DocuSign SOAP API报错:账户权限不足,请求签名失败求助
DocuSign SOAP API 错误:This Account lacks sufficient permissions(错误码111)
问题概述
按照DocuSign官方SOAP API请求签名指南开发,已导入WSDL并创建信封,但调用CreateAndSendEnvelope接口时返回权限不足错误,无法定位具体原因。
已完成的参数替换
{USER_ID}替换为Apps and Keys中的1f8d****-****-****-****-********7bcc{ACCOUNT_ID}替换为Apps and Keys中的2ba4****-****-****-****-********2349{USER_EMAIL}替换为有效邮箱(曾在REST API中正常使用,与账户邮箱不同)
请求内容
POST /api/3.0/api.asmx HTTP/1.1 Host: demo.docusign.net User-Agent: LibDocusign Accept: */* Accept-Encoding: deflate, gzip Content-Type: text/xml; charset=utf-8 Connection: close SOAPAction: "http://www.docusign.net/API/3.0/CreateAndSendEnvelope" X-DocuSign-Authentication: My Docusign Integtation Key Content-Length: 2326 <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" xmlns:SOAP-ENC="http://schemas.xmlsoap.org/soap/encoding/" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> <SOAP-ENV:Header> <wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" SOAP-ENV:mustUnderstand="1"> <wsu:Timestamp wsu:Id="TS-102D96E1E732485F84CD0DCF095C5B08"> <wsu:Created>2023-08-28T08:49:46Z</wsu:Created> <wsu:Expires>2023-08-28T08:50:46Z</wsu:Expires> </wsu:Timestamp> <wsse:UsernameToken wsu:Id="UsernameToken-0280BB10F71641FC8E680E1B93C1D8B0"> <wsse:Username>My Developper User ID</wsse:Username> <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText">My Developper account Password</wsse:Password> <wsse:Nonce EncodingType="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary">1WbYuC7dU8e6SaAqIwlUJw==</wsse:Nonce> <wsu:Created>2023-08-28T08:49:46Z</wsu:Created> </wsse:UsernameToken> </wsse:Security> </SOAP-ENV:Header> <SOAP-ENV:Body> <ns1:CreateAndSendEnvelope xmlns:ns1="http://www.docusign.net/API/3.0"> <ns1:Envelope xmlns:ns1="http://www.docusign.net/API/3.0"> <ns1:Recipients> <ns1:Recipient> <ns1:ID>1</ns1:ID> <ns1:Email>me@mydomain.com</ns1:Email> <ns1:UserName>Me</ns1:UserName> <ns1:Type>Signer</ns1:Type> <ns1:RequireIDLookup>false</ns1:RequireIDLookup> </ns1:Recipient> </ns1:Recipients> <ns1:Documents> <ns1:Document> <ns1:ID>1</ns1:ID> <ns1:Name>Lorem Document</ns1:Name> <ns1:PDFBytes>QzpcVXNlcnNcTk9cRG9jdW1lbnRzXFZTQ29kZVRlbXBcRG9jdXNpZ25cZXhhbXBsZXNfYmFz aFxkZW1vX2RvY3VtZW50c1xXb3JsZF9XaWRlX0NvcnBfbG9yZW0ucGRm</ns1:PDFBytes> </ns1:Document> </ns1:Documents> <ns1:Tabs> <ns1:Tab> <ns1:DocumentID>1</ns1:DocumentID> <ns1:RecipientID>1</ns1:RecipientID> <ns1:Type>SignHere</ns1:Type> <ns1:PageNumber>1</ns1:PageNumber> <ns1:XPosition>100</ns1:XPosition> <ns1:YPosition>100</ns1:YPosition> </ns1:Tab> </ns1:Tabs> <ns1:AccountId>My Developper account ID</ns1:AccountId> <ns1:Subject>Test</ns1:Subject> </ns1:Envelope> </ns1:CreateAndSendEnvelope> </SOAP-ENV:Body> </SOAP-ENV:Envelope>
服务器响应内容
HTTP/1.1 500 Internal Server Error Cache-Control: private Content-Type: text/xml; charset=utf-8 X-DocuSign-Node: DA1DFE5 Date: Mon, 28 Aug 2023 08:49:46 GMT Content-Length: 1393 Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains <?xml version="1.0" encoding="utf-8"?> <soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"> <soap:Header> <wsa:Action>http://schemas.xmlsoap.org/ws/2004/08/addressing/fault</wsa:Action> <wsa:MessageID>urn:uuid:4e384c84-1d55-46b4-ac47-3559fa6ab693</wsa:MessageID> <wsa:RelatesTo>urn:uuid:3c2851d0-6af1-4a5f-a213-539dd39b6aa7</wsa:RelatesTo> <wsa:To>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</wsa:To> <wsse:Security> <wsu:Timestamp wsu:Id="Timestamp-31d1e46c-c71d-4bf5-9bfd-3daa3ed9844d"> <wsu:Created>2023-08-28T08:49:47Z</wsu:Created> <wsu:Expires>2023-08-28T08:54:47Z</wsu:Expires> </wsu:Timestamp> </wsse:Security> </soap:Header> <soap:Body> <soap:Fault> <faultcode>soap:Client</faultcode> <faultstring>This Account lacks sufficient permissions.</faultstring> <faultactor>missing in Web.Config</faultactor> <detail> <ErrorCode xmlns="missing in Web.Config">111</ErrorCode> <ErrorReason xmlns="missing in Web.Config">This Account lacks sufficient permissions.</ErrorReason> </detail> </soap:Fault> </soap:Body> </soap:Envelope>
解决建议
修复认证方式冲突
请求中同时使用了WSSE UsernameToken认证和X-DocuSign-Authentication头,两种认证方式不能混用,需二选一:- 若使用集成密钥(推荐):移除WSSE Security头,将
X-DocuSign-Authentication头改为标准格式:X-DocuSign-Authentication: <DocuSignCredentials><Username>你的用户ID</Username><Password>账户密码</Password><IntegratorKey>你的集成密钥</IntegratorKey></DocuSignCredentials> - 若使用用户名密码认证:移除
X-DocuSign-Authentication头,确保WSSE中的Username是实际用户ID,Password是账户密码。
- 若使用集成密钥(推荐):移除WSSE Security头,将
补全请求中的账户ID
请求里的<ns1:AccountId>My Developper account ID</ns1:AccountId>需替换为实际的账户ID值(即2ba4****-****-****-****-********2349)。验证PDFBytes格式
当前请求中的PDFBytes包含换行符,可能导致文件解析失败,进而触发权限类错误。需确保Base64编码为连续字符串,无换行或多余转义字符。检查账户权限
- 登录DocuSign后台,确认当前用户ID对应的账户拥有发送信封的权限(在用户管理的权限组中查看)。
- 若为沙箱账户,确认账户未过期且已完成激活流程。
确认集成密钥关联
检查集成密钥是否已正确关联到当前账户,且未被禁用。
内容的提问来源于stack exchange,提问作者Dzious
相关产品推荐
相关产品推荐

