Configure Knowledge-Based Authentication (KBA) as a recipient identity-verification method on a DocuSign envelope

domain: developers.docusign.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. In the recipient definition, set requireIdLookup to true on the Signer object, then reference a KBA-typed configuration — either idCheckConfigurationName for the legacy standalone ID Check/KBA workflow, or the recipient's identityVerification object referencing a KBA-typed Identity Verification workflowId — rather than the general photo-ID Verification or SMS OTP methods.
  2. Ensure the target Identity Verification / ID Check workflow is actually configured for Knowledge-Based Authentication in account settings before referencing it from the API; the workflow must exist and be KBA-typed.
  3. Send the envelope as usual; DocuSign, via its identity-verification vendor integration, presents the recipient with an out-of-wallet quiz (e.g., prior addresses, past loans) during the signing ceremony instead of, or in addition to, an access code.
  4. Handle the authentication outcome in your workflow: recipients get a limited number of quiz attempts, and failure locks them out of that signing session — detect this via envelope/recipient status and Connect events.
  5. Reserve KBA for U.S. signers with sufficient public-record history, and fall back to SMS/access-code/ID Verification for recipients outside that scope.

Known gotchas

Related routes

Configure CLEAR as an identity verification (IDV) method for a Docusign envelope recipient as an alternative to Docusign's other IDV providers
docusign.com · 5 steps · unrated
Implement a DocuSign eSignature workflow with a custom authentication SMS OTP step using the Identity Verification (IDV) configuration API
docusign.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans