Skip to content

Self-host Documenso

updated Sep 2026prices checked · Jul 2026
We earn commissions when you shop through the links below. Full disclosure →

A self-hosted DocuSign alternative: upload a PDF, place signature and form fields, send it to signers by email or a direct link, and get back a PDF sealed with your own signing certificate plus an audit log.

Key facts

CategoryE-signature
LicenseAGPL-3.0
StackTypeScript, React Router, Hono
Min RAM2048 MB
Official imageyes
Difficulty
Our recommendation

Pick Documenso when you want a self-hosted DocuSign alternative whose free edition keeps the features other tools charge for: templates, direct signing links, signing order, the REST API, webhooks and API tokens, plus embedded signing (React, Vue, Angular, Svelte, Solid and Preact SDKs), signing reminders and custom branding as admin toggles. It is TypeScript (React Router and Hono, with Prisma on PostgreSQL 14+), AGPL-3.0 except for `packages/ee/`, and the production install is upstream's Docker Compose file with the app and PostgreSQL. You supply the signing certificate, SMTP and a TLS reverse proxy. Upstream's minimum is 1 GB of RAM for testing and 2 GB for production. If you want the fastest possible install instead, DocuSeal is the catalog's other e-signature tool.

What you need

  • Any VPS with at least 2048 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • About an afternoon — budget time for troubleshooting
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Documenso — upstream's production Docker Compose (app + PostgreSQL), per docs.documenso.com/docs/self-hosting/deployment/docker-compose
mkdir documenso && cd documenso
curl -O https://raw.githubusercontent.com/documenso/documenso/v2.18.0/docker/production/compose.yml
sed -i 's|documenso/documenso:latest|documenso/documenso:v2.18.0|' compose.yml
# signing certificate: Documenso ships none, and signing fails without one. The .p12 must have a password
openssl genrsa -out private.key 2048
openssl req -new -x509 -key private.key -out certificate.crt -days 365
openssl pkcs12 -export -out certificate.p12 -inkey private.key -in certificate.crt
sudo mkdir -p /opt/documenso && sudo cp certificate.p12 /opt/documenso/cert.p12
sudo chown 1001:1001 /opt/documenso/cert.p12 && sudo chmod 400 /opt/documenso/cert.p12
PGPASS=$(openssl rand -hex 24)
cat > .env <<EOF
POSTGRES_USER=documenso
POSTGRES_PASSWORD=$PGPASS
POSTGRES_DB=documenso
NEXT_PRIVATE_DATABASE_URL=postgresql://documenso:$PGPASS@database:5432/documenso
NEXTAUTH_SECRET=$(openssl rand -base64 32)
NEXT_PRIVATE_ENCRYPTION_KEY=$(openssl rand -base64 32)
NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEY=$(openssl rand -base64 32)
NEXT_PUBLIC_WEBAPP_URL=https://sign.example.com
NEXT_PRIVATE_SIGNING_PASSPHRASE=the-p12-password-you-set
NEXT_PRIVATE_SMTP_TRANSPORT=smtp-auth
NEXT_PRIVATE_SMTP_HOST=smtp.example.com
NEXT_PRIVATE_SMTP_PORT=587
NEXT_PRIVATE_SMTP_USERNAME=your-smtp-username
NEXT_PRIVATE_SMTP_PASSWORD=your-smtp-password
NEXT_PRIVATE_SMTP_FROM_NAME=Documenso
NEXT_PRIVATE_SMTP_FROM_ADDRESS=noreply@example.com
EOF
docker compose --env-file .env up -d
# app listens on :3000 — put a TLS reverse proxy in front. Signups create regular users; grant ADMIN in the database, then set NEXT_PUBLIC_DISABLE_SIGNUP=true

What you take on

Documenso's own self-hosting docs list what a Compose install leaves to you:

non-negotiableDocumenso ships no signing certificate. Upstream says that without one "the application starts normally but all document signing will fail". Generate a .p12 with OpenSSL and give it a password (a passwordless one fails with "Failed to get private key bags"). Put it at /opt/documenso/cert.p12, owned by UID 1001 with mode 400, and set NEXT_PRIVATE_SIGNING_PASSPHRASE. Keep it outside the container. A self-signed certificate shows as unverified in Adobe Acrobat; for Acrobat's green checkmark you need a certificate from an Adobe Approved Trust List vendor.
non-negotiableSignups create regular users, and there is no first-user-is-admin rule. Grant ADMIN by updating the user's roles in PostgreSQL. Then set NEXT_PUBLIC_DISABLE_SIGNUP=true, since the compose default leaves signup open. SMTP is required: without it, recipients never receive signing requests.
non-negotiableUpstream's compose.yml uses documenso/documenso:latest, and the docs warn that the file "may be outdated" against the documented variables. Pin a release tag such as v2.18.0. Migrations run automatically when the container starts, so back up PostgreSQL before docker compose pull. Documents are stored in PostgreSQL by default; upstream recommends S3-compatible storage for larger volumes.
non-negotiableCode in packages/ee/ is under a commercial licence and needs an Enterprise subscription in production. That covers the organisation SSO portal (SAML and OIDC), passkey and 2FA re-authentication for document actions, 21 CFR Part 11, HIPAA mode, custom email domains, the embedded editor and QES signing through a CSC trust provider. Enterprise pricing is only available from sales.
non-negotiableDocumenso's compliance page lists ESIGN, UETA and eIDAS simple signatures as compliant and eIDAS advanced and qualified as planned. It adds that the validity of simple signatures "depends on the specific transaction and jurisdiction". Check the rules for your document types before relying on it.

An alternative to

Head-to-head

More self-hosted tools

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.