{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/pandadoc.json",
        "name": "PandaDoc",
        "score": 63.1,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status",
          "contracts.generate"
        ],
        "slug": "pandadoc"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/docusign.json",
        "name": "Docusign",
        "score": 62.5,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status",
          "contracts.generate"
        ],
        "slug": "docusign"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/dropbox-sign.json",
        "name": "Dropbox Sign",
        "score": 68.9,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.embed",
          "esign.status"
        ],
        "slug": "dropbox-sign"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/documenso.json",
        "name": "Documenso",
        "score": 62.8,
        "shared": [
          "esign.send",
          "esign.templates",
          "esign.status",
          "esign.embed"
        ],
        "slug": "documenso"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/adobe-pdf-extract.json",
        "name": "Adobe PDF Services / PDF Extract API",
        "score": 55.9,
        "shared": [
          "pdf.forms"
        ],
        "slug": "adobe-pdf-extract"
      },
      {
        "grade": "F",
        "json": "https://www.anchorterminal.com/tools/pdf-co.json",
        "name": "PDF.co API + MCP",
        "score": 37.9,
        "shared": [
          "pdf.forms"
        ],
        "slug": "pdf-co"
      }
    ],
    "tool": {
      "slug": "signnow",
      "name": "airSlate SignNow",
      "vendor": "airSlate, Inc.",
      "vendorUrl": "https://www.signnow.com",
      "kind": "http-api",
      "category": "e-signatures",
      "summary": "airSlate SignNow is an e-signature service. Its REST API prepares documents from templates, sends signature invites, embeds signing in other apps and reports status through webhooks. A hosted MCP server gives AI agents 20 documented tools over the same account.",
      "url": "https://www.anchorterminal.com/tools/signnow",
      "markdownUrl": "https://www.anchorterminal.com/tools/signnow.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/signnow.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/signnow.json",
      "repo": "https://github.com/signnow/sn-mcp-server",
      "license": "Proprietary service under the SignNow Terms of Service. The MCP server and the SDKs on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://api.signnow.com",
      "packages": [
        {
          "registry": "pypi",
          "name": "signnow-mcp-server"
        },
        {
          "registry": "npm",
          "name": "@signnow/api-client"
        },
        {
          "registry": "pypi",
          "name": "signnow-python-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A free developer account creates an application and an API key in the API dashboard, with no app review. The API takes a Bearer API key (no expiry, all API requests) or an OAuth 2.0 access token from POST /oauth2/token using the password, refresh_token or authorization_code grant. The `scope` parameter limits a token to URL patterns such as `document/* GET/user`, and the default `*` allows every action. The hosted MCP server uses OAuth with PKCE and dynamic client registration, and the local package takes an API key or account email, password and Basic token.",
      "pricing": "usage",
      "pricingNotes": "Paid API plans are priced per signature invite, from $2 per invite at 500 invites to $1.20 at 5,000 per the developers page. An agent can start without a contract. Development mode is free on the production host, with 500 requests an hour and up to 500 invites, and documents carry a Development watermark. The developers page also advertises 250 free signature invites. Live mode needs a paid API plan, an API free trial or a site licence. The full plan table is a JavaScript page we couldn't read (checked 2026-10-07).",
      "priceSummary": "$2 / tx",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI spec, the developers page or the MCP server repository (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 21,
      "popularity": {
        "githubStars": 8,
        "npmWeekly": 7740,
        "pypiWeekly": 5269,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://docs.signnow.com",
      "llmsTxt": "https://docs.signnow.com/llms.txt",
      "openapi": "https://docs.signnow.com/api/openapi.json",
      "registryName": "io.github.signnow/sn-mcp-server",
      "capabilities": [
        "esign.send",
        "esign.templates",
        "esign.embed",
        "esign.status",
        "contracts.generate",
        "pdf.forms"
      ],
      "tags": [
        "hosted",
        "usage-based",
        "free-tier",
        "sandbox",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "php",
        "python",
        "typescript",
        "dotnet",
        "java",
        "status-page",
        "sla",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-03",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.5,
        "grade": "B",
        "agentReady": false,
        "rank": 178,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 72,
          "payments": 35,
          "reliability": 93,
          "schema": 81,
          "security": 62,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 93,
            "points": 18.6,
            "reason": "Graded as a hosted API. Statuspage at status.signnow.com with six components including API (20). The incident feed shows one incident in the last 90 days, a minor one on 3 September 2026 that made the SignNow University site unavailable for eight minutes, and none on the API component (30). Limits are published with numbers, 500 requests an hour in Development and 1,000 in Live (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers and advice to back off exponentially. No Retry-After header and no idempotency key were found, and sending an invite is a charged write (8). The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime with credits of 10 or 30 per cent (10). The REST API is generally available (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "Graded on the REST API, with the MCP server noted. OpenAPI 3.0.3 and Swagger 2.0 are public, with 226 paths and 354 operations (25). docs.signnow.com/llms.txt indexes a Markdown copy of every page, with llms-full.txt (10). All 354 operations have a description and the MCP tool descriptions say what to call next, but the API reference rarely says when not to use an endpoint (14). The spec marks required fields often but holds only 29 enums across 354 operations (9). 342 operations have examples and there is an API errors page, though numeric codes aren't unique (12). The changelog is dated by month back to February 2025. The spec version stays at 1.0.0 and paths mix unversioned and /v2 routes (11)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 66,
            "points": 10.73,
            "reason": "Graded on the REST API, with the MCP server noted. List endpoints take page and per_page or limit and offset, with no field selection found. The MCP server loads 20 documented tools, 21 in the v3.1.0 source (15). Pagination, filters and sorting exist but in several parameter styles (`filter:type`, `filters[...]`, `sort:created`, `sort_by`) (15). Errors come as a JSON code and message with a troubleshooting page, but code 65582 covers many causes and the docs tell callers to read the message text (13). No idempotency key on the API. The MCP tools set readOnlyHint, destructiveHint and idempotentHint (8). SDKs for PHP, Node, Python, .NET and Java, and an API key works with one header (15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 62,
            "points": 10.85,
