# Dropbox Sign > Dropbox Sign (formerly HelloSign) is Dropbox's e-signature service. Its REST API sends documents or templates for signature, embeds signing in an iframe, reports status by webhook and returns signed PDFs with an audit trail. - Canonical: https://www.anchorterminal.com/tools/dropbox-sign - Markdown: https://www.anchorterminal.com/tools/dropbox-sign.md (~8,000 tokens) - Slim: https://www.anchorterminal.com/tools/dropbox-sign.min.md (~1,880 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/dropbox-sign.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 68.9/100 · rank #161 of 629 · #1 in Contracts, proposals & e-signatures · not agent-ready · confidence medium** ## Assessment A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation. ## Facts | Field | Value | | --- | --- | | Vendor | Dropbox, Inc. (https://sign.dropbox.com) | | Kind | HTTP API | | Category | Contracts, proposals & e-signatures (https://www.anchorterminal.com/categories/e-signatures) | | Transport | HTTP | | Endpoint | `https://api.hellosign.com/v3` | | Auth | OAuth or key · A self-serve API key from the account's API settings page, sent as the HTTP Basic username with an empty password. Each account can hold up to four keys for rotation, and every key has full access to the account. OAuth 2.0 access tokens (Bearer) act on behalf of other users with seven scopes across two billing models, and OAuth apps need approval by Dropbox Sign support before production. Embedded apps can be self-published in the web app. | | Pricing | Paid (Paid) · Production signature requests need a paid API plan, and the API answers 402 without one. Essentials is $900 a year ($75 a month) from 50 requests a month, Standard $3,000 a year ($250 a month) from 100, and Premium is quoted by sales. Test mode is free on every endpoint from a free account, so an agent can build and test without a contract (checked 2026-10-07). | | x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-07). | | Licence | Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT | | Packages | npm: `@dropbox/sign`; pypi: `dropbox-sign` | | Source | https://github.com/hellosign/hellosign-openapi | | Docs | https://developers.hellosign.com | | llms.txt | https://developers.hellosign.com/llms.txt | | Last release | 2026-09-10 | | GitHub stars | 22 (as of 2026-10-07) | | npm downloads / week | 149,738 | | API | REST at https://api.hellosign.com/v3, OpenAPI 3.0.3, 68 paths and 74 operations. Signature Request 20, Template 11, Team 10, Fax Line 7, API App 5, Fax 5, Account 4, Unclaimed Draft 4, and others | | Credentials | API key over HTTP Basic, up to four keys an account, full account access. OAuth 2.0 Bearer tokens with scopes basic_account_info and request_signature (app owner billed) or account_access, signature_request_access, template_access, team_access and api_app_access (user billed) | | Going to production | Non-embedded sending needs only a paid plan. Embedded apps are self-published in the web app (up to 10 apps). OAuth apps need review by support | | Test mode | `test_mode=true` on any endpoint, free, watermarked and not legally binding, 10 requests a minute, not counted against quota | | Plans | Essentials $900 a year from 50 requests a month, 5 templates. Standard $3,000 a year from 100 requests a month, 15 templates, adds bulk send and embedded signing and requesting. Premium by quote, adds embedded templates, data residency and multiple domains (https://sign.dropbox.com/products/dropbox-sign-api/pricing) | | Rate limits | 100 requests a minute standard, 25 a minute on 17 higher-tier endpoints, 10 a minute in test mode. `X-Ratelimit-Limit`, `X-Ratelimit-Limit-Remaining` and `X-Ratelimit-Reset` headers. 429 with error name `exceeded_rate` | | Errors | 20 HTTP error names with status, cause, remediation and a retryable flag (yes, no or conditional), 10 OAuth error names and 5 asynchronous error events, in the docs and in the spec as `x-error-codes`, `x-oauth-error-codes` and `x-error-events` | | Webhooks | Account and app callbacks, 23 event types, multipart POST. The receiver answers 200 with `Hello API Event Received`. HMAC-SHA256 `event_hash`, a published IP range file, six retries, 30-second timeout, callback URL cleared after ten consecutive failures | | Lists | `page` and `page_size` (1 to 100, default 20) with a `query` search language over fields such as title, to, from, created, complete, declined and metadata | | SDKs | Python dropbox-sign, Node @dropbox/sign, PHP, Java, Ruby and .NET, generated from the OpenAPI spec, version 1.13.0 on 10 September 2026, MIT. Prior major versions patched for 12 months | | Docs MCP | https://developers.hellosign.com/_mcp/server (fern-docs-mcp-server 1.0.0), one tool, searchDocs, marked readOnlyHint. Documentation search only | | Certifications | SOC 2 Type II, SOC 3, ISO 27001, ISO 27018, HIPAA, PCI DSS and eIDAS listed at trust.dropbox.com. Bug bounty and disclosure programme on Intigriti | | Status | status.hellosign.com on Statuspage, 13 components in four groups (Core, Web, API, Integrations) with incident history | | Capabilities | esign.send, esign.templates, esign.embed, esign.status | | Tags | hosted, closed-source, api-key, oauth, openapi, llms-txt, webhooks, sandbox, python, typescript, java, php, ruby, dotnet, status-page, bug-bounty, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 75 | 15.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 88 | 14.3 | | Agent ergonomics | 13% | 16.2 | 72 | 11.7 | | Security & auth | 14% | 17.5 | 65 | 11.4 | | Payments & pricing | 10% | 12.5 | 25 | 3.1 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 85 | 7.4 | | Transparency & trust (editorial 51, provenance 85) | 7% | 8.8 | 68 | 6.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **68.9 → B** | ### Why each score - Reliability 75: Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. status.hellosign.com on Statuspage lists 13 components in four groups with incident history (20). Two incidents in the 90 days to 7 October 2026, both marked minor, a Salesforce integration fault on 21 August (6 h 43 min) and file upload problems on 31 August (54 min). The last major incident was an outage on 2 January 2026 (3 h 12 min), outside the window (20 of 30). Rate limits with numbers, 100 requests a minute standard, 25 on 17 higher-tier endpoints and 10 in test mode, although the header table describes the limit as hourly (15). The docs describe 429 with `X-Ratelimit` headers, tell clients to respect Retry-After and back off, and the error catalogue marks each error retryable or not. No idempotency keys or safe-retry guidance for sends were found (10 of 15). The terms supply the service as is and as available, and no SLA was found (0). The API is at v3 and generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 88: One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SDKs (25). llms.txt at developers.hellosign.com, a Markdown copy of each page by appending .md, and scoped llms-full.txt files by section and language (10). Operation descriptions average about 220 characters and several state consequences, such as cancel being irreversible and asynchronous. A glossary written for models covers core objects, signers, fields and workflows. Few descriptions say when not to use an endpoint (14 of 20). 67 enums, 239 required lists and about 80 length or range constraints. Sends are multipart forms with indexed keys, and `metadata` and `custom_fields` are loosely typed (11 of 15). Request and response examples with SDK samples in six languages, and a catalogue of 20 HTTP error names with cause, remediation and a retryable flag, embedded in the spec as `x-error-codes` (15). The path carries v3 and a dated changelog has 48 entries since November 2022. No written API versioning policy was found beyond the SDK one (13 of 15). - Agent ergonomics 72: List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks stay small. No field selection was found (15 of 25). Page-number pagination with totals in `list_info`, and a `query` search language over title, signer, sender, dates, completion state and metadata. The docs warn of a short indexing delay after creation (18 of 20). Errors carry `error_name` and `error_msg`, with 20 documented names, a remediation line each and a retryable flag, plus warnings in successful responses (20). No idempotency keys in the docs or spec, so a retried send can create a duplicate. Cancel returns 200 when queued and confirms by event. The retryable flags are the only safe-retry aid (4 of 20). A template send needs only `template_ids` and `signers`, `test_mode` is a single flag, and official SDKs cover six languages (15). - Security & auth 65: API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. OAuth 2.0 tokens carry seven scopes but serve apps acting for other users and need support approval. Scored between plain revocable keys and scoped OAuth (25), less 5 because the docs show the key inside the URL as `https://KEY:@api.hellosign.com`, a judgement call since that is URL userinfo, not a query string (20 of 30). The limited OAuth scopes and test mode narrow what a call can do, but there is no read-only key and no confirmation step on cancel, remove or template delete (9 of 20). Responses can carry signer-entered field values and decline reasons, and no injection guidance was found (5 of 15). The API Dashboard records the account's API requests, responses and callbacks, live and test, and each completed document carries an audit trail with timestamps, IP addresses and a SHA-256 hash (13 of 15). SOC 2 Type II, ISO 27001 and ISO 27018 at