The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Oxidize Python listing page.
Rust-powered PDF library for Python. Generate, parse, split, merge, and manipulate PDFs with native performance. Ships with a built-in MCP server so AI agents can work with PDFs out of the box.
No C dependencies. No Java. No subprocess calls.
Platforms: Linux (x86_64, aarch64) | macOS (x86_64, Apple Silicon) | Windows (x86_64) Requires: Python 3.10+
| oxidize-pdf | Pure-Python libs | C/Java wrappers | |
|---|---|---|---|
| Performance | Native (compiled Rust) | Interpreted | Native but heavy |
| Dependencies | Zero | Varies | Poppler, Java, Ghostscript |
| Memory safety | Rust ownership model | GC-dependent | Manual / GC |
| Type stubs | Full (mypy/pyright) | Partial | Rare |
| AI-ready (MCP) | Built-in | No | No |
Give your AI agent full PDF capabilities in one line:
The built-in Model Context Protocol server exposes 12 tools, 6 resources, and 5 prompts — compatible with Claude, GPT, and any MCP client.
Add to your claude_desktop_config.json:
Copilot's agent mode speaks MCP. Add .vscode/mcp.json to your workspace:
Open the Chat view, switch to Agent mode, and the 12 PDF tools appear in
the tool picker. (The same block also works under the mcp.servers key in your
user settings.json if you prefer a global install.)
The OpenAI Agents SDK spawns the server over stdio and exposes its tools to an agent:
A runnable version is in examples/openai_agents_quickstart.py.
Both integrations run the server locally over stdio, so its tools operate on PDFs in the configured workspace directory. Remote/hosted use (e.g. the OpenAI Responses API hosted MCP tool) needs an HTTP transport and is not yet exposed.
| Tool | What it does |
|---|---|
read_pdf | Read metadata — page count, version, encryption status, title, author |
extract_text | Extract text from all pages or a specific page |
convert_pdf | Convert to markdown, chunks, or RAG-optimized format |
create_pdf | Create a new PDF with optional metadata |
save_pdf | Save a session to disk, with optional encryption |
add_content | Add pages, text, and graphics to a session |
annotate_pdf | Add text annotations and highlights |
manipulate_pdf | Split, merge, rotate, extract pages, reverse, overlay |
manage_forms | Create, fill, read, and validate form fields |
secure_pdf | Encrypt, check permissions, verify signatures |
extract_entities | Extract structured entities from pages |
analyze_pdf | Validate structure, detect corruption, check PDF/A compliance |
The server also exposes resources (session data, capabilities, version info) and prompts (guided workflows for summarization, data extraction, form filling, and more).
The server is configured entirely through environment variables:
| Variable | Default | Purpose |
|---|---|---|
OXIDIZE_WORKSPACE | ~/Documents/oxidize-mcp | Sandbox root; all paths must resolve inside it. |
OXIDIZE_ALLOWED_PATHS | (none) | Comma-separated extra directories allowed outside the workspace. |
OXIDIZE_MAX_FILE_SIZE_MB | 100 | Reject input PDFs larger than this on disk. |
OXIDIZE_MAX_PAGES | 10000 | Reject documents with more pages than this before any extraction work. |
OXIDIZE_MAX_OUTPUT_BYTES | 10485760 | Cap the serialized size of a tool's JSON response (10 MB). |
OXIDIZE_MAX_SESSIONS | 10 | Maximum concurrent stateful PDF-creation sessions. |
OXIDIZE_MAX_SESSION_BYTES | 10485760 | Cap the content a single session may accumulate (10 MB). |
OXIDIZE_SESSION_TIMEOUT | 3600 | Session expiry, in seconds. |
Resource caps (OXIDIZE_MAX_*) protect the server from a large or malicious
PDF: oversized documents are rejected up front and tool responses are bounded
rather than serialized unbounded. Exceeding a cap returns an error with code
RESOURCE_LIMIT.
Or start programmatically:
Exception hierarchy: PdfError > PdfIoError, PdfParseError, PdfEncryptionError, PdfPermissionError
oxidize-pdf includes an MCP server that exposes PDF capabilities to AI assistants like Claude. Install with the mcp extra:
Add this to your claude_desktop_config.json:
| Tool | Description |
|---|---|
read_pdf | Open a PDF and get metadata (pages, version, encryption) |
extract_text | Extract text content from PDF pages |
convert_pdf | Convert between PDF versions |
analyze_pdf | Analyze structure, fonts, images, and compliance |
extract_entities | Extract images and digital signatures |
manipulate_pdf | Split, merge, rotate, extract, and reorder pages |
annotate_pdf | Add text annotations, highlights, and stamps |
manage_forms | Create, fill, and read PDF form fields |
secure_pdf | Encrypt, decrypt, and set document permissions |
create_pdf | Create a new PDF document with pages |
add_pdf_content | Add text, shapes, and images to pages |
save_pdf | Save the document to file or bytes |
oxidize://fonts — Available built-in PDF fontsoxidize://page-sizes — Standard page sizes with dimensionsoxidize://capabilities — Server capabilities and tool listingoxidize://version — Version informationoxidize://workspace — PDF files in the workspace directoryoxidize://session/{id} — Session data by IDDocument.encrypt() configures encryption parameters but the underlying Rust library does not yet serialize the encryption dictionary to the PDF output. Reading encrypted PDFs works correctly.extract_images_from_pdf extracts each embedded image as-is (e.g. a DCTDecode JPEG is written byte-for-byte). Image preprocessing — auto rotation-correction, contrast enhancement, denoise, upscaling, force-grayscale — is not available, because the build excludes the upstream external-images feature (and its image-crate dependency). This keeps extraction faithful and lossless; it does not silently return empty or stub results.MIT — see LICENSE for details.