PDF native MCP server: generate, validate, sign PAdES, embed, extract. AI-powered.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
๐ก Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Model Context Protocol (MCP) server that bridges the pdfnative library โ a zero-dependency, ISO 32000-1 compliant PDF engine โ to any MCP-compatible AI client (Claude Desktop, Cursor, Continue, ChatGPT, Zed, โฆ).
pdfnative-mcp exposes 24 production-grade tools to any MCP host:
| Tool | Purpose |
|---|---|
generate_basic_pdf | Multi-page A4 documents from structured blocks (headings, paragraphs, lists, page breaks). Embedded newlines auto-split into paragraphs. Optional pdfA. |
add_barcode | QR Code, Code 128, EAN-13, Data Matrix, PDF417 โ embedded in a single-page PDF. |
add_international_text | 24 scripts (incl. Latin & COLRv1 colour emoji) with BiDi & OpenType shaping; multi-lang per document. |
add_table | Tabular reports with smart fields (wrap, repeatHeader, zebra, caption, minRowHeight, cellPadding). |
add_form | Create a new interactive AcroForm PDF with text fields, checkboxes, radio buttons, dropdowns. |
read_form_fields (new in v1.5.0) | Read-only enumeration of an existing AcroForm's field tree (names, types, values, widgets). |
fill_form (new in v1.5.0) | Fill and/or flatten an existing AcroForm (non-destructive incremental update). |
add_chart (new in v1.5.0) | Native vector charts โ bar / horizontal-bar / line / pie / donut (pure PDF path operators, PDF/A-safe). |
embed_image | Embed a JPEG or PNG image (base64) into a titled PDF document. |
prepare_signature_placeholder | Step 1 of the two-step sign workflow โ create a PDF with a /Sig AcroForm placeholder. |
sign_pdf | Apply a PAdES-compatible CMS signature (RSA-SHA256 / ECDSA-SHA256 P-256). Auto-injects a placeholder when needed. |
verify_pdf | Verify every PAdES signature in a PDF (integrity + signature value + optional chain trust). |
validate_pdf (new in v1.1.0) | Validate a Tagged PDF for PDF/UA (ISO 14289-1) structural conformance (read-only). |
add_attachment | Generate a PDF/A-3 document with embedded files (Factur-X / ZUGFeRD invoices). |
extract_attachments | Read-only extraction of embedded files (Factur-X / ZUGFeRD XML round-trip) with byte-for-byte payloads. |
extract_text | Unicode text extraction (resolves /ToUnicode) with optional positioned runs; opens encrypted PDFs via password. |
inspect_pdf | Read-only inspection: PDF version, page count, encryption (+ precise encryptionInfo), PDF/A claim, signatures, attachments, placeholder state. |
encrypt_pdf (new in v1.5.0) | Re-secure a PDF with AES-128 / AES-256 (owner/user passwords, permissions, password rotation). |
decrypt_pdf (new in v1.5.0) | Emit an unencrypted copy of an RC4 / AES-128 / AES-256 document. |
merge_pdfs (new in v1.3.0) | Concatenate 2โ50 PDFs into one via pdfnative's page-tree API. |
split_pdf (new in v1.3.0) | Split one PDF into one document per page range (multi-output). |
extract_pages (new in v1.3.0) | Pull an arbitrary page subset into a single PDF. |
annotate_pdf (new in v1.4.0) | Add markup annotations (highlight, note, square/circle, line, freetext) as a visual overlay โ not a redaction. |
draft_governance_issue (new in v1.4.0) | Draft a governance-compliant GitHub issue locally for human review; never submits, no network. |
New in v1.5.0:
