{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/signnow.json",
        "name": "airSlate SignNow",
        "score": 68.5,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status"
        ],
        "slug": "signnow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/pandadoc.json",
        "name": "PandaDoc",
        "score": 63.1,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status"
        ],
        "slug": "pandadoc"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/documenso.json",
        "name": "Documenso",
        "score": 62.8,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.status",
          "esign.embed"
        ],
        "slug": "documenso"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/docusign.json",
        "name": "Docusign",
        "score": 62.5,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status"
        ],
        "slug": "docusign"
      }
    ],
    "tool": {
      "slug": "dropbox-sign",
      "name": "Dropbox Sign",
      "vendor": "Dropbox, Inc.",
      "vendorUrl": "https://sign.dropbox.com",
      "kind": "http-api",
      "category": "e-signatures",
      "summary": "Dropbox Sign (formerly HelloSign) is Dropbox's e-signature service. Its REST API sends documents or templates for signature, embeds signing in an iframe, reports status by webhook and returns signed PDFs with an audit trail.",
      "url": "https://www.anchorterminal.com/tools/dropbox-sign",
      "markdownUrl": "https://www.anchorterminal.com/tools/dropbox-sign.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/dropbox-sign.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json",
      "repo": "https://github.com/hellosign/hellosign-openapi",
      "license": "Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.hellosign.com/v3",
      "packages": [
        {
          "registry": "npm",
          "name": "@dropbox/sign"
        },
        {
          "registry": "pypi",
          "name": "dropbox-sign"
        }
      ],
      "auth": "mixed",
      "authNotes": "A self-serve API key from the account's API settings page, sent as the HTTP Basic username with an empty password. Each account can hold up to four keys for rotation, and every key has full access to the account. OAuth 2.0 access tokens (Bearer) act on behalf of other users with seven scopes across two billing models, and OAuth apps need approval by Dropbox Sign support before production. Embedded apps can be self-published in the web app.",
      "pricing": "paid",
      "pricingNotes": "Production signature requests need a paid API plan, and the API answers 402 without one. Essentials is $900 a year ($75 a month) from 50 requests a month, Standard $3,000 a year ($250 a month) from 100, and Premium is quoted by sales. Test mode is free on every endpoint from a free account, so an agent can build and test without a contract (checked 2026-10-07).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 22,
        "npmWeekly": 149738,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.hellosign.com",
      "llmsTxt": "https://developers.hellosign.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/hellosign/hellosign-openapi/main/openapi.yaml",
      "capabilities": [
        "esign.send",
        "esign.templates",
        "esign.embed",
        "esign.status"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "api-key",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "python",
        "typescript",
        "java",
        "php",
        "ruby",
        "dotnet",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-10",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.9,
        "grade": "B",
        "agentReady": false,
        "rank": 161,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 85,
          "payments": 25,
          "reliability": 75,
          "schema": 88,
          "security": 65,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 75,
            "points": 15,
            "reason": "Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. status.hellosign.com on Statuspage lists 13 components in four groups with incident history (20). Two incidents in the 90 days to 7 October 2026, both marked minor, a Salesforce integration fault on 21 August (6 h 43 min) and file upload problems on 31 August (54 min). The last major incident was an outage on 2 January 2026 (3 h 12 min), outside the window (20 of 30). Rate limits with numbers, 100 requests a minute standard, 25 on 17 higher-tier endpoints and 10 in test mode, although the header table describes the limit as hourly (15). The docs describe 429 with `X-Ratelimit` headers, tell clients to respect Retry-After and back off, and the error catalogue marks each error retryable or not. No idempotency keys or safe-retry guidance for sends were found (10 of 15). The terms supply the service as is and as available, and no SLA was found (0). The API is at v3 and generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 88,
            "points": 14.3,
            "reason": "One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SDKs (25). llms.txt at developers.hellosign.com, a Markdown copy of each page by appending .md, and scoped llms-full.txt files by section and language (10). Operation descriptions average about 220 characters and several state consequences, such as cancel being irreversible and asynchronous. A glossary written for models covers core objects, signers, fields and workflows. Few descriptions say when not to use an endpoint (14 of 20). 67 enums, 239 required lists and about 80 length or range constraints. Sends are multipart forms with indexed keys, and `metadata` and `custom_fields` are loosely typed (11 of 15). Request and response examples with SDK samples in six languages, and a catalogue of 20 HTTP error names with cause, remediation and a retryable flag, embedded in the spec as `x-error-codes` (15). The path carries v3 and a dated changelog has 48 entries since November 2022. No written API versioning policy was found beyond the SDK one (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 72,
            "points": 11.7,
            "reason": "List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks stay small. No field selection was found (15 of 25). Page-number pagination with totals in `list_info`, and a `query` search language over title, signer, sender, dates, completion state and metadata. The docs warn of a short indexing delay after creation (18 of 20). Errors carry `error_name` and `error_msg`, with 20 documented names, a remediation line each and a retryable flag, plus warnings in successful responses (20). No idempotency keys in the docs or spec, so a retried send can create a duplicate. Cancel returns 200 when queued and confirms by event. The retryable flags are the only safe-retry aid (4 of 20). A template send needs only `template_ids` and `signers`, `test_mode` is a single flag, and official SDKs cover six languages (15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 65,
            "points": 11.38,
            "reason": "API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. OAuth 2.0 tokens carry seven scopes but serve apps acting for other users and need support approval. Scored between plain revocable keys and scoped OAuth (25), less 5 because the docs show the key inside the URL as `https://KEY:@api.hellosign.com`, a judgement call since that is URL userinfo, not a query string (20 of 30). The limited OAuth scopes and test mode narrow what a call can do, but there is no read-only key and no confirmation step on cancel, remove or template delete (9 of 20). Responses can carry signer-entered field values and decline reasons, and no injection guidance was found (5 of 15). The API Dashboard records the account's API requests, responses and callbacks, live and test, and each completed document carries an audit trail with timestamps, IP addresses and a SHA-256 hash (13 of 15). SOC 2 Type II, ISO 27001 and ISO 27018 at trust.dropbox.com, a bug bounty and disclosure programme on Intigriti, and webhook HMAC verification. No standard security.txt on the Sign hosts (18 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 25,
            "points": 3.13,