trust.dropbox.com, a bug bounty and disclosure programme on Intigriti, and webhook HMAC verification. No standard security.txt on the Sign hosts (18 of 20). - Payments & pricing 25: Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, Essentials at $900 a year from 50 requests a month and Standard at $3,000 a year from 100, with larger volumes on a selector and Premium by quote. That is plan pricing, not a per-request price (10 of 20). Test mode is free on every endpoint from a free account, but its requests aren't legally binding, and the pages we read don't say whether signup needs a card (15 of 20). A person has to create the account and copy the key from the web app, and production needs a paid plan (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 85: SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, among them a new Document Field Detection endpoint (30). Dated changelog entries on 31 July, 19 August and 3 September 2026, plus SDK 1.12.0 and 1.13.0 on 10 September (20). A closed service with a public changelog, an API support address (apisupport@hellosign.com), a help centre and public GitHub issues, nine open on the spec repository. We didn't test response times (11 of 15). Current official SDKs for Python, Node, PHP, Java, Ruby and .NET, all pushed in September 2026 (15). CI in the spec repository builds the spec and each SDK and fails on uncommitted generated code, and Node dependencies were upgraded on 6 October (9 of 10). - Transparency & trust 68: The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). The terms let Dropbox delete customer data any time after 30 days from termination. The data processing agreement, dated 25 October 2021, promises deletion within a commercially reasonable period on request and still points to a hellosign.com sub-processor address. The privacy policy of 14 January 2025 gives no retention period. The documents agree but stay vague (18 of 30). Prior SDK major versions are patched for 12 months and the API returns a `deprecated_parameter` warning, but no API deprecation policy with notice periods was found (8 of 20). The privacy policy links a Sign sub-processor list and the agreement promises advance notice of new sub-processors with a 60-day objection window. The list itself returned only its title to our reader, so names and locations are unconfirmed. Data residency is a Premium option (10 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/dropbox-sign.md (JSON https://www.anchorterminal.com/fixes/dropbox-sign.json) ### What we couldn't check - unchecked: the Sign sub-processor list at www.dropbox.com/privacy/subprocessor/sign, which returned only its title to our reader, so names and locations are unconfirmed. - unchecked: PyPI weekly downloads for dropbox-sign. pypistats.org refused us for a rate limit. - unchecked: whether creating a free account for test mode needs a card. The docs and pricing page don't say and we didn't sign up. - unchecked: prices at the 250, 500 and 750+ steps of the pricing selector, and the month-to-month price. The static page showed $75 and $250 a month beside $900 and $3,000 a year. - unchecked: documents in the trust centre beyond the public summary, such as the SOC 2 report and penetration test summary. - The rate-limit docs give per-minute limits, describe `X-Ratelimit-Limit` as hourly and show an example message of 2,000 an hour. Which window applies wasn't established. - The glossary says 429 responses carry Retry-After, while the main rate-limit section lists only the `X-Ratelimit` headers. We didn't trigger a 429 to confirm. - No SLA was found for any plan in the terms or on the pricing page. A Premium contract may include one. - No vendor MCP server for signing was found. The registry entry io.usefulapi/dropbox-sign is third-party and wasn't graded. ### Sources - API product page: (seen 2026-10-07) - API pricing: (seen 2026-10-07) - llms.txt and docs index: (seen 2026-10-07) - docs overview, test mode, plans by endpoint and rate limits: (seen 2026-10-07) - authentication and key rotation: (seen 2026-10-07) - OAuth overview and scopes: (seen 2026-10-07) - app approval: (seen 2026-10-07) - self-publishing API apps: (seen 2026-10-07) - warnings and errors: (seen 2026-10-07) - events walkthrough, verification and retries: (seen 2026-10-07) - security and compliance glossary, audit trail and quotas: (seen 2026-10-07) - search on list endpoints: (seen 2026-10-07) - API Dashboard guide: (seen 2026-10-07) - SDK overview: (seen 2026-10-07) - SDK versioning policy: (seen 2026-10-07) - changelog: (seen 2026-10-07) - quickstart: (seen 2026-10-07) - docs MCP server (initialize and tools/list): (seen 2026-10-07) - OpenAPI spec and SDK source repository: (seen 2026-10-07) - vendor repositories: (seen 2026-10-07) - npm package: (seen 2026-10-07) - npm