# Dropbox Sign (slim) > Dropbox Sign (formerly HelloSign) is Dropbox's e-signature service. Its REST API sends documents or templates for signature, embeds signing in an iframe, reports status by webhook and returns signed PDFs with an audit trail. - Full: https://www.anchorterminal.com/tools/dropbox-sign.md (~8,000 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/dropbox-sign.json · canonical https://www.anchorterminal.com/tools/dropbox-sign - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 68.9/100 · rank #161 of 629 · #1 in Contracts, proposals & e-signatures · not agent-ready · confidence medium** Assessment: A public OpenAPI 3.0.3 spec, llms.txt, six official SDKs and a free test mode let an agent build the whole flow before paying. Production sends need a paid plan from $900 a year, the API key has full account access, and no idempotency keys were found in the reviewed documentation. ## Facts - Kind: HTTP API · vendor: Dropbox, Inc. · category: Contracts, proposals & e-signatures · legal entity: Dropbox, Inc. · provenance 85/100 - Endpoint: `https://api.hellosign.com/v3` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under the Dropbox Sign terms of service. The OpenAPI spec repository is Apache 2.0 and the official SDKs are MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.hellosign.com/v3, OpenAPI 3.0.3, 68 paths and 74 operations. Signature Request 20, Template 11, Team 10, Fax Line 7, API App 5, Fax 5, Account 4, Unclaimed Draft 4, and others - Credentials: API key over HTTP Basic, up to four keys an account, full account access. OAuth 2.0 Bearer tokens with scopes basic_account_info and request_signature (app owner billed) or account_access, signature_request_access, template_access, team_access and api_app_access (user billed) - Going to production: Non-embedded sending needs only a paid plan. Embedded apps are self-published in the web app (up to 10 apps). OAuth apps need review by support - Test mode: `test_mode=true` on any endpoint, free, watermarked and not legally binding, 10 requests a minute, not counted against quota - Plans: Essentials $900 a year from 50 requests a month, 5 templates. Standard $3,000 a year from 100 requests a month, 15 templates, adds bulk send and embedded signing and requesting. Premium by quote, adds embedded templates, data residency and multiple domains (https://sign.dropbox.com/products/dropbox-sign-api/pricing) - Rate limits: 100 requests a minute standard, 25 a minute on 17 higher-tier endpoints, 10 a minute in test mode. `X-Ratelimit-Limit`, `X-Ratelimit-Limit-Remaining` and `X-Ratelimit-Reset` headers. 429 with error name `exceeded_rate` - Errors: 20 HTTP error names with status, cause, remediation and a retryable flag (yes, no or conditional), 10 OAuth error names and 5 asynchronous error events, in the docs and in the spec as `x-error-codes`, `x-oauth-error-codes` and `x-error-events` - Webhooks: Account and app callbacks, 23 event types, multipart POST. The receiver answers 200 with `Hello API Event Received`. HMAC-SHA256 `event_hash`, a published IP range file, six retries, 30-second timeout, callback URL cleared after ten consecutive failures - Lists: `page` and `page_size` (1 to 100, default 20) with a `query` search language over fields such as title, to, from, created, complete, declined and metadata - SDKs: Python dropbox-sign, Node @dropbox/sign, PHP, Java, Ruby and .NET, generated from the OpenAPI spec, version 1.13.0 on 10 September 2026, MIT. Prior major versions patched for 12 months - Docs MCP: https://developers.hellosign.com/_mcp/server (fern-docs-mcp-server 1.0.0), one tool, searchDocs, marked readOnlyHint. Documentation search only - Certifications: SOC 2 Type II, SOC 3, ISO 27001, ISO 27018, HIPAA, PCI DSS and eIDAS listed at trust.dropbox.com. Bug bounty and disclosure programme on Intigriti - Status: status.hellosign.com on Statuspage, 13 components in four groups (Core, Web, API, Integrations) with incident history - Scores: Reliability 75, Performance pending, Schema & documentation 88, Agent ergonomics 72, Security & auth 65, Payments & pricing 25, Task success pending, Maintenance & community 85, Transparency & trust 68 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the public REST API at api.hellosign.com, the surface an agent would call. · Schema & documentation, One public OpenAPI 3.0.3 spec in hellosign/hellosign-openapi with 68 paths, 74 operations and 227 schemas, which also drives the docs and SD… · Agent ergonomics, List calls take `page_size` from 1 to 100 (default 20), and files are fetched by separate calls as binary, data URI or URL, so status checks… · Security & auth, API keys go in an HTTP Basic header, up to four an account for rotation, and each has full access to the account. · Payments & pricing, Read with the hosted rubric. · Maintenance & community, SDK version 1.13.0 reached npm and PyPI on 10 September 2026, 27 days before the check, and the spec repository had commits on 6 October, am… · Transparency & trust, The service is closed under terms effective 7 January 2025. The spec repository is Apache 2.0 and the SDKs are MIT (15). - Sources: 34, open questions: 9, both in the full twin - Capabilities: esign.send, esign.templates, esign.embed, esign.status - JSON: https://www.anchorterminal.com/api/v1/tools/dropbox-sign.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/dropbox-sign.svg` or a link to https://www.anchorterminal.com/tools/dropbox-sign from a page on hellosign.com or sign.dropbox.com or one of their subdomains, or the README of github.com/hellosign/hellosign-openapi, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `test_mode=true` while building. Test requests are free, watermarked and not legally binding, and are limited to 10 requests a minute 2. Don't blind-retry a send after a timeout. No idempotency key exists, so list requests by `metadata` or title first to check whether it was created 3. Authenticate with HTTP Basic, the API key as username and an empty password. Keep the key out of URLs, although the docs show that form 4. Answer every webhook with HTTP 200 and the body `Hello API Event Received`, and verify `event_hash`. Ten consecutive failures clear the callback URL 5. Treat a 200 from cancel as queued only. Confirmation arrives later as a `signature_request_canceled` event ## Connect ```bash npm install @dropbox/sign ``` ```bash curl "https://api.hellosign.com/v3/template/list" \ -u "${API_KEY}:" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/dropbox-sign ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | airSlate SignNow | B | 68.5 | esign.send, esign.templates, esign.embed, esign.status | https://www.anchorterminal.com/tools/signnow.min.md | | PandaDoc | B | 63.1 | esign.send, esign.templates, esign.embed, esign.status | https://www.anchorterminal.com/tools/pandadoc.min.md | | Documenso | B | 62.8 | esign.send, esign.templates, esign.status, esign.embed | https://www.anchorterminal.com/tools/documenso.min.md | | Docusign | B | 62.5 | esign.send, esign.templates, esign.embed, esign.status | https://www.anchorterminal.com/tools/docusign.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)