            "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, Essentials at $900 a year from 50 requests a month and Standard at $3,000 a year from 100, with larger volumes on a selector and Premium by quote. That is plan pricing, not a per-request price (10 of 20). Test mode is free on every endpoint from a free account, but its requests aren't legally binding, and the pages we read don't say whether signup needs a card (15 of 20). A person has to create the account and copy the key from the web app, and production needs a paid plan (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 85,
            "points": 7.44,
            "reason": "SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, among them a new Document Field Detection endpoint (30). Dated changelog entries on 31 July, 19 August and 3 September 2026, plus SDK 1.12.0 and 1.13.0 on 10 September (20). A closed service with a public changelog, an API support address (apisupport@hellosign.com), a help centre and public GitHub issues, nine open on the spec repository. We didn't test response times (11 of 15). Current official SDKs for Python, Node, PHP, Java, Ruby and .NET, all pushed in September 2026 (15). CI in the spec repository builds the spec and each SDK and fails on uncommitted generated code, and Node dependencies were upgraded on 6 October (9 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 68,
            "points": 5.95,
            "note": "editorial 51, provenance 85",
            "reason": "The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). The terms let Dropbox delete customer data any time after 30 days from termination. The data processing agreement, dated 25 October 2021, promises deletion within a commercially reasonable period on request and still points to a hellosign.com sub-processor address. The privacy policy of 14 January 2025 gives no retention period. The documents agree but stay vague (18 of 30). Prior SDK major versions are patched for 12 months and the API returns a `deprecated_parameter` warning, but no API deprecation policy with notice periods was found (8 of 20). The privacy policy links a Sign sub-processor list and the agreement promises advance notice of new sub-processors with a 60-day objection window. The list itself returned only its title to our reader, so names and locations are unconfirmed. Data residency is a Premium option (10 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks stay small. No field selection was found (15 of 25). Page-number pagination with totals in `list_info`, and a `query` search language over title, signer, sender, dates, completion state and metadata. The docs warn of a short indexing delay after creation (18 of 20). Errors carry `error_name` and `error_msg`, with 20 documented names, a remediation line each and a retryable flag, plus warnings in successful responses (20). No idempotency keys in the docs or spec, so a retried send can create a duplicate. Cancel returns 200 when queued and confirms by event. The retryable flags are the only safe-retry aid (4 of 20). A template send needs only `template_ids` and `signers`, `test_mode` is a single flag, and official SDKs cover six languages (15).",
            "maintenance": "SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, among them a new Document Field Detection endpoint (30). Dated changelog entries on 31 July, 19 August and 3 September 2026, plus SDK 1.12.0 and 1.13.0 on 10 September (20). A closed service with a public changelog, an API support address (apisupport@hellosign.com), a help centre and public GitHub issues, nine open on the spec repository. We didn't test response times (11 of 15). Current official SDKs for Python, Node, PHP, Java, Ruby and .NET, all pushed in September 2026 (15). CI in the spec repository builds the spec and each SDK and fails on uncommitted generated code, and Node dependencies were upgraded on 6 October (9 of 10).",
            "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, Essentials at $900 a year from 50 requests a month and Standard at $3,000 a year from 100, with larger volumes on a selector and Premium by quote. That is plan pricing, not a per-request price (10 of 20). Test mode is free on every endpoint from a free account, but its requests aren't legally binding, and the pages we read don't say whether signup needs a card (15 of 20). A person has to create the account and copy the key from the web app, and production needs a paid plan (0).",
            "reliability": "Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. status.hellosign.com on Statuspage lists 13 components in four groups with incident history (20). Two incidents in the 90 days to 7 October 2026, both marked minor, a Salesforce integration fault on 21 August (6 h 43 min) and file upload problems on 31 August (54 min). The last major incident was an outage on 2 January 2026 (3 h 12 min), outside the window (20 of 30). Rate limits with numbers, 100 requests a minute standard, 25 on 17 higher-tier endpoints and 10 in test mode, although the header table describes the limit as hourly (15). The docs describe 429 with `X-Ratelimit` headers, tell clients to respect Retry-After and back off, and the error catalogue marks each error retryable or not. No idempotency keys or safe-retry guidance for sends were found (10 of 15). The terms supply the service as is and as available, and no SLA was found (0). The API is at v3 and generally available (10).",
            "schema": "One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SDKs (25). llms.txt at developers.hellosign.com, a Markdown copy of each page by appending .md, and scoped llms-full.txt files by section and language (10). Operation descriptions average about 220 characters and several state consequences, such as cancel being irreversible and asynchronous. A glossary written for models covers core objects, signers, fields and workflows. Few descriptions say when not to use an endpoint (14 of 20). 67 enums, 239 required lists and about 80 length or range constraints. Sends are multipart forms with indexed keys, and `metadata` and `custom_fields` are loosely typed (11 of 15). Request and response examples with SDK samples in six languages, and a catalogue of 20 HTTP error names with cause, remediation and a retryable flag, embedded in the spec as `x-error-codes` (15). The path carries v3 and a dated changelog has 48 entries since November 2022. No written API versioning policy was found beyond the SDK one (13 of 15).",
            "security": "API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. OAuth 2.0 tokens carry seven scopes but serve apps acting for other users and need support approval. Scored between plain revocable keys and scoped OAuth (25), less 5 because the docs show the key inside the URL as `https://KEY:@api.hellosign.com`, a judgement call since that is URL userinfo, not a query string (20 of 30). The limited OAuth scopes and test mode narrow what a call can do, but there is no read-only key and no confirmation step on cancel, remove or template delete (9 of 20). Responses can carry signer-entered field values and decline reasons, and no injection guidance was found (5 of 15). The API Dashboard records the account's API requests, responses and callbacks, live and test, and each completed document carries an audit trail with timestamps, IP addresses and a SHA-256 hash (13 of 15). SOC 2 Type II, ISO 27001 and ISO 27018 at trust.dropbox.com, a bug bounty and disclosure programme on Intigriti, and webhook HMAC verification. No standard security.txt on the Sign hosts (18 of 20).",
            "transparency": "The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). The terms let Dropbox delete customer data any time after 30 days from termination. The data processing agreement, dated 25 October 2021, promises deletion within a commercially reasonable period on request and still points to a hellosign.com sub-processor address. The privacy policy of 14 January 2025 gives no retention period. The documents agree but stay vague (18 of 30). Prior SDK major versions are patched for 12 months and the API returns a `deprecated_parameter` warning, but no API deprecation policy with notice periods was found (8 of 20). The privacy policy links a Sign sub-processor list and the agreement promises advance notice of new sub-processors with a 60-day objection window. The list itself returned only its title to our reader, so names and locations are unconfirmed. Data residency is a Premium option (10 of 20)."
