I tested the token method for securing the documentserver and it worked - thanks @dnutan for the hint…
Edit /etc/onlyoffice/documentserver/default.json
and execute supervisorctl restart all
to restart the docserver as described here:
https://api.onlyoffice.com/editors/signature/
Enter the secret in Nextcloud onlyoffice advanced settings: