Signing provider origins
Signing provider origins require server approval before providers can be saved or any document bytes can be uploaded. Configure SigningProviders:{ProviderType}:AllowedOrigins as an array of exact HTTPS origins in deployment configuration; the supported provider names are ValidSign, DocuSign, and AdobeSign.
For example, an environment variable named SigningProviders__DocuSign__AllowedOrigins__0 contains the trusted origin approved by the operator. Use an origin such as https://approved-host.example with no path, query, fragment or user information. Regional hosts must be approved individually. Provider BaseUrl values may include an API path beneath that origin.
There are no default trusted origins. An empty list refuses provider creation, origin updates and document signing. Existing provider rows require the same server approval at runtime. Changing origins requires changing deployment configuration, independently of the administrator's provider editor. Existing public-address checks, pinned DNS and disabled redirects continue to apply in each adapter.