Documenso (documenso.com) is an open-source electronic signature platform — its own tagline on both the website and the GitHub repository is "The Open Source DocuSign Alternative." It offers the same end-to-end flow as mainstream e-signature services: upload a PDF, place signature fields, send to recipients in order, sign online, and keep an audit trail. The difference is that the source code is published under AGPL-3.0, so an organization can either sign up for the hosted cloud or deploy the entire signing stack on its own infrastructure with Docker (homepage, GitHub repository, checked 2026-10-01). As of 2026-10-01 the repository has about 15,280 stars and 3,300 forks, and the latest release, v2.19.0, shipped on 2026-09-29 — the project is actively developed (GitHub API).

The screenshot above shows the homepage: the hero headline "Enterprise-Grade E-Signatures. For Everyone." with the sub-line "Fully compliant signatures out of the box. Ready to use or ready to be built upon"; on the right, a sample signing interface embedded in a third-party app with signature, name and email fields plus a drawn signature; below, a customer bar shows companies such as Vial, Mautic and Cal.com.
At a Glance
| Item | Details |
|---|---|
| URL | https://documenso.com/ (app at app.documenso.com) |
| Type | Open-source e-signature platform (hosted SaaS + self-hosted) |
| License | AGPL-3.0; enterprise features such as SSO, white-label embed editor and 21 CFR Part 11 require a commercial license key (self-hosting docs) |
| Pricing | Cloud free tier 25/month billed yearly; self-hosted Community Edition free (pricing page, as of 2026-10-01) |
| Sign-up | Cloud use requires an account: name + email + password, or Google sign-up; no credit card for the free tier (sign-up page, verified 2026-10-01) |
| Interface languages | Marketing site in English, French, Spanish and German (Germany); the app repository ships translations for 12 locales — de, en, es, fr, it, ja, ko, nl, pl, pt-BR, sq, zh (including Chinese; completeness not individually verified) (translations directory) |
| Project status | Active; v2.19.0 (2026-09-29); repository created 2023-03-12 (GitHub, as of 2026-10-01) |
Background
- On December 29, 2022, Timur Ercan announced the project in the blog post "Announcing Documenso," signed "Cheers from Hamburg, Timur." His stated motivation: digital signing is fundamentally a trust business, and tools that carry trust should be open and auditable — hence open source, with a first release planned for early 2023 (announcement post).
- The company behind it is Documenso, Inc. (site footer, © 2026). According to its public Open Startup page, the co-founders are Timur Ercan (CEO, Germany) and Lucas Smith (CTO, Australia), with a remote team across Ghana, Romania, Malaysia and elsewhere; all salaries and salary bands are published (Open Startup, as of 2026-10-01).
- The same page discloses funding of 1,538,999 (July 2023), with a cap table of 75.5% founders, 14.5% investors and a 10% team pool. The company runs as an "Open Startup," publishing metrics, finances and operations data (Open Startup).
- The homepage features customer stories and quotes from Prisma, Vial and Cal.com, among others.
Core Features
- Signing workflow: upload a PDF, place fields (signature, name, email, date, etc.), add recipients with roles and a signing order, and send the request by email. Recipients sign in the browser via a link; the document is finalized once all parties have signed (site feature navigation).
- Signature technology and audit trail: per the official docs, completed documents are digitally signed using the PDF signature capabilities of ISO 32000, with X.509 certificates identifying signers, optional RFC 3161 trusted timestamps, and a visual signature appearance. Completed documents are cryptographically sealed — any later modification invalidates the signature. Each document keeps an audit trail logging creation, sending, views (with IP address), field completion and finalization events with timestamps (Standards & Regulations, E-Sign Compliance).
- Templates and Direct Links: save frequently used documents as reusable templates and generate a Direct Link — share the link and anyone can start signing on demand (an NDA is the canonical example) (homepage).
- Teams: create multiple teams with member roles (Owner/Member), collaborate on shared signing workflows while keeping personal documents separate (homepage).
- Also: public profiles, white-labeling, embedded signing and a Zapier integration (site footer navigation).
