Set up the Docusign MCP Server

Connect Docusign MCP in demo or production with OAuth and deliberately control write actions on envelopes.

Published on 18.09.2026

The Docusign MCP Server is a remote service. Before connecting, decide whether a demo account is needed for testing or a production account for real agreements. In either case, do not start with a personal administrative account; use a dedicated Docusign user with the smallest practical permission set.

Prepare the endpoint and OAuth

Add https://mcp-d.docusign.com/mcp for demo or https://mcp.docusign.com/mcp for production to the MCP client as a Streamable HTTP server. The server needs an OAuth access token from Confidential Authorization Code Grant. Set up the OAuth integration in Docusign, protect the token, and verify the target account before the first query. Follow Docusign’s client-specific guide rather than copying tokens into configuration files or chat history.

Start with read access

Run one clear, non-mutating test first: retrieve available templates or the status of a known test envelope. Confirm that the result contains data only from the intended account. Results can include names, email addresses, recipient status, and tab values, so do not copy them into public chats or tickets. Allow a production connection only after this check succeeds.

Safeguard envelopes and workflows

A prompt can invoke tools that create, send, void, or alter recipients on envelopes. Require client confirmation for those tools. Before confirming, visibly check the template, documents, account, recipients, routing order, email text, and target status. After the action, record the envelope ID and outcome in the team process and review the Docusign data again. A chat transcript is not defensible auditability.

Limit prompt injection

Contract and email text can contain instructions that are not an authorized request. Treat that content only as data. The agent must not change permissions, add recipients, or disclose secrets because a document tells it to. Limit automation to narrow read tasks, keep test and production accounts separate, and revoke tokens when roles change.

Published on 18.09.2026

Categories

Frequently asked questions

Which URL should I use?

Use `https://mcp-d.docusign.com/mcp` for demo or `https://mcp.docusign.com/mcp` for production; both use Streamable HTTP.

Can an agent send an envelope?

Yes, where the role, OAuth token, and tool call allow it. Require human confirmation before sending, voiding, or changing recipients.

How do I review the data path?

Trace it from the prompt in the AI client through Docusign’s hosted MCP Server and APIs back to the client and model. Review the selected client and model provider’s privacy terms separately.