Integrate DocuSign with UserLock Single Sign-On

Allow your users to access DocuSign with their corporate credentials through UserLock SSO, while ensuring every signature request follows your security policies.

Published September 26, 2025

Introduction

This guide explains how to integrate DocuSign with UserLock Single Sign-On (SSO) using the SAML 2.0 protocol.

Once integrated, DocuSign logins are authenticated by UserLock against Active Directory. This provides a smooth sign-in experience for users and allows administrators to enforce UserLock access policies (MFA, time, machine, or location restrictions) on SSO sessions.

🚩️ Before starting:

Step 1. Configure DocuSign (Service Provider)

  1. Open the DocuSign Admin console:

    • In the eSignature console, go to Settings.

    • Click SWITCH TO, then select DOCUSIGN ADMIN.

  2. In the top menu, click Identity Providers.

  3. Click ADD IDENTITY PROVIDER.

  4. Enter the following values, using your UserLock SSO URL (visible in UserLock console ▸⚙️ Server settings ▸ Single Sign-On).

    Example with https://sso.contoso.com

  5. Save the settings.

  6. Add a certificate:

    • Go to UserLock console ▸ ⚙️ Server settings ▸ Single Sign-On

    • Click on Download ▸ SAML certificate.

    • In DocuSign Admin, click Add certificate and upload the file.

Step 2. Configure DocuSign in UserLoc

  1. In the UserLock console, go to ⚙️ Server settings ▸ Single Sign-On.

  2. Click on the DocuSign row.

  3. Fill in the fields with information from DocuSign Admin:

    Settings

    Values

    Email domain

    The domain used for DocuSign logins (e.g. contoso.com).

    Issuer

    Available in DocuSign Admin ▸ Identity Providers ▸ Endpoints (Actions menu).

    ACS URL

    Available in the same Endpoints section.

    Certificate

    In DocuSign Admin ▸ Identity Providers, open the Endpoints view (Actions ▸ Endpoints) and download the metadata. Copy the X.509 certificate from this metadata file and paste it here.

  4. Save the profile.

Update the SAML certificate in DocuSign

When you renew the SAML certificate in UserLock (see Renew the SAML certificate), you must also update the configuration in DocuSign:

  1. In the UserLock console, go to ⚙️ Server settings ▸ Single Sign-On.

  2. Click Download ▸ SAML certificate and save the file.

  3. Open the certificate in a text editor (Notepad) and copy the full contents.

  4. In DocuSign Admin, go to Identity Providers and select your IdP.

  5. Replace the existing IdP certificate with the new file.

  6. Save the configuration.

DocuSign will now trust the renewed UserLock certificate for SSO logins.

Troubleshooting

For common issues, see Troubleshooting SSO.
If the problem persists, please contact IS Decisions Support.

Next steps

You can extend the security of SSO sessions by applying UserLock access policies in addition to authentication.