airSlate SignNow
by airSlate, Inc. HTTP API in Contracts, proposals & e-signatures
Hosted Local
airSlate, Inc. · signnow.com since 2001 · status page · who's behind it
airSlate SignNow is an e-signature service. Its REST API prepares documents from templates, sends signature invites, embeds signing in other apps and reports status through webhooks. A hosted MCP server gives AI agents 20 documented tools over the same account.
Good for An agent that sends agreements from templates, embeds signing in another product or tracks invites, and teams that want per-invite pricing with a free test mode.
Is this your product? Claim this listing or verify it
Assessment. The REST API has a public OpenAPI 3.0 spec with 354 operations, Markdown docs, a free Development mode with 500 invites and a hosted MCP server with OAuth. API keys don't expire and carry full account access, no idempotency keys were found, and the MCP server's GitHub repository was archived when checked on 7 October 2026.
Facts
- Transport
- HTTP, Streamable HTTP, stdio
- Endpoint
https://api.signnow.com- Auth
- OAuth or key
- Pricing
- Pay per use · $2 / tx
- x402
- No
- Licence
- Proprietary service under the SignNow Terms of Service. The MCP server and the SDKs on GitHub are MIT
- Tools exposed
- 21
- Packages
pypisignnow-mcp-servernpm@signnow/api-clientpypisignnow-python-sdk- MCP registry
io.github.signnow/sn-mcp-server- Docs
- docs.signnow.com
- llms.txt
- published
- Last release
- GitHub stars
- 8
- npm / week
- 7.7k
- PyPI / week
- 5.3k
- API
- REST at https://api.signnow.com, OpenAPI 3.0.3 with 226 paths and 354 operations, a mix of unversioned and /v2 paths. One host for Development and Live modes
- MCP server
- Hosted at https://mcp-server.signnow.com/mcp (Streamable HTTP, OAuth). Also the PyPI package signnow-mcp-server 3.1.0 for stdio or self-hosted HTTP, MIT, Python 3.10 or later. Connectors listed for Claude and ChatGPT
- MCP tools
- list_all_templates, create_from_template, create_template, upload_document, list_documents, get_document, view_document, update_document_fields, rename_entity, get_document_download_link, list_contacts, send_invite, get_invite_status, get_signing_link, send_invite_reminder, update_invite_recipient, cancel_invite, create_embedded_invite, create_embedded_sending, create_embedded_editor, plus signnow_skills in the v3.1.0 source
- Credentials
- API keys from the API dashboard (no expiry, all API requests, unlimited keys per application, deleted to revoke). OAuth 2.0 with password, refresh_token and authorization_code grants. The auth guide's code-grant example returns
expires_in2592000.scopetakes URL patterns, default* - Rate limits
- 500 requests an hour per application in Development, 1,000 an hour by default in Live, raised through support. X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset on every response. 429 on excess
- Errors
- 400, 401, 403, 404 and 429 with a JSON
errorsarray of numeric code and message. Code 65582 covers many validation errors, so the message text identifies the problem - Webhooks
- Event subscriptions for document, document group and user events. Optional
secret_keyadds anX-SignNow-SignatureHMAC SHA-256 header. 20-second timeout, 5 retries 10 seconds apart then more 4 hours apart,retry_countup to 10. Accounts without an API plan are limited to 10 active webhooks - Embedded flows
- Embedded signing, sending, editor and view links for documents and document groups. Embedded sending links expire after 15 to 45 minutes
- Document generation
- POST /v2/document-generations/upload and /url fill a tagged .docx from data and return a document ready for signature, with a status endpoint
- Audit
- GET /document/{document_id}/historyfull and the document group equivalent return the signing history. The API dashboard logs every request and webhook delivery, and API-log endpoints are in the reference
- SDKs
