pdfnative MCP — PDF/A & PDF/X-4 generation, PAdES signing & introspection
Local package path declaredNo credentials listedRepository declared by sourceUpdated 2026-09-24
io.github.Nizoka/pdfnative-mcp · Registry status: active
At a glance
PDF MCP: generate PDF/A & PDF/X-4, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools
Vendor's own description, untranslated and unverified
- Execution location
- Local package path declaredMCP-Register · 2026-08-06
- Required secrets declared
- No credentials listedMCP-Register · 2026-08-06
- Declared version and change
1.7.0· Source-reported change date 2026-09-24MCP-Register · 2026-09-25- Repository as declared
- github.com/Nizoka/pdfnative-mcpMCP-Register · 2026-08-06
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers for documents1,375
- MCP servers without declared required secrets35,800
- Locally executed MCP servers17,056
- MCP servers with a repository URL30,107
- MCP servers with a path argument498
- Local MCP servers without declared required secrets13,238
6 of 14 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Local package path declared
- Credentials
- No credentials listed
- Registry record changed
- 2026-09-24
- Setup
- Template available
- Registry name
io.github.Nizoka/pdfnative-mcp- Package coordinate
npm:pdfnative-mcp- Declared version
1.7.0- Source-reported listing date
- 2026-09-24
- Source-reported change date
- 2026-09-24
- First seen by tracevero
- 2026-08-06
- Vendor's website
- https://github.com/Nizoka/pdfnative-mcp#readme
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Required secrets declared | No credentials listed no Original data – Required secret variables (raw): confirmed absent Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-08-06 · derived |
|---|---|
| Execution location | Local package path declared local Original data – Transports (raw): stdio Source: MCP-Register · collected on 2026-08-06 · derived |
| Path argument present | yes Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): PDFNATIVE_MCP_CACHE_DIR, PDFNATIVE_MCP_OUTPUT_DIR Source: MCP-Register · collected on 2026-08-24 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/Nizoka/pdfnative-mcp Source: MCP-Register · collected on 2026-08-06 · derived |
| Field of use, derived from the vendor description | Documents Original data – Description (raw): PDF MCP: generate PDF/A & PDF/X-4, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools Source: MCP-Register · collected on 2026-08-26 · derived |
| Declared version | 1.7.0 Source: MCP-Register · collected on 2026-09-25 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | PDF MCP: generate PDF/A & PDF/X-4, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools Source: MCP-Register · collected on 2026-09-25 · self-declared |
|---|---|
| Environment variables (raw) | PDFNATIVE_MCP_OUTPUT_DIR, PDFNATIVE_MCP_CACHE_DIR, PDFNATIVE_MCP_PORT, PDFNATIVE_MCP_HTTP_TOKEN, PDFNATIVE_MCP_MAX_INFLATE_BYTES, PDFNATIVE_MCP_CREATION_DATE, SOURCE_DATE_EPOCH, PDFNATIVE_MCP_TSA_URL, PDFNATIVE_MCP_TSA_AUTH, PDFNATIVE_MCP_REVOCATION, PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS, PDFNATIVE_MCP_NETWORK_TIMEOUT_MS Source: MCP-Register · collected on 2026-09-25 · self-declared |
| Required secret variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Transports (raw) | stdio Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Repository (raw) | https://github.com/Nizoka/pdfnative-mcp Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Package registries (raw) | npm Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | PDFNATIVE_MCP_CACHE_DIR, PDFNATIVE_MCP_OUTPUT_DIR Source: MCP-Register · collected on 2026-08-24 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-09-24 Source: MCP-Register · collected on 2026-09-25 · self-declared |
| Last changed in the registry (raw) | 2026-09-24 Source: MCP-Register · collected on 2026-09-25 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | package Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | pdfnative-mcp Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | 1.7.0 Source: MCP-Register · collected on 2026-09-25 · self-declared |
| Runtime hints (raw) | npx Source: MCP-Register · collected on 2026-08-24 · self-declared |
| Environment variable formats (raw) | filepath, number Source: MCP-Register · collected on 2026-08-24 · self-declared |
| Environment variable descriptions (raw) | PDFNATIVE_MCP_CACHE_DIR=Opt-in content-addressed response cache directory (SHA-256 keyed, 1h TTL, 256 MiB LRU, plaintext at rest). Never caches encrypt/decrypt, sign, timestamp, add_ltv, update_metadata, encrypted builds or file output. · PDFNATIVE_MCP_CREATION_DATE=ISO 8601 instant with a time zone (e.g. 2026-01-01T00:00:00Z) pinned as the creation date of every generated document: reproducible bytes on any host. A call's own creationDate still wins. An invalid value refuses to start the server. · PDFNATIVE_MCP_HTTP_TOKEN=Opt-in bearer token for the HTTP transport (>= 16 chars, no whitespace). When set, /mcp requires 'Authorization: Bearer <token>' or answers 401. Never logged. · PDFNATIVE_MCP_MAX_INFLATE_BYTES=Per-stream FlateDecode decompression cap in bytes (zip-bomb mitigation; default 104857600 = 100 MiB). Integer >= 1024; an invalid value refuses to start the server. · PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS=Comma-separated allow-list of OCSP / CRL responder hosts ('host', 'host:port' or '*.suffix'). Mandatory when PDFNATIVE_MCP_REVOCATION is set: responder URLs found in certificates are fetched only if the host matches (http(s) only, no credentials, no redirects, internal addresses rejected unless listed verbatim). · PDFNATIVE_MCP_NETWORK_TIMEOUT_MS=Per-request timeout for TSA / OCSP / CRL calls in milliseconds, 1000-120000 (default 10000). · PDFNATIVE_MCP_OUTPUT_DIR=Absolute path of a sandboxed directory where outputMode='file' may write PDFs. Unset: every tool returns base64 only (file output disabled). · PDFNATIVE_MCP_PORT=Serve Streamable HTTP on this loopback port instead of stdio (MCP 2026-07-28, stateless). Unauthenticated unless PDFNATIVE_MCP_HTTP_TOKEN is set. · PDFNATIVE_MCP_REVOCATION='ocsp', 'crl' or 'ocsp,crl': enables online revocation collection for add_ltv mode='online' (PAdES B-LT). Unset: that mode fails with REVOCATION_NOT_CONFIGURED; mode='offline' stays fully offline. Requires PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS. · PDFNATIVE_MCP_TSA_AUTH=Optional Authorization header value sent to the TSA (e.g. 'Basic ...' or 'Bearer ...'). Never logged or echoed. · PDFNATIVE_MCP_TSA_URL=http(s) URL of the RFC 3161 timestamp authority used by sign_pdf timestamp=true and timestamp_pdf (PAdES B-T / B-LTA). Unset: those calls fail with TSA_NOT_CONFIGURED and no network request is made. Tool arguments can never supply a URL. · SOURCE_DATE_EPOCH=reproducible-builds.org convention: integer seconds since the Unix epoch, used as the pinned creation date when PDFNATIVE_MCP_CREATION_DATE is unset. An invalid value refuses to start the server. Source: MCP-Register · collected on 2026-09-25 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"pdfnative-mcp","version":"1.7.0","runtimeHint":"npx","transport":"stdio","environment":[{"name":"PDFNATIVE_MCP_OUTPUT_DIR","description":"Absolute path of a sandboxed directory where outputMode='file' may write PDFs. Unset: every tool returns base64 only (file output disabled).","format":"filepath","required":false,"secret":false},{"name":"PDFNATIVE_MCP_CACHE_DIR","description":"Opt-in content-addressed response cache directory (SHA-256 keyed, 1h TTL, 256 MiB LRU, plaintext at rest). Never caches encrypt/decrypt, sign, timestamp, add_ltv, update_metadata, encrypted builds or file output.","format":"filepath","required":false,"secret":false},{"name":"PDFNATIVE_MCP_PORT","description":"Serve Streamable HTTP on this loopback port instead of stdio (MCP 2026-07-28, stateless). Unauthenticated unless PDFNATIVE_MCP_HTTP_TOKEN is set.","format":"number","required":false,"secret":false},{"name":"PDFNATIVE_MCP_HTTP_TOKEN","description":"Opt-in bearer token for the HTTP transport (>= 16 chars, no whitespace). When set, /mcp requires 'Authorization: Bearer <token>' or answers 401. Never logged.","required":false,"secret":true},{"name":"PDFNATIVE_MCP_MAX_INFLATE_BYTES","description":"Per-stream FlateDecode decompression cap in bytes (zip-bomb mitigation; default 104857600 = 100 MiB). Integer >= 1024; an invalid value refuses to start the server.","format":"number","required":false,"secret":false},{"name":"PDFNATIVE_MCP_CREATION_DATE","description":"ISO 8601 instant with a time zone (e.g. 2026-01-01T00:00:00Z) pinned as the creation date of every generated document: reproducible bytes on any host. A call's own creationDate still wins. An invalid value refuses to start the server.","required":false,"secret":false},{"name":"SOURCE_DATE_EPOCH","description":"reproducible-builds.org convention: integer seconds since the Unix epoch, used as the pinned creation date when PDFNATIVE_MCP_CREATION_DATE is unset. An invalid value refuses to start the server.","format":"number","required":false,"secret":false},{"name":"PDFNATIVE_MCP_TSA_URL","description":"http(s) URL of the RFC 3161 timestamp authority used by sign_pdf timestamp=true and timestamp_pdf (PAdES B-T / B-LTA). Unset: those calls fail with TSA_NOT_CONFIGURED and no network request is made. Tool arguments can never supply a URL.","required":false,"secret":false},{"name":"PDFNATIVE_MCP_TSA_AUTH","description":"Optional Authorization header value sent to the TSA (e.g. 'Basic ...' or 'Bearer ...'). Never logged or echoed.","required":false,"secret":true},{"name":"PDFNATIVE_MCP_REVOCATION","description":"'ocsp', 'crl' or 'ocsp,crl': enables online revocation collection for add_ltv mode='online' (PAdES B-LT). Unset: that mode fails with REVOCATION_NOT_CONFIGURED; mode='offline' stays fully offline. Requires PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS.","required":false,"secret":false},{"name":"PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS","description":"Comma-separated allow-list of OCSP / CRL responder hosts ('host', 'host:port' or '*.suffix'). Mandatory when PDFNATIVE_MCP_REVOCATION is set: responder URLs found in certificates are fetched only if the host matches (http(s) only, no credentials, no redirects, internal addresses rejected unless listed verbatim).","required":false,"secret":false},{"name":"PDFNATIVE_MCP_NETWORK_TIMEOUT_MS","description":"Per-request timeout for TSA / OCSP / CRL calls in milliseconds, 1000-120000 (default 10000).","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} Source: MCP-Register · collected on 2026-09-25 · self-declared |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/io-github-nizoka-pdfnative-mcp)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-09-25 | Declared version: 1.6.0 → 1.7.0 |
|---|---|
| 2026-09-25 | Description (raw): PDF MCP server: generate PDF/A, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools → PDF MCP: generate PDF/A & PDF/X-4, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools |
| 2026-09-25 | Last changed in the registry (raw): 2026-08-23 → 2026-09-24 |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-nizoka-pdfnative-mcp