Skip to content
Storage ⇄ Business productivity

Box to Docusign integration — real-time, two-way sync

Keep Box and Docusign in sync without custom scripts. Cut weeks of integration work, eliminate silent data drift, and give your team a single, reliable source of truth.

  • SOC 2 and 6 other compliance frameworks
  • POC with real engineers in minutes

Adopted by fast-scaling companies moving mission-critical data in real time

Case study
Migrated from MuleSoft
Case study
Migrated from Celigo
Migrated from Heroku Connect
Migrated from Matillion
Case study
Migrated from Fivetran
Case study
Migrated from Celigo
Why teams connect Box and Docusign

Land the records and documents that build up in Docusign into Box as they are created, and surface Box's file details on the Docusign records that point to them, without an export job to maintain.

Docusign and Box hold different kinds of data. Docusign carries records and the activity around them — the tickets, messages, orders, or issues a team works through, often with documents attached. Box holds files and the metadata that describes them. Where the two meet is narrow but real: much of what Docusign produces has to be kept somewhere durable, and many of the files Box stores are the very documents Docusign's records point to.

Stacksync syncs Users, Envelopes, Recipients, Documents in Docusign with Tasks, Events, Files, Folders in Box in real time. Records and attachments created in Docusign are written into Box as objects or files within seconds of being created. In the other direction, the metadata Box keeps about those files — name, location, owner, modified date — flows back onto the matching record in Docusign, so people see the current document without leaving the tool. Field-level mapping controls exactly what crosses over and in which direction, so you keep a durable copy of what matters without an extract to schedule or a nightly dump that leaves the copy a day behind.

Common use cases

  • 01 Create and send an Envelope from a Template when a CRM Opportunity reaches closed-won, then write the returned envelopeId and status back onto the record.
  • 02 Extract Tabs data captured from signers — text fields, checkboxes, dates — into a warehouse to populate downstream contract or onboarding tables.
  • 03 Two-way sync of Files and Folders between Box and an operational database so applications track document status without calling the Box API directly.
  • 04 Mirror Metadata template instances on Files into database columns so contracts and assets are searchable and reportable alongside other business data.

Common sync patterns

Where Docusign generates attachments: keep the files in Box

Documents attached to records in Docusign land in the storage system automatically, with the source record holding a link back, so files live in one governed place instead of inside the tool.

Where Box holds the source documents: file details on the record

A file's name, location, owner, and modified date from Box sync onto the matching record in Docusign, so whoever is working there sees the current version without switching tools.

A copy that outlives the tool

A continuously synced copy in Box preserves records and documents even as they age out of Docusign or get changed inside it, so history stays intact and reachable.

What you can sync between Box and Docusign

Representative objects on each side — any object or custom field can map to any target. Schemas are auto-detected; types are converted between the two systems.

Box objects Docusign objects How this pairing syncs
Folders Hierarchical containers whose tree, names, and parent moves are mirrored so a target system reflects Box's structure; the account root is always folder ID 0. Folders Containers such as Inbox, Sent, and Draft plus custom folders; listed and moved to organize envelopes and drive reporting queries. Same entity on both sides — records pair one-to-one and field-level changes reconcile in both directions. Custom fields on either side are included in the mapping.
Users Managed and app users in the enterprise; provisioned, updated, and deprovisioned to keep Box access aligned with an HR or identity source. Users Account members and senders; the eSignature Users resource exposes them for attribution and reporting, while bulk org-wide user provisioning uses the separate Admin API. Same entity on both sides — records pair one-to-one and field-level changes reconcile in both directions.
Groups Named user collections used for bulk collaboration; membership synced from a directory or IdP. Recipients Signers, carbon copies, and agents on an envelope, each with a routing order and status; read recipient progress, write recipient lists when an envelope is created. Groups is specific to Box and Recipients to Docusign — each maps to any object or custom field on the other side.
Tasks Review or approval assignments on a file with due dates and states; read for workflow reporting or written to start approvals. Documents The PDF files inside an envelope plus the certificate of completion; read signed output out to a store, or supply source documents on create. Tasks is specific to Box and Documents to Docusign — each maps to any object or custom field on the other side.
Events Enterprise admin event stream, an audit log of uploads, deletes, logins, and shares across the account; read-only, consumed for reporting or change feeds. Templates Reusable envelope definitions with predefined recipients and tab placement; read to map fields and referenced by ID to generate new envelopes. Events is specific to Box and Templates to Docusign — each maps to any object or custom field on the other side.
Files Core content object with versions, name, size, and metadata; synced two-way so files and their attributes move between Box and a database or another store. Tabs (form fields) Signature, initial, date, text, and checkbox fields on a document; they carry the data a signer entered and are read out into databases. Files is specific to Box and Tabs (form fields) to Docusign — each maps to any object or custom field on the other side.

How changes propagate between Box and Docusign

Each direction of the sync is driven by what the source system can signal and what the destination accepts — detection, delivery, and expected latency below.

Box Docusign Sub-second propagation

DetectionBox notifies Stacksync of record changes through webhook events. V2 webhooks fire on triggers such as FILE.UPLOADED, FILE.TRASHED, and METADATA_INSTANCE.UPDATED.