            "reason": "OAuth 2.0 with password, refresh and authorisation code grants and a `scope` parameter that limits a token to URL patterns. API keys can be deleted but don't expire and work for all API requests, and the hosted MCP server adds OAuth with PKCE (24). We deducted 5 of the possible 10 for secrets in URLs, because embedded links returned by the API carry an `access_token` query parameter, with a 15 to 45 minute expiry on embedded sending links (19). A URL-pattern scope allows a read-only token, the hosted MCP grant covers documents and templates only, and the bundled skill tells agents to wait for confirmation before sending. Nothing enforces that confirmation (12). The API returns document text and field values written by signers, and no prompt-injection guidance was found (3). The API dashboard logs every request and webhook delivery, and documents carry a full history endpoint (13). SOC 2 Type II, PCI DSS and HIPAA per the security page and a HackerOne bug bounty by invitation. security.txt returns 404, and the MCP repository's SECURITY.md still has a placeholder contact (15)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 35,
            "points": 4.38,
            "reason": "No x402, MPP or L402 found (0). The developers page states per-invite prices, from $2 at 500 invites to $1.20 at 5,000. The full plan table is a JavaScript page we couldn't read, so we scored between plan-only and per-unit (15). Development mode is free with up to 500 invites, and the help centre says the free trial needs no credit card (20). A person has to register in a browser and verify an email address before the first key exists (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "reason": "The API changelog's newest entry is September 2026, dated by month only, and the PHP SDK v3.5.4 shipped on 3 September 2026, 34 days before this check. We scored between the 30-day and 90-day bands (25). The changelog has entries for July, August and September 2026 (20). Closed service with a monthly changelog and API support at api@signnow.com. The MCP repository that the docs name for issue reports is archived (8). SDKs for five languages are current, with PHP in September 2026, Python in April and Node in March. The official MCP registry lists io.github.signnow/sn-mcp-server at 0.3.1 while PyPI has 3.1.0 (13). The MCP repository has CI with ruff, mypy and pytest and 60 test files, and it is archived (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 74,
            "points": 6.48,
            "note": "editorial 62, provenance 86",
            "reason": "Closed service with public terms last updated 2 March 2023, and MIT licences on the MCP server and SDKs (17). The DPA of 1 July 2025 promises deletion or return of customer personal data within 30 days on request after the service ends. The privacy notice of 12 August 2026 gives no retention periods and says usage analysis includes training AI models, while the MCP security page says MCP data is never used for training (20). No deprecation policy was found. The terms say material changes take effect at the next subscription period, and the changelog mentions retired settings without dates (5). The subprocessor list of 18 September 2026 names each subprocessor with its country, with AWS in the United States, Germany and Australia (20)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API, with the MCP server noted. List endpoints take page and per_page or limit and offset, with no field selection found. The MCP server loads 20 documented tools, 21 in the v3.1.0 source (15). Pagination, filters and sorting exist but in several parameter styles (`filter:type`, `filters[...]`, `sort:created`, `sort_by`) (15). Errors come as a JSON code and message with a troubleshooting page, but code 65582 covers many causes and the docs tell callers to read the message text (13). No idempotency key on the API. The MCP tools set readOnlyHint, destructiveHint and idempotentHint (8). SDKs for PHP, Node, Python, .NET and Java, and an API key works with one header (15).",
            "maintenance": "The API changelog's newest entry is September 2026, dated by month only, and the PHP SDK v3.5.4 shipped on 3 September 2026, 34 days before this check. We scored between the 30-day and 90-day bands (25). The changelog has entries for July, August and September 2026 (20). Closed service with a monthly changelog and API support at api@signnow.com. The MCP repository that the docs name for issue reports is archived (8). SDKs for five languages are current, with PHP in September 2026, Python in April and Node in March. The official MCP registry lists io.github.signnow/sn-mcp-server at 0.3.1 while PyPI has 3.1.0 (13). The MCP repository has CI with ruff, mypy and pytest and 60 test files, and it is archived (6).",
            "payments": "No x402, MPP or L402 found (0). The developers page states per-invite prices, from $2 at 500 invites to $1.20 at 5,000. The full plan table is a JavaScript page we couldn't read, so we scored between plan-only and per-unit (15). Development mode is free with up to 500 invites, and the help centre says the free trial needs no credit card (20). A person has to register in a browser and verify an email address before the first key exists (0).",
            "reliability": "Graded as a hosted API. Statuspage at status.signnow.com with six components including API (20). The incident feed shows one incident in the last 90 days, a minor one on 3 September 2026 that made the SignNow University site unavailable for eight minutes, and none on the API component (30). Limits are published with numbers, 500 requests an hour in Development and 1,000 in Live (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers and advice to back off exponentially. No Retry-After header and no idempotency key were found, and sending an invite is a charged write (8). The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime with credits of 10 or 30 per cent (10). The REST API is generally available (10).",
            "schema": "Graded on the REST API, with the MCP server noted. OpenAPI 3.0.3 and Swagger 2.0 are public, with 226 paths and 354 operations (25). docs.signnow.com/llms.txt indexes a Markdown copy of every page, with llms-full.txt (10). All 354 operations have a description and the MCP tool descriptions say what to call next, but the API reference rarely says when not to use an endpoint (14). The spec marks required fields often but holds only 29 enums across 354 operations (9). 342 operations have examples and there is an API errors page, though numeric codes aren't unique (12). The changelog is dated by month back to February 2025. The spec version stays at 1.0.0 and paths mix unversioned and /v2 routes (11).",
            "security": "OAuth 2.0 with password, refresh and authorisation code grants and a `scope` parameter that limits a token to URL patterns. API keys can be deleted but don't expire and work for all API requests, and the hosted MCP server adds OAuth with PKCE (24). We deducted 5 of the possible 10 for secrets in URLs, because embedded links returned by the API carry an `access_token` query parameter, with a 15 to 45 minute expiry on embedded sending links (19). A URL-pattern scope allows a read-only token, the hosted MCP grant covers documents and templates only, and the bundled skill tells agents to wait for confirmation before sending. Nothing enforces that confirmation (12). The API returns document text and field values written by signers, and no prompt-injection guidance was found (3). The API dashboard logs every request and webhook delivery, and documents carry a full history endpoint (13). SOC 2 Type II, PCI DSS and HIPAA per the security page and a HackerOne bug bounty by invitation. security.txt returns 404, and the MCP repository's SECURITY.md still has a placeholder contact (15).",
            "transparency": "Closed service with public terms last updated 2 March 2023, and MIT licences on the MCP server and SDKs (17). The DPA of 1 July 2025 promises deletion or return of customer personal data within 30 days on request after the service ends. The privacy notice of 12 August 2026 gives no retention periods and says usage analysis includes training AI models, while the MCP security page says MCP data is never used for training (20). No deprecation policy was found. The terms say material changes take effect at the next subscription period, and the changelog mentions retired settings without dates (5). The subprocessor list of 18 September 2026 names each subprocessor with its country, with AWS in the United States, Germany and Australia (20)."
