# DocSend > DocSend is a secure document sharing and analytics platform, part of Dropbox since 2021, used to share pitch decks, sales collateral and fundraising materials with page-by-page viewer tracking, granular access controls, virtual data rooms (Spaces) and eSignature. DocSend publishes no public REST API and no OpenAPI. Its one programmatic surface is a hosted, OAuth-gated Model Context Protocol (MCP) server at https://docsend.com/mcp, discoverable through RFC 8414 authorization-server metadata and RFC 9728 protected-resource metadata. Generated by the API Evangelist enrichment pipeline from live probes of DocSend's discovery surface and from the artifacts harvested into this repository. DocSend publishes no /llms.txt of its own (HTTP 404 on every host). ## Agent access - [DocSend MCP server](https://docsend.com/mcp): Hosted Streamable-HTTP MCP endpoint. OAuth 2.0 bearer required — anonymous `initialize` and `tools/list` both return HTTP 401. Also reachable at https://mcp.docsend.com/mcp. - [Protected resource metadata](https://docsend.com/.well-known/oauth-protected-resource/mcp): RFC 9728 — resource `https://docsend.com/mcp`, authorization server `https://docsend.com`, bearer in header. - [Authorization server metadata](https://docsend.com/.well-known/oauth-authorization-server): RFC 8414 — authorize / token / register / revoke, PKCE S256 mandatory, dynamic client registration (RFC 7591), public clients (`token_endpoint_auth_methods_supported: ["none"]`). ## Scopes DocSend advertises five resource-scoped OAuth scopes. Only Spaces is writable. - `documents:read` — documents and the links that share them - `spaces:read` — Spaces (virtual data rooms) and their contents - `spaces:write` — write access to Spaces - `analytics:read` — viewer and page-by-page engagement analytics - `contacts:read` — contacts / visitors captured against shared links The tool list itself is auth-gated and could not be enumerated, and DocSend publishes no MCP tool documentation, so an agent must discover the tools after authorizing. ## What does not exist Recording absences so an agent does not go looking: - No public REST API, no OpenAPI/Swagger document on any DocSend host. - No developer portal, no API reference, no getting-started guide. - No first-party SDK in any registry; the github.com/docsend org holds only dependency forks. - No A2A agent card (`/.well-known/agent-card.json` and `/.well-known/agent.json` both 404). - No security.txt on docsend.com; no OIDC discovery; no `/.well-known/api-catalog`. - No published rate limits, and no rate-limit headers on the wire. - No direct webhooks — DocSend's seven events reach developers only via its Zapier app. ## Artifacts - [MCP server profile](mcp/docsend-mcp.yml): endpoint, transport, deployment mode, OAuth requirements - [Authentication profile](authentication/docsend-authentication.yml): OAuth 2.0 flows, DCR, PKCE, protected-resource metadata - [OAuth scopes](scopes/docsend-scopes.yml): the five resource scopes and what each covers - [Well-known index](well-known/docsend-well-known.yml): the full /.well-known probe surface, plus the robots.txt sitemap defect - [Conformance](conformance/docsend-conformance.yml): OAuth2, RFC 8414, RFC 9728, RFC 7591, PKCE, MCP, SOC 2, ISO 27001 - [Plans and pricing](plans/docsend-plans-pricing.yml): Standard $30/user/mo, Advanced $150/mo, Advanced Data Rooms $180/mo - [Rate limits](rate-limits/docsend-rate-limits.yml): none published, none observed - [Lifecycle](lifecycle/docsend-lifecycle.yml): status via the Dropbox status page (named DocSend component); no deprecation policy - [Packages](packages/docsend-packages.yml): no first-party SDK anywhere - [Event surface](asyncapi/docsend-events.yml): seven events, Zapier-only delivery - [Trust center](security/docsend-trust-center.yml): SOC 1/2/3, ISO/IEC 27001/27017/27018/27701, PCI DSS, HIPAA, CSA STAR L2, GDPR - [Vulnerability disclosure](security/docsend-vulnerability-disclosure.yml): Dropbox Intigriti program (parent brand) - [Domain security](security/docsend-domain-security.yml): TLS/HSTS/SPF/DMARC probes ## Links - [DocSend](https://www.docsend.com/) - [Pricing](https://www.docsend.com/pricing/) - [Help Center](https://help.docsend.com/hc/en-us) - [Trust Center](https://www.docsend.com/trust-center/) - [Terms of Service](https://www.docsend.com/terms-of-service/) - [Privacy Policy](https://www.docsend.com/privacy-policy) - [Integrations](https://www.docsend.com/integrations/) - [Blog](https://www.docsend.com/blog) - [Status (Dropbox, DocSend component)](https://status.dropbox.com/) - [GitHub organization](https://github.com/docsend)