DeliveryEach detected change is written to Docusign through its API, with automatic retries and rate-limit backoff.

Docusign Box Sub-second propagation

DetectionDocusign notifies Stacksync of record changes through webhook events. Docusign Connect webhooks push envelope and recipient status-change events in real time.

DeliveryEach detected change is written to Box through its API, with automatic retries and rate-limit backoff.

Rate-limit considerations

  • Box: Per user: 1,000 API calls per minute and 240 file uploads per minute; exceeding limits returns HTTP 429 with a Retry-After header. Box Business plans also carry a licensed monthly API-call allotment per enterprise.
  • Docusign: Default 3,000 API requests per hour per account across all integrations, plus a burst limit of 500 calls per 30-second window; usage is exposed via the RateLimit and BurstLimit response headers.
What ships with Box ⇄ Docusign

Connect Box and Docusign for flexible, real-time data sync.

Real-time sync, workflow automation, event queues, EDI, and monitoring, for every Box–Docusign connection.

Real-time

Two-way sync

Changes in Box or Docusign instantly reflect in both systems. No stale data, no manual imports.

No-code + pro-code

Workflow automation

Trigger automated workflows whenever Box or Docusign data changes, update records, fire webhooks, or kick off sequences without brittle API scripts.

At scale

Event queues

Handle millions of events per minute without losing a single Box or Docusign record.

Observability

Monitoring

Track your Box ⇄ Docusign sync health, view errors, and replay failed events in one click.

Trading partners

EDI

Transform legacy EDI complexity into simple database interactions between Box and Docusign.

How the Box and Docusign connectors work

Box

Integration surface
REST API (api.box.com/2.0), plus the Events API and V2 Webhooks
Authentication
OAuth 2.0 for user-delegated access, or server-to-server auth via JWT (RSA keypair) or Client Credentials Grant (CCG) using a Box app; short-lived developer tokens for testing
Change detection
V2 webhooks fire on triggers such as FILE.UPLOADED, FILE.TRASHED, and METADATA_INSTANCE.UPDATED; the Events API (user stream via long-poll by stream_position, or enterprise/admin events) provides a near-real-time change feed
Capabilities
read · write · webhooks
Rate limits
Per user: 1,000 API calls per minute and 240 file uploads per minute; exceeding limits returns HTTP 429 with a Retry-After header. Box Business plans also carry a licensed monthly API-call allotment per enterprise.

Docusign

Integration surface
eSignature REST API v2.1 (plus Docusign Connect webhooks; separate CLM, Rooms, and Admin APIs)
Authentication
OAuth 2.0 — Authorization Code Grant for interactive apps, or JWT Grant (RSA key pair with user impersonation) for server-to-server integrations
Change detection
Docusign Connect webhooks push envelope and recipient status-change events in real time; polling is the fallback and is limited to once every 15 minutes per envelope
Capabilities
read · write · webhooks
Rate limits
Default 3,000 API requests per hour per account across all integrations, plus a burst limit of 500 calls per 30-second window; usage is exposed via the RateLimit and BurstLimit response headers
Docusign setup guide
How it works

How to connect Box to Docusign — three steps, no code

Configure and sync within minutes, no code. Whether you sync 50k or 100M+ records, Stacksync handles the queues, infra, and plumbing. Integrations are non-invasive and need zero setup on your systems.

  1. 01

    Connect your apps

    Authenticate Box and Docusign with each platform's native method — OAuth, API keys, or service accounts — plus secure options like SSH tunneling, IP whitelisting, and VPC peering.

    • OAuth 2.0
    • SSH tunnel
    • VPC peering
    Box connected
    Docusign connected
    OAuth 2.0
    SSH tunnel
    SSL certificate
    VPC peering
  2. 02

    Choose tables

    Pick the Box and Docusign objects to sync — Stacksync auto-detects both schemas, including custom fields where the platform exposes them. Sync to existing tables, or let Stacksync create new ones with ideal data types.

    • Standard objects
    • Custom objects
    • Auto-schema
    objects · Box ⇄ Docusign
    Customers 12,480
    Sales Orders 8,213
    Invoices 5,902
    Items 1,344
  3. 03

    Map fields

    Fields map automatically even when names and types differ. Stacksync handles transformation and type casting for you, zero configuration required.

    • Auto-map
    • Type casting
    • Transforms
    Box Docusign
    Company company_name text
    Email email text
    Amount amount numeric
    Created created_at timestamp
FAQ

Box and Docusign integration FAQ

SECURITY

Security teams trust Stacksync

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

SOC 2 Type II
ISO 27001
HIPAA BAA
GDPR
CCPA
DPF US-EU-UK-CH
→ SECURITY WITH BENEFITS

SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

Secure connection options

Securely connects to your systems with:

Related integrations

Every pair below is a real-time, two-way sync. Search all 502 integrations available for Box and Docusign.

Popular · 7 of 502
Coworkers laughing in front of a laptop in a casual office setting

Your last integration took months.
Your next one takes a prompt.