Skip to content

Paperless MCP

Local package path declaredNo credentials listedRepository declared by sourceUpdated 2026-09-21

io.github.pvliesdonk/paperless-mcp · Registry status: active

Report data on this entry

At a glance

Paperless-NGX over MCP: search, read, upload and tag documents; manage correspondents and types.

Vendor's own description, untranslated and unverified

Execution location
Local package path declaredMCP-Register · 2026-09-18
Required secrets declared
No credentials listedMCP-Register · 2026-09-18
Declared version and change
3.0.0 · Source-reported change date 2026-09-21MCP-Register · 2026-09-22
Repository as declared
github.com/pvliesdonk/paperless-mcpMCP-Register · 2026-09-18
Configuration
can be built from the disclosed start template

Inspect connection paths and prerequisites

Related categories

6 of 11 categories. All categories in the segment catalogue

Page last changed:

Sources and collection
Runs
Local package path declared
Credentials
No credentials listed
Registry record changed
2026-09-21
Setup
Template available
Registry name
io.github.pvliesdonk/paperless-mcp
Package coordinate
pypi:pvliesdonk-paperless-mcp
Declared version
3.0.0
Source-reported listing date
2026-09-21
Source-reported change date
2026-09-21
First seen by tracevero
2026-09-18
Vendor's website
https://pvliesdonk.github.io/paperless-mcp/

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean

Measured values

Measured values
Required secrets declaredNo credentials listed no
Original data – Required secret variables (raw): confirmed absent
Original data – Required secret headers (raw): confirmed absent
Source: MCP-Register · collected on 2026-09-18 · derived
Execution locationLocal package path declared local
Original data – Transports (raw): stdio, streamable-http
Source: MCP-Register · collected on 2026-09-18 · derived
Path argument presentyes
Original data – Path arguments (raw): confirmed absent
Original data – Path environment variables (raw): PAPERLESS_MCP_BEARER_TOKENS_FILE
Source: MCP-Register · collected on 2026-09-18 · derived
Repository URL listedRepository declared by source yes
Original data – Repository (raw): https://github.com/pvliesdonk/paperless-mcp
Source: MCP-Register · collected on 2026-09-18 · derived
Field of use, derived from the vendor descriptionDocuments
Original data – Description (raw): Paperless-NGX over MCP: search, read, upload and tag documents; manage correspondents and types.
Source: MCP-Register · collected on 2026-09-18 · derived
Declared version3.0.0
Source: MCP-Register · collected on 2026-09-22 · self-declared

What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.

Source data25

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.