add_chart renders bar / horizontal-bar / line / pie / donut charts as pure PDF path operators (zero rasterisation, PDF/A-safe with auto alt text). generate_basic_pdf also accepts a chart block for composition with text and tables.read_form_fields lists an existing AcroForm's fields; fill_form fills and/or flattens it via a non-destructive incremental update (the counterpart to add_form).encrypt_pdf re-secures with AES-128 / AES-256 (RC4 never emitted), decrypt_pdf recovers an unencrypted copy, a password input opens encrypted sources on the read-only tools, and merge_pdfs / split_pdf / extract_pages gain password + encrypt.extract_text now resolves each font's /ToUnicode CMap (no more glyph-index output) and can return positioned runs.pdfnative://output/โฆ resources (resources/list + resources/read), with a resource_link in file-mode results for cross-call re-reference.readOnlyHint / destructiveHint / idempotentHint / openWorldHint.extractText, fill/flatten, charts; colour-emoji subset 221 โ 1167 glyphs).New in v1.4.0:
draft_governance_issue lets an agent draft a fully compliant GitHub issue locally (draft .md + machine-readable compliance report). The agent is a draftsman, never an autonomous submitter: a human is the only gate, and the server makes zero GitHub writes and no outbound network calls. Backed by the governance_contract and draft_issue_workflow MCP prompts.annotate_pdf overlays highlight, sticky-note, underline, strikeout, squiggly, square, circle, line, and freetext annotations on an existing PDF via incremental update. It is a visual review layer, not a redaction โ underlying bytes remain.inspect_pdf โ read-only surfacing of /PageLabels ranges (roman, decimal, prefixed).add_international_text accepts lang: 'math' (explicit, like emoji) to embed the Noto Sans Math face on demand.prompts capability with governance_contract and draft_issue_workflow.New in v1.3.0:
๐ Three page-tree tools โ merge_pdfs, split_pdf, extract_pages (built on pdfnative v1.4.0's page-tree API; encrypted sources are rejected).
๐ Bookmarks, page labels & nested lists โ generate_basic_pdf gains outline ('auto' or explicit tree), pageLabels, multi-level list items, and viewerPreferences.
๐ Table cell borders & alignment โ add_table gains cellBorders, cellVAlign, and viewerPreferences; add_international_text gains viewerPreferences.
๐ Constant-time signing โ sign_pdf signs RSA and EC-DER keys through a node:crypto provider with a transparent pure-JS fallback; signatures stay interoperable.
โฌ Engine upgrade โ pdfnative v1.4.0.
๐ Tool extract_attachments โ read embedded files back out of a PDF (completes the Factur-X / ZUGFeRD round-trip) with byte-for-byte payloads, a filename filter, and an includeData: false metadata-only probe.
๐ง Watermarks โ generate_basic_pdf and add_table accept an optional watermark (text, opacity, angle, colour, position) rendered on every page.
๐ Unicode normalize โ opt-in NFC/NFD/NFKC/NFKD on generate_basic_pdf and add_international_text.
๐ช Token-frugal reads โ the read-only tools (inspect_pdf, verify_pdf, validate_pdf, extract_text, extract_attachments) accept optional verbosity: 'summary' and fields: [โฆ] inputs for ~90% smaller responses on large results, with no loss of the fields agents branch on. Defaults are unchanged.
๐ช No base64 duplication โ generated PDFs (base64 mode) are returned once as an embedded resource content block instead of also being copied into structuredContent.
๐ง MCP registry publish fix โ mcpName now uses the canonical GitHub login casing (io.github.Nizoka/pdfnative-mcp) so the registry's case-sensitive validation accepts the npm package.
โฌ Dependency โ upgraded to zod 4.