- PHP signnow/api-php-sdk v3.5.4 (3 September 2026), Node @signnow/api-client 3.2.0 (11 March 2026), Python signnow-python-sdk 3.0.0 (22 April 2026), .NET, Java and Android, plus a Postman collection
- Pricing
- Development mode free. Paid API plans from $2 per invite at 500 invites to $1.20 per invite at 5,000 per the developers page, which also advertises 250 free signature invites. A site licence covers the web app and API for many users
- SLA
- 99.9 per cent monthly uptime on commercially reasonable efforts, credits of 10 per cent below 99.9 and 30 per cent below 99.0, claims within 30 days. Last updated 11 January 2023
- Status
- status.signnow.com on Statuspage, components Web, Mobile apps, API, Integrations, Payments and Support. Three incidents since April 2026, all minor and on Web
- Certifications
- SOC 2 Type II (report on request), PCI DSS, HIPAA, GDPR, 21 CFR Part 11, CCPA, ESIGN and UETA per signnow.com/security. Bug bounty through HackerOne by invitation
Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.0.3 spec with 354 operations, 342 of them with examples, plus llms.txt and a Markdown copy of every docs page
- Development mode is free on the production host, with 500 requests an hour and up to 500 signature invites without a plan
- Hosted MCP server at mcp-server.signnow.com/mcp with OAuth, PKCE and dynamic client registration, and read-only and destructive hints on its tools
- Webhooks carry an HMAC SHA-256 signature header and a documented retry schedule, and the API dashboard logs every request and delivery attempt
- Status page shows three minor incidents since April 2026, none on the API component, and a 99.9 per cent SLA with credits is published
Weaknesses
- API keys don't expire and work for all API requests. Narrower access needs an OAuth token requested with a URL-pattern scope
- No idempotency key was found in the spec or guides, and each signature invite sent is charged
- The sn-mcp-server GitHub repository was archived when checked on 7 October 2026, while the docs still send issue reports there
- Numeric error codes aren't unique. The docs tell callers to identify a problem by its message text
- The API plan table is a JavaScript page we couldn't read. Only the per-invite range on the developers page is public text
Before you call it notes for agents
- Call https://api.signnow.com with
Authorization: Bearer <API key or access token>. Development and Live share this host, and Development documents carry a watermark - Request OAuth tokens with a narrow
scopesuch asdocument/* GET/user. The default*grants every API action - Read
X-RateLimit-RemainingandX-RateLimit-Reseton each response. The limit is 500 requests an hour in Development and 1,000 in Live, and 429 has no Retry-After - Check invite status before resending. No idempotency key exists, and a repeated invite call counts as another charged invite
- Set
secret_keywhen creating an event subscription and verifyX-SignNow-Signature(HMAC SHA-256 of the body) on every callback
Who's behind it provenance 86/100
- Legal entity namedairSlate, Inc.20/20
- Domain agesignnow.com, registered 2001-04-05 (25 years)15/15
- Endpoint on the vendor's domainapi.signnow.com15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 2 clauses that cost points6/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.signnow.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2023-03-02, states 7 of 7, 4 to know
TL;DR Dated 2023-03-02. States all 7 things a reader expects. To know before relying on it, limits on automated access, limits on benchmarking, arbitration or a class action waiver and no update in three years.
Restricts automated accesscosts points
(iv) share your login credentials with anyone or use any automated system, including robots, spiders, or offline readers, to access or operate the Services;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
(vi) use the Services for the benefit of a competitive offering;
A clause against publishing test results or using the service to build something that competes.