Raw values
Description (raw)Paperless-NGX over MCP: search, read, upload and tag documents; manage correspondents and types.
Source: MCP-Register · collected on 2026-09-18 · self-declared
Environment variables (raw)PAPERLESS_MCP_KV_STORE_URL, PAPERLESS_MCP_TOOLS_ALLOW, PAPERLESS_MCP_TOOLS_DENY, PAPERLESS_MCP_SERVER_NAME, PAPERLESS_MCP_INSTANCE_DESCRIPTION, PAPERLESS_MCP_INSTRUCTIONS_EXTRA, PAPERLESS_MCP_INSTRUCTIONS, PAPERLESS_MCP_LOG_LEVEL, PAPERLESS_MCP_LOG_FORMAT, PAPERLESS_MCP_PAPERLESS_URL, PAPERLESS_MCP_API_TOKEN, PAPERLESS_MCP_HTTP_TIMEOUT_SECONDS, PAPERLESS_MCP_HTTP_RETRIES, PAPERLESS_MCP_DEFAULT_PAGE_SIZE, PAPERLESS_MCP_PAPERLESS_PUBLIC_URL, PAPERLESS_MCP_TRANSFER_TTL_DEFAULT_S, PAPERLESS_MCP_TRANSFER_TTL_MAX_S, PAPERLESS_MCP_TRANSFER_GRACE_TTL_S, PAPERLESS_MCP_TRANSFER_LEASE_S, PAPERLESS_MCP_TRANSFER_MAX_UPLOAD_BYTES, PAPERLESS_MCP_SHUTDOWN_GRACE_S, PAPERLESS_MCP_BASE_URL, PAPERLESS_MCP_BEARER_TOKEN, PAPERLESS_MCP_OIDC_CONFIG_URL, PAPERLESS_MCP_OIDC_CLIENT_ID, PAPERLESS_MCP_OIDC_CLIENT_SECRET, PAPERLESS_MCP_OIDC_AUDIENCE, PAPERLESS_MCP_OIDC_REQUIRED_SCOPES, PAPERLESS_MCP_OIDC_ADVERTISED_SCOPES, PAPERLESS_MCP_OIDC_JWT_SIGNING_KEY, PAPERLESS_MCP_OIDC_VERIFY_ACCESS_TOKEN, PAPERLESS_MCP_KV_STORE_URL, PAPERLESS_MCP_APP_DOMAIN, PAPERLESS_MCP_TOOLS_ALLOW, PAPERLESS_MCP_TOOLS_DENY, PAPERLESS_MCP_AUTH_MODE, PAPERLESS_MCP_BEARER_TOKENS_FILE, PAPERLESS_MCP_BEARER_DEFAULT_SUBJECT, PAPERLESS_MCP_SERVER_NAME, PAPERLESS_MCP_INSTANCE_DESCRIPTION, PAPERLESS_MCP_INSTRUCTIONS_EXTRA, PAPERLESS_MCP_INSTRUCTIONS, PAPERLESS_MCP_HTTP_PATH, PAPERLESS_MCP_HEALTH_DETAIL, PUID, PGID, PAPERLESS_MCP_LOG_LEVEL, PAPERLESS_MCP_LOG_FORMAT, PAPERLESS_MCP_PAPERLESS_URL, PAPERLESS_MCP_API_TOKEN, PAPERLESS_MCP_HTTP_TIMEOUT_SECONDS, PAPERLESS_MCP_HTTP_RETRIES, PAPERLESS_MCP_DEFAULT_PAGE_SIZE, PAPERLESS_MCP_PAPERLESS_PUBLIC_URL, PAPERLESS_MCP_TRANSFER_TTL_DEFAULT_S, PAPERLESS_MCP_TRANSFER_TTL_MAX_S, PAPERLESS_MCP_TRANSFER_GRACE_TTL_S, PAPERLESS_MCP_TRANSFER_LEASE_S, PAPERLESS_MCP_TRANSFER_MAX_UPLOAD_BYTES
Source: MCP-Register · collected on 2026-09-22 · self-declared
Required secret variables (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Transports (raw)stdio, streamable-http
Source: MCP-Register · collected on 2026-09-18 · self-declared
Path arguments (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Repository (raw)https://github.com/pvliesdonk/paperless-mcp
Source: MCP-Register · collected on 2026-09-18 · self-declared
Package registries (raw)oci, pypi
Source: MCP-Register · collected on 2026-09-18 · self-declared
Required secret headers (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Path environment variables (raw)PAPERLESS_MCP_BEARER_TOKENS_FILE
Source: MCP-Register · collected on 2026-09-18 · self-declared
Remote URLs (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Remote hosts (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Registry status message (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
First listed in the registry (raw)2026-09-21
Source: MCP-Register · collected on 2026-09-22 · self-declared
Last changed in the registry (raw)2026-09-21
Source: MCP-Register · collected on 2026-09-22 · self-declared
Schema version of the raw record (raw)https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
Source: MCP-Register · collected on 2026-09-18 · self-declared
Delivery form (raw)package
Source: MCP-Register · collected on 2026-09-18 · self-declared
Repository platform (raw)github
Source: MCP-Register · collected on 2026-09-18 · self-declared
Repository subfolder (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Package identifiers (raw)ghcr.io/pvliesdonk/paperless-mcp:v3.0.0, pvliesdonk-paperless-mcp
Source: MCP-Register · collected on 2026-09-22 · self-declared
Package versions (raw)3.0.0
Source: MCP-Register · collected on 2026-09-22 · self-declared
Runtime hints (raw)uvx
Source: MCP-Register · collected on 2026-09-18 · self-declared
