Docusign MCP Server

Official remote MCP server for Docusign agreements, eSignature envelopes, and workflow tasks.

Description

The Docusign MCP Server is Docusign's official remote service for the Model Context Protocol. It connects an MCP-capable AI client to Docusign capabilities so that teams can query agreements, eSignature envelopes, and workflows through natural language or, where permission allows, initiate actions. Docusign labels the service Open Beta and provides endpoints for both demo and production environments. This is not a locally installed package: the client uses Streamable HTTP with https://mcp-d.docusign.com/mcp for demo or https://mcp.docusign.com/mcp for production. Docusign's official product documentation does not publish a directly associated source repository for this hosted server, so the catalog deliberately leaves the repository link and GitHub stars empty.

Agreements, documents, and envelopes

The scope is agreement and document work, not general file-system access. Docusign's official tool reference lists retrieval of individual agreement details and all agreements in a Docusign account for Agreement Manager. For eSignature, a client can read accounts, templates, users, a single envelope, and filtered envelope lists. A Create Envelope tool creates an envelope from a template with documents, recipients, and tabs. That lets an assistant prepare an approved onboarding template, for example, rather than sending documents outside the Docusign process.

Write access matters: Update Envelope can send a draft, void an envelope, or change email details; Update Envelope Recipients can add, update, or remove recipients. Send Reminder notifies pending recipients. These are not merely textual suggestions: they can change a business transaction's state and communication with signers. Workflow Builder tools can start, pause, resume, or cancel instances. According to Docusign, the production server currently supports a limited set of API groups; developer contexts may expose more APIs and endpoints for exploration. Before production use, explicitly review the target account, template, recipient list, and intended envelope status.

Tokens, accounts, and roles

Connecting requires a valid OAuth access token. Docusign's official developer documentation says the MCP Server supports access tokens from the Confidential Authorization Code Grant. A Docusign developer account is the starting point for development and demo use, and the server is now also available for production accounts. Docusign's connector guidance also distinguishes standard users who connect a production account through the client UI from developers using a demo account for custom integrations.

A token does not expand existing Docusign rights. The tool reference explicitly says that every tool is governed by existing Docusign permissions and OAuth authentication, so the assistant should access only information the authenticated person is authorized to view. That is a boundary, not a recommendation to grant broad access. Use a demo account for testing and, in production, a separate least-privileged user account with only the required account, template, and envelope permissions. Never place an OAuth token in chat, source code, or version-controlled MCP configuration; revoke it when staff or roles change.

Signer data, model path, and auditability

Envelope and recipient data can include names, email addresses, status, account context, and tab values. Agreement details and document fields can also carry confidential contract or identity data. The practical data path is: a person writes a request in the chosen AI client; that client's assistant or model decides on a tool call; parameters go to the hosted Docusign MCP Server and authorized Docusign APIs; results return to the client and can be provided to the model to formulate an answer. Docusign connects its APIs, but it does not determine the privacy, retention, or training terms of the selected AI client and model provider. Review those terms separately before enabling access to sensitive agreement data.

Do not treat chat history as a defensible audit trail. For accountable work, record the envelope ID, template, account, requester, confirmed recipients, and outcome in the team's own process, then review the relevant Docusign envelope or agreement data. A human should reconcile before and after a send, void, or recipient change. Docusign specifically warns that fully automated agents increase exposure to prompt-injection attacks and that a malicious remote MCP server can exfiltrate sensitive data.

Secure operation

Enable confirmation for write tools in the AI client whenever the client offers it. Never grant text inside a contract, email, or tool result the same authority as a human instruction: embedded content can attempt to persuade an agent to send, alter, or disclose data. Limit available tools, automation, and account scope, then visibly verify the draft, recipients, and consequences before sending. Docusign advises a human in the loop for tools and for the accuracy and appropriateness of AI output. The Beta label also means behaviour and availability can change, so production approvals need a tested fallback path outside chat.

FAQ

Is this a self-hosted open-source server? No. Docusign documents hosted remote endpoints and its official product documentation does not link a separate server repository. The catalog therefore has no GitHub star value.

Can a prompt really send an envelope? Yes, if the client invokes the relevant tool, the OAuth token and Docusign role permit the action, and the request directs it. Require human confirmation before sending, voiding, or changing recipients.

Do signer details reach an AI model? Tool results can contain recipient and agreement data and return to the chosen AI client. Whether and how that client supplies them to its model depends on the client and model provider; review that data path in advance.

Requirements

A Docusign developer or production account, an OAuth integration using Confidential Authorization Code Grant, and an MCP client with Streamable HTTP support. Use a dedicated least-privileged user account for production.

Installation instructions

Demo remote URL: https://mcp-d.docusign.com/mcp; production: https://mcp.docusign.com/mcp. Configure the client for Streamable HTTP, obtain an OAuth token through Confidential Authorization Code Grant, and connect only after verifying the intended account. Use Docusign’s official guide for the specific client configuration flow.

Authentication

A valid OAuth access token from Confidential Authorization Code Grant. Access and actions remain bound to the authenticated Docusign account and its existing permissions.

Required access permissions

According to Docusign, tools follow existing Docusign permissions and OAuth. Depending on the role, they can read agreement, envelope, and recipient data and change envelopes, recipients, or workflows. Connect only dedicated least-privilege accounts.

Transmitted or stored data

Prompts are handled in the selected AI client; tool parameters go to Docusign’s hosted MCP Server and authorized APIs. Results can contain agreement, document, envelope, and signer data and return to the AI client and its model. Review the client and model provider’s privacy and retention terms separately.

Security risks

Write tools can send drafts, void envelopes, change recipients, or trigger workflows. Docusign warns about prompt injection with fully automated agents and data exfiltration by malicious remote MCP servers. Chat history is not an audit trail: document the envelope ID, recipients, confirmation, and outcome outside chat, and require human confirmation for every mutation.

License and costs

License
Not recorded yet.
Cost
free

Docusign provides the MCP Server as an Open Beta. A Docusign account is required; check Docusign directly for current contract and plan terms.

Alternatives

Not recorded yet.

At a glance

Provider
Docusign
Status
Official server
Deployment
Remote
Current version
Open Beta
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.