Productivity
DocuSign Webhooks
Electronic signature and agreement platform. Receive events for envelope and recipient lifecycle changes via DocuSign Connect.
Connecting DocuSign to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into DocuSign. Then:
- 1Go to DocuSign eSignature Admin → Connect → Add Configuration (Custom)
- 2Set the "URL to Publish" to your Hookbase ingest URL and choose JSON as the message format
- 3Under "Events", select the envelope and/or recipient statuses that should trigger a notification (e.g. Envelope Sent, Envelope Completed)
- 4Enable HMAC signing and add one or more secret keys; add the first key to your Hookbase source
- 5Save the configuration — DocuSign sends an X-DocuSign-Signature-1 header (and -2, -3… per additional active key) with each notification
Signature verification
DocuSign signs its webhooks with HMAC-SHA256 (base64) in X-DocuSign-Signature-1, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if DocuSign can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at eSignature Admin → Connect → Add Configuration → HMAC Signature keys (up to 5 keys; DocuSign sends X-DocuSign-Signature-1..N, one header per active key).
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
DocuSign event types
8 of the events people route most often. Hookbase accepts every event DocuSign sends, whether or not it is listed here.
envelope-sent
An envelope was sent to its recipients
envelope-delivered
All recipients have viewed the envelope
envelope-completed
All recipients completed their required actions and the envelope is finished
envelope-declined
A recipient declined to sign the envelope
envelope-voided
The sender voided the envelope before completion
recipient-completed
An individual recipient finished signing or approving
recipient-declined
An individual recipient declined to sign
recipient-authenticationfailed
A recipient failed an identity authentication check
What a DocuSign webhook looks like
A envelope-sent payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"event": "envelope-sent",
"apiVersion": "v2.1",
"uri": "/restapi/v2.1/accounts/1234567/envelopes/a1b2c3d4-5678-90ab-cdef-1234567890ab",
"retryCount": 0,
"configurationId": 10000001,
"generatedDateTime": "2024-01-15T10:30:00.0000000Z",
"data": {
"accountId": "1234567",
"envelopeId": "a1b2c3d4-5678-90ab-cdef-1234567890ab",
"envelopeSummary": {
"status": "sent",
"emailSubject": "Please sign: Services Agreement",
"sentDateTime": "2024-01-15T10:30:00.0000000Z",
"recipients": {
"signers": [
{
"recipientId": "1",
"name": "Alex Doe",
"email": "alex@example.com",
"status": "sent"
}
]
}
}
}
}Start receiving DocuSign webhooks
Create a source, paste the URL into DocuSign, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free