Environment variable formats (raw)boolean, filepath, number
Source: MCP-Register · collected on 2026-09-18 · self-declared
Environment variable descriptions (raw)PAPERLESS_MCP_API_TOKEN=Paperless service-account token used for outbound API requests. The server refuses to start without it. · PAPERLESS_MCP_APP_DOMAIN=MCP Apps iframe domain, used for CSP sandboxing. Overrides the host derived from `base_url`. · PAPERLESS_MCP_AUTH_MODE=Explicit auth-mode override, accepting `remote` or `oidc-proxy` (case- and whitespace-insensitive). When unset the mode is auto-detected from which auth variables are set; the override exists because having all four OIDC variables set is ambiguous between those two modes. Other values are ignored with a warning. · PAPERLESS_MCP_BASE_URL=Public base URL of the deployed server, for example `https://mcp.example.com`. Required for OIDC. Also the fallback source of the MCP Apps domain when `app_domain` is unset. · PAPERLESS_MCP_BEARER_DEFAULT_SUBJECT=Subject assigned to the single-token bearer mode; ignored when `bearer_tokens_file` is set, since mapped mode carries per-token subjects. · PAPERLESS_MCP_BEARER_TOKEN=Single shared bearer token; enables bearer auth unless `bearer_tokens_file` is set, which takes precedence. · PAPERLESS_MCP_BEARER_TOKENS_FILE=Path to a TOML file mapping bearer tokens to subjects; overrides the single-token `bearer_token` mode. · PAPERLESS_MCP_DEFAULT_PAGE_SIZE=Default page size for list tools, from 1 through 100. · PAPERLESS_MCP_HEALTH_DETAIL=How much the unauthenticated /health and /health/ready bodies say: status, standard (adds name, version and per-check verdicts), or full (adds redacted reasons; trusted networks only). · PAPERLESS_MCP_HTTP_PATH=Mount path for the MCP endpoint; the health routes derive their prefix from it. · PAPERLESS_MCP_HTTP_RETRIES=Retries for idempotent requests after network errors or 5xx responses. · PAPERLESS_MCP_HTTP_TIMEOUT_SECONDS=Per-request HTTP timeout in seconds. · PAPERLESS_MCP_INSTANCE_DESCRIPTION=Concise routing context that distinguishes this deployment's material or responsibility. · PAPERLESS_MCP_INSTRUCTIONS=Legacy: replaces all generated MCP instructions (deprecated; use _INSTANCE_DESCRIPTION for routing and _INSTRUCTIONS_EXTRA for policy). · PAPERLESS_MCP_INSTRUCTIONS_EXTRA=Deployment-specific behavioral policy added to the generated MCP instructions. · PAPERLESS_MCP_KV_STORE_URL=Persistent-state backend URL shared by every pvl-core subsystem that needs state. `memory://` is in-process and lost on restart; `file:///path` persists on one server; `redis://`, `dynamodb://` and `mongodb://` each need their matching extra. When unset, defaults to `file:///data/state` (the volume family Docker images mount), or to `memory://` (with a warning) on a host where that directory is not usable. · PAPERLESS_MCP_LOG_FORMAT=Log rendering. rich is one colour event key=value line per record, for a terminal; json is one JSON object per record, for a collector. Unset picks rich when stderr is a terminal and json everywhere else, so a container or journald gets JSON with no configuration. · PAPERLESS_MCP_LOG_LEVEL=Log level for every logger in the process, FastMCP's included (DEBUG / INFO / WARNING / ERROR / CRITICAL). The -v CLI flag overrides to DEBUG. The unprefixed FASTMCP_LOG_LEVEL still works for one major version and logs a deprecation warning. · PAPERLESS_MCP_OIDC_ADVERTISED_SCOPES=Scopes advertised to MCP clients in protected-resource metadata, space- or comma-separated. Overrides the default `openid offline_access`; `oidc_required_scopes` is always added on top. Set this when the registered client is not permitted `offline_access`, or to have clients request extra claim scopes (such as `groups`) without also requiring them in every token. · PAPERLESS_MCP_OIDC_AUDIENCE=Expected `aud` claim; tokens issued for another audience are