API, Webhooks and Extensibility
- REST API v2: the cloud base URL is
https://app.documenso.com/api/v2, authenticated with an API key (Authorization: api_xxx), covering documents, recipients, fields and templates. The docs note that the documents/templates endpoints are being migrated to an envelopes model; the OpenAPI reference is the source of truth for current endpoints (API Reference). - Webhooks: events for the full document lifecycle (created, sent, opened, signed, completed, rejected, cancelled), recipient-level events and template events, delivered as HTTP POSTs to your endpoint with signature verification support (Webhooks docs).
- Embedding and white-label: the signing experience can be embedded into your own application; the Platform plan adds white-label embedded signing and Slack integration support (pricing page).
- Rate limits: a global ceiling of 1,000 API requests per minute per IP; exceeding it returns HTTP 429 with a
Retry-Afterheader. Enterprise plans can set custom limits, and self-hosted instances control their own (Fair Use Policy).
Cloud Pricing (as of 2026-10-01)
Prices below are from the pricing page, quoted at yearly billing (the page defaults to "Billed yearly"):
| Plan | Price | Highlights |
|---|---|---|
| Free | $0 | 5 documents/month, up to 10 recipients per document, no credit card |
| Individual | 300/yr) | Unlimited documents, API access for personal use, email support |
| Teams | 480/yr) | 5 users included (extra users $8/user/mo), 1 team, API access for automation, embedded signing |
| Platform | 3,000/yr) | Unlimited documents and users, unlimited API, Slack integration support, white-label embedded signing |
| Enterprise | Custom | Cloud or self-hosted, advanced compliance and admin features |
Paid plans carry no hard signing-volume cap but are governed by the official Fair Use Policy: for example, an Individual plan's API must not power an external platform product, and usage beyond a plan's intended scope triggers an upgrade conversation — the company says it will not block an account without reaching out first.

The screenshot above shows the pricing page: the header reads "Signing for every scale. Powered by our Fair-Use-Policy," with the four yearly-billed plans side by side, the Teams plan highlighted, plus an Enterprise contact section and a "Hosted by us / Self-hosted" toggle below.
Self-Hosting and Licensing
Self-hosting is Documenso's defining difference from most closed-source signing services. Officially documented deployment options include Docker (single container with an external database), Docker Compose, one-click Railway deployment and Kubernetes (self-hosting docs); an official image, documenso/documenso, is published on Docker Hub. Requirements (Requirements):
- Signing certificate (.p12): not bundled — without one the app starts but cannot sign. You can generate a self-signed certificate, use a CA-issued one, or Google Cloud HSM.
- PostgreSQL 14+: the only supported database (no MySQL/SQLite).
- SMTP server: delivers signing requests, reminders and completion notices; smtp-auth, smtp-api, Resend and MailChannels transports are supported.
- Reverse proxy: nginx, Caddy, Traefik or similar for TLS termination in production.
- Optional: S3-compatible storage (documents are stored in the database by default) and Redis for the BullMQ job provider (the default queue uses PostgreSQL).
On licensing: the self-hosted core is AGPL-3.0; enterprise features — SSO, the white-label embed editor, 21 CFR Part 11 — are activated with a purchased license key (self-hosting docs). The docs also state that an Enterprise Edition commercial license removes the AGPL-3.0 source-disclosure requirement, allowing integration into proprietary products (Fair Use Policy page). Self-hosted deployments come in three editions (Self-Hosted page):
| Edition | Pricing | Official positioning |
|---|---|---|
| Community Edition (CE) | Free forever, no usage limits | Testing, evaluation, internal POCs; community support only |
| Business Edition (BE) | Fixed yearly license | "Serious production use"; enterprise feature set and application support |
| Enterprise Edition (EE) | Tailored pricing | Large-scale, mission-critical; SLAs, infrastructure support, AATL-compliant certificate, etc. |
A neutral caveat: CE is a complete AGPL-3.0 application with no usage limits, yet the official comparison table labels its intended use as testing/evaluation/internal POCs and steers production deployments toward the paid editions. That is the vendor's commercial positioning rather than a license restriction — readers can weigh it for themselves.

