Atlas / MCP servers / esignaturescom / ESignatures

ESignaturesSAFE

mcp/esignaturescom/esignatures

MCP server for eSignatures (https://esignatures.com)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
31 13r · 13w · 5d
Transport
stdio · streamable-http
License
MIT
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The most developer- and AI-friendly electronic signature platform.

Traditional eSignature tools lock you into rigid, static PDF files. eSignatures.com takes a different approach — contracts remain fully editable, Markdown-based content throughout their entire lifecycle, making them effortless for developers, automation systems, and AI agents to create, understand, modify, and manage.

This MCP server gives AI agents (such as Claude) real-time access to the complete eSignatures API, enabling:

  • Dynamic contract creation and editing — even after sending
  • Markdown-based content that AI can generate, understand, and update
  • End-to-end workflows: drafting → placeholder filling → sending → signing → amendments
  • Flexible templates and reusable contract workflows
  • Contract links: reusable public signing URLs for waivers, NDAs and onboarding forms
  • Signer management, notifications, and lifecycle automation

Built for intelligent, adaptive contract workflows — not outdated PDF-based signing.

Tools

Read from source at commit 56c24640bf2dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-server-esignatures -- uvx mcp-server-esignatures
claude-desktop
{
  "mcpServers": {
    "mcp-server-esignatures": {
      "command": "uvx",
      "args": [
        "mcp-server-esignatures"
      ]
    }
  }
}
03

Exposed tools (31)

13 read · 13 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_contract_signerwriteAdds a signer to an existing contract. Note: adding a signer does NOT automatically send the contract to them; use resend_contract_signer_request to send it.
add_template_collaboratorwriteCreates a HTTPS link for editing a contract template; sends an invitation email if an email is provided.
create_contractwriteCreates and sends a new contract. Unless save_as_draft is
create_contract_linkwriteCreates a new Contract link: a reusable public signing URL where anyone can review and sign the same document, and each signing creates a separate contract. Recommend this instead of create_contract when the signers aren
create_templatewriteCreates a reusable contract template for contracts to be based on. The body is provided as Markdown; Signer fields, alignment, and header counters are expressed with the extended-syntax JSON config in backticks at the end of a line.
delete_contractdestructiveDeletes a contract. The contract can only be deleted if it
delete_contract_linkdestructiveDeletes a Contract link. The public signing URL stops working; contracts already signed via the link are not affected.
delete_contract_signerdestructiveRemoves a signer from a contract.
delete_templatedestructiveDeletes a contract template.
list_contract_linksreadLists the Contract links, including their public signing URLs and published status.
list_recent_contractsreadReturns the details of the latest contracts, 100 per page, newest first. Use the page parameter to fetch older contracts.
list_template_collaboratorsreadReturns the list of template collaborators, including their GUID, name, email, and the HTTPS link for editing the template
list_templatesreadLists the templates.
query_contractreadResponds with the contract details, contract_id, status, final PDF url if present, title, labels, metadata, expiry time if present, and signer details with all signer events (signer events are included only for recent contracts, with rate limiting).
query_contract_contentreadReturns the raw Markdown content (body) of a contract, before any Placeholder fields ({{...}}) have been applied.
query_contract_linkreadResponds with the Contract link details: contract_link_id, public signing URL, title, verification method, redirect URL, thank you message, CC email addresses, second signer settings, and published status. Use query_contract_link_content to fetch the Markdown body.
query_contract_link_contentreadReturns the Markdown content (body) of a Contract link.
query_contract_placeholder_fieldsreadReturns the current values assigned to all Placeholder fields ({{...}}) in a contract. Each value is returned in one of three formats: plain text, Markdown, or a linked template.
query_templatereadResponds with the template metadata: template_id, title, labels, created_at, list of Placeholder fields and Signer field IDs in the template. Use query_template_content to fetch the Markdown body.
query_template_contentreadReturns the Markdown content (body) of a template.
remove_template_collaboratordestructiveRemoves the template collaborator
resend_contract_signer_requestreadSends (or resends) the signature request to a specific signer on a contract.
send_draft_contractwriteSends a draft contract to its signers to collect signatures. Only applicable to contracts with a status of
update_contract_contentwriteEdits Markdown content of a draft or active contract by applying an ordered list of find/replace operations. Each `edits` entry replaces the exact matches of `find_markdown` with `replace_with_markdown`. The response includes the updated content.
update_contract_linkwriteUpdates a Contract link
update_contract_link_contentwriteEdits a Contract link
update_contract_placeholder_fieldswriteUpdates Placeholder field values ({{...}}) on an active contract. Only the fields you include will be changed. Each field can be filled with plain text, Markdown content, or the full content of another template.
update_contract_signerwriteUpdates the contact details of an existing signer on a contract. Note: the contract is NOT automatically re-sent when the signer is updated.
update_templatewriteUpdates a template
update_template_contentwriteEdits a template
withdraw_contractreadWithdraws a sent contract.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_contract, delete_contract_link, delete_contract_signer, delete_template, remove_template_collaborator
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 56c24640bf2dfull audit observations/trust-audit/mcp-server/esignaturescom__esignatures.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0856c24640bf2dSAFEB89first audit
06

Questions

What is the ESignatures MCP server?

MCP server for eSignatures (https://esignatures.com)

What tools does ESignatures expose?

31 in total: 13 read-only, 13 that write, and 5 that can delete or overwrite (delete_contract, delete_contract_link, delete_contract_signer, delete_template, remove_template_collaborator). Every one is listed on this page with its risk.

Is ESignatures safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ESignatures need?

No credential environment variables were found in its source, so it appears to need none.

How does ESignatures run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-server-esignatures.

How current is this page?

The grade is for one exact copy of the source (56c24640bf2d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement