Back to Browse

Addsign MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Send documents for e-signature from templates, track status, remind signers, get signed PDFs.

About

Send documents for e-signature from templates, track status, remind signers, get signed PDFs.

Remote endpoints: streamable-http: https://addsign.io/api/mcp

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-designed MCP server with excellent security practices. The codebase properly authenticates via API keys, implements comprehensive input validation with Zod, redacts credentials from all error messages, and maintains a stateless architecture that limits blast radius. Permissions are appropriately scoped to the server's purpose (network API calls for document signing). Minor observations around error handling breadth and logging do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

5 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

AddSign API key — create one at https://addsign.io/settings/apiRequired

Environment variable: ADDSIGN_API_KEY

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

addsign-mcp

MCP server for AddSign — lets AI agents send documents for signature, track signing status, remind signers, and download signed, hash-verifiable PDFs.

Stateless by design: it speaks only AddSign's public v1 API with your API key. No database access, no shared secrets. Revoking the key at addsign.io/settings/api kills the integration instantly.

Setup

  1. Create an API key at addsign.io → Settings → API Keys (free on every plan; Free includes 8 documents/month).
  2. Set it in the environment — never in prompts or config committed to git:
export ADDSIGN_API_KEY=sk_...

Claude Code

claude mcp add addsign --env ADDSIGN_API_KEY=sk_... -- npx -y addsign-mcp

(Until the npm package is published, point at a checkout instead: claude mcp add addsign --env ADDSIGN_API_KEY=sk_... -- node /path/to/simple-sign/mcp/dist/index.js)

Claude Desktop (claude_desktop_config.json)

{
  "mcpServers": {
    "addsign": {
      "command": "node",
      "args": ["/path/to/simple-sign/mcp/dist/index.js"],
      "env": { "ADDSIGN_API_KEY": "sk_..." }
    }
  }
}

Environment

VariableRequiredDefaultPurpose
ADDSIGN_API_KEYyes—Your AddSign API key (sk_...)
ADDSIGN_BASE_URLnohttps://addsign.ioPoint at a different deployment

Tools

ToolKindWhat it does
list_templatesreadTemplates + the signer roles each expects + field summary
send_for_signaturewriteCreate from template + email signers; idempotent via request_id
check_statusreadDocument + per-signer state + recent audit events
download_signedread5-minute signed URL + the ledger's SHA-256 for verification
remindwriteNudge pending signers (4h per-signer server-side cooldown)
list_documentsreadPaginated document list, filterable by status

No destructive tools: an agent cannot cancel or delete a legal document through this server.

A typical agent flow

list_templates                      → find "Contract to Lease", roles: [tenant_1, tenant_2]
send_for_signature {template_id,
  signers: [Artem…, Valeria…],
  request_id: <uuid>}               → document_id, status: pending, usage 3/8
check_status {document_id}          → Artem signed, Valeria viewed
remind {document_id, valeria@…}     → reminded (or skipped: reminded_recently)
download_signed {document_id}       → url + sha256 → fetch, verify, file it

Error semantics

Every AddSign error carries a stable error_code; this server appends the right next step for the agent. The two that matter most:

  • rate_limited (429) — back off retry_after seconds, retry.
  • plan_limit_reached (402) — never retry; the monthly cap resets on the 1st or the human upgrades.

Development

cd mcp
npm install
npm run build     # → dist/index.js
ADDSIGN_API_KEY=sk_... node dist/index.js

Reviews

No reviews yet

Be the first to review this server!