          },
          "sources": [
            {
              "what": "developers page, per-invite prices and Development limits",
              "url": "https://www.signnow.com/developers",
              "seen": "2026-10-07"
            },
            {
              "what": "docs index for agents",
              "url": "https://docs.signnow.com/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "OpenAPI 3.0.3 spec",
              "url": "https://docs.signnow.com/api/openapi.json",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication guide",
              "url": "https://docs.signnow.com/docs/authentication.md",
              "seen": "2026-10-07"
            },
            {
              "what": "go-live checklist and rate limits",
              "url": "https://docs.signnow.com/docs/go-live-checklist.md",
              "seen": "2026-10-07"
            },
            {
              "what": "API dashboard, modes, logs and invite charging",
              "url": "https://docs.signnow.com/docs/account.md",
              "seen": "2026-10-07"
            },
            {
              "what": "API errors",
              "url": "https://docs.signnow.com/docs/api-errors.md",
              "seen": "2026-10-07"
            },
            {
              "what": "API changelog",
              "url": "https://docs.signnow.com/docs/signnow-api-changelog.md",
              "seen": "2026-10-07"
            },
            {
              "what": "webhooks guide",
              "url": "https://docs.signnow.com/docs/guides-webhooks.md",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server overview, tools and security pages",
              "url": "https://docs.signnow.com/docs/mcp-server.md",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP tool catalogue",
              "url": "https://docs.signnow.com/docs/mcp-tools.md",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server security page",
              "url": "https://docs.signnow.com/docs/mcp-server-security.md",
              "seen": "2026-10-07"
            },
            {
              "what": "hosted MCP OAuth metadata",
              "url": "https://mcp-server.signnow.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server repository (cloned, v3.1.0, archived per the GitHub API)",
              "url": "https://github.com/signnow/sn-mcp-server",
              "seen": "2026-10-07"
            },
            {
              "what": "official MCP registry entry",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=signnow",
              "seen": "2026-10-07"
            },
            {
              "what": "PyPI package",
              "url": "https://pypi.org/project/signnow-mcp-server/",
              "seen": "2026-10-07"
            },
            {
              "what": "status incidents feed",
              "url": "https://status.signnow.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "SLA",
              "url": "https://legal.signnow.com/sla",
              "seen": "2026-10-07"
            },
            {
              "what": "terms of service",
              "url": "https://legal.signnow.com/terms",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy notice",
              "url": "https://legal.signnow.com/privacy-notice",
              "seen": "2026-10-07"
            },
            {
              "what": "DPA",
              "url": "https://legal.signnow.com/dpa",
              "seen": "2026-10-07"
            },
            {
              "what": "subprocessor list",
              "url": "https://legal.signnow.com/subprocessors",
              "seen": "2026-10-07"
            },
            {
              "what": "contracting entity table",
              "url": "https://legal.signnow.com/contracting-entity-table",
              "seen": "2026-10-07"
            },
            {
              "what": "security and compliance page",
              "url": "https://www.signnow.com/security",
              "seen": "2026-10-07"
            },
            {
              "what": "bug bounty programme",
              "url": "https://policies.airslate.com/bug-bounty-program",
              "seen": "2026-10-07"
            },
            {
              "what": "plans and pricing help page",
              "url": "https://www.signnow.com/help/plans-pricing.md",
              "seen": "2026-10-07"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.verisign.com/com/v1/domain/signnow.com",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the API plan table at snseats.signnow.com/purchase/api/pricing (JavaScript-only page). Prices come from the developers page",
            "unchecked: whether the API free trial asks for a card. The help centre says the free trial needs no credit card, without naming the API trial",
            "Why the sn-mcp-server GitHub repository is archived and whether the hosted server at mcp-server.signnow.com is still developed elsewhere. The README and docs carry no notice",
            "unchecked: the hosted MCP server's live tool list, which needs an OAuth sign-in. The count comes from the docs (20) and the v3.1.0 source (21)",
            "Whether the access_token in embedded link URLs is a short-lived link token or the caller's own token",
            "Access-token lifetime. The auth guide's examples show `expires_in` as 2592000 in one response and a timestamp in another",
            "Whether SignNow holds ISO 27001. The security page doesn't list it",
            "unchecked: the help centre article on AI data use (helpcenter.signnow.com), which the MCP security page cites"
          ]
        },
        "negative": -2,
        "negativeNotes": [
          "Until release v2.7.0 on 8 July 2026 the MCP server's signing links carried the user's raw SignNow access token in the URL query string. The fix and a regression test are documented in the pull request, so we deducted 2 (https://github.com/signnow/sn-mcp-server/pull/65)."
        ],
        "verdict": "The REST API has a public OpenAPI 3.0 spec with 354 operations, Markdown docs, a free Development mode with 500 invites and a hosted MCP server with OAuth. API keys don't expire and carry full account access, no idempotency keys were found, and the MCP server's GitHub repository was archived when checked on 7 October 2026.",
        "bestFor": "An agent that sends agreements from templates, embeds signing in another product or tracks invites, and teams that want per-invite pricing with a free test mode.",
        "strengths": [
          "Public OpenAPI 3.0.3 spec with 354 operations, 342 of them with examples, plus llms.txt and a Markdown copy of every docs page",
          "Development mode is free on the production host, with 500 requests an hour and up to 500 signature invites without a plan",
          "Hosted MCP server at mcp-server.signnow.com/mcp with OAuth, PKCE and dynamic client registration, and read-only and destructive hints on its tools",
          "Webhooks carry an HMAC SHA-256 signature header and a documented retry schedule, and the API dashboard logs every request and delivery attempt",
          "Status page shows three minor incidents since April 2026, none on the API component, and a 99.9 per cent SLA with credits is published"
        ],
        "weaknesses": [
          "API keys don't expire and work for all API requests. Narrower access needs an OAuth token requested with a URL-pattern scope",
          "No idempotency key was found in the spec or guides, and each signature invite sent is charged",
          "The sn-mcp-server GitHub repository was archived when checked on 7 October 2026, while the docs still send issue reports there",
          "Numeric error codes aren't unique. The docs tell callers to identify a problem by its message text",
          "The API plan table is a JavaScript page we couldn't read. Only the per-invite range on the developers page is public text"
        ],
        "agentNotes": [
          "Call https://api.signnow.com with `Authorization: Bearer \u003cAPI key or access token\u003e`. Development and Live share this host, and Development documents carry a watermark",
          "Request OAuth tokens with a narrow `scope` such as `document/* GET/user`. The default `*` grants every API action",
          "Read `X-RateLimit-Remaining` and `X-RateLimit-Reset` on each response. The limit is 500 requests an hour in Development and 1,000 in Live, and 429 has no Retry-After",
          "Check invite status before resending. No idempotency key exists, and a repeated invite call counts as another charged invite",
          "Set `secret_key` when creating an event subscription and verify `X-SignNow-Signature` (HMAC SHA-256 of the body) on every callback"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.5
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 72,
          "payments": 35,
          "reliability": 93,
          "schema": 81,
          "security": 62,
          "transparency": 62
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "uvx --from signnow-mcp-server sn-mcp serve",
        "http": "curl --request POST \\\n  --url https://api.signnow.com/v2/documents/url \\\n  --header 'Authorization: Bearer {{your_api_key}}' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"url\": \"https://www.signnow.com/whitepapers/signnow_api_test_invite.pdf\"}'",
        "config": {
          "mcpServers": {
            "signnow-local": {
              "args": [
                "--from",
                "signnow-mcp-server",
                "sn-mcp",
                "serve"
              ],
              "command": "uvx",
              "env": {
                "SIGNNOW_API_KEY": "your-api-key"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/esign.send",
        "tool": "https://letme.dev/signnow"
      },
      "notable": [
        "The API reference is published as OpenAPI 3.0.3 and Swagger 2.0, with 226 paths and 354 operations against https://api.signnow.com (https://docs.signnow.com/api/openapi.json)",
        "The hosted MCP server answers at https://mcp-server.signnow.com/mcp and returns 401 with OAuth metadata that lists authorisation code and refresh grants, S256 PKCE and a registration endpoint (https://mcp-server.signnow.com/.well-known/oauth-authorization-server)",
        "SignNow documents 20 MCP tools for templates, documents, contacts, invites and embedded sessions. Release v3.1.0 registers those 20 plus `signnow_skills` (https://docs.signnow.com/docs/mcp-tools)",
        "The sn-mcp-server repository is marked archived on GitHub, last pushed 27 July 2026, while the docs still point to its issue tracker (https://github.com/signnow/sn-mcp-server)",
