receive docusign connect webhooks and verify hmac signatures

domain: docusign.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

In-depth guide

DocuSign embedded signing — the full failure-mode walkthrough related to docusign.com, checked against official docs, with linked verified routes.

Steps

  1. In the DocuSign Admin console, configure a Connect subscription pointing to your HTTPS endpoint and enable HMAC authentication, saving the generated HMAC key.
  2. On each inbound POST, read the X-DocuSign-Signature-1 header and the raw request body bytes.
  3. Compute HMAC-SHA256 of the raw body using your stored HMAC key, then base64-encode the digest.
  4. Compare your computed value to the header value using a constant-time string comparison; reject requests that do not match with HTTP 401.
  5. Parse the XML or JSON payload (depending on your Connect format setting) to extract envelopeId and status, then enqueue processing to avoid timing out the HTTP response.

Known gotchas

Related routes

Retrieve and cache a DocuSign Connect HMAC-verified webhook payload, then replay failed deliveries using the retry API
docusign.com · 5 steps · unrated
Create a DocuSign envelope using anchor-string (auto-place) tabs, then verify inbound Connect webhook events with HMAC before trusting them
developers.docusign.com · 5 steps · unrated
Register a Daily.co webhook and verify inbound event signatures with HMAC
docs.daily.co · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans