# PandaDoc (slim) > PandaDoc is a document platform for proposals, quotes, contracts and e-signatures. Its REST API and hosted MCP server create documents from templates, send them for signature, embed signing sessions and report status through webhooks. - Full: https://www.anchorterminal.com/tools/pandadoc.md (~8,000 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/pandadoc.json · canonical https://www.anchorterminal.com/tools/pandadoc - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 63.1/100 · rank #287 of 629 · #3 in Contracts, proposals & e-signatures · not agent-ready · confidence medium** Assessment: The public OpenAPI spec lists 133 operations and reached version 8.21.0 on 2 October 2026, and the hosted MCP server, with OAuth and dynamic client registration, is open to every plan including Free. The status page records three incidents affecting document creation, sending or the API between 15 July and 6 September 2026, and writes have no idempotency keys. ## Facts - Kind: HTTP API · vendor: PandaDoc · category: Contracts, proposals & e-signatures · legal entity: PandaDoc · provenance 84/100 - Endpoint: `https://api.pandadoc.com/public/v1` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under PandaDoc's Master Services Agreement. The OpenAPI specification, the API client SDKs and the MCP server guide on GitHub are MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.pandadoc.com/public/v1 (EU accounts at https://api.pandadoc.eu/public/v1), with some endpoints under /public/v2 and /public/beta. OpenAPI 3.0.3, version 8.21.0, 133 operations - MCP server: Hosted, streamable HTTP at https://mcp.pandadoc.com/v1/mcp and https://mcp.pandadoc.eu/v1/mcp. OAuth with PKCE (S256) and dynamic client registration. Registry entry com.pandadoc.mcp/mcp, version 1.0.0, published 18 June 2026. The full tool list is visible only after sign-in - MCP tools named in PandaDoc's skills: documents_create, documents_update, documents_send, documents_list, documents_search, documents_details_get, documents_status_get, documents_status_change, documents_fields_assign, documents_metadata_get, documents_metadata_batch_get, documents_summary_get, documents_content_get, documents_audit_trail_get, templates_list, templates_details_get, templates_create - Credentials: OAuth 2.0 authorisation code with `read` and `write` scopes (recommended), or a workspace API key that carries its owner's role (legacy). MCP scopes are read, write, documents:read, documents:edit and documents:send - Access: Sandbox key self-serve from the developer centre. Production key on approval from Sales. OAuth applications need production API access - Sandbox: Same environment with a sandbox key. 10 requests a minute per endpoint, watermarked PDFs, a [DEV] title prefix and sending only within the sender's email domain. Not charged - Rate limits: Per user over a sliding 60 seconds. Create from template 500 a minute, create from PDF 300, send 400, document details 600, list, status and delete 2,000, download 100. Request body up to 2 MB, PDF upload up to 50 MB - Errors: JSON with a type and detail, or an error object with a code and message on newer endpoints. 409 while a document isn't ready, 403 when usage credits run out, 423 on a locked account, 429 over the limit. Retry-After only on four download and content endpoints - Signing: Email, SMS or link delivery, signing order, embedded signing sessions created with POST /documents/{id}/session, and qualified e-signature through identity providers - Webhooks: Document state changed, recipient completed, document updated, document deleted, completed PDF ready, creation failed and template events. HMAC-SHA256 signature, 20-second read timeout, no automatic retry, `X-PandaDoc-Webhook-Event-Id` for de-duplication - SDKs: Official Python (pandadoc-python-client 6.2.0, 8 April 2024), Node (pandadoc-node-client 6.2.0 as latest, 7.0.0-rc.9 on 25 February 2026), Java and PHP, all MIT - Audit: API request logs in the developer centre and at /public/v2/logs, a per-document audit trail endpoint, and an account audit log covering 30 days on Enterprise - Regions: Global (pandadoc.com) and EU (pandadoc.eu) accounts are separate. AI processing runs only on the US instance, per the AI policy - Status: status.pandadoc.com on Statuspage, with components for API, Webhooks, sending, uploading and downloading in two regions - Scores: Reliability 58, Performance pending, Schema & documentation 87, Agent ergonomics 68, Security & auth 61, Payments & pricing 30, Task success pending, Maintenance & community 77, Transparency & trust 59 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the REST API, which the hosted MCP server calls. · Schema & documentation, Scored on the REST API. · Agent ergonomics, List endpoints take `count` (default 50, maximum 100) and `page`. · Security & auth, OAuth 2.0 authorisation code for the API with `read` and `write` scopes, and for the MCP server OAuth with PKCE (S256), dynamic client regis… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, API 8.21.0 on 2 October 2026, which added the `recipient_qes_verified` webhook event (30). · Transparency & trust, The service is closed under a Master Services Agreement named in the OpenAPI spec. - Sources: 45, open questions: 8, both in the full twin - Capabilities: esign.send, esign.templates, esign.embed, esign.status, contracts.generate - JSON: https://www.anchorterminal.com/api/v1/tools/pandadoc.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/pandadoc.svg` or a link to https://www.anchorterminal.com/tools/pandadoc from a page on pandadoc.com or one of its subdomains, or the README of github.com/PandaDoc/pandadoc-openapi-specification, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Wait for `document.draft` before sending. Creation is asynchronous and a new document stays in `document.uploaded` for a few seconds 2. Match the region. Accounts on app.pandadoc.eu use api.pandadoc.eu and mcp.pandadoc.eu, and the global hosts reject them 3. Check for an existing document before retrying a create. There's no idempotency key and each production create uses a usage credit 4. Retry 409 after a pause and back off on 429. A sandbox key allows 10 requests a minute per endpoint 5. Don't rely on webhooks alone. Failed deliveries aren't retried, so poll the status endpoint as a fallback ## Connect ```bash curl "https://api.pandadoc.com/public/v1/documents?count=5" \ -H "Authorization: API-Key $PANDADOC_API_KEY" ``` ```bash claude mcp add pandadoc --transport http https://mcp.pandadoc.com/v1/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/pandadoc ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | airSlate SignNow | B | 68.5 | esign.send, esign.templates, esign.embed, esign.status, contracts.generate | https://www.anchorterminal.com/tools/signnow.min.md | | Docusign | B | 62.5 | esign.send, esign.templates, esign.embed, esign.status, contracts.generate | https://www.anchorterminal.com/tools/docusign.min.md | | Dropbox Sign | B | 68.9 | esign.send, esign.templates, esign.embed, esign.status | https://www.anchorterminal.com/tools/dropbox-sign.min.md | | Documenso | B | 62.8 | esign.send, esign.templates, esign.status, esign.embed | https://www.anchorterminal.com/tools/documenso.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)