        "Development mode runs on the production host with 500 requests an hour and up to 500 signature invites without a plan. Live mode defaults to 1,000 requests an hour (https://docs.signnow.com/docs/account)",
        "The developers page prices paid API plans from $2 per invite at 500 invites to $1.20 per invite at 5,000 (https://www.signnow.com/developers)",
        "The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime, with credits of 10 or 30 per cent (https://legal.signnow.com/sla)",
        "The subprocessor list, updated 18 September 2026, names AWS in the United States, Germany and Australia, and OpenAI, Anthropic and Google as LLM subprocessors (https://legal.signnow.com/subprocessors)"
      ],
      "area": "business",
      "details": [
        {
          "label": "API",
          "value": "REST at https://api.signnow.com, OpenAPI 3.0.3 with 226 paths and 354 operations, a mix of unversioned and /v2 paths. One host for Development and Live modes"
        },
        {
          "label": "MCP server",
          "value": "Hosted at https://mcp-server.signnow.com/mcp (Streamable HTTP, OAuth). Also the PyPI package signnow-mcp-server 3.1.0 for stdio or self-hosted HTTP, MIT, Python 3.10 or later. Connectors listed for Claude and ChatGPT"
        },
        {
          "label": "MCP tools",
          "value": "list_all_templates, create_from_template, create_template, upload_document, list_documents, get_document, view_document, update_document_fields, rename_entity, get_document_download_link, list_contacts, send_invite, get_invite_status, get_signing_link, send_invite_reminder, update_invite_recipient, cancel_invite, create_embedded_invite, create_embedded_sending, create_embedded_editor, plus signnow_skills in the v3.1.0 source"
        },
        {
          "label": "Credentials",
          "value": "API keys from the API dashboard (no expiry, all API requests, unlimited keys per application, deleted to revoke). OAuth 2.0 with password, refresh_token and authorization_code grants. The auth guide's code-grant example returns `expires_in` 2592000. `scope` takes URL patterns, default `*`"
        },
        {
          "label": "Rate limits",
          "value": "500 requests an hour per application in Development, 1,000 an hour by default in Live, raised through support. X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset on every response. 429 on excess"
        },
        {
          "label": "Errors",
          "value": "400, 401, 403, 404 and 429 with a JSON `errors` array of numeric code and message. Code 65582 covers many validation errors, so the message text identifies the problem"
        },
        {
          "label": "Webhooks",
          "value": "Event subscriptions for document, document group and user events. Optional `secret_key` adds an `X-SignNow-Signature` HMAC SHA-256 header. 20-second timeout, 5 retries 10 seconds apart then more 4 hours apart, `retry_count` up to 10. Accounts without an API plan are limited to 10 active webhooks"
        },
        {
          "label": "Embedded flows",
          "value": "Embedded signing, sending, editor and view links for documents and document groups. Embedded sending links expire after 15 to 45 minutes"
        },
        {
          "label": "Document generation",
          "value": "POST /v2/document-generations/upload and /url fill a tagged .docx from data and return a document ready for signature, with a status endpoint"
        },
        {
          "label": "Audit",
          "value": "GET /document/{document_id}/historyfull and the document group equivalent return the signing history. The API dashboard logs every request and webhook delivery, and API-log endpoints are in the reference"
        },
        {
          "label": "SDKs",
          "value": "PHP signnow/api-php-sdk v3.5.4 (3 September 2026), Node @signnow/api-client 3.2.0 (11 March 2026), Python signnow-python-sdk 3.0.0 (22 April 2026), .NET, Java and Android, plus a Postman collection"
        },
        {
          "label": "Pricing",
          "value": "Development mode free. Paid API plans from $2 per invite at 500 invites to $1.20 per invite at 5,000 per the developers page, which also advertises 250 free signature invites. A site licence covers the web app and API for many users"
        },
        {
          "label": "SLA",
          "value": "99.9 per cent monthly uptime on commercially reasonable efforts, credits of 10 per cent below 99.9 and 30 per cent below 99.0, claims within 30 days. Last updated 11 January 2023"
        },
        {
          "label": "Status",
          "value": "status.signnow.com on Statuspage, components Web, Mobile apps, API, Integrations, Payments and Support. Three incidents since April 2026, all minor and on Web"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II (report on request), PCI DSS, HIPAA, GDPR, 21 CFR Part 11, CCPA, ESIGN and UETA per signnow.com/security. Bug bounty through HackerOne by invitation"
        }
      ],
      "unitPrices": [
        {
          "item": "Signature invite, 500-invite plan",
          "unit": "tx",
          "usd": 2,
          "note": "starting price per the developers page on 2026-10-07"
        },
        {
          "item": "Signature invite, 5,000-invite plan",
          "unit": "tx",
          "usd": 1.2,
          "note": "per the developers page on 2026-10-07"
        },
        {
          "item": "Development mode",
          "unit": "tx",
          "usd": 0,
          "note": "up to 500 invites without a plan, watermarked"
        }
      ],
      "provenance": {
        "legalEntity": "airSlate, Inc.",
        "domain": "signnow.com",
        "domainRegistered": "2001-04-05",
        "endpointOnVendorDomain": true,
        "terms": "https://legal.signnow.com/terms",
        "privacy": "https://legal.signnow.com/privacy-notice",
        "statusPage": "https://status.signnow.com",
        "changelog": "https://docs.signnow.com/docs/signnow-api-changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The privacy notice (last updated 12 August 2026) names airSlate, Inc., 17 Station Street, Ste. 203, Brookline, MA 02445. The contracting entity table (last updated 1 October 2026) lists seven airSlate companies, and the one that applies depends on the service, location and payment method.",
          "The API answers at api.signnow.com and the hosted MCP server at mcp-server.signnow.com, both signnow.com subdomains.",
          "www.signnow.com/.well-known/security.txt returns 404. Vulnerability reports go through the airSlate bug bounty programme on HackerOne, which needs an invitation requested by email (policy last updated 7 October 2025).",
          "The terms of service were last updated 2 March 2023, the SLA 11 January 2023 and the DPA 1 July 2025.",
          "RDAP for signnow.com gives a registration date of 2001-04-05 and GoDaddy.com, LLC as registrar."
        ],
        "score": 86,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "airSlate, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "signnow.com, registered 2001-04-05 (25 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.signnow.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 6,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.signnow.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://legal.signnow.com/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2023-03-02",
            "words": 5317,
            "points": 6,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: March 2, 2023",
                "says": "Last updated 2023-03-02"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "If any part of the Agreement is found unenforceable by a court of competent jurisdiction, the rest of the Agreement will nonetheless continue in effect, and both parties agree that the unenforceable provisions will be modified so as to best accomplish the objectives of the Agreement within the limits of applicable law."
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "EXCEPT FOR YOUR BREACH OF ANY OF YOUR OBLIGATIONS IN SECTION 5 ABOVE, IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES OF ANY KIND, INCLUDING, WITHOUT LIMITATION, LOST REVENUES, PROFITS, OR GOODWILL, LOST DATA OR CONTENT, DATA BREACHES, LOST C…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If Provider reasonably determines that you violate any of the use restrictions above, Provider may suspend or terminate your access to the Services or utilize other mechanisms available to Provider to prevent violations, including removing violating content and deactivating URLs or links provided by the Services."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "PROVIDER MAY FROM TIME TO TIME PROPOSE CHANGES TO THIS AGREEMENT BY POSTING AN UPDATED VERSION OF THE AGREEMENT ON ITS WEBSITES.",
                "says": "Changes are posted, with no other notice named"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "If you lose your credentials (including deleting or losing access to your email), you may not be able to restore access to your account and Your Content."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "“Service Level Agreement”, which governs the availability of the Subscription Services for Subscribers, available at https://www.signnow.com/sla."
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(iv) share your login credentials with anyone or use any automated system, including robots, spiders, or offline readers, to access or operate the Services;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(vi) use the Services for the benefit of a competitive offering;",
                "costsPoints": true
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "PLEASE ALSO NOTE THAT THESE TERMS CONTAIN A CLASS ACTION WAIVER."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last Updated: March 2, 2023"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Usage above the plan limit is billed as excess usage, and the vendor is not obliged to warn the customer before those fees are incurred.",
                "quote": "(iv) you are responsible for tracking your usage, and Provider is not obligated to notify you before you incur excess usage fees."
              },
              {
                "date": "2026-10-08",
                "text": "After termination the customer has 30 days to ask for access to download its content, after which the vendor may delete it.",
                "quote": "On request made within thirty (30) days after termination, Provider will grant you reasonable access to your Services solely for you to download Your Content using Services’ standard download functionalities."
