# Documenso: self-hosting the AGPL document signing stack

> Documenso is the AGPL-3.0 TypeScript application that positions itself as the open source DocuSign alternative. It runs as a Docker-backed monorepo, and the interesting question is not whether it signs PDFs but who should be running it.

**documenso/documenso** — The Open Source DocuSign Alternative.

- Repository: https://github.com/documenso/documenso
- Website: https://documenso.com
- Stars: 15,191 · Forks: 3,273
- Language: TypeScript
- License: AGPL-3.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/documenso-documenso

## The trust problem Documenso is aimed at

Every electronic signature adds a third party to the transaction. The document leaves your systems, passes through a vendor's infrastructure, and comes back with a certificate you cannot inspect. Documenso's README frames this directly: signing digitally "should be the best practice for every document signed worldwide", and the project argues that the signing provider becomes a party to every signature. Its stated answer is to let you self-host and read the code.

The audience follows from that. This is not aimed at someone who wants a free DocuSign account. It is aimed at engineering and compliance teams who are willing to operate a Postgres database, an S3-compatible store and a mail server in exchange for holding the signing keys and the audit trail themselves. The README also points to a hosted option at documenso.com, so the project serves both a self-hoster and a buyer who wants the same code managed for them.

## What the monorepo actually contains

The repository is an npm workspace monorepo. The root package.json declares workspaces for apps/* and packages/*, and the root package is named @documenso/root at version 2.18.0. Recent releases are tagged v2.17.0, v2.16.0 and v2.15.0, with the last push to main on 2026-08-19.

The stack is TypeScript end to end. React Router v7 handles the framework layer, Hono is the server, Prisma is the ORM, and tRPC carries the API. PDF work is split across three libraries: @libpdf/core for signatures, pdf.js for viewing, and @cantoo/pdf-lib for manipulation. Email templates use react-email, internationalisation uses Lingui, and Stripe handles payments. Biome does linting and formatting, Playwright does end-to-end testing.

Two repository files are worth reading before the code. ARCHITECTURE.md and SIGNING.md sit at the top level, and both are more likely to answer a design question than the README, which is mostly a quickstart.

## Running Documenso locally with npm run dx

The README documents a developer quickstart that assumes Docker and docker-compose are installed. Node.js v22 or above and a Postgres database are the stated requirements. The first step is to fork the repository and clone your fork, then create the environment file. The project ships a .env.example with what the README calls handpicked defaults, so copying it is the intended starting point.

```bash
cp .env.example .env
```

The .env.example sets NEXT_PUBLIC_WEBAPP_URL and NEXT_PRIVATE_INTERNAL_WEBAPP_URL to http://localhost:3000, PORT to 3000, and NEXTAUTH_SECRET to the literal string "secret". Two crypto variables are marked REQUIRED and must be random strings of at least 32 characters: NEXT_PRIVATE_ENCRYPTION_KEY and NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEY. The file ships them as "CAFEBABE" and "DEADBEEF", which are placeholders, not usable keys.

With the environment in place, the quickstart runs a single command from the repository root. According to the package.json scripts, dx chains npm ci, the Docker compose stack, Prisma migrations and seeding.

```bash
npm run dx
```

The compose file at docker/development/compose.yml brings up Postgres and an inbucket mailserver. The README lists the access points you should see afterwards: the app on port 3000, incoming mail on port 9000, the database on port 54320, and an S3 storage dashboard on port 9001. Start the development server next.

```bash
npm run dev
```

The README notes a shorter alias, npm run d, which runs dx, compiles translations and starts the dev server in one step. The dev script itself runs npm run translate:compile before turbo run dev --filter=@documenso/remix, so a missing Lingui compile step is not something you have to remember.

## Docker images, deployment and the environment surface

For anything past local development, the README points to official images on DockerHub and the GitHub Container Registry under the documenso organisation. The repository also carries railway.toml and render.yaml, which indicates the maintainers keep deployment configuration for those two platforms in tree.

The environment file is where the real operational cost lives. Beyond the database and crypto keys, .env.example exposes optional Google and Microsoft OAuth credentials, a generic OIDC block with NEXT_PRIVATE_OIDC_WELL_KNOWN, NEXT_PRIVATE_OIDC_CLIENT_ID, NEXT_PRIVATE_OIDC_CLIENT_SECRET, NEXT_PRIVATE_OIDC_PROVIDER_LABEL, NEXT_PRIVATE_OIDC_SKIP_VERIFY and NEXT_PRIVATE_OIDC_PROMPT, and a webhook setting called NEXT_PRIVATE_WEBHOOK_SSRF_BYPASS_HOSTS. That last one is a comma-separated list of hostnames or IPs whose webhooks are allowed to resolve to private or loopback addresses. Leaving it empty is the safe default; populating it widens what your instance will call.

