You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否通过Authorization Code grant模拟组织用户,无需用户同意交付信封草稿?

Solution to Transfer Draft Envelope to Another User's Draft Folder Without Their Authorization

Hey there! Let's tackle your problem head-on—this is a common scenario for team-based envelope workflows, and there's a straightforward way to make this work using the Authorization Code grant with user impersonation.

First, Let's Diagnose Why Your Current Setup Isn't Working

  • When you set the envelope status to created using U1's authorization, the envelope lands in U1's draft folder because the API context is tied directly to U1's account—this is the expected default behavior.
  • Setting the status to sent pushes it to U2's inbox because that triggers a formal signing workflow, not a draft transfer. The sent status is for initiating signature requests, not sharing editable drafts.

Yes, You Can Do This (With the Right Permissions)

To move a draft from U1 to U2's draft folder without U2's explicit authorization, you'll need to use user impersonation alongside the Authorization Code grant. Here's how it works:

1. Ensure U1 Has Impersonation Permissions

First, your organization's admin needs to grant U1 the ability to impersonate other users in Org1. This is done by assigning U1 a role that includes the "Impersonate Users" permission (check your DocuSign admin console under User Settings > Roles). Without this permission, you won't be able to act on behalf of U2.

2. Use Authorization Code Grant with Impersonation

When U1 authenticates via the Authorization Code flow, include an extra parameter in the token request to specify that you want to act as U2. Here's what that request looks like:

POST /oauth/token
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&code=YOUR_AUTHORIZATION_CODE_FROM_U1
&redirect_uri=YOUR_REGISTERED_REDIRECT_URI
&client_id=YOUR_INTEGRATION_KEY
&client_secret=YOUR_CLIENT_SECRET
&impersonation_user_id=U2_USER_ID

The impersonation_user_id is U2's unique user ID in your DocuSign organization (you can fetch this via the Users API if you don't have it handy).

3. Create/Transfer the Envelope as U2

Once you have the access token that's impersonating U2, use that token to either:

  • Create the envelope directly with status created—it will automatically save to U2's draft folder, or
  • Copy an existing draft from U1's account to U2's draft folder using the Envelopes API's copy endpoint.

For example, creating the envelope as U2 would look like this (simplified JSON payload):

POST /v2.1/accounts/{accountId}/envelopes
Authorization: Bearer YOUR_IMPERSONATED_ACCESS_TOKEN
Content-Type: application/json

{
  "emailSubject": "Draft for U2 to Review",
  "status": "created",
  "documents": [
    {
      "documentId": "1",
      "name": "Document.pdf",
      "documentBase64": "BASE64_ENCODED_DOCUMENT"
    }
  ]
}

Key Notes

  • Impersonation is only allowed within the same organization, so U1 and U2 must both be part of Org1.
  • This approach complies with DocuSign's security model—only users with explicit admin-granted impersonation rights can act on behalf of others.
  • If you don't want to create the envelope directly as U2, you can also transfer U1's existing draft by fetching it, then re-creating it under U2's context using the impersonated token.

That should solve your problem—you'll be able to get U1's draft into U2's folder without U2 having to log in or authorize anything.

内容的提问来源于stack exchange,提问作者Kaishu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 13:07:32