              },
              {
                "date": "2026-10-08",
                "text": "The vendor may use the customer's name and logo to identify it as a customer, including on the vendor's website.",
                "quote": "Provider may use your name and logo for the limited purpose of identifying you as a customer, including by listing your company’s name and logo on Provider’s website."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://legal.signnow.com/privacy-notice",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-08-12",
            "words": 5185,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: August 12, 2026",
                "says": "Last updated 2026-08-12"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Notice describes what personal information we collect, why and when we collect it, how we may use, disclose, and retain it, and what choices or rights you may have about your personal information."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We generally retain personal information for as long as necessary for the purposes we collected it, including satisfying any legal, financial, or reporting obligations, establishing or defending legal claims, or for compliance and protection.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Process personal information as a service provider or data processor for our enterprise customer(s)."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "SignNow does not sell or otherwise monetize personal information except for sharing it only for cross-context behavioral advertising (CCBA) as described below:",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If we declined your Privacy Rights request, you may contact us about our decision or submit a request again."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If we declined your Privacy Rights request, you may contact us about our decision or submit a request again."
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "All our US-based Contracting Entities comply with the principles and are self-certified under the EU-US Data Privacy Framework (DPF), the Swiss-U.S.",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We may share your personal information with our third-party advertising partners to target advertising to you."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The notice says analysing how the services are used and interacted with includes training the vendor's AI models.",
                "quote": "This includes training our artificial intelligence (AI) models"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/signnow.json",
      "live": {
        "slug": "signnow",
        "probe": {
          "target": "https://api.signnow.com",
          "method": "get",
          "lastAt": "2026-10-08T19:53:02.055545374Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 238,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 252,
          "p95ms24h": 558,
          "samples24h": 50,
          "samples30d": 50,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.signnow.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:02.901266807Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "signnow/sn-mcp-server",
            "version": "v3.1.0",
            "released": "2026-07-27",
            "seenAt": "2026-10-08T16:29:25.573934814Z"
          },
          {
            "registry": "npm",
            "name": "@signnow/api-client",
            "version": "3.2.0",
            "seenAt": "2026-10-08T16:29:23.703958905Z"
          },
          {
            "registry": "pypi",
            "name": "signnow-mcp-server",
            "version": "3.1.0",
            "released": "2026-07-27",
            "seenAt": "2026-10-08T16:29:23.463809186Z"
          },
          {
            "registry": "pypi",
            "name": "signnow-python-sdk",
            "version": "3.0.0",
            "released": "2026-04-22",
            "seenAt": "2026-10-08T16:29:24.862815003Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 7740,
        "pypiWeekly": 70,
        "securityTxt": {
          "url": "https://signnow.com/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:43.774562572Z"
        },
        "pages": [
          {
            "url": "https://docs.signnow.com/docs/signnow-api-changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:25.175101948Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f7e65ecd983f"
          },
          {
            "url": "https://legal.signnow.com/privacy-notice",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:31.1526774Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "379fe4bab8f4"
          },
          {
            "url": "https://legal.signnow.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:33.269754055Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ab6de5f8c31e"
          }
        ],
        "updatedAt": "2026-10-08T19:53:02.055545374Z"
      }
    },
    "verify": {
      "accepts": "a page on signnow.com or one of its subdomains, or the README of github.com/signnow/sn-mcp-server",
      "badgeUrl": "https://www.anchorterminal.com/badges/signnow.svg",
      "body": {
        "slug": "signnow",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/signnow",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/signnow\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/signnow.svg\" alt=\"airSlate SignNow on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![airSlate SignNow on Anchor Terminal](https://www.anchorterminal.com/badges/signnow.svg)](https://www.anchorterminal.com/tools/signnow)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/signnow\"\u003eairSlate SignNow on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/signnow",
    "json": "https://www.anchorterminal.com/tools/signnow.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/signnow.md",
    "slim": "https://www.anchorterminal.com/tools/signnow.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 68.5/100 · rank #178 of 722 · #2 in Contracts, proposals \u0026 e-signatures · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST API has a public OpenAPI 3.0 spec with 354 operations, Markdown docs, a free Development mode with 500 invites and a hosted MCP server with OAuth. API keys don't expire and carry full account access, no idempotency keys were found, and the MCP server's GitHub repository was archived when checked on 7 October 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | airSlate, Inc. (https://www.signnow.com) |\n| Kind | HTTP API |\n| Category | Contracts, proposals \u0026 e-signatures (https://www.anchorterminal.com/categories/e-signatures) |\n| Transport | HTTP, Streamable HTTP, stdio |\n| Endpoint | `https://api.signnow.com` |\n| Auth | OAuth or key · Access is self-serve. A free developer account creates an application and an API key in the API dashboard, with no app review. The API takes a Bearer API key (no expiry, all API requests) or an OAuth 2.0 access token from POST /oauth2/token using the password, refresh_token or authorization_code grant. The `scope` parameter limits a token to URL patterns such as `document/* GET/user`, and the default `*` allows every action. The hosted MCP server uses OAuth with PKCE and dynamic client registration, and the local package takes an API key or account email, password and Basic token. |\n| Pricing | Pay per use ($2 / tx) · Paid API plans are priced per signature invite, from $2 per invite at 500 invites to $1.20 at 5,000 per the developers page. An agent can start without a contract. Development mode is free on the production host, with 500 requests an hour and up to 500 invites, and documents carry a Development watermark. The developers page also advertises 250 free signature invites. Live mode needs a paid API plan, an API free trial or a site licence. The full plan table is a JavaScript page we couldn't read (checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI spec, the developers page or the MCP server repository (checked 2026-10-07). |\n| Licence | Proprietary service under the SignNow Terms of Service. The MCP server and the SDKs on GitHub are MIT |\n| Tools exposed | 21 |\n| Packages | pypi: `signnow-mcp-server`; npm: `@signnow/api-client`; pypi: `signnow-python-sdk` |\n| MCP registry name | `io.github.signnow/sn-mcp-server` |\n| Source | https://github.com/signnow/sn-mcp-server |\n| Docs | https://docs.signnow.com |\n| llms.txt | https://docs.signnow.com/llms.txt |\n| Last release | 2026-09-03 |\n| GitHub stars | 8 (as of 2026-10-07) |\n| npm downloads / week | 7,740 |\n| PyPI downloads / week | 5,269 |\n| API | REST at https://api.signnow.com, OpenAPI 3.0.3 with 226 paths and 354 operations, a mix of unversioned and /v2 paths. One host for Development and Live modes |\n| MCP server | Hosted at https://mcp-server.signnow.com/mcp (Streamable HTTP, OAuth). Also the PyPI package signnow-mcp-server 3.1.0 for stdio or self-hosted HTTP, MIT, Python 3.10 or later. Connectors listed for Claude and ChatGPT |\n| MCP tools | list_all_templates, create_from_template, create_template, upload_document, list_documents, get_document, view_document, update_document_fields, rename_entity, get_document_download_link, list_contacts, send_invite, get_invite_status, get_signing_link, send_invite_reminder, update_invite_recipient, cancel_invite, create_embedded_invite, create_embedded_sending, create_embedded_editor, plus signnow_skills in the v3.1.0 source |\n| Credentials | API keys from the API dashboard (no expiry, all API requests, unlimited keys per application, deleted to revoke). OAuth 2.0 with password, refresh_token and authorization_code grants. The auth guide's code-grant example returns `expires_in` 2592000. `scope` takes URL patterns, default `*` |\n| Rate limits | 500 requests an hour per application in Development, 1,000 an hour by default in Live, raised through support. X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset on every response. 