>I was annoyed that they didn’t provide a secret key to authorize API requests
Yeah... they don't do that for a reason. They appear to support a fully fledged OAuth implementation (https://developers.docusign.com/esign-rest-api/guides/). I haven't used it, so maybe it's terrible, but I'm suspicious of the author at this point.
>DocuSign API docs are very quirky
But no discussion of why, or what he would expect instead. This actually sounds like the author is lost because they don't understand OAuth again (and to be fair, I've implemented OAuth and it's easy to get wrong).
>Someone on the team noticed that if you refresh the page, you get logged in as the user that was making the API request. [...] About a week later, we were informed that this is intentional, and they were worried about breaking anyone that is using this as a feature.
This honestly sounds like they were politely telling you that you haven't implemented OAuth correctly. You should be making the request with the token of the delegated user, not a generic account.
>I got this working, but it took some janky work to re-work the JWT flow to manage hourly expiring tokens for all of our user that choose to enable the esignature feature.
This is what refresh tokens are for. I highly doubt the refresh token expired in an hour, but hey - I haven't used it so maybe I'm wrong.
---
I honestly believe I can summarize this whole article as: Dev takes first steps into OAuth and gets lost...