weekly downloads: (seen 2026-10-07) - PyPI package: (seen 2026-10-07) - status page summary: (seen 2026-10-07) - status incident history: (seen 2026-10-07) - trust page: (seen 2026-10-07) - trust centre: (seen 2026-10-07) - terms of service: (seen 2026-10-07) - privacy policy: (seen 2026-10-07) - data processing agreement: (seen 2026-10-07) - security.txt on the Sign host (404): (seen 2026-10-07) - security.txt on dropbox.com: (seen 2026-10-07) - official MCP registry search: (seen 2026-10-07) - domain registration (RDAP): (seen 2026-10-07) ## Who's behind it (provenance 85/100, checked 2026-10-07) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Dropbox, Inc. | 20/20 | | Domain age | hellosign.com, registered 2004-03-05 (22 years) | 15/15 | | Endpoint on the vendor's domain | api.hellosign.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.hellosign.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Dropbox Sign terms (effective 7 January 2025) put the agreement with Dropbox, Inc. for customers in the United States, Canada and Mexico and with Dropbox International Unlimited Company elsewhere. The API host is api.hellosign.com and the docs are at developers.hellosign.com. The marketing site is sign.dropbox.com. RDAP gives 2004-03-05 for hellosign.com and 1995-06-28 for dropbox.com. sign.dropbox.com/.well-known/security.txt and api.hellosign.com/.well-known/security.txt return 404. www.dropbox.com/.well-known/security.txt serves a plain-text file that names the Intigriti bug bounty and disclosure programmes without the standard Contact and Expires fields. The privacy policy is dated 14 January 2025. The data processing agreement at assets.dropbox.com is dated 25 October 2021. The sub-processor list at www.dropbox.com/privacy/subprocessor/sign returned only its title to our reader. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://sign.dropbox.com/about/terms), read 2026-10-08, dated 2025-01-07, states 6 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "access the Dropbox Sign Services for the purpose of building a competitive product or service or copying its features or user interface;" - To know. Says the terms or the service can change without notice (costs points). "We reserve the right to change the prices, features, or options included in a particular Subscription Plan without notice, provided that such changes shall not take effect until your next applicable Subscription Term (as defined below).‍" - To know. Requires arbitration or waives class actions. "WAIVER OF CLASS ACTIONS." - Gives the date it was last updated. Last updated 2025-01-07. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Not found in the text. Says how changes to the terms are announced. - Also in the text (2026-10-08). After termination the customer loses access to Customer Data, and Dropbox may delete it at any time after 30 days. "Customer’s right to access any Customer Data in the applicable Dropbox Sign Services will cease and Dropbox may delete the Customer Data at any time after 30 days from the date of termination." - Also in the text (2026-10-08). A customer that exceeds its plan's usage limits is upgraded automatically to the next highest plan and must pay for it. "If Customer exceeds their Subscription Plan’s usage limits, Customer will be automatically upgraded into the next highest Subscription Plan and Customer expressly acknowledges and agrees that it will pay for the upgraded Subscription Plan." - Also in the text (2026-10-08). Renewals are priced at Dropbox's rates in force at the time of renewal. "Pricing for any Subscription Term renewal, new order form, or order form changes will be at Dropbox’s then-applicable rates." **Privacy policy** (https://sign.dropbox.com/about/privacy), read 2026-10-08, dated 2025-01-14, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2025-01-14. - Gives a privacy contact. privacy@dropbox.com. - Says where data is transferred or stored. Relies on standard contractual clauses. ## Live (updated 2026-10-08 19:08 UTC) - Right now: up, HTTP 404, 148 ms, checked 2026-10-08 19:08 UTC (get on `https://api.hellosign.com/v3`) - Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 138 ms · p95 258 ms - Vendor status page: none, All Systems Operational - npm `@dropbox/sign` 1.13.0 - pypi `dropbox-sign` 1.13.0, released 2026-09-10 - security.txt: none - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/dropbox-sign.