Requires arbitration or waives class actions
PLEASE ALSO NOTE THAT THESE TERMS CONTAIN A CLASS ACTION WAIVER.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Has not been updated for three years or more
Last Updated: March 2, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-03-02
Last Updated: March 2, 2023
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
If any part of the Agreement is found unenforceable by a court of competent jurisdiction, the rest of the Agreement will nonetheless continue in effect, and both parties agree that the unenforceable provisions will be modified so as to best accomplish the objectives of the Agreement within the limits of applicable law.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
EXCEPT FOR YOUR BREACH OF ANY OF YOUR OBLIGATIONS IN SECTION 5 ABOVE, IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES OF ANY KIND, INCLUDING, WITHOUT LIMITATION, LOST REVENUES, PROFITS, OR GOODWILL, LOST DATA OR CONTENT, DATA BREACHES, LOST C…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If Provider reasonably determines that you violate any of the use restrictions above, Provider may suspend or terminate your access to the Services or utilize other mechanisms available to Provider to prevent violations, including removing violating content and deactivating URLs or links provided by the Services.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Changes are posted, with no other notice named
PROVIDER MAY FROM TIME TO TIME PROPOSE CHANGES TO THIS AGREEMENT BY POSTING AN UPDATED VERSION OF THE AGREEMENT ON ITS WEBSITES.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you lose your credentials (including deleting or losing access to your email), you may not be able to restore access to your account and Your Content.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
“Service Level Agreement”, which governs the availability of the Subscription Services for Subscribers, available at https://www.signnow.com/sla.
Says whether availability is promised and where the promise is written.
Usage above the plan limit is billed as excess usage, and the vendor is not obliged to warn the customer before those fees are incurred.
(iv) you are responsible for tracking your usage, and Provider is not obligated to notify you before you incur excess usage fees.
Noted by a second reader on 2026-10-08.
After termination the customer has 30 days to ask for access to download its content, after which the vendor may delete it.
On request made within thirty (30) days after termination, Provider will grant you reasonable access to your Services solely for you to download Your Content using Services’ standard download functionalities.
Noted by a second reader on 2026-10-08.
The vendor may use the customer's name and logo to identify it as a customer, including on the vendor's website.
Provider may use your name and logo for the limited purpose of identifying you as a customer, including by listing your company’s name and logo on Provider’s website.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,317 words
Privacy policy dated 2026-08-12, states 8 of 8, 1 to know
TL;DR Dated 2026-08-12. States all 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
We may share your personal information with our third-party advertising partners to target advertising to you.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-08-12
Last Updated: August 12, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Notice describes what personal information we collect, why and when we collect it, how we may use, disclose, and retain it, and what choices or rights you may have about your personal information.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We generally retain personal information for as long as necessary for the purposes we collected it, including satisfying any legal, financial, or reporting obligations, establishing or defending legal claims, or for compliance and protection.
Says when data sent to the service is deleted.
Says who else receives the data
Process personal information as a service provider or data processor for our enterprise customer(s).
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
SignNow does not sell or otherwise monetize personal information except for sharing it only for cross-context behavioral advertising (CCBA) as described below:
A plain statement either way.
Says what rights people have over their data
If we declined your Privacy Rights request, you may contact us about our decision or submit a request again.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
If we declined your Privacy Rights request, you may contact us about our decision or submit a request again.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
All our US-based Contracting Entities comply with the principles and are self-certified under the EU-US Data Privacy Framework (DPF), the Swiss-U.S.
The countries data goes to and the safeguard used.
The notice says analysing how the services are used and interacted with includes training the vendor's AI models.
This includes training our artificial intelligence (AI) models
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,185 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The privacy notice (last updated 12 August 2026) names airSlate, Inc., 17 Station Street, Ste. 203, Brookline, MA 02445. The contracting entity table (last updated 1 October 2026) lists seven airSlate companies, and the one that applies depends on the service, location and payment method.
The API answers at api.signnow.com and the hosted MCP server at mcp-server.signnow.com, both signnow.com subdomains.
www.signnow.com/.well-known/security.txt returns 404. Vulnerability reports go through the airSlate bug bounty programme on HackerOne, which needs an invitation requested by email (policy last updated 7 October 2025).
The terms of service were last updated 2 March 2023, the SLA 11 January 2023 and the DPA 1 July 2025.
RDAP for signnow.com gives a registration date of 2001-04-05 and GoDaddy.com, LLC as registrar.
Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.signnow.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- github
signnow/sn-mcp-serverv3.1.0, released 2026-07-27 - npm
@signnow/api-client3.2.0 - pypi
signnow-mcp-server3.1.0, released 2026-07-27 - pypi
signnow-python-sdk3.0.0, released 2026-04-22 - GitHub stars 8
- npm downloads a week 7.7k
- PyPI downloads a week 70
- security.txt unknown · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/signnow.json
Notable
- The API reference is published as OpenAPI 3.0.3 and Swagger 2.0, with 226 paths and 354 operations against https://api.signnow.com source
- The hosted MCP server answers at https://mcp-server.signnow.com/mcp and returns 401 with OAuth metadata that lists authorisation code and refresh grants, S256 PKCE and a registration endpoint source
- SignNow documents 20 MCP tools for templates, documents, contacts, invites and embedded sessions. Release v3.1.0 registers those 20 plus
signnow_skillssource - The sn-mcp-server repository is marked archived on GitHub, last pushed 27 July 2026, while the docs still point to its issue tracker source
- Development mode runs on the production host with 500 requests an hour and up to 500 signature invites without a plan. Live mode defaults to 1,000 requests an hour source
- The developers page prices paid API plans from $2 per invite at 500 invites to $1.20 per invite at 5,000 source
- The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime, with credits of 10 or 30 per cent source
- The subprocessor list, updated 18 September 2026, names AWS in the United States, Germany and Australia, and OpenAI, Anthropic and Google as LLM subprocessors source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 18.6 | |
| Graded as a hosted API. Statuspage at status.signnow.com with six components including API (20). The incident feed shows one incident in the last 90 days, a minor one on 3 September 2026 that made the SignNow University site unavailable for eight minutes, and none on the API component (30). Limits are published with numbers, 500 requests an hour in Development and 1,000 in Live (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers and advice to back off exponentially. No Retry-After header and no idempotency key were found, and sending an invite is a charged write (8). The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime with credits of 10 or 30 per cent (10). The REST API is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.2 | |
| Graded on the REST API, with the MCP server noted. OpenAPI 3.0.3 and Swagger 2.0 are public, with 226 paths and 354 operations (25). docs.signnow.com/llms.txt indexes a Markdown copy of every page, with llms-full.txt (10). All 354 operations have a description and the MCP tool descriptions say what to call next, but the API reference rarely says when not to use an endpoint (14). The spec marks required fields often but holds only 29 enums across 354 operations (9). 342 operations have examples and there is an API errors page, though numeric codes aren't unique (12). The changelog is dated by month back to February 2025. The spec version stays at 1.0.0 and paths mix unversioned and /v2 routes (11). | |||
| Agent ergonomics | 13%16.2 | 10.7 | |
Graded on the REST API, with the MCP server noted. List endpoints take page and per_page or limit and offset, with no field selection found. The MCP server loads 20 documented tools, 21 in the v3.1.0 source (15). Pagination, filters and sorting exist but in several parameter styles (filter:type, filters[...], sort:created, sort_by) (15). Errors come as a JSON code and message with a troubleshooting page, but code 65582 covers many causes and the docs tell callers to read the message text (13). No idempotency key on the API. The MCP tools set readOnlyHint, destructiveHint and idempotentHint (8). SDKs for PHP, Node, Python, .NET and Java, and an API key works with one header (15). | |||
| Security & auth | 14%17.5 | 10.8 | |
OAuth 2.0 with password, refresh and authorisation code grants and a scope parameter that limits a token to URL patterns. API keys can be deleted but don't expire and work for all API requests, and the hosted MCP server adds OAuth with PKCE (24). We deducted 5 of the possible 10 for secrets in URLs, because embedded links returned by the API carry an access_token query parameter, with a 15 to 45 minute expiry on embedded sending links (19). A URL-pattern scope allows a read-only token, the hosted MCP grant covers documents and templates only, and the bundled skill tells agents to wait for confirmation before sending. Nothing enforces that confirmation (12). The API returns document text and field values written by signers, and no prompt-injection guidance was found (3). The API dashboard logs every request and webhook delivery, and documents carry a full history endpoint (13). SOC 2 Type II, PCI DSS and HIPAA per the security page and a HackerOne bug bounty by invitation. security.txt returns 404, and the MCP repository's SECURITY.md still has a placeholder contact (15). | |||
