DocuSign
Connect your DocuSign account to Ploy to automatically sync users, their permission profiles, and groups, so you can manage and review access to DocuSign alongside the rest of your stack. Ploy can also provision and deprovision DocuSign access for you: adding or removing users from DocuSign groups, inviting new account users, and closing account users when someone leaves.
Before you begin: You'll need admin access to your DocuSign account. Ploy connects using a DocuSign integration app (JWT Grant) that impersonates an API user — use a DocuSign account administrator so Ploy can read the account's full user list and manage users and group membership. If you're using a DocuSign developer (demo) account, select the Demo environment in Ploy; for a live account, select Production.
Create an integration app in DocuSign
Log in to DocuSign as an admin and create an integration app for Ploy.
Log in to DocuSign as an admin and open Settings.
Navigate to Integrations > Apps and Keys.
Note the User ID shown at the top of the page — this is the API Username GUID of the user Ploy will impersonate.
Click Add App and Integration Key, name the app "Ploy" and create it.
Copy the Integration Key (a GUID) — you'll enter it in Ploy.
Connect DocuSign to Ploy
In Ploy, add the DocuSign integration and enter the credentials from DocuSign.
In Ploy, click Integrations in the left sidebar.
In the main Integrations tab, click Add new integration and search for DocuSign.
Choose your Environment — Demo for a DocuSign developer account, Production for a live account.
Enter the Integration Key from Apps and Keys.
Enter the API Username (User ID) — the User ID GUID of the user Ploy will impersonate. This user must be a DocuSign account administrator.
Save — Ploy generates an RSA public key for you to upload to DocuSign in the next step.
Upload the public key and grant consent
Upload the RSA public key to DocuSign and grant consent so Ploy can impersonate the API user.
Copy the public key Ploy generated.
Back in DocuSign Apps and Keys, open the integration key you created.
Under Service Integration, click Add RSA Keypair, then Upload RSA, and paste the public key.
Under Additional settings, add the Redirect URI shown in Ploy (it must match exactly, or granting consent will fail).
Save your changes in DocuSign.
In Ploy, click the Grant consent link, sign in as the API user and click Accept — this one-time consent allows Ploy to impersonate the API user.
Back in Ploy, click Test Connection to verify the connection and finish the setup.
What data syncs
Ploy imports the following from DocuSign:
Users: every user in your DocuSign account, with their name, email, status, created date, permission profile, user type, and admin flag.
DocuSign access: each user's access to DocuSign, with their permission profile as the entitlement. Users whose DocuSign status is not Active (for example Closed or Disabled) are shown as having had their access removed.
Groups: DocuSign groups (including empty groups) and each group's members. Groups deleted in DocuSign are archived in Ploy, and memberships removed in DocuSign are revoked in Ploy on the next sync. DocuSign's built-in "Everyone" group is listed but its membership is not synced, because DocuSign manages it implicitly.
Data syncs periodically to keep Ploy's access graph up to date.
What Ploy can change in DocuSign
Scans only ever read from DocuSign. Ploy writes to DocuSign only when a workflow you configure in Ploy — such as an access flow, an onboarding or offboarding action, or an access change actioned from an access review — targets DocuSign. The integration supports exactly these changes:
Add a user to a group / remove a user from a group: Ploy adds or removes the user's membership of the chosen DocuSign group. Group membership is the resource type you grant and revoke access to in Ploy's access flows and reviews. Ploy will not change membership of the "Everyone" group (DocuSign manages it automatically), and will not add a Closed user to a group.
Create a user: Ploy invites a new user to your DocuSign account by email. DocuSign creates the membership in "Activation Sent" status and emails the person to activate — Ploy never sets a password.
Remove a user: Ploy closes the user's DocuSign account membership. DocuSign has no hard delete — closing revokes their access and frees the seat. Closing an already-closed user is harmless.
Every change Ploy makes is also reflected immediately in Ploy's access records, so the next scan agrees with the action.
Permissions and security
This section sets out exactly what access Ploy is granted, so it can be shared with your security, change-control, or audit teams.
OAuth scopes
At the consent step, Ploy requests exactly two DocuSign OAuth scopes — no others:
signature— access the DocuSign eSignature API as the impersonated userimpersonation— allows Ploy to act on behalf of the nominated API user via JWT Grant, without an interactive login
How the connection is secured
Ploy authenticates with DocuSign's JWT Grant flow, impersonating the single API user you nominate. No DocuSign password is shared.
Ploy generates an RSA key pair: you upload only the public key to DocuSign, and the private key never leaves Ploy.
Access is granted through a one-time consent you approve as the API user, and you can revoke it at any time from DocuSign.
What Ploy reads and writes
Reads: the account's users (including permission profile and admin flag), groups, and group memberships.
Writes: only the changes listed under "What Ploy can change in DocuSign" above — adding or removing a user from a group, inviting a new account user, and closing an account user. Writes happen only when triggered by a Ploy workflow you have set up; scheduled scans never write.
What is not included
Ploy does not send, void, or read envelopes or documents, does not read document content, does not edit existing users' profiles or permission profiles, does not create, rename, or delete groups, and does not change DocuSign account settings. All reads and writes are limited to the account of the impersonated API user.