Documenso (documenso.com) is an open-source electronic signature platform — its own tagline on both the website and the GitHub repository is "The Open Source DocuSign Alternative." It offers the same end-to-end flow as mainstream e-signature services: upload a PDF, place signature fields, send to recipients in order, sign online, and keep an audit trail. The difference is that the source code is published under AGPL-3.0, so an organization can either sign up for the hosted cloud or deploy the entire signing stack on its own infrastructure with Docker (homepage, GitHub repository, checked 2026-10-01). As of 2026-10-01 the repository has about 15,280 stars and 3,300 forks, and the latest release, v2.19.0, shipped on 2026-09-29 — the project is actively developed (GitHub API).

Screenshot of Documenso's homepage: hero headline "Enterprise-Grade E-Signatures. For Everyone." with an embedded signing interface on the right

The screenshot above shows the homepage: the hero headline "Enterprise-Grade E-Signatures. For Everyone." with the sub-line "Fully compliant signatures out of the box. Ready to use or ready to be built upon"; on the right, a sample signing interface embedded in a third-party app with signature, name and email fields plus a drawn signature; below, a customer bar shows companies such as Vial, Mautic and Cal.com.

At a Glance

Item Details
URL https://documenso.com/ (app at app.documenso.com)
Type Open-source e-signature platform (hosted SaaS + self-hosted)
License AGPL-3.0; enterprise features such as SSO, white-label embed editor and 21 CFR Part 11 require a commercial license key (self-hosting docs)
Pricing Cloud free tier 0(5documents/month);paidplansfrom0 (5 documents/month); paid plans from25/month billed yearly; self-hosted Community Edition free (pricing page, as of 2026-10-01)
Sign-up Cloud use requires an account: name + email + password, or Google sign-up; no credit card for the free tier (sign-up page, verified 2026-10-01)
Interface languages Marketing site in English, French, Spanish and German (Germany); the app repository ships translations for 12 locales — de, en, es, fr, it, ja, ko, nl, pl, pt-BR, sq, zh (including Chinese; completeness not individually verified) (translations directory)
Project status Active; v2.19.0 (2026-09-29); repository created 2023-03-12 (GitHub, as of 2026-10-01)

Background

  • On December 29, 2022, Timur Ercan announced the project in the blog post "Announcing Documenso," signed "Cheers from Hamburg, Timur." His stated motivation: digital signing is fundamentally a trust business, and tools that carry trust should be open and auditable — hence open source, with a first release planned for early 2023 (announcement post).
  • The company behind it is Documenso, Inc. (site footer, © 2026). According to its public Open Startup page, the co-founders are Timur Ercan (CEO, Germany) and Lucas Smith (CTO, Australia), with a remote team across Ghana, Romania, Malaysia and elsewhere; all salaries and salary bands are published (Open Startup, as of 2026-10-01).
  • The same page discloses funding of 288,000(May2023)and288,000 (May 2023) and1,538,999 (July 2023), with a cap table of 75.5% founders, 14.5% investors and a 10% team pool. The company runs as an "Open Startup," publishing metrics, finances and operations data (Open Startup).
  • The homepage features customer stories and quotes from Prisma, Vial and Cal.com, among others.

Core Features

  • Signing workflow: upload a PDF, place fields (signature, name, email, date, etc.), add recipients with roles and a signing order, and send the request by email. Recipients sign in the browser via a link; the document is finalized once all parties have signed (site feature navigation).
  • Signature technology and audit trail: per the official docs, completed documents are digitally signed using the PDF signature capabilities of ISO 32000, with X.509 certificates identifying signers, optional RFC 3161 trusted timestamps, and a visual signature appearance. Completed documents are cryptographically sealed — any later modification invalidates the signature. Each document keeps an audit trail logging creation, sending, views (with IP address), field completion and finalization events with timestamps (Standards & Regulations, E-Sign Compliance).
  • Templates and Direct Links: save frequently used documents as reusable templates and generate a Direct Link — share the link and anyone can start signing on demand (an NDA is the canonical example) (homepage).
  • Teams: create multiple teams with member roles (Owner/Member), collaborate on shared signing workflows while keeping personal documents separate (homepage).
  • Also: public profiles, white-labeling, embedded signing and a Zapier integration (site footer navigation).