          },
          "sources": [
            {
              "what": "API product page",
              "url": "https://sign.dropbox.com/features/api",
              "seen": "2026-10-07"
            },
            {
              "what": "API pricing",
              "url": "https://sign.dropbox.com/products/dropbox-sign-api/pricing",
              "seen": "2026-10-07"
            },
            {
              "what": "llms.txt and docs index",
              "url": "https://developers.hellosign.com/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "docs overview, test mode, plans by endpoint and rate limits",
              "url": "https://developers.hellosign.com/docs/overview",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication and key rotation",
              "url": "https://developers.hellosign.com/api/api-reference-authentication",
              "seen": "2026-10-07"
            },
            {
              "what": "OAuth overview and scopes",
              "url": "https://developers.hellosign.com/docs/guides/o-auth/overview",
              "seen": "2026-10-07"
            },
            {
              "what": "app approval",
              "url": "https://developers.hellosign.com/docs/guides/app-approval/overview",
              "seen": "2026-10-07"
            },
            {
              "what": "self-publishing API apps",
              "url": "https://developers.hellosign.com/docs/guides/app-approval/self-publish",
              "seen": "2026-10-07"
            },
            {
              "what": "warnings and errors",
              "url": "https://developers.hellosign.com/api/manual-reference-pages/warnings-and-errors",
              "seen": "2026-10-07"
            },
            {
              "what": "events walkthrough, verification and retries",
              "url": "https://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough",
              "seen": "2026-10-07"
            },
            {
              "what": "security and compliance glossary, audit trail and quotas",
              "url": "https://developers.hellosign.com/api/manual-reference-pages/glossary/security-compliance",
              "seen": "2026-10-07"
            },
            {
              "what": "search on list endpoints",
              "url": "https://developers.hellosign.com/api/manual-reference-pages/search",
              "seen": "2026-10-07"
            },
            {
              "what": "API Dashboard guide",
              "url": "https://developers.hellosign.com/docs/guides/api-dashboard",
              "seen": "2026-10-07"
            },
            {
              "what": "SDK overview",
              "url": "https://developers.hellosign.com/docs/sdks/overview",
              "seen": "2026-10-07"
            },
            {
              "what": "SDK versioning policy",
              "url": "https://developers.hellosign.com/docs/sdks/versioning-policy",
              "seen": "2026-10-07"
            },
            {
              "what": "changelog",
              "url": "https://developers.hellosign.com/changelog",
              "seen": "2026-10-07"
            },
            {
              "what": "quickstart",
              "url": "https://developers.hellosign.com/api/api-quickstart",
              "seen": "2026-10-07"
            },
            {
              "what": "docs MCP server (initialize and tools/list)",
              "url": "https://developers.hellosign.com/_mcp/server",
              "seen": "2026-10-07"
            },
            {
              "what": "OpenAPI spec and SDK source repository",
              "url": "https://github.com/hellosign/hellosign-openapi",
              "seen": "2026-10-07"
            },
            {
              "what": "vendor repositories",
              "url": "https://api.github.com/orgs/hellosign/repos?per_page=100\u0026sort=pushed",
              "seen": "2026-10-07"
            },
            {
              "what": "npm package",
              "url": "https://registry.npmjs.org/@dropbox/sign",
              "seen": "2026-10-07"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@dropbox/sign",
              "seen": "2026-10-07"
            },
            {
              "what": "PyPI package",
              "url": "https://pypi.org/pypi/dropbox-sign/json",
              "seen": "2026-10-07"
            },
            {
              "what": "status page summary",
              "url": "https://status.hellosign.com/api/v2/summary.json",
              "seen": "2026-10-07"
            },
            {
              "what": "status incident history",
              "url": "https://status.hellosign.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "trust page",
              "url": "https://sign.dropbox.com/trust",
              "seen": "2026-10-07"
            },
            {
              "what": "trust centre",
              "url": "https://trust.dropbox.com/?product=dropboxsign",
              "seen": "2026-10-07"
            },
            {
              "what": "terms of service",
              "url": "https://sign.dropbox.com/about/terms",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy policy",
              "url": "https://sign.dropbox.com/about/privacy",
              "seen": "2026-10-07"
            },
            {
              "what": "data processing agreement",
              "url": "https://assets.dropbox.com/documents/en/legal/hs-data-processing-agreement.pdf",
              "seen": "2026-10-07"
            },
            {
              "what": "security.txt on the Sign host (404)",
              "url": "https://sign.dropbox.com/.well-known/security.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "security.txt on dropbox.com",
              "url": "https://www.dropbox.com/.well-known/security.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=dropbox",
              "seen": "2026-10-07"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.verisign.com/com/v1/domain/hellosign.com",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the Sign sub-processor list at www.dropbox.com/privacy/subprocessor/sign, which returned only its title to our reader, so names and locations are unconfirmed.",
            "unchecked: PyPI weekly downloads for dropbox-sign. pypistats.org refused us for a rate limit.",
            "unchecked: whether creating a free account for test mode needs a card. The docs and pricing page don't say and we didn't sign up.",
            "unchecked: prices at the 250, 500 and 750+ steps of the pricing selector, and the month-to-month price. The static page showed $75 and $250 a month beside $900 and $3,000 a year.",
            "unchecked: documents in the trust centre beyond the public summary, such as the SOC 2 report and penetration test summary.",
            "The rate-limit docs give per-minute limits, describe `X-Ratelimit-Limit` as hourly and show an example message of 2,000 an hour. Which window applies wasn't established.",
            "The glossary says 429 responses carry Retry-After, while the main rate-limit section lists only the `X-Ratelimit` headers. We didn't trigger a 429 to confirm.",
            "No SLA was found for any plan in the terms or on the pricing page. A Premium contract may include one.",
            "No vendor MCP server for signing was found. The registry entry io.usefulapi/dropbox-sign is third-party and wasn't graded."
          ]
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation.",
        "bestFor": "An agent that sends a prepared PDF or a saved template for signature from one company account and tracks it to completion by webhook or polling, with the signed PDF and audit trail at the end.",
        "strengths": [
          "Public OpenAPI 3.0.3 spec with 74 operations, plus llms.txt and a Markdown copy of every docs page",
          "Free test mode works on every endpoint from a free account, with watermarked, non-binding requests that don't count against quota",
          "Error catalogue of 20 HTTP error names with cause, remediation and a retryable flag, also embedded in the spec as `x-error-codes`",
          "Rate limits published with numbers (100 a minute standard, 25 on higher-tier endpoints, 10 in test mode) and returned in response headers",
          "Official SDKs in six languages at version 1.13.0, released 10 September 2026, with semantic versioning"
        ],
        "weaknesses": [
          "No idempotency keys found in the docs or the spec, so a retried send can create a second signature request",
          "An API key grants full access to the account, with no scoped or read-only keys. Scopes exist only on OAuth tokens",
          "OAuth apps need manual approval by Dropbox Sign support before production use",
          "The terms supply the service as is, and no SLA was found. A major outage on 2 January 2026 lasted 3 hours 12 minutes",
          "Embedded signing and bulk send need the Standard plan ($3,000 a year), and embedded templates need Premium, priced by quote"
        ],
        "agentNotes": [
          "Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute",
          "Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created",
          "Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form",
          "Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL",
          "Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.9
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 85,
          "payments": 25,
          "reliability": 75,
          "schema": 88,
          "security": 65,
          "transparency": 51
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "npm install @dropbox/sign",
        "http": "curl \"https://api.hellosign.com/v3/template/list\" \\\n    -u \"${API_KEY}:\""
      },
      "letme": {
        "capability": "https://letme.dev/esign.send",
        "tool": "https://letme.dev/dropbox-sign"
      },
      "notable": [
        "The API answers at https://api.hellosign.com/v3 and is described by one OpenAPI 3.0.3 spec with 68 paths and 74 operations, covering signature requests, templates, embedded URLs, unclaimed drafts, bulk send, teams, API apps, reports and fax (https://github.com/hellosign/hellosign-openapi)",
        "Test mode works on every endpoint from a free account. Test requests are watermarked, not legally binding and don't count against quota (https://developers.hellosign.com/docs/overview)",
        "Rate limits are 100 requests a minute for standard calls, 25 a minute for 17 higher-tier endpoints such as send and file download, and 10 a minute in test mode (https://developers.hellosign.com/docs/overview)",
        "Webhooks cover 23 event types, carry an HMAC-SHA256 `event_hash` keyed on the primary API key, retry up to six times and clear the callback URL after ten consecutive failures (https://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough)",
        "The docs site runs an MCP server at https://developers.hellosign.com/_mcp/server with one read-only tool, searchDocs. It searches documentation and can't send or read signature requests (https://developers.hellosign.com/llms.txt)",
        "No vendor MCP server for the signing product was found. The official MCP registry lists io.usefulapi/dropbox-sign, a third-party server (https://registry.modelcontextprotocol.io/v0/servers?search=dropbox)",
        "The completed PDF carries an audit trail with timestamps, signer IP addresses and a SHA-256 document hash (https://developers.hellosign.com/api/manual-reference-pages/glossary/security-compliance)",
        "status.hellosign.com lists two minor incidents in the last 90 days, a Salesforce integration fault on 21 August 2026 and file upload problems on 31 August 2026 (https://status.hellosign.com/history)"
      ],
      "area": "business",
      "details": [
        {
          "label": "API",
          "value": "REST at https://api.hellosign.com/v3, OpenAPI 3.0.3, 68 paths and 74 operations. Signature Request 20, Template 11, Team 10, Fax Line 7, API App 5, Fax 5, Account 4, Unclaimed Draft 4, and others"
        },
        {
          "label": "Credentials",
          "value": "API key over HTTP Basic, up to four keys an account, full account access. OAuth 2.0 Bearer tokens with scopes basic_account_info and request_signature (app owner billed) or account_access, signature_request_access, template_access, team_access and api_app_access (user billed)"
        },
        {
          "label": "Going to production",
          "value": "Non-embedded sending needs only a paid plan. Embedded apps are self-published in the web app (up to 10 apps). OAuth apps need review by support"
        },
        {
          "label": "Test mode",
          "value": "`test_mode=true` on any endpoint, free, watermarked and not legally binding, 10 requests a minute, not counted against quota"
        },
        {
          "label": "Plans",
          "value": "Essentials $900 a year from 50 requests a month, 5 templates. Standard $3,000 a year from 100 requests a month, 15 templates, adds bulk send and embedded signing and requesting. Premium by quote, adds embedded templates, data residency and multiple domains (https://sign.dropbox.com/products/dropbox-sign-api/pricing)"
        },
        {
          "label": "Rate limits",
          "value": "100 requests a minute standard, 25 a minute on 17 higher-tier endpoints, 10 a minute in test mode. `X-Ratelimit-Limit`, `X-Ratelimit-Limit-Remaining` and `X-Ratelimit-Reset` headers. 429 with error name `exceeded_rate`"
        },
        {
          "label": "Errors",
          "value": "20 HTTP error names with status, cause, remediation and a retryable flag (yes, no or conditional), 10 OAuth error names and 5 asynchronous error events, in the docs and in the spec as `x-error-codes`, `x-oauth-error-codes` and `x-error-events`"
        },
        {
          "label": "Webhooks",
          "value": "Account and app callbacks, 23 event types, multipart POST. The receiver answers 200 with `Hello API Event Received`. HMAC-SHA256 `event_hash`, a published IP range file, six retries, 30-second timeout, callback URL cleared after ten consecutive failures"
        },
        {
          "label": "Lists",
          "value": "`page` and `page_size` (1 to 100, default 20) with a `query` search language over fields such as title, to, from, created, complete, declined and metadata"
        },
        {
          "label": "SDKs",
          "value": "Python dropbox-sign, Node @dropbox/sign, PHP, Java, Ruby and .NET, generated from the OpenAPI spec, version 1.13.0 on 10 September 2026, MIT. Prior major versions patched for 12 months"
        },
        {
          "label": "Docs MCP",
          "value": "https://developers.hellosign.com/_mcp/server (fern-docs-mcp-server 1.0.0), one tool, searchDocs, marked readOnlyHint. Documentation search only"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II, SOC 3, ISO 27001, ISO 27018, HIPAA, PCI DSS and eIDAS listed at trust.dropbox.com. Bug bounty and disclosure programme on Intigriti"
        },
        {
          "label": "Status",
          "value": "status.hellosign.com on Statuspage, 13 components in four groups (Core, Web, API, Integrations) with incident history"
        }
      ],
      "provenance": {
        "legalEntity": "Dropbox, Inc.",
        "domain": "hellosign.com",
        "domainRegistered": "2004-03-05",
        "endpointOnVendorDomain": true,
        "terms": "https://sign.dropbox.com/about/terms",
        "privacy": "https://sign.dropbox.com/about/privacy",
        "statusPage": "https://status.hellosign.com",
        "changelog": "https://developers.hellosign.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Dropbox Sign terms (effective 7 January 2025) put the agreement with Dropbox, Inc. for customers in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere.",
          "The API host is api.hellosign.com and the docs are at developers.hellosign.com. The marketing site is sign.dropbox.com. RDAP gives 2004-03-05 for hellosign.com and 1995-06-28 for dropbox.com.",
          "sign.dropbox.com/.well-known/security.txt and api.hellosign.com/.well-known/security.txt return 404. www.dropbox.com/.well-known/security.txt serves a plain-text file that names the Intigriti bug bounty and disclosure programmes without the standard Contact and Expires fields.",
          "The privacy policy is dated 14 January 2025. The data processing agreement at assets.dropbox.com is dated 25 October 2021.",
          "The sub-processor list at www.dropbox.com/privacy/subprocessor/sign returned only its title to our reader."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Dropbox, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "hellosign.com, registered 2004-03-05 (22 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.hellosign.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.hellosign.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://sign.dropbox.com/about/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-01-07",
            "words": 7791,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Posted: January 7, 2025",
                "says": "Last updated 2025-01-07"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These terms will be interpreted, construed, and enforced in all respects in accordance with the local laws of the State of California, U.S.A., without reference to its choice of law rules to the contrary.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "DROPBOX’S AND ITS SUPPLIERS’ TOTAL LIABILITY WILL NOT EXCEED IN AGGREGATE THE AMOUNT ACTUALLY PAID BY CUSTOMER TO DROPBOX FOR THE APPLICABLE DROPBOX SIGN SERVICES OR RELATED SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Dropbox may terminate Customer’s right to use any Free Access Subscriptions or Beta Releases at any time for any reason or no reason in Dropbox’s sole discretion, without liability."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You must have the authority to bind that organization to these terms, otherwise you must not sign up for the Dropbox Sign Services."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Nevertheless, and without limiting the other disclaimers and limitations in these Terms, CUSTOMER AGREES THAT ANY FREE ACCESS SUBSCRIPTION OR BETA RELEASES ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS WITHOUT ANY WARRANTY, SUPPORT, MAINTENANCE, STORAGE, SLA, OR INDEMNITY OBLIGATIONS OF ANY KIND."
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "access the Dropbox Sign Services for the purpose of building a competitive product or service or copying its features or user interface;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We reserve the right to change the prices, features, or options included in a particular Subscription Plan without notice, provided that such changes shall not take effect until your next applicable Subscription Term (as defined below).‍",
                "costsPoints": true
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "WAIVER OF CLASS ACTIONS."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "After termination the customer loses access to Customer Data, and Dropbox may delete it at any time after 30 days.",
                "quote": "Customer’s right to access any Customer Data in the applicable Dropbox Sign Services will cease and Dropbox may delete the Customer Data at any time after 30 days from the date of termination."
              },
              {
                "date": "2026-10-08",
                "text": "A customer that exceeds its plan's usage limits is upgraded automatically to the next highest plan and must pay for it.",
                "quote": "If Customer exceeds their Subscription Plan’s usage limits, Customer will be automatically upgraded into the next highest Subscription Plan and Customer expressly acknowledges and agrees that it will pay for the upgraded Subscription Plan."
              },
              {
                "date": "2026-10-08",
                "text": "Renewals are priced at Dropbox's rates in force at the time of renewal.",
                "quote": "Pricing for any Subscription Term renewal, new order form, or order form changes will be at Dropbox’s then-applicable rates."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://sign.dropbox.com/about/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-01-14",
            "words": 3675,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Posted: January 14, 2025",
                "says": "Last updated 2025-01-14"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "When registering for or using the Dropbox Sign Services we collect personal information provided by you."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We will retain your personal information for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law, for legal, tax or regulatory reasons, or other lawful purposes."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may share and/or collect additional information about you from third parties primarily to assist us in understanding how we can maintain and improve the services we offer to better serve you."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "If you wish to opt out of interest-based advertising, click www.aboutads.info/choices [or if located in the European Union click www.youronlinechoices.eu]."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Dropbox acknowledges that you have the right to access your personal information."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions about the security of your personal information, you can contact us at privacy@dropbox.com.‍",
                "says": "privacy@dropbox.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "When transferring data from the European Union, the European Economic Area, the United Kingdom, and Switzerland, Dropbox relies upon a variety of legal mechanisms, such as contracts with our customers and affiliates, Standard Contractual Clauses, the EU-U.S.",
                "says": "Relies on standard contractual clauses"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/dropbox-sign.json",
      "live": {
        "slug": "dropbox-sign",
        "probe": {
          "target": "https://api.hellosign.com/v3",
          "method": "get",
          "lastAt": "2026-10-08T17:36:34.934414884Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 138,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 143,
          "p95ms24h": 306,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hellosign.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T17:38:49.334914583Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@dropbox/sign",
            "version": "1.13.0",
            "seenAt": "2026-10-08T16:09:21.702754102Z"
          },
          {
            "registry": "pypi",
            "name": "dropbox-sign",
            "version": "1.13.0",
            "released": "2026-09-10",
            "seenAt": "2026-10-08T16:09:25.156865046Z"
          }
        ],
        "githubStars": 22,
        "npmWeekly": 149738,
        "pypiWeekly": 73874,
        "securityTxt": {
          "url": "https://hellosign.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:08.009752876Z"
        },
        "updatedAt": "2026-10-08T17:38:49.334914583Z"
      }
    },
    "verify": {
      "accepts": "a page on hellosign.com or sign.dropbox.com or one of their subdomains, or the README of github.com/hellosign/hellosign-openapi",
      "badgeUrl": "https://www.anchorterminal.com/badges/dropbox-sign.svg",
      "body": {
        "slug": "dropbox-sign",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/dropbox-sign",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/dropbox-sign\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/dropbox-sign.svg\" alt=\"Dropbox Sign on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Dropbox Sign on Anchor Terminal](https://www.anchorterminal.com/badges/dropbox-sign.svg)](https://www.anchorterminal.com/tools/dropbox-sign)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/dropbox-sign\"\u003eDropbox Sign on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/dropbox-sign",
    "json": "https://www.anchorterminal.com/tools/dropbox-sign.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/dropbox-sign.md",
    "slim": "https://www.anchorterminal.com/tools/dropbox-sign.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 68.9/100 · rank #161 of 629 · #1 in Contracts, proposals \u0026 e-signatures · not agent-ready · confidence medium**\n\n\n## Assessment\n\nA public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Dropbox, Inc. (https://sign.dropbox.com) |\n| Kind | HTTP API |\n| Category | Contracts, proposals \u0026 e-signatures (https://www.anchorterminal.com/categories/e-signatures) |\n| Transport | HTTP |\n| Endpoint | `https://api.hellosign.com/v3` |\n| Auth | OAuth or key · A self-serve API key from the account's API settings page, sent as the HTTP Basic username with an empty password. Each account can hold up to four keys for rotation, and every key has full access to the account. OAuth 2.0 access tokens (Bearer) act on behalf of other users with seven scopes across two billing models, and OAuth apps need approval by Dropbox Sign support before production. Embedded apps can be self-published in the web app. |\n| Pricing | Paid (Paid) · Production signature requests need a paid API plan, and the API answers 402 without one. Essentials is $900 a year ($75 a month) from 50 requests a month, Standard $3,000 a year ($250 a month) from 100, and Premium is quoted by sales. Test mode is free on every endpoint from a free account, so an agent can build and test without a contract (checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT |\n| Packages | npm: `@dropbox/sign`; pypi: `dropbox-sign` |\n| Source | https://github.com/hellosign/hellosign-openapi |\n| Docs | https://developers.hellosign.com |\n| llms.txt | https://developers.hellosign.com/llms.txt |\n| Last release | 2026-09-10 |\n| GitHub stars | 22 (as of 2026-10-07) |\n| npm downloads / week | 149,738 |\n| API | REST at https://api.hellosign.com/v3, OpenAPI 3.0.3, 68 paths and 74 operations. Signature Request 20, Template 11, Team 10, Fax Line 7, API App 5, Fax 5, Account 4, Unclaimed Draft 4, and others |\n| Credentials | API key over HTTP Basic, up to four keys an account, full account access. OAuth 2.0 Bearer tokens with scopes basic_account_info and request_signature (app owner billed) or account_access, signature_request_access, template_access, team_access and api_app_access (user billed) |\n| Going to production | Non-embedded sending needs only a paid plan. Embedded apps are self-published in the web app (up to 10 apps). OAuth apps need review by support |\n| Test mode | `test_mode=true` on any endpoint, free, watermarked and not legally binding, 10 requests a minute, not counted against quota |\n| Plans | Essentials $900 a year from 50 requests a month, 5 templates. Standard $3,000 a year from 100 requests a month, 15 templates, adds bulk send and embedded signing and requesting. Premium by quote, adds embedded templates, data residency and multiple domains (https://sign.dropbox.com/products/dropbox-sign-api/pricing) |\n| Rate limits | 100 requests a minute standard, 25 a minute on 17 higher-tier endpoints, 10 a minute in test mode. `X-Ratelimit-Limit`, `X-Ratelimit-Limit-Remaining` and `X-Ratelimit-Reset` headers. 429 with error name `exceeded_rate` |\n| Errors | 20 HTTP error names with status, cause, remediation and a retryable flag (yes, no or conditional), 10 OAuth error names and 5 asynchronous error events, in the docs and in the spec as `x-error-codes`, `x-oauth-error-codes` and `x-error-events` |\n| Webhooks | Account and app callbacks, 23 event types, multipart POST. The receiver answers 200 with `Hello API Event Received`. HMAC-SHA256 `event_hash`, a published IP range file, six retries, 30-second timeout, callback URL cleared after ten consecutive failures |\n| Lists | `page` and `page_size` (1 to 100, default 20) with a `query` search language over fields such as title, to, from, created, complete, declined and metadata |\n| SDKs | Python dropbox-sign, Node @dropbox/sign, PHP, Java, Ruby and .NET, generated from the OpenAPI spec, version 1.13.0 on 10 September 2026, MIT. Prior major versions patched for 12 months |\n| Docs MCP | https://developers.hellosign.com/_mcp/server (fern-docs-mcp-server 1.0.0), one tool, searchDocs, marked readOnlyHint. Documentation search only |\n| Certifications | SOC 2 Type II, SOC 3, ISO 27001, ISO 27018, HIPAA, PCI DSS and eIDAS listed at trust.dropbox.com. Bug bounty and disclosure programme on Intigriti |\n| Status | status.hellosign.com on Statuspage, 13 components in four groups (Core, Web, API, Integrations) with incident history |\n| Capabilities | esign.send, esign.templates, esign.embed, esign.status |\n| Tags | hosted, closed-source, api-key, oauth, openapi, llms-txt, webhooks, sandbox, python, typescript, java, php, ruby, dotnet, status-page, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 75 | 15.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 88 | 14.3 |\n| Agent ergonomics | 13% | 16.2 | 72 | 11.7 |\n| Security \u0026 auth | 14% | 17.5 | 65 | 11.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 25 | 3.1 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 85 | 7.4 |\n| Transparency \u0026 trust (editorial 51, provenance 85) | 7% | 8.8 | 68 | 6.0 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **68.9 → B** |\n\n### Why each score\n\n- Reliability 75: Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. status.hellosign.com on Statuspage lists 13 components in four groups with incident history (20). Two incidents in the 90 days to 7 October 2026, both marked minor, a Salesforce integration fault on 21 August (6 h 43 min) and file upload problems on 31 August (54 min). The last major incident was an outage on 2 January 2026 (3 h 12 min), outside the window (20 of 30). Rate limits with numbers, 100 requests a minute standard, 25 on 17 higher-tier endpoints and 10 in test mode, although the header table describes the limit as hourly (15). The docs describe 429 with `X-Ratelimit` headers, tell clients to respect Retry-After and back off, and the error catalogue marks each error retryable or not. No idempotency keys or safe-retry guidance for sends were found (10 of 15). The terms supply the service as is and as available, and no SLA was found (0). The API is at v3 and generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 88: One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SDKs (25). llms.txt at developers.hellosign.com, a Markdown copy of each page by appending .md, and scoped llms-full.txt files by section and language (10). Operation descriptions average about 220 characters and several state consequences, such as cancel being irreversible and asynchronous. A glossary written for models covers core objects, signers, fields and workflows. Few descriptions say when not to use an endpoint (14 of 20). 67 enums, 239 required lists and about 80 length or range constraints. Sends are multipart forms with indexed keys, and `metadata` and `custom_fields` are loosely typed (11 of 15). Request and response examples with SDK samples in six languages, and a catalogue of 20 HTTP error names with cause, remediation and a retryable flag, embedded in the spec as `x-error-codes` (15). The path carries v3 and a dated changelog has 48 entries since November 2022. No written API versioning policy was found beyond the SDK one (13 of 15).\n- Agent ergonomics 72: List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks stay small. No field selection was found (15 of 25). Page-number pagination with totals in `list_info`, and a `query` search language over title, signer, sender, dates, completion state and metadata. The docs warn of a short indexing delay after creation (18 of 20). Errors carry `error_name` and `error_msg`, with 20 documented names, a remediation line each and a retryable flag, plus warnings in successful responses (20). No idempotency keys in the docs or spec, so a retried send can create a duplicate. Cancel returns 200 when queued and confirms by event. The retryable flags are the only safe-retry aid (4 of 20). A template send needs only `template_ids` and `signers`, `test_mode` is a single flag, and official SDKs cover six languages (15).\n- Security \u0026 auth 65: API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. OAuth 2.0 tokens carry seven scopes but serve apps acting for other users and need support approval. Scored between plain revocable keys and scoped OAuth (25), less 5 because the docs show the key inside the URL as `https://KEY:@api.hellosign.com`, a judgement call since that is URL userinfo, not a query string (20 of 30). The limited OAuth scopes and test mode narrow what a call can do, but there is no read-only key and no confirmation step on cancel, remove or template delete (9 of 20). Responses can carry signer-entered field values and decline reasons, and no injection guidance was found (5 of 15). The API Dashboard records the account's API requests, responses and callbacks, live and test, and each completed document carries an audit trail with timestamps, IP addresses and a SHA-256 hash (13 of 15). SOC 2 Type II, ISO 27001 and ISO 27018 at trust.dropbox.com, a bug bounty and disclosure programme on Intigriti, and webhook HMAC verification. No standard security.txt on the Sign hosts (18 of 20).\n- Payments \u0026 pricing 25: Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, Essentials at $900 a year from 50 requests a month and Standard at $3,000 a year from 100, with larger volumes on a selector and Premium by quote. That is plan pricing, not a per-request price (10 of 20). Test mode is free on every endpoint from a free account, but its requests aren't legally binding, and the pages we read don't say whether signup needs a card (15 of 20). A person has to create the account and copy the key from the web app, and production needs a paid plan (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 85: SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, among them a new Document Field Detection endpoint (30). Dated changelog entries on 31 July, 19 August and 3 September 2026, plus SDK 1.12.0 and 1.13.0 on 10 September (20). A closed service with a public changelog, an API support address (apisupport@hellosign.com), a help centre and public GitHub issues, nine open on the spec repository. We didn't test response times (11 of 15). Current official SDKs for Python, Node, PHP, Java, Ruby and .NET, all pushed in September 2026 (15). CI in the spec repository builds the spec and each SDK and fails on uncommitted generated code, and Node dependencies were upgraded on 6 October (9 of 10).