09 Aug 2026 · 7 min read
Install a Review-Gated DocuSeal Plugin in Codex
A bounded Codex plugin pattern for preparing DocuSeal signing workflows while server-side review gates and explicit human approval retain send authority.
The plugin is not the security boundary
A Codex plugin can expose a focused workflow for searching templates, creating or uploading templates, applying layouts, validating fields, preparing a send preflight, sending after approval, and reading sanitized evidence. It must not expose unrestricted REST access, token administration, user administration, review bypasses, or direct database access.
The DocuSeal server must already enforce pending review, human approval, exact short-lived preflights, send-time validation, and durable delivery evidence. Installing a plugin against an unmodified server does not create those protections.
Separate remote signing tools from local file upload
The remote MCP server owns bounded DocuSeal operations. A minimal local MCP adapter can read a PDF, DOCX, or DOC directly from an absolute workstation path and upload it to a dedicated server endpoint without inserting the document bytes into the model conversation.
The local adapter should restrict extensions, MIME types, size, path shape, and timeout, then return only sanitized template metadata. It should never send invitations.
Use a named and revocable operator credential
Each operator or runtime should receive a dedicated credential that is independently revocable and attributable in audit logs. Its value must remain outside plugin manifests, MCP configuration, skills, marketplace files, source control, shell history, Gists, and operational notes.
The server should accept the credential only at the bounded MCP and upload surfaces and reject it for unrelated REST and administrative endpoints.
Prove the review and send controls with a dummy workflow
Installation validation should use a clearly named dummy document and controlled recipient. The test should prove that a newly uploaded template is pending, layout page numbering reads back correctly, sending fails while pending, and a human can approve the exact template inside DocuSeal.
After approval, the workflow should revalidate, create an exact preflight, obtain explicit approval for one send, and confirm one submission with durable provider evidence and no duplicate after worker replay or restart. Ambiguous results must not trigger automatic retry.
Keep the operating skill short and explicit
The plugin skill should state that DocuSeal is the system of record, credentials are never printed, agent-created or edited templates remain pending, page numbering is explicit, approved revisions are revalidated, sends require unchanged preflights, and delivery claims follow the available evidence.
The living Gist includes the plugin scaffold, manifest, MCP configuration, local upload adapter, skill text, credential handling, validation commands, acceptance test, update workflow, troubleshooting, and security checklist.
Share and save
Living source
This post is the stable site version. The source gist may be updated as the working pattern develops.
Read the complete Codex plugin guideSelf-host DocuSeal for productionAgentic Document Signing architecture