Is Docusign PKI safe?

Low risk

DocuSign PKI writes the extension's runtime ID into the DOM on DocuSign signing pages, where other scripts on that page can read it.

The extension bridges DocuSign signing pages to a locally installed DocuSign PKI native app using Chrome's native messaging API. Content scripts run only on DocuSign signing pages (*.docusign.com, .net, .mil). As part of its handshake mechanism, the extension inserts a hidden div containing its Chrome runtime ID, which any other JavaScript on the same DocuSign page — including third-party analytics or scripts injected by an XSS — can read to confirm the extension is installed.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

DocuSign Inc.v25.1.00.00Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

com.docusign.chrome.sign
Updated 17 September 2026hcclkhcbkkdkaedoogloknhdbkjjgdem