Skip to content
Last updated

DocuSign integration

DocuSign is a digital signature and agreement cloud platform.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through DocuSign's own hosted MCP server, so your AI agents work with the same agreement, envelope, and workflow tools DocuSign exposes to MCP clients like Claude and Copilot.
  • In-house — Agen.co wraps the DocuSign eSignature REST API directly through its own integration layer, using a dedicated Integration Key you register in DocuSign, with a separate sandbox/production toggle.

Pick Official if the built-in MCP tools cover what your agents need. Fall back to In-house if you need broader API coverage, such as managing users, groups, and identity providers, or want to develop against the free sandbox before going live.


Connect via the official MCP server

Prerequisites

  • A DocuSign production account on a plan that supports API integrations (for example Business Pro or higher), with access to Apps and Keys at admin.docusign.com. The Official panel has no sandbox/production switch — it only accepts an Integration Key registered in production; a key created in the free developer account (apps-d.docusign.com) is rejected with The client id provided is not registered with Docusign.
  • The DocuSign MCP Server is in Open Beta, with no intake form or approval required. Steps 1 to 6 below cover creating the Integration Key in a developer account and promoting it to production when your account cannot create one directly.
  1. Check whether your production account can create an Integration Key directly: sign in and go to Admin → Integrations → Apps and Keys (admin.docusign.com). If you see Add App and Integration Key, skip to step 7.
  2. If production instead shows "You cannot create an integration key in production. To create an IK, use your developer account", your account hasn't been through DocuSign's Go-Live process yet. Create the key in the free developer account first, at apps-d.docusign.com/admin/apps-and-keys: click Add App and Integration Key, name it, and click Create App.
  3. On the app's detail page, click Edit, and select the Integration Type that matches your use case. Click Save.
  4. Back on the Apps and Keys list, next to your app, click Actions and select Select Go-Live account.
  5. Sign in to the production account you want to connect to Agen.co. DocuSign runs automatic validation and, if your account is eligible, promotes the integration key to production instantly.
  6. Open the production Apps and Keys page — your app now appears there with the same Integration Key.
  7. Click Add App and Integration Key, name it (for example Agen.co Integration), and click Create App. Skip this step if you already have a production app from steps 2–6.
  8. Copy the Integration Key DocuSign generates — this is your Client ID.
  9. Scroll to the Authentication section and click Add Secret Key to generate a Client Secret. Copy it now — it's shown only once.
  10. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  11. In the search bar, type DocuSign and select it from the results.
  12. In the Instance Slug field, enter a slug for this connector instance — it prefixes each imported tool as slug__tool, so a second instance of the same connector needs a slug of its own. Use lowercase kebab-case. You can change it later from the connector's settings.
  13. Get back to DocuSign. Scroll to Additional settings and add both URLs shown on the Add DocuSign panel in Agen.co as redirect URIs: Callback URL / Gateway callback URL. Click Save.
  14. Paste the Integration Key and Secret Key into the matching Client ID and Client Secret fields on the Add DocuSign panel in Agen.co.
  15. Click Connect.
  16. You're redirected to DocuSign to sign in and approve access.
  17. Return to Agen.co and click Add below the list of tools that were added.

Once connected, DocuSign appears under My connectors with tools spanning:

AreaWhat it covers
AgreementsRetrieving agreement and envelope context, metadata, status, and key dates
InsightsReading clauses and agreement insights
WorkflowsTriggering workflow actions and routing
EnvelopesManaging envelopes

Enabling the DocuSign connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the DocuSign REST API

DocuSign is a digital signature and agreement cloud platform. Integrating DocuSign with Frontegg allows your application to manage envelopes, templates, and documents on behalf of your users through OAuth 2.0 authentication. DocuSign provides both a production environment and a free developer sandbox for testing your integration before going live.

Prerequisites

Connect DocuSign

Step 1: Open the Apps and Keys page

Sign in to DocuSign and navigate to Admin → Integrations → Apps and Keys. The URL depends on which environment you are using:

EnvironmentAdmin URL
Productionhttps://admin.docusign.com
Sandboxhttps://admindemo.docusign.com

Which environment to choose

Use the sandbox environment (admindemo.docusign.com) for development and testing. Sandbox accounts are free and can be created at developers.docusign.com. Use production (admin.docusign.com) only when you are ready to work with real documents and signatures.

This page lists all OAuth applications registered under your account. Click Add App and Integration Key.

DocuSign Apps and Keys page

Step 2: Name the application

In the Add Integration Key dialog, enter a descriptive name for your application.

Add Integration Key dialog

Enter Frontegg Integration and click Create App.

Integration Key name filled in

Step 3: Copy the Integration Key

DocuSign creates the app and opens its configuration page. The Integration Key serves as the Client ID. Copy it from the General Info section and store it securely.

DocuSign app details showing Integration Key

Step 4: Generate a Secret Key

Scroll to the Authentication section and click Add Secret Key to generate a Client Secret.

Add Secret Key button highlighted

One-time display

The Secret Key is shown once. Copy it immediately before leaving this page — it cannot be retrieved later.

DocuSign Secret Key generated

Step 5: Add redirect URIs

Scroll to Additional settings. Click Add URI and enter the Frontegg callback URI:

https://YOUR_MCP_GATEWAY_URL/integration-callback

This redirect URI is the same for both sandbox and production environments.

DocuSign redirect URI configured

Step 6: Save the configuration

Click Save at the bottom of the page. DocuSign confirms the integration key was saved successfully.

DocuSign integration key saved

Configure the Frontegg portal

Once you have the Integration Key (Client ID) and Secret Key (Client Secret) from the steps above, enter them in the integration configuration page of the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Connectors → DocuSign.
  2. Under Connector credentials, select Bring your own and enter the Integration Key in the Client ID field and the Secret Key in the Client Secret field.
  3. Configure the Use Sandbox toggle:
    • Enabled — connects to the DocuSign developer sandbox (account-d.docusign.com). Use this for testing and development.
    • Disabled — connects to the DocuSign production environment (account.docusign.com). Use this for live data.

Sandbox vs. production

DocuSign provides a free developer sandbox at developers.docusign.com. Sandbox credentials are separate from production — make sure the Client ID and Client Secret match the environment selected by the toggle.

  1. Select the required scopes:
ScopeDescription
signatureRequest signatures on documents
extendedExtended access to DocuSign features
impersonationAct on behalf of other users
organization_readRead organization information
group_readRead group information
permission_readRead permission profile information
user_readRead user information
user_writeCreate and update users
account_readRead account information
domain_readRead domain information
identity_provider_readRead identity provider information
  1. Click Save.

Keep your credentials secure

Never share or commit your Secret Key to version control.

Migrate from sandbox to production

If you initially configured the connector with sandbox credentials, follow these steps to switch to production.

API-enabled plan required

Your production DocuSign account must be on a plan that supports API integrations (e.g., Business Pro or higher). Standard plans without API access will show the error "These accounts don't support API integrations" during the Go-Live process. Contact DocuSign support to verify or upgrade your plan before proceeding.

Promote your integration key

Open the sandbox Apps and Keys page at https://admindemo.docusign.com. Find your application, click Edit, and select the Integration Type that matches your use case (e.g., eSignature). Enter your production account credentials when prompted. DocuSign runs automatic validation and, if eligible, promotes the integration key instantly.

Simplified Go-Live

DocuSign no longer requires 20 API calls before promoting an integration. The process is now automatic for most integration types. See Docusign Go-Live for full details.

Generate a new Secret Key in production

Once promoted, open the production Apps and Keys page at https://admin.docusign.com. Your application now appears there with the same Integration Key (Client ID). Click Actions → Edit, scroll to Authentication, and click Add Secret Key to generate a new Client Secret for production.

Sandbox secrets do not carry over

The Secret Key from sandbox is not valid in production. You must generate a new one and copy it immediately — it is displayed only once.

Verify redirect URIs

Confirm that the Frontegg callback URI is listed under Additional settings → Redirect URIs in the production app. The URI is the same as in sandbox:

https://YOUR_MCP_GATEWAY_URL/integration-callback
Update the Frontegg portal

Open the Frontegg portal and navigate to the DocuSign connector settings:

  1. Replace the Client Secret with the new production Secret Key.
  2. Disable the Use Sandbox toggle to connect to the production environment (account.docusign.com).
  3. Click Save.

The Client ID remains the same and does not need to be changed.

Additional resources