PandaDoc Block
Create, send, manage, and download PandaDoc documents and use the complete public business API
The PandaDoc block exposes 123 REST business operations and two MCP actions through the searchable Action selector. Humans and workflow agents use the same action names and conditional input fields. Each action ID is pandadoc. followed by an operation below, such as pandadoc.createDocument.
Connect an account
Choose API key (the default) or MCP when connecting PandaDoc, then select the account in PandaDoc Account:
| Connection | Actions | Authorization |
|---|---|---|
| API key | 123 REST business operations | PandaDoc sandbox or production API key |
| MCP | List MCP Tools, Call MCP Tool | PandaDoc OAuth |
MCP opens PandaDoc's authorization flow. Select the account you want to authorize and complete the connection. Plain REST OAuth is not offered. Never put API keys or OAuth tokens into action configuration.
Workflows uses the selected account to authorize each action. A connected account alone does not prove access to every PandaDoc endpoint: workspace roles, plan entitlements, and sandbox restrictions still apply.
If a request returns 403, check the selected account's authorization and PandaDoc permissions. Verify a read such as List Templates for an API-key account or List MCP Tools for an MCP account before testing writes. Local tests do not establish production access; verify the deployed runtime with a read against its own connection.
Action coverage
Coverage follows PandaDoc's OpenAPI 8.17.0 specification, checked September 16, 2026. It publishes 124 operations; OAuth token exchange is excluded from workflow actions, leaving 123 REST operations.
Previously, the selector exposed five operations: createDocument, sendDocument, getDocumentStatus, listDocuments, and downloadDocument. Thirteen additional existing executors are now selectable, and 105 new business operations complete this API inventory. Existing action names remain valid.
| API group | Count | Workflows operations |
|---|---|---|
| Documents | 23 | listDocuments, createDocument, bulkDeleteDocuments, createDocumentFromUpload, getDocumentStatus, deleteDocument, updateDocument, documentESignDisclosure, updateDocumentStatus, changeDocumentStatusWithUpload, documentRevertToDraft, getDocument, sendDocument, createDocumentEditingSession, createDocumentLink, downloadDocument, downloadProtectedDocument, transferDocumentOwnership, transferAllDocumentsOwnership, documentMoveToFolder, appendContentLibraryItemToDocument, createExportDocxTask, getDocxExportTask |
| Document Reminders | 4 | updateDocumentAutoReminderSettings, getDocumentAutoReminderSettings, statusDocumentAutoReminder, createManualReminder |
| Document Link to CRM | 4 | listDocumentsByLinkedObject, listLinkedObjects, createLinkedObject, deleteLinkedObject |
| Document Attachments | 6 | listDocumentAttachments, createDocumentAttachment, createDocumentAttachmentFromFileUpload, detailsDocumentAttachment, deleteDocumentAttachment, downloadDocumentAttachment |
| Document Fields | 3 | listDocumentFields, updateDocumentFieldsAssignment, createDocumentFields |
| Document Audit Trail | 1 | listDocumentAuditTrail |
| Document Settings | 2 | documentSettingsGet, documentSettingsUpdate |
| Document Recipients | 4 | addDocumentRecipient, deleteDocumentRecipient, editDocumentRecipient, reassignDocumentRecipient |
| Document Sections (Bundles) | 6 | listSections, uploadSection, uploadSectionWithUpload, sectionDetails, sectionInfo, deleteSection |
| Content Library Items | 5 | listContentLibraryItems, createContentLibraryItem, createContentLibraryItemFromUpload, statusContentLibraryItem, detailsContentLibraryItem |
| Templates | 9 | listTemplates, createTemplate, createTemplateWithUpload, duplicateTemplate, getTemplate, deleteTemplate, statusTemplate, updateTemplate, createTemplateEditingSession |
| Template Settings | 4 | templateSettingsGet, templateSettingsUpdate, getTemplateShares, updateTemplateSharingSettings |
| Forms | 1 | listForm |
| Folders | 6 | listFolders, createFolder, renameFolder, listTemplateFolders, createTemplateFolder, renameTemplateFolder |
| API Logs | 4 | listLogs, detailsLog, listLogsV2, detailsLogV2 |
| Contacts | 5 | listContacts, createContact, detailsContact, deleteContact, updateContact |
| Members | 4 | listMembers, detailsCurrentMember, detailsMember, createMemberToken |