\n- Transparency \u0026 trust 68: The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). The terms let Dropbox delete customer data any time after 30 days from termination. The data processing agreement, dated 25 October 2021, promises deletion within a commercially reasonable period on request and still points to a hellosign.com sub-processor address. The privacy policy of 14 January 2025 gives no retention period. The documents agree but stay vague (18 of 30). Prior SDK major versions are patched for 12 months and the API returns a `deprecated_parameter` warning, but no API deprecation policy with notice periods was found (8 of 20). The privacy policy links a Sign sub-processor list and the agreement promises advance notice of new sub-processors with a 60-day objection window. The list itself returned only its title to our reader, so names and locations are unconfirmed. Data residency is a Premium option (10 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/dropbox-sign.md (JSON https://www.anchorterminal.com/fixes/dropbox-sign.json)\n\n### What we couldn't check\n\n- unchecked: the Sign sub-processor list at www.dropbox.com/privacy/subprocessor/sign, which returned only its title to our reader, so names and locations are unconfirmed.\n- unchecked: PyPI weekly downloads for dropbox-sign. pypistats.org refused us for a rate limit.\n- unchecked: whether creating a free account for test mode needs a card. The docs and pricing page don't say and we didn't sign up.\n- unchecked: prices at the 250, 500 and 750+ steps of the pricing selector, and the month-to-month price. The static page showed $75 and $250 a month beside $900 and $3,000 a year.\n- unchecked: documents in the trust centre beyond the public summary, such as the SOC 2 report and penetration test summary.\n- The rate-limit docs give per-minute limits, describe `X-Ratelimit-Limit` as hourly and show an example message of 2,000 an hour. Which window applies wasn't established.\n- The glossary says 429 responses carry Retry-After, while the main rate-limit section lists only the `X-Ratelimit` headers. We didn't trigger a 429 to confirm.\n- No SLA was found for any plan in the terms or on the pricing page. A Premium contract may include one.\n- No vendor MCP server for signing was found. The registry entry io.usefulapi/dropbox-sign is third-party and wasn't graded.\n\n### Sources\n\n- API product page: \u003chttps://sign.dropbox.com/features/api\u003e (seen 2026-10-07)\n- API pricing: \u003chttps://sign.dropbox.com/products/dropbox-sign-api/pricing\u003e (seen 2026-10-07)\n- llms.txt and docs index: \u003chttps://developers.hellosign.com/llms.txt\u003e (seen 2026-10-07)\n- docs overview, test mode, plans by endpoint and rate limits: \u003chttps://developers.hellosign.com/docs/overview\u003e (seen 2026-10-07)\n- authentication and key rotation: \u003chttps://developers.hellosign.com/api/api-reference-authentication\u003e (seen 2026-10-07)\n- OAuth overview and scopes: \u003chttps://developers.hellosign.com/docs/guides/o-auth/overview\u003e (seen 2026-10-07)\n- app approval: \u003chttps://developers.hellosign.com/docs/guides/app-approval/overview\u003e (seen 2026-10-07)\n- self-publishing API apps: \u003chttps://developers.hellosign.com/docs/guides/app-approval/self-publish\u003e (seen 2026-10-07)\n- warnings and errors: \u003chttps://developers.hellosign.com/api/manual-reference-pages/warnings-and-errors\u003e (seen 2026-10-07)\n- events walkthrough, verification and retries: \u003chttps://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough\u003e (seen 2026-10-07)\n- security and compliance glossary, audit trail and quotas: \u003chttps://developers.hellosign.com/api/manual-reference-pages/glossary/security-compliance\u003e (seen 2026-10-07)\n- search on list endpoints: \u003chttps://developers.hellosign.com/api/manual-reference-pages/search\u003e (seen 2026-10-07)\n- API Dashboard guide: \u003chttps://developers.hellosign.com/docs/guides/api-dashboard\u003e (seen 2026-10-07)\n- SDK overview: \u003chttps://developers.hellosign.com/docs/sdks/overview\u003e (seen 2026-10-07)\n- SDK versioning policy: \u003chttps://developers.hellosign.com/docs/sdks/versioning-policy\u003e (seen 2026-10-07)\n- changelog: \u003chttps://developers.hellosign.com/changelog\u003e (seen 2026-10-07)\n- quickstart: \u003chttps://developers.hellosign.com/api/api-quickstart\u003e (seen 2026-10-07)\n- docs MCP server (initialize and tools/list): \u003chttps://developers.hellosign.com/_mcp/server\u003e (seen 2026-10-07)\n- OpenAPI spec and SDK source repository: \u003chttps://github.com/hellosign/hellosign-openapi\u003e (seen 2026-10-07)\n- vendor repositories: \u003chttps://api.github.com/orgs/hellosign/repos?per_page=100\u0026sort=pushed\u003e (seen 2026-10-07)\n- npm package: \u003chttps://registry.npmjs.org/@dropbox/sign\u003e (seen 2026-10-07)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@dropbox/sign\u003e (seen 2026-10-07)\n- PyPI package: \u003chttps://pypi.org/pypi/dropbox-sign/json\u003e (seen 2026-10-07)\n- status page summary: \u003chttps://status.hellosign.com/api/v2/summary.json\u003e (seen 2026-10-07)\n- status incident history: \u003chttps://status.hellosign.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- trust page: \u003chttps://sign.dropbox.com/trust\u003e (seen 2026-10-07)\n- trust centre: \u003chttps://trust.dropbox.com/?product=dropboxsign\u003e (seen 2026-10-07)\n- terms of service: \u003chttps://sign.dropbox.com/about/terms\u003e (seen 2026-10-07)\n- privacy policy: \u003chttps://sign.dropbox.com/about/privacy\u003e (seen 2026-10-07)\n- data processing agreement: \u003chttps://assets.dropbox.com/documents/en/legal/hs-data-processing-agreement.pdf\u003e (seen 2026-10-07)\n- security.txt on the Sign host (404): \u003chttps://sign.dropbox.com/.well-known/security.txt\u003e (seen 2026-10-07)\n- security.txt on dropbox.com: \u003chttps://www.dropbox.com/.well-known/security.txt\u003e (seen 2026-10-07)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=dropbox\u003e (seen 2026-10-07)\n- domain registration (RDAP): \u003chttps://rdap.verisign.com/com/v1/domain/hellosign.com\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 85/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Dropbox, Inc. | 20/20 |\n| Domain age | hellosign.com, registered 2004-03-05 (22 years) | 15/15 |\n| Endpoint on the vendor's domain | api.hellosign.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.hellosign.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Dropbox Sign terms (effective 7 January 2025) put the agreement with Dropbox, Inc. for customers in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere.\n\nThe API host is api.hellosign.com and the docs are at developers.hellosign.com. The marketing site is sign.dropbox.com. RDAP gives 2004-03-05 for hellosign.com and 1995-06-28 for dropbox.com.\n\nsign.dropbox.com/.well-known/security.txt and api.hellosign.com/.well-known/security.txt return 404. www.dropbox.com/.well-known/security.txt serves a plain-text file that names the Intigriti bug bounty and disclosure programmes without the standard Contact and Expires fields.\n\nThe privacy policy is dated 14 January 2025. The data processing agreement at assets.dropbox.com is dated 25 October 2021.\n\nThe sub-processor list at www.dropbox.com/privacy/subprocessor/sign returned only its title to our reader.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://sign.dropbox.com/about/terms), read 2026-10-08, dated 2025-01-07, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"access the Dropbox Sign Services for the purpose of building a competitive product or service or copying its features or user interface;\"\n- To know. Says the terms or the service can change without notice (costs points). \"We reserve the right to change the prices, features, or options included in a particular Subscription Plan without notice, provided that such changes shall not take effect until your next applicable Subscription Term (as defined below).‍\"\n- To know. Requires arbitration or waives class actions. \"WAIVER OF CLASS ACTIONS.\"\n- Gives the date it was last updated. Last updated 2025-01-07.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). After termination the customer loses access to Customer Data, and Dropbox may delete it at any time after 30 days. \"Customer’s right to access any Customer Data in the applicable Dropbox Sign Services will cease and Dropbox may delete the Customer Data at any time after 30 days from the date of termination.\"\n- Also in the text (2026-10-08). A customer that exceeds its plan's usage limits is upgraded automatically to the next highest plan and must pay for it. \"If Customer exceeds their Subscription Plan’s usage limits, Customer will be automatically upgraded into the next highest Subscription Plan and Customer expressly acknowledges and agrees that it will pay for the upgraded Subscription Plan.\"\n- Also in the text (2026-10-08). Renewals are priced at Dropbox's rates in force at the time of renewal. \"Pricing for any Subscription Term renewal, new order form, or order form changes will be at Dropbox’s then-applicable rates.\"\n\n**Privacy policy** (https://sign.dropbox.com/about/privacy), read 2026-10-08, dated 2025-01-14, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-01-14.\n- Gives a privacy contact. privacy@dropbox.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n\n## Live (updated 2026-10-08 17:38 UTC)\n\n- Right now: up, HTTP 404, 138 ms, checked 2026-10-08 17:36 UTC (get on `https://api.hellosign.com/v3`)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 143 ms · p95 306 ms\n- Vendor status page: none, All Systems Operational\n- npm `@dropbox/sign` 1.13.0\n- pypi `dropbox-sign` 1.13.0, released 2026-09-10\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/dropbox-sign.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Public OpenAPI 3.0.3 spec with 74 operations, plus llms.txt and a Markdown copy of every docs page\n- Free test mode works on every endpoint from a free account, with watermarked, non-binding requests that don't count against quota\n- Error catalogue of 20 HTTP error names with cause, remediation and a retryable flag, also embedded in the spec as `x-error-codes`\n- Rate limits published with numbers (100 a minute standard, 25 on higher-tier endpoints, 10 in test mode) and returned in response headers\n- Official SDKs in six languages at version 1.13.0, released 10 September 2026, with semantic versioning\n\n## Weaknesses\n\n- No idempotency keys found in the docs or the spec, so a retried send can create a second signature request\n- An API key grants full access to the account, with no scoped or read-only keys. Scopes exist only on OAuth tokens\n- OAuth apps need manual approval by Dropbox Sign support before production use\n- The terms supply the service as is, and no SLA was found. A major outage on 2 January 2026 lasted 3 hours 12 minutes\n- Embedded signing and bulk send need the Standard plan ($3,000 a year), and embedded templates need Premium, priced by quote\n\n## Before you call it (notes for agents)\n\n1. Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute\n2. Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created\n3. Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form\n4. Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL\n5. Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @dropbox/sign\n```\n\nFirst request:\n\n```bash\ncurl \"https://api.hellosign.com/v3/template/list\" \\\n    -u \"${API_KEY}:\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/dropbox-sign (letme picks it for esign.embed, the top-graded tool for the job, letme picks it for esign.send, the top-graded tool for the job, letme picks it for esign.status, the top-graded tool for the job, letme picks it for esign.templates, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| airSlate SignNow | B | 68.5 | 168 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/signnow.md |\n| PandaDoc | B | 63.1 | 287 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/pandadoc.md |\n| Documenso | B | 62.8 | 294 | esign.send, esign.templates, esign.status, esign.embed | no | https://www.anchorterminal.com/tools/documenso.md |\n| Docusign | B | 62.5 | 301 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/docusign.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The API answers at https://api.hellosign.com/v3 and is described by one OpenAPI 3.0.3 spec with 68 paths and 74 operations, covering signature requests, templates, embedded URLs, unclaimed drafts, bulk send, teams, API apps, reports and fax (source: \u003chttps://github.com/hellosign/hellosign-openapi\u003e)\n- Test mode works on every endpoint from a free account. Test requests are watermarked, not legally binding and don't count against quota (source: \u003chttps://developers.hellosign.com/docs/overview\u003e)\n- Rate limits are 100 requests a minute for standard calls, 25 a minute for 17 higher-tier endpoints such as send and file download, and 10 a minute in test mode (source: \u003chttps://developers.hellosign.com/docs/overview\u003e)\n- Webhooks cover 23 event types, carry an HMAC-SHA256 `event_hash` keyed on the primary API key, retry up to six times and clear the callback URL after ten consecutive failures (source: \u003chttps://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough\u003e)\n- The docs site runs an MCP server at https://developers.hellosign.com/_mcp/server with one read-only tool, searchDocs. It searches documentation and can't send or read signature requests (source: \u003chttps://developers.hellosign.com/llms.txt\u003e)\n- No vendor MCP server for the signing product was found. The official MCP registry lists io.usefulapi/dropbox-sign, a third-party server (source: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=dropbox\u003e)\n- The completed PDF carries an audit trail with timestamps, signer IP addresses and a SHA-256 document hash (source: \u003chttps://developers.hellosign.com/api/manual-reference-pages/glossary/security-compliance\u003e)\n- status.hellosign.com lists two minor incidents in the last 90 days, a Salesforce integration fault on 21 August 2026 and file upload problems on 31 August 2026 (source: \u003chttps://status.hellosign.com/history\u003e)\n\n## Compare\n\n- [Documenso vs Dropbox Sign](https://www.anchorterminal.com/compare/documenso-vs-dropbox-sign.md): B 62.8 vs B 68.9\n- [Docusign vs Dropbox Sign](https://www.anchorterminal.com/compare/docusign-vs-dropbox-sign.md): B 62.5 vs B 68.9\n- [Dropbox Sign vs PandaDoc](https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.md): B 68.9 vs B 63.1\n- [Dropbox Sign vs airSlate SignNow](https://www.anchorterminal.com/compare/dropbox-sign-vs-signnow.md): B 68.9 vs B 68.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on hellosign.com or sign.dropbox.com or one of their subdomains, or the README of github.com/hellosign/hellosign-openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"dropbox-sign\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/dropbox-sign\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/dropbox-sign.svg\" alt=\"Dropbox Sign on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Dropbox Sign on Anchor Terminal](https://www.anchorterminal.com/badges/dropbox-sign.svg)](https://www.anchorterminal.com/tools/dropbox-sign)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/dropbox-sign\"\u003eDropbox Sign on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Dropbox Sign is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/dropbox-sign-dark.png\n- Light: https://www.anchorterminal.com/assets/share/dropbox-sign-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Contracts, proposals \u0026 e-signatures",
        "url": "https://www.anchorterminal.com/categories/e-signatures"
      },
      {
        "name": "Dropbox Sign",
        "url": ""
      }
    ],
    "description": "Dropbox Sign (formerly HelloSign) is Dropbox's e-signature service. Its REST API sends documents or templates for signature, embeds signing in an iframe, reports status by webhook and returns signed PDFs with an audit trail.",
    "facts": [
      "rank #161 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Dropbox Sign",
    "image": "https://www.anchorterminal.com/assets/og/tools-dropbox-sign.png",
    "path": "/tools/dropbox-sign",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Dropbox Sign review for AI agents, grade B (68.9/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/dropbox-sign"
  },
  "tokens": {
    "markdown": 7950,
    "slim": 1880
  },
  "version": 1
}