| Payments & pricing | 10%12.5 | 4.4 | |
| No x402, MPP or L402 found (0). The developers page states per-invite prices, from $2 at 500 invites to $1.20 at 5,000. The full plan table is a JavaScript page we couldn't read, so we scored between plan-only and per-unit (15). Development mode is free with up to 500 invites, and the help centre says the free trial needs no credit card (20). A person has to register in a browser and verify an email address before the first key exists (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.3 | |
| The API changelog's newest entry is September 2026, dated by month only, and the PHP SDK v3.5.4 shipped on 3 September 2026, 34 days before this check. We scored between the 30-day and 90-day bands (25). The changelog has entries for July, August and September 2026 (20). Closed service with a monthly changelog and API support at api@signnow.com. The MCP repository that the docs name for issue reports is archived (8). SDKs for five languages are current, with PHP in September 2026, Python in April and Node in March. The official MCP registry lists io.github.signnow/sn-mcp-server at 0.3.1 while PyPI has 3.1.0 (13). The MCP repository has CI with ruff, mypy and pytest and 60 test files, and it is archived (6). | |||
| Transparency & trusteditorial 62, provenance 86 | 7%8.8 | 6.5 | |
| Closed service with public terms last updated 2 March 2023, and MIT licences on the MCP server and SDKs (17). The DPA of 1 July 2025 promises deletion or return of customer personal data within 30 days on request after the service ends. The privacy notice of 12 August 2026 gives no retention periods and says usage analysis includes training AI models, while the MCP security page says MCP data is never used for training (20). No deprecation policy was found. The terms say material changes take effect at the next subscription period, and the changelog mentions retired settings without dates (5). The subprocessor list of 18 September 2026 names each subprocessor with its country, with AWS in the United States, Germany and Australia (20). | |||
| Negative events | ≤15 |
| -2 |
| Total | 68.5 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 18 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on airSlate SignNow, or have the agent fetch /fixes/signnow.md. A fix counts at the next check, once it's public.
Show it
# Fix list: airSlate SignNow From Anchor Terminal's listing at https://www.anchorterminal.com/tools/signnow, the October 2026 research run, assessed 7 October 2026. Grade B, 68.5 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on airSlate SignNow: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 35 out of 100, up to 8.1 more on the total Why it scored 35: No x402, MPP or L402 found (0). The developers page states per-invite prices, from $2 at 500 invites to $1.20 at 5,000. The full plan table is a JavaScript page we couldn't read, so we scored between plan-only and per-unit (15). Development mode is free with up to 500 invites, and the help centre says the free trial needs no credit card (20). A person has to register in a browser and verify an email address before the first key exists (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Security & auth, 62 out of 100, up to 6.7 more on the total Why it scored 62: OAuth 2.0 with password, refresh and authorisation code grants and a `scope` parameter that limits a token to URL patterns. API keys can be deleted but don't expire and work for all API requests, and the hosted MCP server adds OAuth with PKCE (24). We deducted 5 of the possible 10 for secrets in URLs, because embedded links returned by the API carry an `access_token` query parameter, with a 15 to 45 minute expiry on embedded sending links (19). A URL-pattern scope allows a read-only token, the hosted MCP grant covers documents and templates only, and the bundled skill tells agents to wait for confirmation before sending. Nothing enforces that confirmation (12). The API returns document text and field values written by signers, and no prompt-injection guidance