{
 "categories": [
  "documents",
  "communications"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-08",
   "fact": "homepage",
   "note": "Penneo presents digital document signing with national eIDs and an Open API for audit, accounting, and other signing flows.",
   "source": "https://penneo.com/use-cases/digital-document-signing/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "license",
   "note": "The signing page says pricing is flexible and based on the organization's needs and usage, and it points to a pricing page.",
   "source": "https://penneo.com/use-cases/digital-document-signing/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.exists",
   "note": "Penneo documents production and sandbox API bases for Penneo Sign and Penneo Collect.",
   "source": "https://developer.penneo.com/docs/penneo-core-concepts",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.kinds[0]",
   "note": "The OAuth guide shows HTTPS GET https://sandbox.penneo.com/api/v3/casefiles with a JSON accept header.",
   "source": "https://developer.penneo.com/docs/using-oauth",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.auth[0]",
   "note": "Penneo recommends OAuth 2.0. Authorization Code is the grant for integrations where a Penneo user logs in.",
   "source": "https://developer.penneo.com/docs/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.auth[1]",
   "note": "API Keys Grant posts grant_type=api_keys to /oauth/token with client id, client secret, key, nonce, created_at, and a SHA1 digest. It is the headless grant and does not return a refresh token.",
   "source": "https://developer.penneo.com/docs/using-oauth",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.coverage",
   "note": "Sign is organized around case files, documents, and signers. Collect is organized around signed form submissions. The opened pages do not establish every account-admin action.",
   "source": "https://developer.penneo.com/docs/penneo-core-concepts",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.sdk.exists",
   "note": "The authentication page says integrators can use Penneo's PHP SDKs or build a custom integration.",
   "source": "https://developer.penneo.com/docs/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.sdk.official",
   "note": "The PHP SDKs are named on Penneo's own authentication page.",
   "source": "https://developer.penneo.com/docs/authentication",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.sdk.languages",
   "note": "The OAuth guide points PHP samples at github.com/Penneo/sdk-php. JavaScript and C# blocks on that page are request examples, not additional named SDKs.",
   "source": "https://developer.penneo.com/docs/using-oauth",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.extensibility.webhooks",
   "note": "Penneo Sign supports webhooks for events such as a completed case file. Penneo Collect does not offer webhooks yet.",
   "source": "https://developer.penneo.com/docs/penneo-core-concepts",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.data_access.export[0]",
   "note": "Token responses and the case-file list example are JSON.",
   "source": "https://developer.penneo.com/docs/using-oauth",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened https://developer.penneo.com/llms.txt. It is a plain-text index of Penneo authentication, Sign, Collect, webhook, and API reference pages.",
   "source": "https://developer.penneo.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "verdict.scores.api",
   "note": "The HTTP API covers case files and OAuth for both interactive and headless clients. Access tokens expire after 600 seconds, API Keys uses a custom digest, and Collect has no webhooks, so the score stays at 7.",
   "source": "https://developer.penneo.com/docs/using-oauth",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "freshness.watch[0].url",
   "note": "Opened the OAuth guide, including Authorization Code, API Keys, 600-second access tokens, and the case-file list call.",
   "source": "https://developer.penneo.com/docs/using-oauth",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "freshness.watch[1].url",
   "note": "Opened core concepts for Sign and Collect, including environment URLs and the webhook split.",
   "source": "https://developer.penneo.com/docs/penneo-core-concepts",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Penneo documentation index.",
   "source": "https://developer.penneo.com/llms.txt",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-08",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://developer.penneo.com/docs/using-oauth"
   },
   {
    "type": "docs",
    "url": "https://developer.penneo.com/docs/penneo-core-concepts"
   },
   {
    "type": "docs",
    "url": "https://developer.penneo.com/llms.txt"
   }
  ]
 },
 "homepage": "https://penneo.com/use-cases/digital-document-signing/",
 "id": "penneo",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "oauth2-authorization-code",
    "oauth2-api-keys"
   ],
   "coverage": "partial",
   "docs": "https://developer.penneo.com/docs/using-oauth",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Case files, signers, and Collect submissions are documented as HTTP calls.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "php"
   ],
   "official": true
  }
 },
 "name": "Penneo",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "visma-sign",
   "scrive",
   "oneflow"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Penneo",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 7,
   "rpa": null
  },
  "summary": "Penneo Sign and Penneo Collect are automatable today through the documented HTTP APIs. This record is those two products. It is not Visma Sign or Scrive. Production API base is https://app.penneo.com and sandbox is https://sandbox.penneo.com. Login hosts are https://login.penneo.com and https://login-sandbox.penneo.com. Recommended authentication is OAuth 2.0. Authorization Code is for a user login and returns a refresh token. API Keys is for server-to-server calls: POST /oauth/token with grant_type=api_keys, a client id and secret, and a SHA1 digest of a nonce, timestamp, and API secret. Access tokens expire after 600 seconds. Refresh tokens last 5 days, expire when used, and are omitted on the API Keys grant. A documented call is GET /api/v3/casefiles with Authorization: Bearer and Accept: application/json. OAuth clients are created by an account administrator and are not shared between sandbox and production. Penneo Sign can subscribe to webhooks. Penneo Collect does not offer webhooks yet. The authentication guide says Penneo provides PHP SDKs. Legacy Web Services Security and JWT methods are documented and not recommended. The docs index lists a Microsoft Power Platform guide. That connector page was not opened, and Zapier, Make, and n8n were not opened. A first-party MCP server was not established. Computer-use viability is unassessed. The API scores 7 and is the best path. The ten-minute access token and the API Keys digest are the main operational limits.\n"
 }
}