> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# BoldSign

> E-signature — users, teams & access

<Tabs>
  <Tab title="Overview">
    Connect BoldSign with an API key to sync account users with their roles and status, teams, brands, templates, and sender identities, and run access reviews. Read-only. Data feeds into your Access accounts and Inventory pages.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the **users** of the BoldSign account the key belongs to, with their name (or their email address when BoldSign stores no name), their email, their BoldSign role as BoldSign reports it (for example **Account Admin** or **Team Admin**; **Member** when none is reported) and the date the user was created. People whose invitation is still pending are left out. BoldSign's own status is respected: a user the account has deactivated is shown as **Inactive**, everyone else as **Active**. BoldSign reports no per-user MFA state, so the **MFA** column is blank (shown as a dash).
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the BoldSign account user roster — names, emails, roles, status and creation dates — which appears on your **Access** page; and your BoldSign **teams**, **brands** (the default brand is marked), **templates** (with their status) and **sender identities** (with their status and email address), which appear on your **Inventory** page. All four are read best-effort after the roster: a failure on any of those calls leaves that part of the Inventory page empty without failing the sync. A new account shows its default team and default brand from the first sync; templates and sender identities appear once you create a template or add a sender identity. Documents and their audit logs, contacts and the account's API credit balance are never read, and no last-login time is shown: the BoldSign user record carries none.

    It calls these BoldSign endpoints on `api.boldsign.com` (or `api-eu.boldsign.com`, `api-ca.boldsign.com` or `api-au.boldsign.com` for the region you enter):

    * `/v1/users/list`
    * `/v1/teams/list`
    * `/v1/brand/list`
    * `/v1/template/list`
    * `/v1/senderIdentities/list`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your BoldSign environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        The key is invalid, the account's plan does not include the API, or the **Region** is wrong. Only the values `eu`, `ca` and `au` are recognised: anything else — including a misspelling — is treated as US, and a key sent to the wrong regional host is rejected like a bad key. Enter the region exactly, or leave it empty for a US account. The Essential, Growth and Business e-signature plans cannot generate an API key at all; only the free developer sandbox or a paid API plan can.
      </Accordion>

      <Accordion title="The sync stopped working">
        A key generated with **Token Validity** switched on stops working on its expiry date, and the sync stops with it — there is no warning beforehand. Generate a new key with Token Validity off, then disconnect and connect again; note that disconnecting permanently deletes the data already collected from BoldSign. Separately, a sandbox account allows 50 API requests per hour: when that limit is hit, the sync reports the rate limit and the next scheduled sync retries.
      </Accordion>

      <Accordion title="Inventory shows only the default team and brand">
        Templates and sender identities are empty until the account creates a template or adds a sender identity — a new account has none. Teams, brands, templates and sender identities are also read best-effort after the roster: a failure on any of those calls leaves that part of the page empty without failing the sync. Click **Sync from integrations** on the **Integrations** page to retry.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    A BoldSign API key from the API Key page. The account is detected automatically. Read-only.

    **Before you begin**

    * A BoldSign account whose plan includes the API — the free developer sandbox or a paid API plan. The Essential, Growth and Business e-signature plans cannot generate a key.
    * Your account's data-residency region, if it is not US.

    You will need:

    | Field | Where to find it | Example |
    | - | - | - |
    | **API key** | Left navigation → **API → API Key → Generate API Key** | Copied from the Generate API Key dialog |
    | **Region (optional)** | Your account's data-residency region; leave empty for US | `eu`, `ca` or `au` |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **BoldSign**, and click **Connect** to open the connect panel.
      </Step>

      <Step title="Sign in to an account with API access">
        Sign in at [app.boldsign.com](https://app.boldsign.com) with an account whose plan includes the API: the free developer sandbox or a paid API plan. The Essential, Growth and Business e-signature plans have no API and cannot generate a key.
      </Step>

      <Step title="Generate an API key">
        In the left navigation open **API → API Key** and click **Generate API Key**. Name the key, leave **Token Validity** off, and keep the environment on **Sandbox** for a sandbox account (**Live** needs an API subscription). Click **Generate Token** and copy the key.

        <Info>
          A key with Token Validity switched on silently stops the sync on its expiry date; a key without an expiry stays valid until it is deleted. At most 2 keys can exist per environment.
        </Info>
      </Step>

      <Step title="Paste the key and connect">
        Return to the connect panel and paste the API key. Enter the account's data-residency region — exactly `eu`, `ca` or `au` — only if it is not US: a wrong region is rejected like a bad key. Then click **Connect**.
      </Step>
    </Steps>

    <Check>
      DSALTA validates the key when you click **Connect**, by listing the account's users with it. On success the integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly**. Checks begin reporting after the first sync.
    </Check>

    <Warning>
      **If the connection is rejected.** An invalid or expired key, a wrong region, or an account whose plan does not include the API.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check | Severity | What it verifies |
    | - | - | - |
    | [User access to Critical System should be valid](/integrations/boldsign/user-access-to-critical-system-should-be-valid) | Info | Checks that everyone with BoldSign access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/boldsign/offboarded-users-should-not-have-active-access) | High | Checks that offboarded employees no longer have active BoldSign access. |
  </Tab>

  <Tab title="Useful links">
    | Topic | Link |
    | - | - |
    | Setup | [BoldSign API key authentication](https://developers.boldsign.com/authentication/api-key/) · [Developer sandbox account](https://developers.boldsign.com/api-overview/developer-sandbox-account/) |
    | General | [BoldSign](https://app.boldsign.com) |
    | DSALTA | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
