date it was last updated. Last updated 2025-10-09.\n- Gives a privacy contact. privacy@docusign.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Docusign says it places no third-party advertising cookies in customer products such as eSignature and does not disclose customer data to advertising and marketing partners. \"Note that we do not deploy third-party advertising cookies in our products used by customers, such as eSignature, Contact Lifecycle, and Identify or disclose customer data to advertising and marketing partners.\"\n- Also in the text (2026-10-08). Third-party integrations a customer connects may use, transfer or store Customer Data outside the services, and Docusign accepts no responsibility for that. \"Certain features of third party integrations may use, transfer, and/or store Your Customer Data or information outside of the Services, and Docusign is not responsible for any such use, transfer, or storage.\"\n\n## Live (updated 2026-10-08 17:36 UTC)\n\n- Right now: up, HTTP 403, 69 ms, checked 2026-10-08 17:36 UTC (get on `https://mcp.docusign.com/mcp`, asks for auth)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 86 ms · p95 276 ms\n- Vendor status page: unknown, no machine-readable status found\n- github `docusign/OpenAPI-Specifications` 20.1.00, released 2020-04-17\n- npm `docusign-esign` 10.0.0\n- pypi `docusign-esign` 6.1.0, released 2026-03-13\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/docusign.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Starter plan | $50 | per month (plan) | Starting amount of 40 envelopes a month, $600 billed annually |\n| Intermediate plan | $300 | per month (plan) | Starting amount of 100 envelopes a month, $3,600 billed annually |\n| Advanced plan | $480 | per month (plan) | Adds PowerForms, Bulk Send, signer attachments and Connect, $5,760 billed annually |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public Spec files under MIT on GitHub for eSignature v2.1 (213 paths, 414 operations) and ten other APIs\n- Free developer account with no time limit, on a separate demo environment (demo.docusign.net, mcp-d.docusign.com)\n- Rate limits published with numbers (3,000 calls an hour per account, 500 per 30 seconds in production) and returned in response headers\n- Each envelope has an audit_events endpoint, and Connect webhooks support HMAC signatures, OAuth and mutual TLS\n- Sub-processor list updated 18 September 2026 with an RSS feed, and 30 days' notice of new sub-processors in the data protection attachment\n\n## Weaknesses\n\n- health.docusign.com lists 34 incidents since 9 July 2026, including a two-hour NA4 disruption on 30 July and email notification failures from 25 to 30 September\n- Production access needs a paid account, an admin and a Go-Live review, and MCP integration keys need Docusign's approval since 30 September 2026\n- The eSignature spec is Swagger 2.0 with no enums, no required lists and no security definitions. Valid values sit in prose\n- The `signature` scope covers most of the eSignature API, and MCP admins can only switch access on or off, with no read or write tool control\n- No llms.txt, no security.txt, and no bug bounty, written deprecation policy or SLA found in the pages reviewed\n\n## Before you call it (notes for agents)\n\n1. Call /oauth/userinfo once after sign-in, cache `base_uri` and the account ID, and send every eSignature call to that host under /restapi/v2.1\n2. Create and send an envelope in one Envelopes:create call with `status` set to `sent`. Docusign asks for five calls or fewer per envelope\n3. Subscribe to Connect or set `eventNotification` for status. Polling one envelope more than once every 15 minutes is flagged and can fail the Go-Live review\n4. Set `transactionId` on envelope creation so a retry after a lost response can find the envelope. The ID is valid for seven days\n5. Read `X-RateLimit-Reset` and `X-BurstLimit-Remaining`, and stop calling until the reset after a 429\n\n## Connect\n\nInstall:\n\n```bash\nnpm install docusign-esign -save\n```\n\nThrough letme (picks today, calling later): https://letme.dev/docusign. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| airSlate SignNow | B | 68.5 | 168 | esign.send, esign.templates, esign.embed, esign.status, contracts.generate | no | https://www.anchorterminal.com/tools/signnow.md |\n| PandaDoc | B | 63.1 | 287 | esign.send, esign.templates, esign.embed, esign.status, contracts.generate | no | https://www.anchorterminal.com/tools/pandadoc.md |\n| Dropbox Sign | B | 68.9 | 161 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/dropbox-sign.md |\n| Documenso | B | 62.8 | 294 | esign.send, esign.templates, esign.status, esign.embed | no | https://www.anchorterminal.com/tools/documenso.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The docs say the MCP server reached general availability on 30 September 2026, and that production integration keys with no MCP calls from 1 to 30 September were disabled until Docusign approves them (source: \u003chttps://developers.docusign.com/platform/mcp-server/limitations-workarounds/\u003e)\n- The APIs page still describes the MCP server as in open beta (source: \u003chttps://www.docusign.com/products/apis\u003e)\n- The MCP docs list 42 tools for the demo environment and 29 for production. The descriptions of sendReminder and updateEnvelopeRecipients appear to be swapped in the table (source: \u003chttps://developers.docusign.com/platform/mcp-server/\u003e)\n- A blog post of 23 June 2026 moved hourly, burst and polling limit errors from HTTP 400 to 429 and changed 16 error messages, with the production rollout expected in July 2026 (source: \u003chttps://www.docusign.com/blog/developers/clearer-docusign-api-error-message-and-status-code-improvements\u003e)\n- An app may request the status of one envelope once every 15 minutes. More frequent polling doesn't fail but is flagged and can fail the Go-Live review (source: \u003chttps://developers.docusign.com/platform/resource-limits/\u003e)\n- The status feed holds 111 incidents since 3 December 2025, nine with a post-mortem (source: \u003chttps://health.docusign.com/production/1ds/ssg/apps/health/dynamic/incidents.json\u003e)\n\n## Compare\n\n- [Documenso vs Docusign](https://www.anchorterminal.com/compare/documenso-vs-docusign.md): B 62.8 vs B 62.5\n- [Docusign vs Dropbox Sign](https://www.anchorterminal.com/compare/docusign-vs-dropbox-sign.md): B 62.5 vs B 68.9\n- [Docusign vs PandaDoc](https://www.anchorterminal.com/compare/docusign-vs-pandadoc.md): B 62.5 vs B 63.1\n- [Docusign vs airSlate SignNow](https://www.anchorterminal.com/compare/docusign-vs-signnow.md): B 62.5 vs B 68.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on docusign.com or one of its subdomains, or the README of github.com/docusign/OpenAPI-Specifications. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"docusign\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/docusign\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/docusign.svg\" alt=\"Docusign on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Docusign on Anchor Terminal](https://www.anchorterminal.com/badges/docusign.svg)](https://www.anchorterminal.com/tools/docusign)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/docusign\"\u003eDocusign on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Docusign is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/docusign-dark.png\n- Light: https://www.anchorterminal.com/assets/share/docusign-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Contracts, proposals \u0026 e-signatures",
        "url": "https://www.anchorterminal.com/categories/e-signatures"
      },
      {
        "name": "Docusign",
        "url": ""
      }
    ],
    "description": "Docusign is an e-signature and agreement management service. Its eSignature REST API creates envelopes from documents or templates, sends them to signers, embeds signing in an app and reports status. A hosted MCP server exposes a subset as tools.",
    "facts": [
      "rank #301 of 629",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Docusign",
    "image": "https://www.anchorterminal.com/assets/og/tools-docusign.png",
    "path": "/tools/docusign",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Docusign review for AI agents, grade B (62.5/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/docusign"
  },
  "tokens": {
    "markdown": 8400,
    "slim": 2280
  },
  "version": 1
}
