关于DocuSign Connect签署完成后回调POST请求来源URL的技术问询
DocuSign Connect Request Source for Whitelisting
Great question—this is a super common ask when locking down firewalls for DocuSign Connect integrations!
First, a key clarification: DocuSign Connect doesn't send webhook POST requests from a single fixed URL. Instead, the requests originate from DocuSign's official IP address ranges, which are segmented by your DocuSign environment (production vs. sandbox) and geographic region.
Here's what your team needs to know:
- Production Environment: You'll need to whitelist the current production IP ranges published by DocuSign. These ranges can change periodically as DocuSign scales its infrastructure, so it's critical to stay updated.
- Sandbox/Developer Environment: There's a separate set of IP ranges for sandbox testing—make sure you don't mix these up with production!
- Verifying Authenticity Beyond IPs: For extra security (and to avoid issues if IP ranges shift), enable HMAC signature validation for your Connect configuration. This lets your endpoint verify that incoming requests are actually from DocuSign, regardless of the source IP.
To get the latest, official IP ranges:
- Log into your DocuSign Admin console, navigate to the Connect settings section, and look for links to the official IP documentation.
- Subscribe to DocuSign's official update channels (like developer announcements or account notifications) to be alerted if IP ranges change.
内容的提问来源于stack exchange,提问作者Mike Faber
相关产品推荐
相关产品推荐