The screenshot above shows the self-hosting licenses page: it explains that self-hosting provides data ownership, compliance control and no per-signature pricing, and begins the Community / Business / Enterprise edition comparison (Pricing row: Free Forever, Fixed Yearly License, Tailored Pricing).
Compliance and Legal Validity (Official Statements)
Legal validity is the central question for any e-signature tool. Here is what Documenso itself states (Compliance overview, E-Sign Compliance docs, checked 2026-10-01):
- The compliance page marks the U.S. ESIGN Act, UETA, eIDAS-SES (Simple Electronic Signature), 21 CFR Part 11, SOC 2 and HIPAA as "Compliant." The certifications doc further qualifies 21 CFR Part 11 and HIPAA as "Compliant (Enterprise)" — tied to the enterprise license (Certifications docs).
- ISO 27001 and Switzerland's ZertES are marked "Planned (2026)"; eIDAS AES (Advanced) and QES (Qualified) are "Planned (H2 2026)."
- The docs state the current boundary plainly: Documenso supports SES-level compliance; QES is not supported (it requires a qualified trust service provider), AES is partially supported (full AES needs identity verification services), there is no built-in KYC, and no qualified certificates are issued. For transactions requiring AES or QES, the docs advise consulting legal counsel.
- Documenso also notes that its documentation is not legal advice and that requirements vary by jurisdiction, document type and industry; the ESIGN Act, for example, excludes wills, family-law documents and court documents.
In short: for ordinary commercial contracts in the U.S. and EU, the official position is that SES-level signatures plus the audit trail satisfy ESIGN/UETA/eIDAS-SES. For high-assurance scenarios such as EU qualified signatures (QES), the platform is not yet suitable as of 2026-10-01.

The screenshot above shows the compliance page: cards list each regulation's status — ESIGN Act, UETA, eIDAS-SES, 21 CFR Part 11, SOC 2 and HIPAA all show "Status: Compliant," while ISO 27001, ZertES and eIDAS-AES below are marked Planned.
Who It Suits
- Developers or SaaS teams embedding signing into their own product: API + webhooks + white-label embedding; the Platform plan targets exactly this.
- Organizations with data-sovereignty or deployment-compliance requirements: a full AGPL-3.0 self-hosted stack keeps documents and data on their own infrastructure.
- Individuals or small teams with occasional signing needs: the cloud free tier covers 5 documents a month with no credit card.
- Repetitive signature collection: templates + Direct Links fit standardized paperwork such as NDAs and authorization forms.
Limitations
- Modest free tier: 5 documents per month and 10 recipients per document; anything more requires payment (pricing page, as of 2026-10-01).
- High-assurance signatures not yet available: per the official docs, QES is unsupported and AES only partially — EU qualified-signature scenarios must wait for the H2 2026 roadmap or use another solution (E-Sign Compliance).
- Some compliance tied to the enterprise license: the 21 CFR Part 11 and HIPAA compliance badges carry an "Enterprise" condition not included in the free or lower cloud tiers (Certifications docs).
- Self-hosting operational burden: you must supply a signing certificate, PostgreSQL, SMTP and a reverse proxy. The docs explicitly warn that outbound-request checks (e.g., for webhooks) are best-effort and fail open — egress filtering and blocking access to internal services and cloud metadata endpoints are the operator's responsibility (self-hosting docs).
- API model in migration: documents/templates endpoints are being migrated to envelopes, so integrators should follow the migration guide (API Reference).
Comparable Services
- DocuSign: the leading closed-source commercial e-signature service, billed per seat and by volume. Documenso explicitly positions itself as the open-source alternative; the key differences are the licensing model (proprietary SaaS vs AGPL-3.0 with a self-hosted option) and the pricing structure.
- Other open-source e-signature projects are occasionally mentioned alongside Documenso in the community but were not individually researched for this profile.
References
- Documenso homepage and pricing page
- GitHub repository documenso/documenso
- Docs: Self-Hosting, Requirements
- Docs: E-Sign Compliance, Certifications, Compliance overview page
- Docs: API Reference, Webhooks, Fair Use Policy
- Self-Hosted editions comparison
- Open Startup (team and funding)
- Announcement blog post (2022-12-29)