| Webhook subscriptions | 6 | listWebhookSubscriptions, createWebhookSubscription, detailsWebhookSubscription, updateWebhookSubscription, deleteWebhookSubscription, updateWebhookSubscriptionSharedKey |
| Webhook events | 2 | listWebhookEvent, detailsWebhookEvent |
| Notary | 5 | listNotaries, listNotarizationRequests, createNotarizationRequest, notarizationRequestDetails, deleteNotarizationRequest |
| Product catalog | 5 | searchCatalogItems, createCatalogItem, getCatalogItem, updateCatalogItem, deleteCatalogItem |
| Quotes | 2 | quoteUpdate, quotesBatchUpdate |
| User and Workspace management | 11 | getWorkspacesList, createWorkspace, deactivateWorkspace, listUsers, createUser, detailsUser, addMember, removeMember, changeMemberRole, createApiKey, updateWorkspace |
| Communication Preferences | 1 | listRecentSmsOptOuts |
The existing Workflows names getDocumentStatus, getDocument, updateDocumentStatus, getTemplate, listFolders, createFolder, and renameFolder correspond to PandaDoc's statusDocument, detailsDocument, changeDocumentStatus, detailsTemplate, listDocumentFolders, createDocumentFolder, and renameDocumentFolder operation IDs. Folder aliases manage document folders; template folders have separate actions.
MCP tools
The MCP connection uses the official PandaDoc MCP server. The current connection choice uses the global server.
- Connect with MCP and select that account.
- Run List MCP Tools (
pandadoc.listMcpTools). It returnstoolswith each tool's name, description, andinputSchema. IfnextCursoris present, supply it as Cursor for the next page. - Run Call MCP Tool (
pandadoc.callMcpTool) with the exact Tool Name and Arguments (JSON) matching that schema. It returns the provider'scontentand, when supplied,structuredContent.
The MCP catalog depends on PandaDoc and the authorized account; it is separate from the 123 REST operations and is discovered at runtime. Tool calls can mutate or send documents. Check tool descriptions before execution. REST actions reject MCP connections, and MCP actions require an MCP connection.
Each action initializes a session, performs one listing page or tool call, and closes the session. Requests time out after 30 seconds; session cleanup has a separate 2-second timeout. Inputs are capped at 1 MiB and streamed responses at 4 MiB. Transport retries and automatic reconnection are disabled. A failed or timed-out write may already have completed: inspect its outcome before retrying or enabling workflow-level retries. Provider error bodies are omitted from errors. Tool outputs remain private workflow data and can include document access links.
Configure an action
IDs and query parameters appear as conditional controls for the selected action. New operations accept their API request body in Data (JSON), using PandaDoc's field names, including required nested fields. Expand Request fields beneath that control to see the selected action's schema guidance; agents receive the same parameter descriptions. Path/query controls use camelCase names such as documentId, templateId, and workspaceId. Refer to the API reference for the selected operation's request schema.
Existing actions keep their named inputs. Their Data (JSON) field accepts additional API properties; explicitly supplied named inputs take precedence. Query (JSON) accepts additional API query parameters. JSON controls accept a JSON value or a JSON-encoded string, so values can come from an earlier step.
For example, create a document from a template:
{
"id": "create_contract",
"type": "action",
"name": "Create contract",
"action": "pandadoc.createDocument",
"config": {
"operation": "createDocument",
"templateId": "<template-uuid>",
"name": "Contract for Example Co",
"recipients": [{ "email": "signer@example.com", "role": "Client" }],
"tokens": [{ "name": "Client.Company", "value": "Example Co" }],
"fields": { "ContractValue": { "value": "5000" } }
}
}Use the template's actual role, token, and field names. Supply either Template ID or a public source URL. Name is required for URL creation; template creation can use the template name. Configure recipients when creating the document; an omitted template recipient list is sent as an empty array. Send Document sends to the existing recipients and accepts subject, message, silent, and forwarding_allowed; its recipients are not supplied again.