was found (3). The API dashboard logs every request and webhook delivery, and documents carry a full history endpoint (13). SOC 2 Type II, PCI DSS and HIPAA per the security page and a HackerOne bug bounty by invitation. security.txt returns 404, and the MCP repository's SECURITY.md still has a placeholder contact (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Agent ergonomics, 66 out of 100, up to 5.5 more on the total Why it scored 66: Graded on the REST API, with the MCP server noted. List endpoints take page and per_page or limit and offset, with no field selection found. The MCP server loads 20 documented tools, 21 in the v3.1.0 source (15). Pagination, filters and sorting exist but in several parameter styles (`filter:type`, `filters[...]`, `sort:created`, `sort_by`) (15). Errors come as a JSON code and message with a troubleshooting page, but code 65582 covers many causes and the docs tell callers to read the message text (13). No idempotency key on the API. The MCP tools set readOnlyHint, destructiveHint and idempotentHint (8). SDKs for PHP, Node, Python, .NET and Java, and an API key works with one header (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Schema & documentation, 81 out of 100, up to 3.1 more on the total Why it scored 81: Graded on the REST API, with the MCP server noted. OpenAPI 3.0.3 and Swagger 2.0 are public, with 226 paths and 354 operations (25). docs.signnow.com/llms.txt indexes a Markdown copy of every page, with llms-full.txt (10). All 354 operations have a description and the MCP tool descriptions say what to call next, but the API reference rarely says when not to use an endpoint (14). The spec marks required fields often but holds only 29 enums across 354 operations (9). 342 operations have examples and there is an API errors page, though numeric codes aren't unique (12). The changelog is dated by month back to February 2025. The spec version stays at 1.0.0 and paths mix unversioned and /v2 routes (11). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Maintenance & community, 72 out of 100, up to 2.5 more on the total Why it scored 72: The API changelog's newest entry is September 2026, dated by month only, and the PHP SDK v3.5.4 shipped on 3 September 2026, 34 days before this check. We scored between the 30-day and 90-day bands (25). The changelog has entries for July, August and September 2026 (20). Closed service with a monthly changelog and API support at api@signnow.com. The MCP repository that the docs name for issue reports is archived (8). SDKs for five languages are current, with PHP in September 2026, Python in April and Node in March. The official MCP registry lists io.github.signnow/sn-mcp-server at 0.3.1 while PyPI has 3.1.0 (13). The MCP repository has CI with ruff, mypy and pytest and 60 test files, and it is archived (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Transparency & trust, 74 out of 100, up to 2.3 more on the total Made of editorial 62, provenance 86. Why it scored 74: Closed service with public terms last updated 2 March 2023, and MIT licences on the MCP server and SDKs (17). The DPA of 1 July 2025 promises deletion or return of customer personal data within 30 days on request after the service ends. The privacy notice of 12 August 2026 gives no retention periods and says usage analysis includes training AI models, while the MCP security page says MCP data is never used for training (20). No deprecation policy was found. The terms say material changes take effect at the next subscription period, and the changelog mentions retired settings without dates (5). The subprocessor list of 18 September 2026 names each subprocessor with its country, with AWS in the United States, Germany and Australia (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points (6 of 10) - security.txt: not found (0 of 10) ## 7. Reliability, 93 out of 100, up to 1.4 more on the total Why it scored 93: Graded as a hosted API. Statuspage at status.signnow.com with six components including API (20). The incident feed shows one incident in the last 90 days, a minor one on 3 September 2026 that made the SignNow University site unavailable for eight minutes, and none on the API component (30). Limits are published with numbers, 500 requests an hour in Development and 1,000 in Live (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers and advice to back off exponentially. No Retry-After header and no idempotency key were found, and sending an invite is a charged write (8). The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime with credits of 10 or 30 per cent (10). The REST API is generally available (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - Until release v2.7.0 on 8 July 2026 the MCP server's signing links carried the user's raw SignNow access token in the URL query string. The fix and a regression test are documented in the pull request, so we deducted 2 (https://github.com/signnow/sn-mcp-server/pull/65). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the API plan table at snseats.signnow.com/purchase/api/pricing (JavaScript-only page). Prices come from the developers page - unchecked: whether the API free trial asks for a card. The help centre says the free trial needs no credit card, without naming the API trial - Why the sn-mcp-server GitHub repository is archived and whether the hosted server at mcp-server.signnow.com is still developed elsewhere. The README and docs carry no notice - unchecked: the hosted MCP server's live tool list, which needs an OAuth sign-in. The count comes from the docs (20) and the v3.1.0 source (21) - Whether the access_token in embedded link URLs is a short-lived link token or the caller's own token - Access-token lifetime. The auth guide's examples show `expires_in` as 2592000 in one response and a timestamp in another - Whether SignNow holds ISO 27001. The security page doesn't list it - unchecked: the help centre article on AI data use (helpcenter.signnow.com), which the MCP security page cites ## Weaknesses - API keys don't expire and work for all API requests. Narrower access needs an OAuth token requested with a URL-pattern scope - No idempotency key was found in the spec or guides, and each signature invite sent is charged - The sn-mcp-server GitHub repository was archived when checked on 7 October 2026, while the docs still send issue reports there - Numeric error codes aren't unique. The docs tell callers to identify a problem by its message text - The API plan table is a JavaScript page we couldn't read. Only the per-invite range on the developers page is public text ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Call https://api.signnow.com with `Authorization: Bearer <API key or access token>`. Development and Live share this host, and Development documents carry a watermark - Request OAuth tokens with a narrow `scope` such as `document/* GET/user`. The default `*` grants every API action - Read `X-RateLimit-Remaining` and `X-RateLimit-Reset` on each response. The limit is 500 requests an hour in Development and 1,000 in Live, and 429 has no Retry-After - Check invite status before resending. No idempotency key exists, and a repeated invite call counts as another charged invite - Set `secret_key` when creating an event subscription and verify `X-SignNow-Signature` (HMAC SHA-256 of the body) on every callback ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the API plan table at snseats.signnow.com/purchase/api/pricing (JavaScript-only page). Prices come from the developers page
- unchecked: whether the API free trial asks for a card. The help centre says the free trial needs no credit card, without naming the API trial
- Why the sn-mcp-server GitHub repository is archived and whether the hosted server at mcp-server.signnow.com is still developed elsewhere. The README and docs carry no notice
- unchecked: the hosted MCP server's live tool list, which needs an OAuth sign-in. The count comes from the docs (20) and the v3.1.0 source (21)
- Whether the access_token in embedded link URLs is a short-lived link token or the caller's own token
- Access-token lifetime. The auth guide's examples show
expires_inas 2592000 in one response and a timestamp in another - Whether SignNow holds ISO 27001. The security page doesn't list it
- unchecked: the help centre article on AI data use (helpcenter.signnow.com), which the MCP security page cites
Sources 27
- developers page, per-invite prices and Development limits signnow.com · seen 2026-10-07
- docs index for agents docs.signnow.com · seen 2026-10-07
- OpenAPI 3.0.3 spec docs.signnow.com · seen 2026-10-07
- authentication guide docs.signnow.com · seen 2026-10-07
- go-live checklist and rate limits docs.signnow.com · seen 2026-10-07
- API dashboard, modes, logs and invite charging docs.signnow.com · seen 2026-10-07
- API errors docs.signnow.com · seen 2026-10-07
- API changelog docs.signnow.com · seen 2026-10-07
- webhooks guide docs.signnow.com · seen 2026-10-07
- MCP server overview, tools and security pages docs.signnow.com · seen 2026-10-07
- MCP tool catalogue docs.signnow.com · seen 2026-10-07