429 on excess |\n| Errors | 400, 401, 403, 404 and 429 with a JSON `errors` array of numeric code and message. Code 65582 covers many validation errors, so the message text identifies the problem |\n| Webhooks | Event subscriptions for document, document group and user events. Optional `secret_key` adds an `X-SignNow-Signature` HMAC SHA-256 header. 20-second timeout, 5 retries 10 seconds apart then more 4 hours apart, `retry_count` up to 10. Accounts without an API plan are limited to 10 active webhooks |\n| Embedded flows | Embedded signing, sending, editor and view links for documents and document groups. Embedded sending links expire after 15 to 45 minutes |\n| Document generation | POST /v2/document-generations/upload and /url fill a tagged .docx from data and return a document ready for signature, with a status endpoint |\n| Audit | GET /document/{document_id}/historyfull and the document group equivalent return the signing history. The API dashboard logs every request and webhook delivery, and API-log endpoints are in the reference |\n| SDKs | PHP signnow/api-php-sdk v3.5.4 (3 September 2026), Node @signnow/api-client 3.2.0 (11 March 2026), Python signnow-python-sdk 3.0.0 (22 April 2026), .NET, Java and Android, plus a Postman collection |\n| Pricing | Development mode free. Paid API plans from $2 per invite at 500 invites to $1.20 per invite at 5,000 per the developers page, which also advertises 250 free signature invites. A site licence covers the web app and API for many users |\n| SLA | 99.9 per cent monthly uptime on commercially reasonable efforts, credits of 10 per cent below 99.9 and 30 per cent below 99.0, claims within 30 days. Last updated 11 January 2023 |\n| Status | status.signnow.com on Statuspage, components Web, Mobile apps, API, Integrations, Payments and Support. Three incidents since April 2026, all minor and on Web |\n| Certifications | SOC 2 Type II (report on request), PCI DSS, HIPAA, GDPR, 21 CFR Part 11, CCPA, ESIGN and UETA per signnow.com/security. Bug bounty through HackerOne by invitation |\n| Capabilities | esign.send, esign.templates, esign.embed, esign.status, contracts.generate, pdf.forms |\n| Tags | hosted, usage-based, free-tier, sandbox, mcp, oauth, api-key, openapi, llms-txt, webhooks, php, python, typescript, dotnet, java, status-page, sla, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/signnow.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 93 | 18.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 81 | 13.2 |\n| Agent ergonomics | 13% | 16.2 | 66 | 10.7 |\n| Security \u0026 auth | 14% | 17.5 | 62 | 10.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 35 | 4.4 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 72 | 6.3 |\n| Transparency \u0026 trust (editorial 62, provenance 86) | 7% | 8.8 | 74 | 6.5 |\n| Negative events | up to −15 | up to −15 | Until release v2.7.0 on 8 July 2026 the MCP server's signing links carried the user's raw SignNow access token in the URL query string. The fix and a regression test are documented in the pull request, so we deducted 2 (https://github.com/signnow/sn-mcp-server/pull/65).  | -2 |\n| **Total** | | | | **68.5 → B** |\n\n### Why each score\n\n- Reliability 93: Graded as a hosted API. Statuspage at status.signnow.com with six components including API (20). The incident feed shows one incident in the last 90 days, a minor one on 3 September 2026 that made the SignNow University site unavailable for eight minutes, and none on the API component (30). Limits are published with numbers, 500 requests an hour in Development and 1,000 in Live (15). 429 is documented with X-RateLimit-Limit, Remaining and Reset headers and advice to back off exponentially. No Retry-After header and no idempotency key were found, and sending an invite is a charged write (8). The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime with credits of 10 or 30 per cent (10). The REST API is generally available (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 81: Graded on the REST API, with the MCP server noted. OpenAPI 3.0.3 and Swagger 2.0 are public, with 226 paths and 354 operations (25). docs.signnow.com/llms.txt indexes a Markdown copy of every page, with llms-full.txt (10). All 354 operations have a description and the MCP tool descriptions say what to call next, but the API reference rarely says when not to use an endpoint (14). The spec marks required fields often but holds only 29 enums across 354 operations (9). 342 operations have examples and there is an API errors page, though numeric codes aren't unique (12). The changelog is dated by month back to February 2025. The spec version stays at 1.0.0 and paths mix unversioned and /v2 routes (11).\n- Agent ergonomics 66: Graded on the REST API, with the MCP server noted. List endpoints take page and per_page or limit and offset, with no field selection found. The MCP server loads 20 documented tools, 21 in the v3.1.0 source (15). Pagination, filters and sorting exist but in several parameter styles (`filter:type`, `filters[...]`, `sort:created`, `sort_by`) (15). Errors come as a JSON code and message with a troubleshooting page, but code 65582 covers many causes and the docs tell callers to read the message text (13). No idempotency key on the API. The MCP tools set readOnlyHint, destructiveHint and idempotentHint (8). SDKs for PHP, Node, Python, .NET and Java, and an API key works with one header (15).\n- Security \u0026 auth 62: OAuth 2.0 with password, refresh and authorisation code grants and a `scope` parameter that limits a token to URL patterns. API keys can be deleted but don't expire and work for all API requests, and the hosted MCP server adds OAuth with PKCE (24). We deducted 5 of the possible 10 for secrets in URLs, because embedded links returned by the API carry an `access_token` query parameter, with a 15 to 45 minute expiry on embedded sending links (19). A URL-pattern scope allows a read-only token, the hosted MCP grant covers documents and templates only, and the bundled skill tells agents to wait for confirmation before sending. Nothing enforces that confirmation (12). The API returns document text and field values written by signers, and no prompt-injection guidance was found (3). The API dashboard logs every request and webhook delivery, and documents carry a full history endpoint (13). SOC 2 Type II, PCI DSS and HIPAA per the security page and a HackerOne bug bounty by invitation. security.txt returns 404, and the MCP repository's SECURITY.md still has a placeholder contact (15).\n- Payments \u0026 pricing 35: No x402, MPP or L402 found (0). The developers page states per-invite prices, from $2 at 500 invites to $1.20 at 5,000. The full plan table is a JavaScript page we couldn't read, so we scored between plan-only and per-unit (15). Development mode is free with up to 500 invites, and the help centre says the free trial needs no credit card (20). A person has to register in a browser and verify an email address before the first key exists (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 72: The API changelog's newest entry is September 2026, dated by month only, and the PHP SDK v3.5.4 shipped on 3 September 2026, 34 days before this check. We scored between the 30-day and 90-day bands (25). The changelog has entries for July, August and September 2026 (20). Closed service with a monthly changelog and API support at api@signnow.com. The MCP repository that the docs name for issue reports is archived (8). SDKs for five languages are current, with PHP in September 2026, Python in April and Node in March. The official MCP registry lists io.github.signnow/sn-mcp-server at 0.3.1 while PyPI has 3.1.0 (13). The MCP repository has CI with ruff, mypy and pytest and 60 test files, and it is archived (6).