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Public OpenAPI 3.0.3 spec with 74 operations, plus llms.txt and a Markdown copy of every docs page - Free test mode works on every endpoint from a free account, with watermarked, non-binding requests that don't count against quota - Error catalogue of 20 HTTP error names with cause, remediation and a retryable flag, also embedded in the spec as `x-error-codes` - Rate limits published with numbers (100 a minute standard, 25 on higher-tier endpoints, 10 in test mode) and returned in response headers - Official SDKs in six languages at version 1.13.0, released 10 September 2026, with semantic versioning ## Weaknesses - No idempotency keys found in the docs or the spec, so a retried send can create a second signature request - An API key grants full access to the account, with no scoped or read-only keys. Scopes exist only on OAuth tokens - OAuth apps need manual approval by Dropbox Sign support before production use - The terms supply the service as is, and no SLA was found. A major outage on 2 January 2026 lasted 3 hours 12 minutes - Embedded signing and bulk send need the Standard plan ($3,000 a year), and embedded templates need Premium, priced by quote ## Before you call it (notes for agents) 1. Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute 2. Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created 3. Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form 4. Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL 5. Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event ## Connect Install: ```bash npm install @dropbox/sign ``` First request: ```bash curl "https://api.hellosign.com/v3/template/list" \ -u "${API_KEY}:" ``` Through letme (picks today, calling later): https://letme.dev/dropbox-sign (letme picks it for esign.embed, the top-graded tool for the job, letme picks it for esign.send, the top-graded tool for the job, letme picks it for esign.status, the top-graded tool for the job, letme picks it for esign.templates, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | airSlate SignNow | B | 68.5 | 168 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/signnow.md | | PandaDoc | B | 63.1 | 287 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/pandadoc.md | | Documenso | B | 62.8 | 294 | esign.send, esign.templates, esign.status, esign.embed | no | https://www.anchorterminal.com/tools/documenso.md | | Docusign | B | 62.5 | 301 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/docusign.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The API answers at https://api.hellosign.com/v3 and is described by one OpenAPI 3.0.3 spec with 68 paths and 74 operations, covering signature requests, templates, embedded URLs, unclaimed drafts, bulk send, teams, API apps, reports and fax (source: ) - Test mode works on every endpoint from a free account. Test requests are watermarked, not legally binding and don't count against quota (source: ) - Rate limits are 100 requests a minute for standard calls, 25 a minute for 17 higher-tier endpoints such as send and file download, and 10 a minute in test mode (source: ) - Webhooks cover 23 event types, carry an HMAC-SHA256 `event_hash` keyed on the primary API key, retry up to six times and clear the callback URL after ten consecutive failures (source: ) - The docs site runs an MCP server at https://developers.hellosign.com/_mcp/server with one read-only tool, searchDocs. It searches documentation and can't send or read signature requests (source: ) - No vendor MCP server for the signing product was found. The official MCP registry lists io.usefulapi/dropbox-sign, a third-party server (source: ) - The completed PDF carries an audit trail with timestamps, signer IP addresses and a SHA-256 document hash (source: ) - status.hellosign.com lists two minor incidents in the last 90 days, a Salesforce integration fault on 21 August 2026 and file upload problems on 31 August 2026 (source: ) ## Compare - [Documenso vs Dropbox Sign](https://www.anchorterminal.com/compare/documenso-vs-dropbox-sign.md): B 62.8 vs B 68.9 - [Docusign vs Dropbox Sign](https://www.anchorterminal.com/compare/docusign-vs-dropbox-sign.md): B 62.5 vs B 68.9 - [Dropbox Sign vs PandaDoc](https://www.anchorterminal.com/compare/dropbox-sign-vs-pandadoc.md): B 68.9 vs B 63.1 - [Dropbox Sign vs airSlate SignNow](https://www.anchorterminal.com/compare/dropbox-sign-vs-signnow.md): B 68.9 vs B 68.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on hellosign.com or sign.dropbox.com or one of their subdomains, or the README of github.com/hellosign/hellosign-openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "dropbox-sign", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Dropbox Sign on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Dropbox Sign on Anchor Terminal](https://www.anchorterminal.com/badges/dropbox-sign.svg)](https://www.anchorterminal.com/tools/dropbox-sign) ``` Plain link: ```html Dropbox Sign on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Dropbox Sign is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/dropbox-sign-dark.png - Light: https://www.anchorterminal.com/assets/share/dropbox-sign-light.png