rejected. · PAPERLESS_MCP_OIDC_CLIENT_ID=OIDC client identifier registered with the provider. · PAPERLESS_MCP_OIDC_CLIENT_SECRET=OIDC client secret registered with the provider. · PAPERLESS_MCP_OIDC_CONFIG_URL=OIDC discovery document URL, for example `https://auth.example.com/.well-known/openid-configuration`. · PAPERLESS_MCP_OIDC_JWT_SIGNING_KEY=Signing key for issued tokens; used in oidc-proxy mode only. When unset, the key is derived deterministically from `oidc_client_secret`, so tokens survive a restart. Rotating that secret then invalidates every issued token. Set this explicitly to decouple token validity from secret rotation. Generate with `openssl rand -hex 32`. · PAPERLESS_MCP_OIDC_REQUIRED_SCOPES=Scopes a caller must present, space- or comma-separated. Defaults to `openid` in oidc-proxy mode. · PAPERLESS_MCP_OIDC_VERIFY_ACCESS_TOKEN=Validate the access token instead of the id token. · PAPERLESS_MCP_PAPERLESS_PUBLIC_URL=Public Paperless UI URL for user-visible links; defaults to PAPERLESS_URL. · PAPERLESS_MCP_PAPERLESS_URL=Base URL of the Paperless-NGX REST API, without a trailing slash. The server refuses to start without it. · PAPERLESS_MCP_SERVER_NAME=Rename this server instance; defaults to the project name. · PAPERLESS_MCP_SHUTDOWN_GRACE_S=Seconds SIGTERM may spend draining in-flight requests before the HTTP server exits. Keep it at or below the termination grace period the orchestrator allows. `0` drops in-flight requests immediately. · PAPERLESS_MCP_TOOLS_ALLOW=Comma-separated explicit tool names this instance exposes; every other tool is hidden from listings and cannot be invoked. Names matching no registered tool are inert. Mutually exclusive with `tools_deny`. Takes effect through `apply_tool_visibility`. · PAPERLESS_MCP_TOOLS_DENY=Comma-separated explicit tool names hidden from this instance (absent from listings, cannot be invoked). Names matching no registered tool are inert. Mutually exclusive with `tools_allow`. Takes effect through `apply_tool_visibility`. · PAPERLESS_MCP_TRANSFER_GRACE_TTL_S=Post-success grace window in seconds: a served token's TTL shrinks to this so a stalled transfer can retry within it. · PAPERLESS_MCP_TRANSFER_LEASE_S=Crashed-handler reclaim window in seconds for an in-flight reservation. · PAPERLESS_MCP_TRANSFER_MAX_UPLOAD_BYTES=Maximum size in bytes of a single upload. · PAPERLESS_MCP_TRANSFER_TTL_DEFAULT_S=Link lifetime in seconds when the caller requests no explicit TTL. · PAPERLESS_MCP_TRANSFER_TTL_MAX_S=Ceiling in seconds a caller-requested link TTL is clamped to. · PGID=Run the server process as this GID; pair with PUID to match the owner of a mounted volume. · PUID=Run the server process as this UID; the container entrypoint reassigns ownership of writable paths to match.
Source: MCP-Register · collected on 2026-09-22 · self-declared
Icon formats (raw)confirmed absent
Source: MCP-Register · collected on 2026-09-18 · self-declared
Connection paths (source structure){"packages":[{"registryType":"pypi","identifier":"pvliesdonk-paperless-mcp","version":"3.0.0","runtimeHint":"uvx","transport":"stdio","environment":[{"name":"PAPERLESS_MCP_KV_STORE_URL","description":"Persistent-state backend URL shared by every pvl-core subsystem that needs state. `memory://` is in-process and lost on restart; `file:///path` persists on one server; `redis://`, `dynamodb://` and `mongodb://` each need their matching extra. When unset, defaults to `file:///data/state` (the volume family Docker images mount), or to `memory://` (with a warning) on a host where that directory is not usable.","required":false,"secret":false},{"name":"PAPERLESS_MCP_TOOLS_ALLOW","description":"Comma-separated explicit tool names this instance exposes; every other tool is hidden from listings and cannot be invoked. Names matching no registered tool are inert. Mutually exclusive with `tools_deny`. Takes effect through `apply_tool_visibility`.","required":false,"secret":false},{"name":"PAPERLESS_MCP_TOOLS_DENY","description":"Comma-separated explicit tool names hidden from this instance (absent from listings, cannot be invoked). Names matching no registered tool are inert. Mutually exclusive with `tools_allow`. Takes effect through `apply_tool_visibility`.","required":false,"secret":false},{"name":"PAPERLESS_MCP_SERVER_NAME","description":"Rename this server instance; defaults to the project name.","required":false,"secret":false},{"name":"PAPERLESS_MCP_INSTANCE_DESCRIPTION","description":"Concise routing context that distinguishes this deployment's material or responsibility.","required":false,"secret":false},{"name":"PAPERLESS_MCP_INSTRUCTIONS_EXTRA","description":"Deployment-specific behavioral policy added to the generated MCP instructions.","required":false,"secret":false},{"name":"PAPERLESS_MCP_INSTRUCTIONS","description":"Legacy: replaces all generated MCP instructions (deprecated; use _INSTANCE_DESCRIPTION for routing and _INSTRUCTIONS_EXTRA for policy).","required":false,"secret":false},{"name":"PAPERLESS_MCP_LOG_LEVEL","description":"Log level for every logger in the process, FastMCP's included (DEBUG / INFO / WARNING / ERROR / CRITICAL). The -v CLI flag overrides to DEBUG. The unprefixed FASTMCP_LOG_LEVEL still works for one major version and logs a deprecation warning.","required":false,"secret":false},{"name":"PAPERLESS_MCP_LOG_FORMAT","description":"Log rendering. rich is one colour event key=value line per record, for a terminal; json is one JSON object per record, for a collector. Unset picks rich when stderr is a terminal and json everywhere else, so a container or journald gets JSON with no configuration.","required":false,"secret":false},{"name":"PAPERLESS_MCP_PAPERLESS_URL","description":"Base URL of the Paperless-NGX REST API, without a trailing slash. The server refuses to start without it.","required":false,"secret":false},{"name":"PAPERLESS_MCP_API_TOKEN","description":"Paperless service-account token used for outbound API requests. The server refuses to start without it.","required":false,"secret":true},{"name":"PAPERLESS_MCP_HTTP_TIMEOUT_SECONDS","description":"Per-request HTTP timeout in seconds.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_HTTP_RETRIES","description":"Retries for idempotent requests after network errors or 5xx responses.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_DEFAULT_PAGE_SIZE","description":"Default page size for list tools, from 1 through 100.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_PAPERLESS_PUBLIC_URL","description":"Public Paperless UI URL for user-visible links; defaults to PAPERLESS_URL.","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_TTL_DEFAULT_S","description":"Link lifetime in seconds when the caller requests no explicit TTL.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_TTL_MAX_S","description":"Ceiling in seconds a caller-requested link TTL is clamped to.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_GRACE_TTL_S","description":"Post-success grace window in seconds: a served token's TTL shrinks to this so a stalled transfer can retry within it.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_LEASE_S","description":"Crashed-handler reclaim window in seconds for an in-flight reservation.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_MAX_UPLOAD_BYTES","description":"Maximum size in bytes of a single upload.","format":"number","required":false,"secret":false}],"additional_arguments_declared":false},{"registryType":"oci","identifier":"ghcr.io/pvliesdonk/paperless-mcp:v3.0.0","transport":"streamable-http","environment":[{"name":"PAPERLESS_MCP_SHUTDOWN_GRACE_S","description":"Seconds SIGTERM may spend draining in-flight requests before the HTTP server exits. Keep it at or below the termination grace period the orchestrator allows. `0` drops in-flight requests immediately.