For a new operation with a nested request body:
{
"id": "create_attachment",
"type": "action",
"name": "Attach supporting file",
"action": "pandadoc.createDocumentAttachment",
"config": {
"operation": "createDocumentAttachment",
"documentId": "{{steps.create_contract.id}}",
"data": {
"name": "Supporting information",
"source": "https://example.com/supporting-information.pdf"
}
}
}Both examples require a selected PandaDoc connection in the workflow. Sending, reminders, recipient changes, and document sharing can notify recipients; use disposable sandbox records for testing.
Contact creation supports email, phone, and other contact fields without requiring email. Contact updates expose only fields supported by the current API; email and country are creation fields.
Status, uploads, and downloads
Creation and uploads are asynchronous. A newly created document commonly returns document.uploaded; use Get Document Status or a document-status webhook to wait for document.draft before sending. Section uploads and DOCX exports return task identifiers: use Section Details or Get Docx Export Task to observe completion before reading their result. A successful task-creation response is not the completed file.
List Documents accepts numeric status values from 0 through 14; 0 means draft, 1 sent, and 2 completed. Update Document Status permits 2 (completed), 10 (paid), 11 (voided, shown as Expired in PandaDoc), and 12 (declined), subject to PandaDoc's transition rules. Paid requires a connected payment app. Existing document.* status strings are normalized for legacy workflows. notifySigner controls PandaDoc's notify_recipients field. Create Document Link requires an existing recipient email and accepts an optional positive lifetime in seconds.
Upload actions expose fileBase64 and filename, plus optional contentType. Put the endpoint's accompanying metadata in Data (JSON); attachment upload uses its Name input. File content must be base64 bytes, not a URL. Uploads are buffered in worker memory and subject to the endpoint limit (50 or 100 MiB); large uploads require a worker with sufficient memory.
JSON responses preserve PandaDoc's properties at the top level, such as id, status, and results, so subsequent steps can reference {{steps.create_contract.id}}. Download actions return status: "ready", contentBase64, contentType, size, and retryAfterSeconds rather than a download URL. A 202 response returns status: "pending" with null file content; wait for retryAfterSeconds when present and call the download action again. With separateFiles: true, a document bundle can return a ZIP archive instead of a single PDF. Wait for the provider's required document state before downloading. Downloads are limited to 14 MiB of raw bytes to bound memory and retained workflow output; larger responses fail explicitly without truncation.
Quotes Batch Update reports each quote's result independently inside results; HTTP success does not mean every quote update succeeded. Inspect each result before continuing.
Credential-producing operations
Create API Key, Create Member Token, Create Webhook Subscription, and Update Webhook Subscription Shared Key require a new Secret Name. Their server-side executor verifies workflow ownership and encrypted-secret storage before contacting PandaDoc. The credential is stored in the workflow's encrypted secrets; results contain only a secret reference and nonsecret metadata. Existing secret names cannot be overwritten by these operations.
Use the returned secret in a subsequent workflow run: the runtime resolves secrets at run start, so a newly saved secret is not automatically available later in the same run. The runtime requires a configured ENCRYPTION_KEY. If a provider mutation succeeds but persistence fails, the action reports the need to recover or revoke the provider credential before retrying; it never returns the plaintext credential as a fallback.
Webhook list/detail/update responses omit shared keys. API log detail responses omit API keys and request/response bodies that may contain credentials. Signing and editing sessions intentionally return document-scoped bearer session values for embedding; use short lifetimes and treat these results as private access links.
Sandbox and production limits
PandaDoc's sandbox-key restrictions apply to test connections. During the free trial, sandbox send requests require sender and recipient email addresses from the same organization domain. Download Protected Document requires a production key; PandaDoc documents a 401 response for sandbox keys. Workspace administration, notary, catalog, and beta features also depend on the connected account's access.
The block exposes available API operations; account permission and live sandbox or production execution must be verified separately. The action inventory is tied to the specification version above and does not promise access to features added later.
Loopfour