Earlier quoted context omitted.
I think it is very unclear what is real and not real. OP is mostly passing blame to DocuSign without achieving full understanding themselves. That is more an indictment on OP than DocuSign even if there is some actual session security problem with DocuSign (likely from the deprecated API).
Yeah and it sounds like they were trying to do something that makes no sense for DocuSign to support: use a single account to sign all users’ documents. DocuSign has a legal obligation here to prove authenticity, how are they ever going to be able to do that if everything is behind a single account? They support oauth and that makes sense and should be the way to do it.
By the signature.
I don't know how it works in DocuSign's internals, but there's no requirement for the signer to have an account. The point of the account is for users to see all of their documents in one place. In OP's case that's everyone's documents because they use a single account.
https://support.docusign.com/articles/How-do-I-sign-a-DocuSi...