New in v1.1.0:
validate_pdf โ read-only PDF/UA (ISO 14289-1) structural conformance check.\n in paragraphs auto-splits into separate paragraphs (Safe PDF/A).add_international_text.New in v1.0.0:
verify_pdf, add_attachment (Factur-X / ZUGFeRD), extract_text.wrap, repeatHeader, zebra, caption, minRowHeight, cellPadding.inspect_pdf now reports hasSignaturePlaceholder and per-attachment summary; new check values 'placeholder' and 'attachments'.sign_pdf accepts ECDSA SEC1 / PKCS#8 DER keys and auto-injects a /Sig placeholder when missing (one-call signing of any PDF).PDFNATIVE_MCP_CACHE_DIR): SHA-256 keyed, 1ย h TTL, 256ย MiB LRU._meta.apiVersion and per-tool _meta.examples for AI-agent discovery โ see docs/API_STABILITY.md.docs/AI_GUIDE.md โ decision tree + common pitfalls. See also the root AGENTS.md operations manual.docs/guides/PDFA.md.PDFNATIVE_MCP_OUTPUT_DIR (was PDFNATIVE_MPC_OUTPUT_DIR; old name still works with a one-shot deprecation warning).merge_pdfs, split_pdf, extract_pages (v1.3.0), annotate_pdf (v1.4.0), and the add_chart / read_form_fields / fill_form / encrypt_pdf / decrypt_pdf tools plus the encrypted round-trip and native MCP resources (v1.5.0). redact_pdf stays deferred โ pdfnative can overlay/flatten but not remove page content, and an overlay-only "redaction" would create false security, so it is intentionally not shipped (tracked as an upstream content-removal request).All tools support two output modes:
base64 (default) โ the generated PDF is returned once as an embedded resource content block (a data:application/pdf;base64,โฆ URI); structuredContent carries only { mode, sizeBytes }.file โ the PDF is written to a sandboxed directory configured via PDFNATIVE_MCP_OUTPUT_DIR. File output is disabled unless this variable is set; absolute paths, path traversal, non-.pdf extensions, and NUL bytes are all rejected.Upgrading from v1.1.0: the only behaviour change is that base64-mode bytes are no longer duplicated into
structuredContent.base64. Read them from the embeddedresourceblock instead:
Token-frugal reads (v1.2.0). The four read-only tools accept two optional inputs:
verbosity: 'summary' โ returns a compact scalar-only verdict (drops the heavy arrays / full text). E.g. verify_pdf โ { signatureCount, allValid, invalid, summary }.fields: ['a', 'b.c'] โ projects the structured result to named dot-paths; composes after verbosity. Unknown paths are omitted leniently.Smallest โis this PDF signed and valid?โ probe: { "pdfBase64": "โฆ", "verbosity": "summary", "fields": ["allValid"] }.
pdfnative-mcp inherits every guarantee of the underlying engine:
Requirements: Node.js โฅ 22.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
Any MCP-compatible client that supports stdio servers will work. Use the same command + args + env triple. Example for Cursor (~/.cursor/mcp.json):
Windsurf / Cline / Roo Code use the same shape inside their respective MCP config files.
pdfnative-mcp is designed for MCP-native environments and works with clients that support MCP over stdio.
Community-verified compatibility includes:
| Variable | Purpose |
|---|---|
PDFNATIVE_MCP_OUTPUT_DIR | Absolute path to the sandbox directory. Required to enable outputMode: 'file'. |
PDFNATIVE_MCP_CACHE_DIR | Absolute path to enable the persistent SHA-256-keyed result cache (1ย h TTL, 256ย MiB LRU). When unset, the cache is disabled. |
PDFNATIVE_MCP_PORT | When set to a valid port (1โ65535), starts an HTTP server on http://127.0.0.1:<port>/mcp instead of stdio. Binds loopback only and enables DNS-rebinding protection (foreign Host/Origin โ 403). |
generate_basic_pdfadd_barcodeSupported formats: qr, code128, ean13, datamatrix, pdf417.
add_international_textSupported lang codes: ar, he, th, ja, zh, ko, el, hi, bn, ta, ru, ka, hy, tr, vi, pl, latin, emoji, math.
Multi-script documents โ pass an array or comma-separated list:
sign_pdfAs of v1.0.0, sign_pdf auto-injects a /Sig placeholder when missing โ you can sign any PDF in one call:
For ECDSA P-256: use algorithm: "ecdsa-sha256" and supply either ecPrivateKeyDerBase64 (SEC1 or PKCS#8 DER) or ecPrivateScalarHex (64 hex chars).
PEM โ DER conversion:
Use
prepare_signature_placeholderonly when you need to customize the placeholder (e.g. largerplaceholderBytesfor >4096-bit RSA keys). Otherwise callsign_pdfdirectly.
add_tableadd_formembed_imageNote: pdfnative does not support alpha-channel PNGs (color type 6). Pre-process such images to remove the alpha channel before embedding.
prepare_signature_placeholderPass the returned PDF bytes to sign_pdf to complete the signing workflow.
inspect_pdfRead-only structural and security inspection โ useful for downstream verification, CI assertions, and AI agents that need to reason about a PDF before acting on it.