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_BASE_URL","description":"Public base URL of the deployed server, for example `https://mcp.example.com`. Required for OIDC. Also the fallback source of the MCP Apps domain when `app_domain` is unset.","required":false,"secret":false},{"name":"PAPERLESS_MCP_BEARER_TOKEN","description":"Single shared bearer token; enables bearer auth unless `bearer_tokens_file` is set, which takes precedence.","required":false,"secret":true},{"name":"PAPERLESS_MCP_OIDC_CONFIG_URL","description":"OIDC discovery document URL, for example `https://auth.example.com/.well-known/openid-configuration`.","required":false,"secret":false},{"name":"PAPERLESS_MCP_OIDC_CLIENT_ID","description":"OIDC client identifier registered with the provider.","required":false,"secret":false},{"name":"PAPERLESS_MCP_OIDC_CLIENT_SECRET","description":"OIDC client secret registered with the provider.","required":false,"secret":true},{"name":"PAPERLESS_MCP_OIDC_AUDIENCE","description":"Expected `aud` claim; tokens issued for another audience are rejected.","required":false,"secret":false},{"name":"PAPERLESS_MCP_OIDC_REQUIRED_SCOPES","description":"Scopes a caller must present, space- or comma-separated. Defaults to `openid` in oidc-proxy mode.","required":false,"secret":false},{"name":"PAPERLESS_MCP_OIDC_ADVERTISED_SCOPES","description":"Scopes advertised to MCP clients in protected-resource metadata, space- or comma-separated. Overrides the default `openid offline_access`; `oidc_required_scopes` is always added on top. Set this when the registered client is not permitted `offline_access`, or to have clients request extra claim scopes (such as `groups`) without also requiring them in every token.","required":false,"secret":false},{"name":"PAPERLESS_MCP_OIDC_JWT_SIGNING_KEY","description":"Signing key for issued tokens; used in oidc-proxy mode only. When unset, the key is derived deterministically from `oidc_client_secret`, so tokens survive a restart. Rotating that secret then invalidates every issued token. Set this explicitly to decouple token validity from secret rotation. Generate with `openssl rand -hex 32`.","required":false,"secret":true},{"name":"PAPERLESS_MCP_OIDC_VERIFY_ACCESS_TOKEN","description":"Validate the access token instead of the id token.","format":"boolean","required":false,"secret":false},{"name":"PAPERLESS_MCP_KV_STORE_URL","description":"Persistent-state backend URL shared by every pvl-core subsystem that needs state. `memory://` is in-process and lost on restart; `file:///path` persists on one server; `redis://`, `dynamodb://` and `mongodb://` each need their matching extra. When unset, defaults to `file:///data/state` (the volume family Docker images mount), or to `memory://` (with a warning) on a host where that directory is not usable.","required":false,"secret":false},{"name":"PAPERLESS_MCP_APP_DOMAIN","description":"MCP Apps iframe domain, used for CSP sandboxing. Overrides the host derived from `base_url`.","required":false,"secret":false},{"name":"PAPERLESS_MCP_TOOLS_ALLOW","description":"Comma-separated explicit tool names this instance exposes; every other tool is hidden from listings and cannot be invoked. Names matching no registered tool are inert. Mutually exclusive with `tools_deny`. Takes effect through `apply_tool_visibility`.","required":false,"secret":false},{"name":"PAPERLESS_MCP_TOOLS_DENY","description":"Comma-separated explicit tool names hidden from this instance (absent from listings, cannot be invoked). Names matching no registered tool are inert. Mutually exclusive with `tools_allow`. Takes effect through `apply_tool_visibility`.","required":false,"secret":false},{"name":"PAPERLESS_MCP_AUTH_MODE","description":"Explicit auth-mode override, accepting `remote` or `oidc-proxy` (case- and whitespace-insensitive). When unset the mode is auto-detected from