generated: '2026-07-19' method: searched source: https://sign.dropbox.com/products/api standards: - id: oauth2 conforms: true evidence: OpenAPI declares an oauth2 bearer scheme; OAuth authorize/token flow documented with 7 scopes. - id: rfc9457-problem-details conforms: false evidence: Errors use a custom {error:{error_name,error_msg,error_path}} envelope, not application/problem+json. - id: webhooks conforms: true evidence: Account- and app-level callbacks (23 event types) delivered as multipart/form-data POST with HMAC event_hash. - id: pagination conforms: true evidence: page/page_size params with a list_info response container across list endpoints. - id: eidas conforms: true evidence: eID / QES signing guides; e-signatures documented as legally binding in the EU/UK. - id: esign-ueta conforms: true evidence: Electronic signatures documented as legally binding in the United States (ESIGN/UETA). compliance_program: published: true source: https://sign.dropbox.com/trust certifications: - HIPAA - ISO 9001 - "SOC (CPA/AICPA attestation)" - Skyhigh Enterprise-Ready note: >- Certification badges published on the Dropbox Sign API product page and the Dropbox Sign Trust Center (security/hellosign-trust-center.yml). SOC 2 / ISO 27001 are held at the Dropbox parent level.