\n- Transparency \u0026 trust 74: Closed service with public terms last updated 2 March 2023, and MIT licences on the MCP server and SDKs (17). The DPA of 1 July 2025 promises deletion or return of customer personal data within 30 days on request after the service ends. The privacy notice of 12 August 2026 gives no retention periods and says usage analysis includes training AI models, while the MCP security page says MCP data is never used for training (20). No deprecation policy was found. The terms say material changes take effect at the next subscription period, and the changelog mentions retired settings without dates (5). The subprocessor list of 18 September 2026 names each subprocessor with its country, with AWS in the United States, Germany and Australia (20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/signnow.md (JSON https://www.anchorterminal.com/fixes/signnow.json)\n\n### What we couldn't check\n\n- unchecked: the API plan table at snseats.signnow.com/purchase/api/pricing (JavaScript-only page). Prices come from the developers page\n- unchecked: whether the API free trial asks for a card. The help centre says the free trial needs no credit card, without naming the API trial\n- Why the sn-mcp-server GitHub repository is archived and whether the hosted server at mcp-server.signnow.com is still developed elsewhere. The README and docs carry no notice\n- unchecked: the hosted MCP server's live tool list, which needs an OAuth sign-in. The count comes from the docs (20) and the v3.1.0 source (21)\n- Whether the access_token in embedded link URLs is a short-lived link token or the caller's own token\n- Access-token lifetime. The auth guide's examples show `expires_in` as 2592000 in one response and a timestamp in another\n- Whether SignNow holds ISO 27001. The security page doesn't list it\n- unchecked: the help centre article on AI data use (helpcenter.signnow.com), which the MCP security page cites\n\n### Sources\n\n- developers page, per-invite prices and Development limits: \u003chttps://www.signnow.com/developers\u003e (seen 2026-10-07)\n- docs index for agents: \u003chttps://docs.signnow.com/llms.txt\u003e (seen 2026-10-07)\n- OpenAPI 3.0.3 spec: \u003chttps://docs.signnow.com/api/openapi.json\u003e (seen 2026-10-07)\n- authentication guide: \u003chttps://docs.signnow.com/docs/authentication.md\u003e (seen 2026-10-07)\n- go-live checklist and rate limits: \u003chttps://docs.signnow.com/docs/go-live-checklist.md\u003e (seen 2026-10-07)\n- API dashboard, modes, logs and invite charging: \u003chttps://docs.signnow.com/docs/account.md\u003e (seen 2026-10-07)\n- API errors: \u003chttps://docs.signnow.com/docs/api-errors.md\u003e (seen 2026-10-07)\n- API changelog: \u003chttps://docs.signnow.com/docs/signnow-api-changelog.md\u003e (seen 2026-10-07)\n- webhooks guide: \u003chttps://docs.signnow.com/docs/guides-webhooks.md\u003e (seen 2026-10-07)\n- MCP server overview, tools and security pages: \u003chttps://docs.signnow.com/docs/mcp-server.md\u003e (seen 2026-10-07)\n- MCP tool catalogue: \u003chttps://docs.signnow.com/docs/mcp-tools.md\u003e (seen 2026-10-07)\n- MCP server security page: \u003chttps://docs.signnow.com/docs/mcp-server-security.md\u003e (seen 2026-10-07)\n- hosted MCP OAuth metadata: \u003chttps://mcp-server.signnow.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-07)\n- MCP server repository (cloned, v3.1.0, archived per the GitHub API): \u003chttps://github.com/signnow/sn-mcp-server\u003e (seen 2026-10-07)\n- official MCP registry entry: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=signnow\u003e (seen 2026-10-07)\n- PyPI package: \u003chttps://pypi.org/project/signnow-mcp-server/\u003e (seen 2026-10-07)\n- status incidents feed: \u003chttps://status.signnow.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- SLA: \u003chttps://legal.signnow.com/sla\u003e (seen 2026-10-07)\n- terms of service: \u003chttps://legal.signnow.com/terms\u003e (seen 2026-10-07)\n- privacy notice: \u003chttps://legal.signnow.com/privacy-notice\u003e (seen 2026-10-07)\n- DPA: \u003chttps://legal.signnow.com/dpa\u003e (seen 2026-10-07)\n- subprocessor list: \u003chttps://legal.signnow.com/subprocessors\u003e (seen 2026-10-07)\n- contracting entity table: \u003chttps://legal.signnow.com/contracting-entity-table\u003e (seen 2026-10-07)\n- security and compliance page: \u003chttps://www.signnow.com/security\u003e (seen 2026-10-07)\n- bug bounty programme: \u003chttps://policies.airslate.com/bug-bounty-program\u003e (seen 2026-10-07)\n- plans and pricing help page: \u003chttps://www.signnow.com/help/plans-pricing.md\u003e (seen 2026-10-07)\n- domain registration: \u003chttps://rdap.verisign.com/com/v1/domain/signnow.com\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 86/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | airSlate, Inc. | 20/20 |\n| Domain age | signnow.com, registered 2001-04-05 (25 years) | 15/15 |\n| Endpoint on the vendor's domain | api.signnow.com | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points | 6/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.signnow.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe privacy notice (last updated 12 August 2026) names airSlate, Inc., 17 Station Street, Ste. 203, Brookline, MA 02445. The contracting entity table (last updated 1 October 2026) lists seven airSlate companies, and the one that applies depends on the service, location and payment method.\n\nThe API answers at api.signnow.com and the hosted MCP server at mcp-server.signnow.com, both signnow.com subdomains.\n\nwww.signnow.com/.well-known/security.txt returns 404. Vulnerability reports go through the airSlate bug bounty programme on HackerOne, which needs an invitation requested by email (policy last updated 7 October 2025).\n\nThe terms of service were last updated 2 March 2023, the SLA 11 January 2023 and the DPA 1 July 2025.\n\nRDAP for signnow.com gives a registration date of 2001-04-05 and GoDaddy.com, LLC as registrar.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://legal.signnow.com/terms), read 2026-10-08, dated 2023-03-02, states 7 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(iv) share your login credentials with anyone or use any automated system, including robots, spiders, or offline readers, to access or operate the Services;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"(vi) use the Services for the benefit of a competitive offering;\"\n- To know. Requires arbitration or waives class actions. \"PLEASE ALSO NOTE THAT THESE TERMS CONTAIN A CLASS ACTION WAIVER.\"\n- To know. Has not been updated for three years or more. \"Last Updated: March 2, 2023\"\n- Gives the date it was last updated. Last updated 2023-03-02.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Changes are posted, with no other notice named.\n- Also in the text (2026-10-08). Usage above the plan limit is billed as excess usage, and the vendor is not obliged to warn the customer before those fees are incurred. \"(iv) you are responsible for tracking your usage, and Provider is not obligated to notify you before you incur excess usage fees.\"\n- Also in the text (2026-10-08). After termination the customer has 30 days to ask for access to download its content, after which the vendor may delete it. \"On request made within thirty (30) days after termination, Provider will grant you reasonable access to your Services solely for you to download Your Content using Services’ standard download functionalities.\"\n- Also in the text (2026-10-08). The vendor may use the customer's name and logo to identify it as a customer, including on the vendor's website. \"Provider may use your name and logo for the limited purpose of identifying you as a customer, including by listing your company’s name and logo on Provider’s website.\"\n\n**Privacy policy** (https://legal.signnow.com/privacy-notice), read 2026-10-08, dated 2026-08-12, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"We may share your personal information with our third-party advertising partners to target advertising to you.\"\n- Gives the date it was last updated. Last updated 2026-08-12.