无需Client ID登录DocuSign并在回调中获取所选应用的Integration Key与Secret Key的实现咨询
Great question! Let’s walk through how to build this workflow with DocuSign, since your request has some unique twists compared to the standard OAuth flow. First, let’s clear up a critical point: DocuSign’s OAuth system requires a valid Client ID (Integration Key) to initiate any login request—so we’ll need a small workaround to make your flow work.
You’ll first need to set up your own Integration Key (IK) in the DocuSign Developer Console. This acts as the entry point for the OAuth flow, since DocuSign won’t let you start a login redirect without a valid Client ID.
- Configure this proxy app with your callback URL as the allowed redirect URI.
- Assign the necessary scopes:
signature(for basic user access) plusorganization_read(to fetch the user’s applications via DocuSign’s Admin API).
Update your redirect logic to include your proxy Integration Key—this is non-negotiable for DocuSign’s OAuth endpoint. Here’s how your adjusted code would look:
Response.Redirect(WebUtilities.AddQueryString(Options.AuthorizationEndpoint, new Dictionary<string, string> { { "client_id", "YOUR_PROXY_INTEGRATION_KEY" }, // Add this mandatory parameter { "scope", "signature organization_read" }, // Updated scope for app access { "response_type", "code" }, { "state", stateString }, { "redirect_uri", Options.AppUrl + Options.CallbackPath.ToString() } }));
After the user logs in and grants permission to your proxy app, DocuSign will redirect back to your callback URL with an authorization code. You’ll need to exchange this code for an access token to call DocuSign APIs on the user’s behalf:
var tokenRequest = new HttpRequestMessage(HttpMethod.Post, Options.TokenEndpoint); tokenRequest.Content = new FormUrlEncodedContent(new Dictionary<string, string> { { "grant_type", "authorization_code" }, { "code", codeFromCallback }, // The code from your callback request { "client_id", "YOUR_PROXY_INTEGRATION_KEY" }, { "client_secret", "YOUR_PROXY_SECRET_KEY" }, { "redirect_uri", Options.AppUrl + Options.CallbackPath.ToString() } }); var httpClient = new HttpClient(); var response = await httpClient.SendAsync(tokenRequest); var tokenResponse = await response.Content.ReadFromJsonAsync<TokenResponse>(); // Store the access token securely (e.g., in a session or encrypted cookie)
Use the access token to retrieve the user’s applications via DocuSign’s API:
- First, call the eSignature API’s
Get User Infoendpoint to get the user’s account ID and user ID:
Include the access token in theGET https://demo.docusign.net/restapi/v2/userinfoAuthorizationheader asBearer {access_token}. - Then, use those IDs to call the Admin API’s
Get User Applicationsendpoint:
Parse the response to extract each application’s name and Integration Key.GET https://demo.docusign.net/restapi/v2.1/admin/accounts/{accountId}/users/{userId}/applications
⚠️ Important Security Note: DocuSign does not expose Secret Keys via any public API. Secret Keys are only visible to the app creator at the time of generation, and can’t be retrieved later (only regenerated). This means your workflow will need to ask the user to manually input their app’s Secret Key, since it can’t be fetched programmatically.
Render a UI page displaying the list of applications you fetched. For each app, show its name and Integration Key, and add an input field for the user to enter the corresponding Secret Key.
Once the user selects an app and provides the Secret Key, redirect to your desired callback URL with the keys as query parameters (or use a POST request for better security):
var callbackUrl = WebUtilities.AddQueryString(Options.TargetCallbackUrl, new Dictionary<string, string> { { "integration_key", selectedAppIntegrationKey }, { "secret_key", userEnteredSecretKey } }); Response.Redirect(callbackUrl);
- Security: Passing keys via query parameters can leave them exposed in server logs or browser history. For production use, consider using a POST request with encrypted form data instead.
- Permissions: Ensure the user has permission to view the applications you’re fetching—some enterprise accounts may restrict access to app management.
- Environment: Adjust API endpoints to match your environment (use
https://www.docusign.netfor production,https://demo.docusign.netfor sandbox).
内容的提问来源于stack exchange,提问作者Shyam Vashista

