A Docusign API integration builds the agreement step directly into your own application: your interface, your data model, your deployment. Docusign provides the eSignature REST API — v2.1 is the current version and the one recommended for new integrations — together with OAuth 2.0 authentication, the Connect webhook service, and APIs for CLM, Navigator and account administration. We design and build the integration that sits on top of them.
This page is for the case where a prebuilt connector is the wrong tool. If the requirement is Salesforce or HubSpot sending envelopes against CRM records, the packaged integrations do that well and the Salesforce integration and CRM and business systems pages cover them. Reach for the API when signing belongs inside a product you ship, inside an internal application, or in a flow no connector models.
Choosing the authentication flow
This is the first design decision and the one most often taken by accident. Authorization Code Grant suits integrations acting on behalf of an interactive user who can consent in a browser. JWT Grant suits a service that must act unattended — a backend job, a scheduled process, an application sending on behalf of an account rather than a person. A JWT is exchanged at the token endpoint for an access token valid for roughly an hour, so the integration must handle token lifetime rather than fetching one at deploy time.
The consequences of choosing wrongly are not theoretical. An unattended process built on Authorization Code Grant stops working when a refresh token expires or the consenting user leaves. We settle this at design time, along with where the private key lives and how it is rotated.
Webhooks over polling
Docusign Connect delivers notifications when envelope and recipient events occur, and Docusign recommends it in preference to polling the service for status. Connect subscriptions can be scoped at account, envelope or recipient level, which matters when a single account serves several integrations that should not all receive each other's traffic.
Polling is worse on every axis: it is slower, it consumes API capacity against rate limits that exist precisely to prevent it, and it scales with envelope volume rather than with event volume. Where we find polling in an existing integration, replacing it is usually the highest-value change available.