Returns:
check[] accepts any of 'pdfa', 'signed', 'encrypted', 'placeholder', 'attachments'. checksPassed is the AND of all requested checks.
validate_pdfRead-only PDF/UA (ISO 14289-1) structural conformance check for a Tagged PDF. Generate an accessible document with any tool using pdfA (e.g. pdfA: 'pdfa2u'), then validate the result:
Returns:
It verifies catalog /MarkInfo /Marked true, /StructTreeRoot (+ /ParentTree), /Metadata (XMP), /Lang, and per-page MCID uniqueness. This is a fast developer-time gate โ not a substitute for a full reference validator (veraPDF), which additionally checks fonts, colour, and rendering.
annotate_pdfOverlay markup annotations on an existing PDF via incremental update. This is a visual review layer, not a redaction โ the underlying content is untouched.
Types: text, highlight, underline, strikeout, squiggly, square, circle, line, freetext. Encrypted sources are rejected (ENCRYPTED_SOURCE).
draft_governance_issueDraft a governance-compliant GitHub issue locally for a human to review and submit. The server never contacts GitHub and makes no outbound network calls; it returns the draft Markdown plus a machine-readable compliance report.
A draft that proposes a runtime dependency, omits a reproduction, or sets duplicateSearchPerformed: false is rejected with GOVERNANCE_VIOLATION. See docs/guides/AI_GOVERNANCE.md for the full human-in-the-loop contract.
verify_pdf, add_attachment, extract_textSee the dedicated sections in docs/AI_GUIDE.md and the reference in docs/KNOWLEDGE_BASE.md. Ready-to-run examples live under examples/.
pdfnative-mcp runs inside the host process and exposes a stdio MCP server. It does not open network sockets and does not perform any I/O outside the configured sandbox.
PDFNATIVE_MCP_OUTPUT_DIR. When unset, the file output mode is rejected with a SecurityError...), NUL bytes, and any extension other than .pdf.See SECURITY.md for the responsible disclosure process.
Smoke-test the server over stdio:
Contributors: see docs/guides/LOCAL_TESTING.md for the full local-verification workflow โ the quality gate, examples-as-tests, validating that generated PDFs are structurally correct (
assertValidPdf,inspect_pdf,validate_pdf,verify_pdf), opening output in a viewer, external PDF/A checking with veraPDF, and the MCP Inspector.
pdfnative-mcp follows the same release formalism as pdfnative:
release-notes/vX.Y.Z.mdCHANGELOG.md mirrors each release bullet listrelease-notes/vX.Y.Z.mdNPM_TOKENSee release-notes/TEMPLATE.md for the canonical structure and publication checklist.
v1.3.0 is shipped. The full plan โ released milestones, in-progress work, and long-term direction โ lives in ROADMAP.md.
Blocked upstream (page-tree manipulation):
redact_pdf and an encrypted-PDF round-trip โ pdfnative does not yet export the content-redaction / decryption primitives required to build these safely. They remain on the roadmap, blocked on an upstream API. (merge_pdfs, split_pdf and extract_pages shipped in v1.3.0.)Have a feature idea? Open an issue or PR.
If pdfnative-mcp is useful to you, please โญ this repository โ and consider also starring the underlying engine Nizoka/pdfnative. Stars help others discover the project and motivate continued development.
Contributions are very welcome. Please read CONTRIBUTING.md, check the open issues, and follow the code of conduct.
MIT ยฉ 2026 Nizoka
pdfnative-mcp is built on top of pdfnative and the Model Context Protocol TypeScript SDK.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/pdfnative-mcp)<a href="https://allmcps.com/mcp/pdfnative-mcp"><img src="https://allmcps.com/api/badge/pdfnative-mcp?style=directory" alt="Pdfnative Mcp on AllMCPs" /></a>