ESignaturesSAFE
MCP server for eSignatures (https://esignatures.com)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The most developer- and AI-friendly electronic signature platform.
Traditional eSignature tools lock you into rigid, static PDF files. eSignatures.com takes a different approach — contracts remain fully editable, Markdown-based content throughout their entire lifecycle, making them effortless for developers, automation systems, and AI agents to create, understand, modify, and manage.
This MCP server gives AI agents (such as Claude) real-time access to the complete eSignatures API, enabling:
- Dynamic contract creation and editing — even after sending
- Markdown-based content that AI can generate, understand, and update
- End-to-end workflows: drafting → placeholder filling → sending → signing → amendments
- Flexible templates and reusable contract workflows
- Contract links: reusable public signing URLs for waivers, NDAs and onboarding forms
- Signer management, notifications, and lifecycle automation
Built for intelligent, adaptive contract workflows — not outdated PDF-based signing.
Tools
56c24640bf2dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-server-esignatures -- uvx mcp-server-esignatures
{
"mcpServers": {
"mcp-server-esignatures": {
"command": "uvx",
"args": [
"mcp-server-esignatures"
]
}
}
}Exposed tools (31)
13 read · 13 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_contract_signer | write | Adds a signer to an existing contract. Note: adding a signer does NOT automatically send the contract to them; use resend_contract_signer_request to send it. |
add_template_collaborator | write | Creates a HTTPS link for editing a contract template; sends an invitation email if an email is provided. |
create_contract | write | Creates and sends a new contract. Unless save_as_draft is |
create_contract_link | write | Creates a new Contract link: a reusable public signing URL where anyone can review and sign the same document, and each signing creates a separate contract. Recommend this instead of create_contract when the signers aren |
create_template | write | Creates a reusable contract template for contracts to be based on. The body is provided as Markdown; Signer fields, alignment, and header counters are expressed with the extended-syntax JSON config in backticks at the end of a line. |
delete_contract | destructive | Deletes a contract. The contract can only be deleted if it |
delete_contract_link | destructive | Deletes a Contract link. The public signing URL stops working; contracts already signed via the link are not affected. |
delete_contract_signer | destructive | Removes a signer from a contract. |
delete_template | destructive | Deletes a contract template. |
list_contract_links | read | Lists the Contract links, including their public signing URLs and published status. |
list_recent_contracts | read | Returns the details of the latest contracts, 100 per page, newest first. Use the page parameter to fetch older contracts. |
list_template_collaborators | read | Returns the list of template collaborators, including their GUID, name, email, and the HTTPS link for editing the template |
list_templates | read | Lists the templates. |
query_contract | read | Responds with the contract details, contract_id, status, final PDF url if present, title, labels, metadata, expiry time if present, and signer details with all signer events (signer events are included only for recent contracts, with rate limiting). |
query_contract_content | read | Returns the raw Markdown content (body) of a contract, before any Placeholder fields ({{...}}) have been applied. |
query_contract_link | read | Responds with the Contract link details: contract_link_id, public signing URL, title, verification method, redirect URL, thank you message, CC email addresses, second signer settings, and published status. Use query_contract_link_content to fetch the Markdown body. |
query_contract_link_content | read | Returns the Markdown content (body) of a Contract link. |
query_contract_placeholder_fields | read | Returns the current values assigned to all Placeholder fields ({{...}}) in a contract. Each value is returned in one of three formats: plain text, Markdown, or a linked template. |
query_template | read | Responds with the template metadata: template_id, title, labels, created_at, list of Placeholder fields and Signer field IDs in the template. Use query_template_content to fetch the Markdown body. |
query_template_content | read | Returns the Markdown content (body) of a template. |
remove_template_collaborator | destructive | Removes the template collaborator |
resend_contract_signer_request | read | Sends (or resends) the signature request to a specific signer on a contract. |
send_draft_contract | write | Sends a draft contract to its signers to collect signatures. Only applicable to contracts with a status of |
update_contract_content | write | Edits Markdown content of a draft or active contract by applying an ordered list of find/replace operations. Each `edits` entry replaces the exact matches of `find_markdown` with `replace_with_markdown`. The response includes the updated content. |
update_contract_link | write | Updates a Contract link |
update_contract_link_content | write | Edits a Contract link |
update_contract_placeholder_fields | write | Updates Placeholder field values ({{...}}) on an active contract. Only the fields you include will be changed. Each field can be filled with plain text, Markdown content, or the full content of another template. |
update_contract_signer | write | Updates the contact details of an existing signer on a contract. Note: the contract is NOT automatically re-sent when the signer is updated. |
update_template | write | Updates a template |
update_template_content | write | Edits a template |
withdraw_contract | read | Withdraws a sent contract. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
delete_contract, delete_contract_link, delete_contract_signer, delete_template, remove_template_collaborator
Gates applied: no_behavioural_pass.
56c24640bf2dfull audit observations/trust-audit/mcp-server/esignaturescom__esignatures.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 56c24640bf2d | SAFE | B | 89 | first audit |
Questions
What is the ESignatures MCP server?
MCP server for eSignatures (https://esignatures.com)
What tools does ESignatures expose?
31 in total: 13 read-only, 13 that write, and 5 that can delete or overwrite (delete_contract, delete_contract_link, delete_contract_signer, delete_template, remove_template_collaborator). Every one is listed on this page with its risk.
Is ESignatures safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ESignatures need?
No credential environment variables were found in its source, so it appears to need none.
How does ESignatures run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-server-esignatures.
How current is this page?
The grade is for one exact copy of the source (56c24640bf2d), read on 2026-10-08. The repository is watched and re-audited when it changes.