There is also NEXT_PRIVATE_DOCUMENSO_LICENSE_KEY, described as the key that enables enterprise features for self-hosters. The README does not enumerate which features sit behind that key, so a self-hoster evaluating the project should treat the free and enterprise boundary as unconfirmed until they check the documentation site.

## Where Documenso is the wrong choice

The contribution model is the sharpest constraint. The README states plainly that external pull requests are no longer accepted, aside from a small group of trusted contributors the maintainers reach out to directly, and links to a blog post explaining the decision. The project remains open source in the sense that you can read, audit, run and fork it, and the README says exactly that. But if your organisation's policy is to upstream a fix and wait for a release, that path is closed. You patch your fork or you open an issue and wait.

Operationally, the project asks you to run a database, an object store and mail delivery. That is a real burden for a team that signs a handful of documents a month, and a hosted plan at documenso.com exists for exactly that case. The AGPL-3.0 licence is the second constraint. It is a strong copyleft licence, and if you modify Documenso and let users interact with it over a network, the licence's source-availability obligation is the thing your legal team needs to read. This article cannot give you legal advice; read LICENSE and CLA.md in the repository and route the question to counsel.

A third boundary is signature law. The README makes no claim about which jurisdictions accept which signature types, and nothing in the repository describes a qualified or advanced electronic signature scheme. If your use case requires a specific regulatory tier, that requirement has to be checked against the documentation before you build on it.

## Documenso against DocuSeal and DocuSign

The comparison people reach for is DocuSeal, and the difference is architectural rather than cosmetic. Documenso is a TypeScript monorepo built on React Router v7, Hono, Prisma and tRPC, with PDF work delegated to @libpdf/core, pdf.js and @cantoo/pdf-lib. A Ruby or Rails signing tool will have a different deployment shape, a different plugin story and a different hiring pool. If your team already runs Node and Prisma, Documenso fits an existing operational model; if it does not, you are adding a runtime your team does not otherwise maintain.

Against DocuSign the split is custody, not features. DocuSign is a managed service where the vendor holds the signing infrastructure and you consume an API. Documenso inverts that: you hold the database, the encryption keys and the storage bucket, and you carry the uptime. The trade is control for operational responsibility, and the README's own framing, that trust is built by letting you self-host and review how it works under the hood, is the honest statement of which side of that trade the project is on.

## Conclusion

Adopt Documenso if you need signing infrastructure you can read, audit and fork under AGPL-3.0, and if you are comfortable running Postgres, S3-compatible storage and the NextAuth secret yourself. Do not adopt it if you depend on outside contributors landing fixes, because the README states external pull requests are no longer accepted except from a small group of trusted contributors. Before committing, verify three things in your own environment: that NEXT_PRIVATE_ENCRYPTION_KEY and NEXT_PRIVATE_ENCRYPTION_SECONDARY_KEY are set to random strings of at least 32 characters, that your outbound webhook targets are reachable without the SSRF bypass variable, and that the enterprise licence key path is not required for the features you actually need.

## FAQ

### Is Documenso free?

The source is published under AGPL-3.0 and can be self-hosted at no licence cost. The .env.example also defines NEXT_PRIVATE_DOCUMENSO_LICENSE_KEY, described as the key that enables enterprise features for self-hosters, so some capabilities sit behind a paid key. The README does not list which ones.

### Is Documenso open source?

Yes. The repository is licensed AGPL-3.0 and the README states that you can read, audit, run and fork the code. Note that the project no longer accepts external pull requests except from a small group of trusted contributors.

### How to install Documenso?

The README's developer quickstart needs Node.js v22 or above, a Postgres database and optionally Docker. Copy .env.example to .env, run npm run dx to start Postgres and the inbucket mailserver and apply Prisma migrations, then run npm run dev. The app is then reachable at http://localhost:3000.

### How to use Documenso?

The README describes two routes: self-host it following the quickstart or the manual setup guide, or sign up at documenso.com. Local development exposes the app on port 3000, incoming mail on port 9000 and an S3 storage dashboard on port 9001. The README does not walk through the signing workflow itself and defers to docs.documenso.com.

### Is Documenso legit?

It is a real, actively released project: version 2.18.0 in the root package.json, with v2.17.0, v2.16.0 and v2.15.0 as recent tags and the last push to main on 2026-08-19. The README links a company website, documentation, a Discord server and a roadmap. Legitimacy for your compliance purposes is a separate question the repository cannot answer.

### What is Documenso?

Documenso is a document signing application written in TypeScript and licensed AGPL-3.0, described in its README as the open source DocuSign alternative. It is built as an npm workspace monorepo with React Router v7, Hono, Prisma and tRPC, and can be self-hosted or used through documenso.com.

## Sources

- [Official documentation](https://documenso.com)
- [Official README](https://github.com/documenso/documenso#readme)
- [Project repository](https://github.com/documenso/documenso)
- [Release notes](https://github.com/documenso/documenso/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/documenso-documenso