API, Webhooks and Extensibility

  • REST API v2: the cloud base URL is https://app.documenso.com/api/v2, authenticated with an API key (Authorization: api_xxx), covering documents, recipients, fields and templates. The docs note that the documents/templates endpoints are being migrated to an envelopes model; the OpenAPI reference is the source of truth for current endpoints (API Reference).
  • Webhooks: events for the full document lifecycle (created, sent, opened, signed, completed, rejected, cancelled), recipient-level events and template events, delivered as HTTP POSTs to your endpoint with signature verification support (Webhooks docs).
  • Embedding and white-label: the signing experience can be embedded into your own application; the Platform plan adds white-label embedded signing and Slack integration support (pricing page).
  • Rate limits: a global ceiling of 1,000 API requests per minute per IP; exceeding it returns HTTP 429 with a Retry-After header. Enterprise plans can set custom limits, and self-hosted instances control their own (Fair Use Policy).

Cloud Pricing (as of 2026-10-01)

Prices below are from the pricing page, quoted at yearly billing (the page defaults to "Billed yearly"):

Plan Price Highlights
Free $0 5 documents/month, up to 10 recipients per document, no credit card
Individual 25/mo(25/mo (300/yr) Unlimited documents, API access for personal use, email support
Teams 40/mo(40/mo (480/yr) 5 users included (extra users $8/user/mo), 1 team, API access for automation, embedded signing
Platform 250/mo(250/mo (3,000/yr) Unlimited documents and users, unlimited API, Slack integration support, white-label embedded signing
Enterprise Custom Cloud or self-hosted, advanced compliance and admin features

Paid plans carry no hard signing-volume cap but are governed by the official Fair Use Policy: for example, an Individual plan's API must not power an external platform product, and usage beyond a plan's intended scope triggers an upgrade conversation — the company says it will not block an account without reaching out first.

Screenshot of Documenso's pricing page: Free, Individual (<span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>25</mn><mi mathvariant="normal">/</mi><mi>m</mi><mi>o</mi><mo stretchy="false">)</mo><mo separator="true">,</mo><mi>T</mi><mi>e</mi><mi>a</mi><mi>m</mi><mi>s</mi><mo stretchy="false">(</mo></mrow><annotation encoding="application/x-tex">25/mo), Teams (</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="katex-base"><span class="katex-strut" style="height:1em;vertical-align:-0.25em;"></span><span class="mord">25/</span><span class="mord mathnormal">m</span><span class="mord mathnormal">o</span><span class="mclose">)</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.1389em;">T</span><span class="mord mathnormal">e</span><span class="mord mathnormal">am</span><span class="mord mathnormal">s</span><span class="mopen">(</span></span></span></span>40/mo) and Platform ($250/mo) at yearly billing

The screenshot above shows the pricing page: the header reads "Signing for every scale. Powered by our Fair-Use-Policy," with the four yearly-billed plans side by side, the Teams plan highlighted, plus an Enterprise contact section and a "Hosted by us / Self-hosted" toggle below.

Self-Hosting and Licensing

Self-hosting is Documenso's defining difference from most closed-source signing services. Officially documented deployment options include Docker (single container with an external database), Docker Compose, one-click Railway deployment and Kubernetes (self-hosting docs); an official image, documenso/documenso, is published on Docker Hub. Requirements (Requirements):

  • Signing certificate (.p12): not bundled — without one the app starts but cannot sign. You can generate a self-signed certificate, use a CA-issued one, or Google Cloud HSM.
  • PostgreSQL 14+: the only supported database (no MySQL/SQLite).
  • SMTP server: delivers signing requests, reminders and completion notices; smtp-auth, smtp-api, Resend and MailChannels transports are supported.
  • Reverse proxy: nginx, Caddy, Traefik or similar for TLS termination in production.
  • Optional: S3-compatible storage (documents are stored in the database by default) and Redis for the BullMQ job provider (the default queue uses PostgreSQL).

On licensing: the self-hosted core is AGPL-3.0; enterprise features — SSO, the white-label embed editor, 21 CFR Part 11 — are activated with a purchased license key (self-hosting docs). The docs also state that an Enterprise Edition commercial license removes the AGPL-3.0 source-disclosure requirement, allowing integration into proprietary products (Fair Use Policy page). Self-hosted deployments come in three editions (Self-Hosted page):

Edition Pricing Official positioning
Community Edition (CE) Free forever, no usage limits Testing, evaluation, internal POCs; community support only
Business Edition (BE) Fixed yearly license "Serious production use"; enterprise feature set and application support
Enterprise Edition (EE) Tailored pricing Large-scale, mission-critical; SLAs, infrastructure support, AATL-compliant certificate, etc.

