We earn commissions when you shop through the links below. Full disclosure →
A self-hosted DocuSign alternative: upload a PDF, place signature and form fields, send it to signers by email or a direct link, and get back a PDF sealed with your own signing certificate plus an audit log.
Pick Documenso when you want a self-hosted DocuSign alternative whose free edition keeps the features other tools charge for: templates, direct signing links, signing order, the REST API, webhooks and API tokens, plus embedded signing (React, Vue, Angular, Svelte, Solid and Preact SDKs), signing reminders and custom branding as admin toggles. It is TypeScript (React Router and Hono, with Prisma on PostgreSQL 14+), AGPL-3.0 except for `packages/ee/`, and the production install is upstream's Docker Compose file with the app and PostgreSQL. You supply the signing certificate, SMTP and a TLS reverse proxy. Upstream's minimum is 1 GB of RAM for testing and 2 GB for production. If you want the fastest possible install instead, DocuSeal is the catalog's other e-signature tool.
What you need
Any VPS with at least 2048 MB of RAM
A domain you control — most self-hosted setups need HTTPS in front of them
About an afternoon — budget time for troubleshooting
Documenso's own self-hosting docs list what a Compose install leaves to you:
non-negotiableDocumenso ships no signing certificate. Upstream says that without one "the application starts normally but all document signing will fail". Generate a .p12 with OpenSSL and give it a password (a passwordless one fails with "Failed to get private key bags"). Put it at /opt/documenso/cert.p12, owned by UID 1001 with mode 400, and set NEXT_PRIVATE_SIGNING_PASSPHRASE. Keep it outside the container. A self-signed certificate shows as unverified in Adobe Acrobat; for Acrobat's green checkmark you need a certificate from an Adobe Approved Trust List vendor.
non-negotiableSignups create regular users, and there is no first-user-is-admin rule. Grant ADMIN by updating the user's roles in PostgreSQL. Then set NEXT_PUBLIC_DISABLE_SIGNUP=true, since the compose default leaves signup open. SMTP is required: without it, recipients never receive signing requests.
non-negotiableUpstream's compose.yml uses documenso/documenso:latest, and the docs warn that the file "may be outdated" against the documented variables. Pin a release tag such as v2.18.0. Migrations run automatically when the container starts, so back up PostgreSQL before docker compose pull. Documents are stored in PostgreSQL by default; upstream recommends S3-compatible storage for larger volumes.
non-negotiableCode in packages/ee/ is under a commercial licence and needs an Enterprise subscription in production. That covers the organisation SSO portal (SAML and OIDC), passkey and 2FA re-authentication for document actions, 21 CFR Part 11, HIPAA mode, custom email domains, the embedded editor and QES signing through a CSC trust provider. Enterprise pricing is only available from sales.
non-negotiableDocumenso's compliance page lists ESIGN, UETA and eIDAS simple signatures as compliant and eIDAS advanced and qualified as planned. It adds that the validity of simple signatures "depends on the specific transaction and jurisdiction". Check the rules for your document types before relying on it.