Agent skill

Documenso Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement security best practices for Documenso document signing integrations.

MITAuto-check: notesBackend & APIs

Install Documenso Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill documenso-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace documenso-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/documenso-security-basics .claude/skills/documenso-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
documenso-security-basics
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
352 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement security best practices for Documenso document signing integrations.

  • Works in 6 steps: API Key Security → Key Rotation with Zero Downtime → Webhook Secret Verification → …
  • Securing API keys
  • SKILL.md covers Output, Examples, Overview and Prerequisites, plus 5 more sections
  • Calls openssl and docker; needs DOCUMENSO_WEBHOOK_SECRET and DOCUMENSO_API_KEY

What it does

Documenso Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement security best practices for Documenso document signing integrations. Use when securing API keys, configuring webhooks securely, or implementing document security measures. Trigger with phrases like "documenso security", "secure documenso", "documenso API key security", "documenso webhook security".

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation-guide.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Webhooks and Authorization and RBAC. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Securing API keys
  • Configuring webhooks securely
  • Implementing document security measures
  • With phrases like documenso security

Example prompts

  • “documenso security”
  • “secure documenso”
  • “documenso API key security”
  • “/documenso-security-basics”

Requirements

  • Python 3
  • Docker
  • A credential in DOCUMENSO_API_KEY
  • A credential in DOCUMENSO_WEBHOOK_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. API Key Security
  2. Key Rotation with Zero Downtime
  3. Webhook Secret Verification
  4. Document Access Control
  5. Signing Certificate Security (Self-Hosted)
  6. Self-Hosted Production Secrets

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.documenso.com
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DOCUMENSO_WEBHOOK_SECRET
    • DOCUMENSO_API_KEY
    • NEXTAUTH_SECRET
    • NEXT_PRIVATE_ENCRYPTION_KEY
    • NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Documenso Security Basics loads about 1.7k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:61
    - Store in `.env` (never committed) or a secrets manager (Vault, AWS Secrets Manager)
  • NoteMentions a .env fileSKILL.md:68
    .env
  • NoteMentions a .env fileSKILL.md:69
    .env.*
  • NoteMentions a .env fileSKILL.md:178
    - [ ] `.env` in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 352 words, ~1,651 tokens.

Download SKILL.mdSave it as .claude/skills/documenso-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
documenso-security-basics
description
Implement security best practices for Documenso document signing integrations. Use when securing API keys, configuring webhooks securely, or implementing document security measures. Trigger with phrases like "documenso security", "secure documenso", "documenso API key security", "documenso webhook security".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.14.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, documenso, api, security, webhooks

Documenso Security Basics

Output

  • A least-privilege Documenso configuration with scoped secrets, signer/document access controls, and an incident/revocation path.
  • A tested boundary for document authorization, webhook validation, and safe audit logging.

Examples

Create a development document with a synthetic signer, validate that only its intended role can view or act on it, and verify any webhook signature before processing. If a token, signing URL, or document is exposed, revoke/contain access and follow the incident procedure before attempting cleanup.

Overview

Essential security practices for Documenso integrations: API key management, webhook verification, document access control, and self-hosted signing certificate configuration.

Prerequisites

  • Documenso account with API access
  • Understanding of environment variables and secret management
  • Completed documenso-install-auth setup

Instructions

Step 1: API Key Security
typescript
// NEVER hardcode keys
const BAD = new Documenso({ apiKey: "api_abc123..." }); // Exposed in source

// ALWAYS use environment variables
const GOOD = new Documenso({ apiKey: process.env.DOCUMENSO_API_KEY! });

Key management rules:

  • Store in .env (never committed) or a secrets manager (Vault, AWS Secrets Manager)
  • Use team-scoped keys for team resources, personal keys for personal documents
  • Rotate keys on employee offboarding -- revoke in dashboard immediately
  • CI/CD: use masked/encrypted secrets (GitHub Secrets, GitLab CI variables)
bash
# .gitignore — always include
.env
.env.*
!.env.example
Step 2: Key Rotation with Zero Downtime
typescript
// Support dual keys during rotation
function getApiKey(): string {
  // Try primary first, fall back to secondary during rotation
  return process.env.DOCUMENSO_API_KEY_PRIMARY
    ?? process.env.DOCUMENSO_API_KEY_SECONDARY
    ?? (() => { throw new Error("No Documenso API key configured"); })();
}

// Rotation procedure:
// 1. Generate new key in Documenso dashboard
// 2. Set as DOCUMENSO_API_KEY_SECONDARY, deploy
// 3. Verify secondary key works
// 4. Move secondary to PRIMARY, deploy
// 5. Revoke old key in dashboard
Step 3: Webhook Secret Verification
typescript
import { timingSafeEqual } from "crypto";

function verifyWebhookSecret(req: Request): boolean {
  const received = req.headers["x-documenso-secret"] as string;
  const expected = process.env.DOCUMENSO_WEBHOOK_SECRET!;

  if (!received || !expected) return false;

  // Use constant-time comparison to prevent timing attacks
  return timingSafeEqual(
    Buffer.from(received, "utf8"),
    Buffer.from(expected, "utf8")
  );
}
python
# Python equivalent
import hmac, os
from flask import request

def verify_webhook(req):
    received = req.headers.get("X-Documenso-Secret", "")
    expected = os.environ["DOCUMENSO_WEBHOOK_SECRET"]
    return hmac.compare_digest(received, expected)
Step 4: Document Access Control
typescript
// Principle of least privilege with API keys
// Personal keys: only YOUR documents
// Team keys: all documents in the team

// Restrict document access by checking ownership
async function getDocumentSecure(documentId: number, userId: string) {
  const doc = await client.documents.getV0(documentId);

  // Verify the requesting user is the owner or a recipient
  const isOwner = doc.userId === parseInt(userId);
  const isRecipient = doc.recipients?.some(r => r.email === userEmail);

  if (!isOwner && !isRecipient) {
    throw new Error("Access denied: not authorized for this document");
  }

  return doc;
}
Step 5: Signing Certificate Security (Self-Hosted)

Self-hosted Documenso requires a .p12 signing certificate for legally valid digital signatures.

bash
# Generate a self-signed certificate (development only)
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes
openssl pkcs12 -export -out signing-cert.p12 -inkey key.pem -in cert.pem

# Mount into Docker container
docker run -v $(pwd)/signing-cert.p12:/opt/documenso/cert.p12 \
  -e NEXT_PRIVATE_SIGNING_LOCAL_FILE_PATH=/opt/documenso/cert.p12 \
  -e NEXT_PRIVATE_SIGNING_PASSPHRASE=your-passphrase \
  documenso/documenso:latest

For production, use a certificate from a trusted CA (e.g., GlobalSign, DigiCert).

Show full SKILL.md (141 more words)Show less
Step 6: Self-Hosted Production Secrets
bash
# Generate cryptographically secure secrets
openssl rand -hex 32  # NEXTAUTH_SECRET
openssl rand -hex 32  # NEXT_PRIVATE_ENCRYPTION_KEY
openssl rand -hex 32  # NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEY

# Never reuse secrets across environments
# Never use default values in production

Security Checklist

  • API key stored in environment variable, never in source code
  • .env in .gitignore
  • CI secrets use masked/encrypted storage
  • Team keys rotated on employee offboarding
  • Webhook secret uses constant-time comparison
  • Self-hosted: HTTPS with valid TLS certificates
  • Self-hosted: signing certificate from trusted CA
  • Self-hosted: secrets generated with openssl rand -hex 32
  • No API keys or secrets in logs (sanitize before logging)
  • Key rotation procedure documented and tested

Error Handling

Security IssueIndicatorResponse
Invalid API key401 errorsRotate key immediately
Webhook spoofingInvalid secret headerReject request, alert team
Key exposed in gitGitHub secret scanning alertRevoke key, rotate, audit access
Brute forceMany 401s from same IPRate limit by IP at reverse proxy

Resources

Next Steps

For production deployment, see documenso-prod-checklist.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/documenso-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/implementation-guide.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Documenso Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Documenso Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Documenso Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: NotesMIT
API Route Patternsbybren-llc/safe-agentic-workflow423—~1.6kAutomated safety check: PassMIT
Workosusenotra/notra256—~6.2kAutomated safety check: PassAGPL-3.0
Sap Btp Build Work Zone Advancedsecondsky/sap-skills462—~3.3kAutomated safety check: PassGPL-3.0
Sec Checkwaynesutton/markdown-site627—~753Automated safety check: PassMIT
Security Threat Modelmajiayu000/spellbook287—~561Automated safety check: PassMIT

Similar skills

  • API Route Patterns

    bybren-llc/safe-agentic-workflow

    API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding server-side…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    256 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Develops and administers SAP Build Work Zone, advanced edition digital workplace solutions.

    462 GitHub stars~3.3k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    627 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Security Threat Model

    majiayu000/spellbook

    Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

    287 GitHub stars~561 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Phx Plan

    oliver-kriska/claude-elixir-phoenix

    Plan features spanning multiple domains: billing (Stripe), auth (RBAC), real-time (Presence), webhooks, jobs (Oban).

    565 GitHub stars~1.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Documenso Security Basics

What does Documenso Security Basics do?

Implement security best practices for Documenso document signing integrations. Documenso Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement security best practices for Documenso document signing integrations.

When should I use Documenso Security Basics?

Documenso Security Basics fits situations like: securing API keys; configuring webhooks securely; implementing document security measures; with phrases like documenso security.

How do I install Documenso Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill documenso-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/documenso-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/documenso-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Documenso Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill documenso-security-basics -a codex`. Or copy the skill folder (skills/.curated/documenso-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/documenso-security-basics in your project. Codex loads it when a task matches its description.

Can I use Documenso Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill documenso-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/documenso-security-basics, .gemini/skills/documenso-security-basics, .github/skills/documenso-security-basics and .opencode/skills/documenso-security-basics in your project.

What does Documenso Security Basics need to run?

Going by SKILL.md and its folder, Documenso Security Basics needs the command-line tools its instructions call (openssl and docker) and credentials named DOCUMENSO_WEBHOOK_SECRET, DOCUMENSO_API_KEY, NEXTAUTH_SECRET and NEXT_PRIVATE_ENCRYPTION_KEY. Our summary lists: Python 3; Docker; A credential in DOCUMENSO_API_KEY; A credential in DOCUMENSO_WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Documenso Security Basics access the network?

SKILL.md names 2 domains. As links in the text: docs.documenso.com and owasp.org. This is read from the text; nothing was executed.

Is Documenso Security Basics safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Documenso Security Basics use?

Documenso Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Documenso Security Basics use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Documenso Security Basics?

Skills that share tags, products or a category with Documenso Security Basics: API Route Patterns (bybren-llc/safe-agentic-workflow, 423 stars), Workos (usenotra/notra, 256 stars), Sap Btp Build Work Zone Advanced (secondsky/sap-skills, 462 stars) and Sec Check (waynesutton/markdown-site, 627 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Documenso Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.