A neutral caveat: CE is a complete AGPL-3.0 application with no usage limits, yet the official comparison table labels its intended use as testing/evaluation/internal POCs and steers production deployments toward the paid editions. That is the vendor's commercial positioning rather than a license restriction — readers can weigh it for themselves.

Screenshot of Documenso's self-hosted page: Self-Hosted Documenso with data ownership and no per-signature fees, plus the CE/BE/EE edition comparison

The screenshot above shows the self-hosting licenses page: it explains that self-hosting provides data ownership, compliance control and no per-signature pricing, and begins the Community / Business / Enterprise edition comparison (Pricing row: Free Forever, Fixed Yearly License, Tailored Pricing).

Compliance and Legal Validity (Official Statements)

Legal validity is the central question for any e-signature tool. Here is what Documenso itself states (Compliance overview, E-Sign Compliance docs, checked 2026-10-01):

  • The compliance page marks the U.S. ESIGN Act, UETA, eIDAS-SES (Simple Electronic Signature), 21 CFR Part 11, SOC 2 and HIPAA as "Compliant." The certifications doc further qualifies 21 CFR Part 11 and HIPAA as "Compliant (Enterprise)" — tied to the enterprise license (Certifications docs).
  • ISO 27001 and Switzerland's ZertES are marked "Planned (2026)"; eIDAS AES (Advanced) and QES (Qualified) are "Planned (H2 2026)."
  • The docs state the current boundary plainly: Documenso supports SES-level compliance; QES is not supported (it requires a qualified trust service provider), AES is partially supported (full AES needs identity verification services), there is no built-in KYC, and no qualified certificates are issued. For transactions requiring AES or QES, the docs advise consulting legal counsel.
  • Documenso also notes that its documentation is not legal advice and that requirements vary by jurisdiction, document type and industry; the ESIGN Act, for example, excludes wills, family-law documents and court documents.

In short: for ordinary commercial contracts in the U.S. and EU, the official position is that SES-level signatures plus the audit trail satisfy ESIGN/UETA/eIDAS-SES. For high-assurance scenarios such as EU qualified signatures (QES), the platform is not yet suitable as of 2026-10-01.

Screenshot of Documenso's compliance page: ESIGN Act, UETA, eIDAS-SES, 21 CFR Part 11, SOC 2 and HIPAA all marked Status: Compliant

The screenshot above shows the compliance page: cards list each regulation's status — ESIGN Act, UETA, eIDAS-SES, 21 CFR Part 11, SOC 2 and HIPAA all show "Status: Compliant," while ISO 27001, ZertES and eIDAS-AES below are marked Planned.

Who It Suits

  • Developers or SaaS teams embedding signing into their own product: API + webhooks + white-label embedding; the Platform plan targets exactly this.
  • Organizations with data-sovereignty or deployment-compliance requirements: a full AGPL-3.0 self-hosted stack keeps documents and data on their own infrastructure.
  • Individuals or small teams with occasional signing needs: the cloud free tier covers 5 documents a month with no credit card.
  • Repetitive signature collection: templates + Direct Links fit standardized paperwork such as NDAs and authorization forms.

Limitations

  • Modest free tier: 5 documents per month and 10 recipients per document; anything more requires payment (pricing page, as of 2026-10-01).
  • High-assurance signatures not yet available: per the official docs, QES is unsupported and AES only partially — EU qualified-signature scenarios must wait for the H2 2026 roadmap or use another solution (E-Sign Compliance).
  • Some compliance tied to the enterprise license: the 21 CFR Part 11 and HIPAA compliance badges carry an "Enterprise" condition not included in the free or lower cloud tiers (Certifications docs).
  • Self-hosting operational burden: you must supply a signing certificate, PostgreSQL, SMTP and a reverse proxy. The docs explicitly warn that outbound-request checks (e.g., for webhooks) are best-effort and fail open — egress filtering and blocking access to internal services and cloud metadata endpoints are the operator's responsibility (self-hosting docs).
  • API model in migration: documents/templates endpoints are being migrated to envelopes, so integrators should follow the migration guide (API Reference).

Comparable Services

  • DocuSign: the leading closed-source commercial e-signature service, billed per seat and by volume. Documenso explicitly positions itself as the open-source alternative; the key differences are the licensing model (proprietary SaaS vs AGPL-3.0 with a self-hosted option) and the pricing structure.
  • Other open-source e-signature projects are occasionally mentioned alongside Documenso in the community but were not individually researched for this profile.

References