- MCP server security page docs.signnow.com · seen 2026-10-07
- hosted MCP OAuth metadata mcp-server.signnow.com · seen 2026-10-07
- MCP server repository (cloned, v3.1.0, archived per the GitHub API) github.com · seen 2026-10-07
- official MCP registry entry registry.modelcontextprotocol.io · seen 2026-10-07
- PyPI package pypi.org · seen 2026-10-07
- status incidents feed status.signnow.com · seen 2026-10-07
- SLA legal.signnow.com · seen 2026-10-07
- terms of service legal.signnow.com · seen 2026-10-07
- privacy notice legal.signnow.com · seen 2026-10-07
- DPA legal.signnow.com · seen 2026-10-07
- subprocessor list legal.signnow.com · seen 2026-10-07
- contracting entity table legal.signnow.com · seen 2026-10-07
- security and compliance page signnow.com · seen 2026-10-07
- bug bounty programme policies.airslate.com · seen 2026-10-07
- plans and pricing help page signnow.com · seen 2026-10-07
- domain registration rdap.verisign.com · seen 2026-10-07
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Pay per use $2 / tx Paid API plans are priced per signature invite, from $2 per invite at 500 invites to $1.20 at 5,000 per the developers page. An agent can start without a contract. Development mode is free on the production host, with 500 requests an hour and up to 500 invites, and documents carry a Development watermark. The developers page also advertises 250 free signature invites. Live mode needs a paid API plan, an API free trial or a site licence. The full plan table is a JavaScript page we couldn't read (checked 2026-10-07).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Signature invite, 500-invite plan | $2 | per transaction | starting price per the developers page on 2026-10-07 |
| Signature invite, 5,000-invite plan | $1.20 | per transaction | per the developers page on 2026-10-07 |
| Development mode | free | per transaction | up to 500 invites without a plan, watermarked |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/signnow.xml, or this listing's score history at history.json.
Connect
Install
uvx --from signnow-mcp-server sn-mcp serve
First request
curl --request POST \
--url https://api.signnow.com/v2/documents/url \
--header 'Authorization: Bearer {{your_api_key}}' \
--header 'Content-Type: application/json' \
--data '{"url": "https://www.signnow.com/whitepapers/signnow_api_test_invite.pdf"}'
MCP client configuration
{
"mcpServers": {
"signnow-local": {
"args": [
"--from",
"signnow-mcp-server",
"sn-mcp",
"serve"
],
"command": "uvx",
"env": {
"SIGNNOW_API_KEY": "your-api-key"
}
}
}
}
Through letme picks today, calling later
GET https://letme.dev/signnow
letme picks this listing for contracts.generate, because it's the top-graded tool for the job. letme picks this listing for pdf.forms, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
PandaDoc BDocusign BDropbox Sign BDocumenso BAdobe PDF Services / PDF Extract API CPDF.co API + MCP F
Head to head Documenso vs airSlate SignNow · Docusign vs airSlate SignNow · Dropbox Sign vs airSlate SignNow · PandaDoc vs airSlate SignNow
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| PandaDoc PandaDoc | B | 63.1 | esign.send esign.templates esign.embed esign.status contracts.generate | no |
| Docusign Docusign, Inc. | B | 62.5 | esign.send esign.templates esign.embed esign.status contracts.generate | no |
| Dropbox Sign Dropbox, Inc. | B | 68.9 | esign.send esign.templates esign.embed esign.status | no |
| Documenso Documenso, Inc. | B | 62.8 | esign.send esign.templates esign.status esign.embed | no |
| Adobe PDF Services / PDF Extract API Adobe | C | 55.9 | pdf.forms | no |
| PDF.co API + MCP PDF.co (Artifex Software) | F | 37.9 | pdf.forms | no |
Machine-readable
- JSON
/api/v1/tools/signnow.json· historyhistory.json· badge/badges/signnow.svg· changes feed/feeds/tools/signnow.xml - Markdown
/tools/signnow.md· slim/tools/signnow.min.md(or sendAccept: text/markdown) - Fix list
/fixes/signnow.md·/fixes/signnow.json - From a terminal
anchor tool signnow --md(the CLI) · over MCPget_tool {"slug": "signnow"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/signnow"><img src="https://www.anchorterminal.com/badges/signnow.svg" alt="airSlate SignNow on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/signnow)<a href="https://www.anchorterminal.com/tools/signnow">airSlate SignNow on Anchor Terminal</a>It counts on a page on signnow.com or one of its subdomains, or the README of github.com/signnow/sn-mcp-server.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "signnow", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
