What is it?
OpenSign is a web app for getting PDFs signed, billed by its repository as "the free and open source alternative to DocuSign". The front end is React; the server is Node.js on Parse Server and MongoDB. You upload a PDF or a DOCX, drop fields on it (signature, initials, stamp, date, checkbox and so on), and each recipient gets an email link to sign in the browser. Once the last one has signed, the server seals the PDF with the instance's certificate and produces a completion certificate, itself signed, with the document's SHA-256 hash and, for each signer, their email, IP address, and the times they viewed and signed.
Documenso covers the same flow in TypeScript on PostgreSQL, and DocuSeal in Ruby on Rails. To write the signature into the PDF, OpenSign relies on @signpdf, a Node.js library.
The open source e-signature comparison sets the signature OpenSign applies, and what its paid plans hold back, against the other tools.
Why is it interesting?
- Signers without an account: the sender can require a one-time code, sent by email, before signing, and enforce a strict order in which nobody can sign until everyone before them has.
- Several ways to sign: draw by hand, upload an image, type a name or reuse a saved signature. Documents can expire after a set number of days, and a signer can decline with a reason that goes back to the sender.
- DOCX uploads: the server's Docker image ships LibreOffice, which converts the file to PDF. A self-hosted instance takes files up to 80 MB, against 10 MB on the cloud.
- Multiple users on your own instance: user management, which the cloud keeps for its Teams and Enterprise plans, is part of the self-hosted version.
- Templates, folders and emails: reusable templates, a document store called "OpenSign Drive", an editor for invitation and completion emails, and a page that reads the signatures in any PDF you drop on it.
- French interface, one of seven UI languages.
Good to know
The default configuration ships a public, expired certificate. The README's install command copies the repo's .env.local_dev to .env.prod. That file already holds, in PFX_BASE64, a self-signed certificate issued to OpenSign Labs, expired since 16 November 2024, along with its passphrase, opensign, so anyone who reads the repo has its private key. Until you replace that variable, your instance signs with it. For Acrobat's green tick, the docs point to a certificate bought from an authority on the Adobe Approved Trust List. The same file sets Parse Server's MASTER_KEY, which grants access to all data, and the docs warn that MongoDB runs without authentication, so its port must stay off the internet.
A CMS signature with no timestamp. OpenSign keeps @signpdf's default subfilter, adbe.pkcs7.detached, which makes it a CMS signature rather than PAdES. The signing time comes from the server's clock; the public code calls no timestamp authority. The signature is applied once, under the name "OpenSign", and the signers only appear in its reason field and in the completion certificate. OpenSign says it complies with the ESIGN Act, UETA and the EU's eIDAS regulation, without saying which eIDAS level its signature reaches.
The API and webhooks live in the paid cloud. The docs cover a REST API in three versions (v1, v1.1, v1.2) and webhooks. A "Live" API token or webhook requires the Professional or Teams plan, and every document created through the API uses up credits. The public code implements neither that API nor webhook delivery. The free cloud tier has no signature limit, and a custom subdomain is an Enterprise feature.
AGPL-3.0, except for one directory. The LICENSE file puts the repo under AGPL-3.0, except for apps/OpenSignServer/cloud/customRoute (DOCX conversion, decrypting protected PDFs, account deletion), which falls under "the license defined" in that directory. There is none there. GitHub doesn't recognise a licence and shows NOASSERTION.
A public repo fed from a private edition. OpenSign has published 83 releases since November 2023, 11 of them in 2026. The latest, 2.41.3, came out on 21 August 2026, and nothing has been pushed since. Its recent merges come from sync-to-public_repo branches on the nxglabs account, and the 2.39.0 notes link to nxglabs/OpenSign-Enterprise, a repository that isn't public. The release notes describe that edition as well: the per-recipient access code announced in 2.41.0 isn't in the public code, and a comment in the server code says the approver role only counts in the "EE" build.
