FreeSign — Free e-signature

Free e-signature for humans and AI agents — zero-document PDF signing from hashes only.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
84%
Naming quality
100%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,244Tokens (tool definitions)
~2.1 KBTypical response size
Moderate attention impact (0.97% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "signing": {
      "url": "https://free-sign.com/mcp"
    }
  }
}

Remote endpoints

https://free-sign.com/mcpstreamable-http

What it can do

Tool inventory

Tools (5)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟡create_signing_envelope(document_sha256)

Create a FreeSign envelope from a PDF SHA-256 hash. Do not send PDF bytes. The created envelope is NOT yet session-bound — the browser that opens the returned signing_url generates an ECDSA P-256 keypair locally and POSTs the public JWK to /api/envelopes/{id}/session-bind before any protected request will succeed. AI agents calling this tool just hand the signing_url to a human, who continues in a browser.

Input Schema

{
  "type": "object",
  "properties": {
    "document_sha256": {
      "type": "string",
      "pattern": "^[a-f0-9]{64}$",
      "description": "SHA-256 of the original PDF bytes, computed locally by the user or agent."
    }
  },
  "required": [
    "document_sha256"
  ]
}

Output Schema

{
  "type": "object",
  "properties": {
    "envelope_id": {
      "type": "string"
    },
    "signing_url": {
      "type": "string"
    },
    "expires_at": {
      "type": "string"
    },
    "session_binding_required": {
      "type": "boolean",
      "description": "True when the envelope still needs the browser to call /api/envelopes/{id}/session-bind. Always true for MCP-created envelopes."
    }
  },
  "required": [
    "envelope_id",
    "signing_url",
    "expires_at"
  ]
}
🟢verify_document_hash(document_sha256)

Find FreeSign receipts matching a local document SHA-256 hash.

Input Schema

{
  "type": "object",
  "properties": {
    "document_sha256": {
      "type": "string",
      "pattern": "^[a-f0-9]{64}$"
    }
  },
  "required": [
    "document_sha256"
  ]
}

Output Schema

{
  "type": "object",
  "properties": {
    "matches": {
      "type": "array",
      "items": {
        "type": "object"
      }
    }
  },
  "required": [
    "matches"
  ]
}
🟢get_receipt(envelope_id)

Return the envelope record (including final_pdf_sha256, final_signature_base64url, final_payload_json), per-signer signing receipts, and OpenTimestamps anchor metadata. Evidence only, never PDF bytes.

Input Schema

{
  "type": "object",
  "properties": {
    "envelope_id": {
      "type": "string"
    }
  },
  "required": [
    "envelope_id"
  ]
}

Output Schema

{
  "type": "object",
  "properties": {
    "envelope": {
      "type": "object"
    },
    "receipts": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "ots_anchors": {
      "type": "array",
      "items": {
        "type": "object"
      }
    }
  },
  "required": [
    "envelope",
    "receipts",
    "ots_anchors"
  ]
}
🟡get_ots_proof(envelope_id, anchor_id)

Return the .ots proof (base64) for a given OpenTimestamps anchor on an envelope. Use the official `ots-cli` to verify offline against Bitcoin block headers. Each seal has two anchors: `kind: "byterange"` commits to the signed document, `kind: "signed_attrs"` commits to SHA-256 of the CMS SignedAttributes (which carry the post-quantum key commitment).

Input Schema

{
  "type": "object",
  "properties": {
    "envelope_id": {
      "type": "string",
      "pattern": "^env_[a-f0-9]{32}$"
    },
    "anchor_id": {
      "type": "string",
      "pattern": "^ots_[a-f0-9]{32}$"
    }
  },
  "required": [
    "envelope_id",
    "anchor_id"
  ]
}

Output Schema

{
  "type": "object",
  "properties": {
    "envelope_id": {
      "type": "string"
    },
    "anchor_id": {
      "type": "string"
    },
    "status": {
      "type": "string",
      "enum": [
        "pending",
        "confirmed"
      ]
    },
    "kind": {
      "type": "string",
      "enum": [
        "byterange",
        "signed_attrs"
      ]
    },
    "anchored_hash": {
      "type": "string"
    },
    "proof_base64": {
      "type": "string",
      "description": "Complete .ots file bytes, base64."
    },
    "calendar_urls": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "btc_block_height": {
      "type": [
        "integer",
        "null"
      ]
    },
    "btc_block_hash": {
      "type": [
        "string",
        "null"
      ]
    }
  },
  "required": [
    "envelope_id",
    "anchor_id",
    "status",
    "anchored_hash",
    "proof_base64"
  ]
}
⚪verify_audit_chain(envelope_id)

Return an envelope's append-only audit-event hash chain together with a server-computed integrity verdict: every event_hash is recomputed from its canonical material, and the prev_event_hash linkage and per-envelope seq contiguity are checked. Evidence only, never PDF bytes. The raw events are included verbatim so the caller can independently re-derive the verdict instead of trusting `chain.valid`.

Input Schema

{
  "type": "object",
  "properties": {
    "envelope_id": {
      "type": "string",
      "pattern": "^env_[a-f0-9]{32}$"
    }
  },
  "required": [
    "envelope_id"
  ]
}

Output Schema

{
  "type": "object",
  "properties": {
    "envelope_id": {
      "type": "string"
    },
    "attested_audit_chain_head_hash": {
      "type": [
        "string",
        "null"
      ],
      "description": "The audit-chain head derived from the signer-signed v2 final payload (G-01), fed into the verdict's head cross-check. NULL until the envelope is finalized."
    },
    "attested_head_signature_verified": {
      "type": "boolean",
      "description": "True when the final-payload signature carrying the attested head was re-verified against the signer's on-file public key. False when not finalized or the signature did not verify."
    },
    "chain": {
      "type": "object",
      "properties": {
        "valid": {
          "type": "boolean"
        },
        "event_count": {
          "type": "integer"
        },
        "broken_at": {
          "type": [
            "integer",
            "null"
          ],
          "description": "seq of the first broken event, or null (also null for a head_mismatch — no single event is at fault)."
        },
        "reason": {
          "type": [
            "string",
            "null"
          ],
          "enum": [
            "hash_mismatch",
            "broken_link",
            "seq_bad_start",
            "seq_gap",
            "seq_duplicate",
            "head_mismatch",
            null
          ]
        },
        "head_checked": {
          "type": "boolean",
          "description": "True when an attested head was supplied and cross-checked against the recomputed chain."
        },
        "head_match": {
          "type": [
            "boolean",
            "null"
          ],
          "description": "Result of the head cross-check, or null when no attested head was available."
        },
        "events": {
          "type": "array",
          "items": {
            "type": "object"
          }
        }
      },
      "required": [
        "valid",
        "event_count",
        "broken_at",
        "reason",
        "head_checked",
        "head_match",
        "events"
      ]
    },
    "events": {
      "type": "array",
      "items": {
        "type": "object"
      }
    }
  },
  "required": [
    "envelope_id",
    "attested_audit_chain_head_hash",
    "attested_head_signature_verified",
    "chain",
    "events"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded5 tools
verifiedversion not recorded5 tools
verifiedversion not recorded5 tools