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). The notice says analysing how the services are used and interacted with includes training the vendor's AI models. \"This includes training our artificial intelligence (AI) models\"\n\n## Live (updated 2026-10-08 19:53 UTC)\n\n- Right now: up, HTTP 404, 238 ms, checked 2026-10-08 19:53 UTC (get on `https://api.signnow.com`)\n- Uptime 24h 100.0% (50 probes) · 30 days 100.0% (50 probes) · p50 252 ms · p95 558 ms\n- Vendor status page: none, All Systems Operational\n- github `signnow/sn-mcp-server` v3.1.0, released 2026-07-27\n- npm `@signnow/api-client` 3.2.0\n- pypi `signnow-mcp-server` 3.1.0, released 2026-07-27\n- pypi `signnow-python-sdk` 3.0.0, released 2026-04-22\n- security.txt: unknown\n- Watching changelog \u003chttps://docs.signnow.com/docs/signnow-api-changelog\u003e\n- Watching privacy \u003chttps://legal.signnow.com/privacy-notice\u003e\n- Watching terms \u003chttps://legal.signnow.com/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/signnow.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Signature invite, 500-invite plan | $2 | per transaction | starting price per the developers page on 2026-10-07 |\n| Signature invite, 5,000-invite plan | $1.20 | per transaction | per the developers page on 2026-10-07 |\n| Development mode | free | per transaction | up to 500 invites without a plan, watermarked |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0.3 spec with 354 operations, 342 of them with examples, plus llms.txt and a Markdown copy of every docs page\n- Development mode is free on the production host, with 500 requests an hour and up to 500 signature invites without a plan\n- Hosted MCP server at mcp-server.signnow.com/mcp with OAuth, PKCE and dynamic client registration, and read-only and destructive hints on its tools\n- Webhooks carry an HMAC SHA-256 signature header and a documented retry schedule, and the API dashboard logs every request and delivery attempt\n- Status page shows three minor incidents since April 2026, none on the API component, and a 99.9 per cent SLA with credits is published\n\n## Weaknesses\n\n- API keys don't expire and work for all API requests. Narrower access needs an OAuth token requested with a URL-pattern scope\n- No idempotency key was found in the spec or guides, and each signature invite sent is charged\n- The sn-mcp-server GitHub repository was archived when checked on 7 October 2026, while the docs still send issue reports there\n- Numeric error codes aren't unique. The docs tell callers to identify a problem by its message text\n- The API plan table is a JavaScript page we couldn't read. Only the per-invite range on the developers page is public text\n\n## Before you call it (notes for agents)\n\n1. Call https://api.signnow.com with `Authorization: Bearer \u003cAPI key or access token\u003e`. Development and Live share this host, and Development documents carry a watermark\n2. Request OAuth tokens with a narrow `scope` such as `document/* GET/user`. The default `*` grants every API action\n3. Read `X-RateLimit-Remaining` and `X-RateLimit-Reset` on each response. The limit is 500 requests an hour in Development and 1,000 in Live, and 429 has no Retry-After\n4. Check invite status before resending. No idempotency key exists, and a repeated invite call counts as another charged invite\n5. Set `secret_key` when creating an event subscription and verify `X-SignNow-Signature` (HMAC SHA-256 of the body) on every callback\n\n## Connect\n\nInstall:\n\n```bash\nuvx --from signnow-mcp-server sn-mcp serve\n```\n\nFirst request:\n\n```bash\ncurl --request POST \\\n  --url https://api.signnow.com/v2/documents/url \\\n  --header 'Authorization: Bearer {{your_api_key}}' \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"url\": \"https://www.signnow.com/whitepapers/signnow_api_test_invite.pdf\"}'\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"signnow-local\": {\n      \"args\": [\n        \"--from\",\n        \"signnow-mcp-server\",\n        \"sn-mcp\",\n        \"serve\"\n      ],\n      \"command\": \"uvx\",\n      \"env\": {\n        \"SIGNNOW_API_KEY\": \"your-api-key\"\n      }\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/signnow (letme picks it for contracts.generate, the top-graded tool for the job, letme picks it for pdf.forms, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| PandaDoc | B | 63.1 | 319 | esign.send, esign.templates, esign.embed, esign.status, contracts.generate | no | https://www.anchorterminal.com/tools/pandadoc.md |\n| Docusign | B | 62.5 | 335 | esign.send, esign.templates, esign.embed, esign.status, contracts.generate | no | https://www.anchorterminal.com/tools/docusign.md |\n| Dropbox Sign | B | 68.9 | 171 | esign.send, esign.templates, esign.embed, esign.status | no | https://www.anchorterminal.com/tools/dropbox-sign.md |\n| Documenso | B | 62.8 | 326 | esign.send, esign.templates, esign.status, esign.embed | no | https://www.anchorterminal.com/tools/documenso.md |\n| Adobe PDF Services / PDF Extract API | C | 55.9 | 497 | pdf.forms | no | https://www.anchorterminal.com/tools/adobe-pdf-extract.md |\n| PDF.co API + MCP | F | 37.9 | 699 | pdf.forms | no | https://www.anchorterminal.com/tools/pdf-co.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The API reference is published as OpenAPI 3.0.3 and Swagger 2.0, with 226 paths and 354 operations against https://api.signnow.com (source: \u003chttps://docs.signnow.com/api/openapi.json\u003e)\n- The hosted MCP server answers at https://mcp-server.signnow.com/mcp and returns 401 with OAuth metadata that lists authorisation code and refresh grants, S256 PKCE and a registration endpoint (source: \u003chttps://mcp-server.signnow.com/.well-known/oauth-authorization-server\u003e)\n- SignNow documents 20 MCP tools for templates, documents, contacts, invites and embedded sessions. Release v3.1.0 registers those 20 plus `signnow_skills` (source: \u003chttps://docs.signnow.com/docs/mcp-tools\u003e)\n- The sn-mcp-server repository is marked archived on GitHub, last pushed 27 July 2026, while the docs still point to its issue tracker (source: \u003chttps://github.com/signnow/sn-mcp-server\u003e)\n- Development mode runs on the production host with 500 requests an hour and up to 500 signature invites without a plan. Live mode defaults to 1,000 requests an hour (source: \u003chttps://docs.signnow.com/docs/account\u003e)\n- The developers page prices paid API plans from $2 per invite at 500 invites to $1.20 per invite at 5,000 (source: \u003chttps://www.signnow.com/developers\u003e)\n- The SLA commits to commercially reasonable efforts for 99.9 per cent monthly uptime, with credits of 10 or 30 per cent (source: \u003chttps://legal.signnow.com/sla\u003e)\n- The subprocessor list, updated 18 September 2026, names AWS in the United States, Germany and Australia, and OpenAI, Anthropic and Google as LLM subprocessors (source: \u003chttps://legal.signnow.com/subprocessors\u003e)\n\n## Compare\n\n- [Documenso vs airSlate SignNow](https://www.anchorterminal.com/compare/documenso-vs-signnow.md): B 62.8 vs B 68.5\n- [Docusign vs airSlate SignNow](https://www.anchorterminal.com/compare/docusign-vs-signnow.md): B 62.5 vs B 68.5\n- [Dropbox Sign vs airSlate SignNow](https://www.anchorterminal.com/compare/dropbox-sign-vs-signnow.md): B 68.9 vs B 68.5\n- [PandaDoc vs airSlate SignNow](https://www.anchorterminal.com/compare/pandadoc-vs-signnow.md): B 63.1 vs B 68.5\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on signnow.com or one of its subdomains, or the README of github.com/signnow/sn-mcp-server. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"signnow\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/signnow\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/signnow.svg\" alt=\"airSlate SignNow on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![airSlate SignNow on Anchor Terminal](https://www.anchorterminal.com/badges/signnow.svg)](https://www.anchorterminal.com/tools/signnow)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/signnow\"\u003eairSlate SignNow on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say airSlate SignNow is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/signnow-dark.png\n- Light: https://www.anchorterminal.com/assets/share/signnow-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Contracts, proposals \u0026 e-signatures",
        "url": "https://www.anchorterminal.com/categories/e-signatures"
      },
      {
        "name": "airSlate SignNow",
        "url": ""
      }
    ],
    "description": "airSlate SignNow is an e-signature service. Its REST API prepares documents from templates, sends signature invites, embeds signing in other apps and reports status through webhooks. A hosted MCP server gives AI agents 20 documented tools over the same account.",
    "facts": [
      "rank #178 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "airSlate SignNow",
    "image": "https://www.anchorterminal.com/assets/og/tools-signnow.png",
    "path": "/tools/signnow",
    "published": "2026-10-01",
    "section": "tools",
    "title": "airSlate SignNow review for AI agents, grade B (68.5/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/signnow"
  },
  "tokens": {
    "markdown": 8100,
    "slim": 2130
  },
  "version": 1
}