which auth variables are set; the override exists because having all four OIDC variables set is ambiguous between those two modes. Other values are ignored with a warning.","required":false,"secret":false},{"name":"PAPERLESS_MCP_BEARER_TOKENS_FILE","description":"Path to a TOML file mapping bearer tokens to subjects; overrides the single-token `bearer_token` mode.","format":"filepath","required":false,"secret":false},{"name":"PAPERLESS_MCP_BEARER_DEFAULT_SUBJECT","description":"Subject assigned to the single-token bearer mode; ignored when `bearer_tokens_file` is set, since mapped mode carries per-token subjects.","required":false,"secret":false},{"name":"PAPERLESS_MCP_SERVER_NAME","description":"Rename this server instance; defaults to the project name.","required":false,"secret":false},{"name":"PAPERLESS_MCP_INSTANCE_DESCRIPTION","description":"Concise routing context that distinguishes this deployment's material or responsibility.","required":false,"secret":false},{"name":"PAPERLESS_MCP_INSTRUCTIONS_EXTRA","description":"Deployment-specific behavioral policy added to the generated MCP instructions.","required":false,"secret":false},{"name":"PAPERLESS_MCP_INSTRUCTIONS","description":"Legacy: replaces all generated MCP instructions (deprecated; use _INSTANCE_DESCRIPTION for routing and _INSTRUCTIONS_EXTRA for policy).","required":false,"secret":false},{"name":"PAPERLESS_MCP_HTTP_PATH","description":"Mount path for the MCP endpoint; the health routes derive their prefix from it.","required":false,"secret":false},{"name":"PAPERLESS_MCP_HEALTH_DETAIL","description":"How much the unauthenticated /health and /health/ready bodies say: status, standard (adds name, version and per-check verdicts), or full (adds redacted reasons; trusted networks only).","required":false,"secret":false},{"name":"PUID","description":"Run the server process as this UID; the container entrypoint reassigns ownership of writable paths to match.","format":"number","required":false,"secret":false},{"name":"PGID","description":"Run the server process as this GID; pair with PUID to match the owner of a mounted volume.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_LOG_LEVEL","description":"Log level for every logger in the process, FastMCP's included (DEBUG / INFO / WARNING / ERROR / CRITICAL). The -v CLI flag overrides to DEBUG. The unprefixed FASTMCP_LOG_LEVEL still works for one major version and logs a deprecation warning.","required":false,"secret":false},{"name":"PAPERLESS_MCP_LOG_FORMAT","description":"Log rendering. rich is one colour event key=value line per record, for a terminal; json is one JSON object per record, for a collector. Unset picks rich when stderr is a terminal and json everywhere else, so a container or journald gets JSON with no configuration.","required":false,"secret":false},{"name":"PAPERLESS_MCP_PAPERLESS_URL","description":"Base URL of the Paperless-NGX REST API, without a trailing slash. The server refuses to start without it.","required":false,"secret":false},{"name":"PAPERLESS_MCP_API_TOKEN","description":"Paperless service-account token used for outbound API requests. The server refuses to start without it.","required":false,"secret":true},{"name":"PAPERLESS_MCP_HTTP_TIMEOUT_SECONDS","description":"Per-request HTTP timeout in seconds.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_HTTP_RETRIES","description":"Retries for idempotent requests after network errors or 5xx responses.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_DEFAULT_PAGE_SIZE","description":"Default page size for list tools, from 1 through 100.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_PAPERLESS_PUBLIC_URL","description":"Public Paperless UI URL for user-visible links; defaults to PAPERLESS_URL.","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_TTL_DEFAULT_S","description":"Link lifetime in seconds when the caller requests no explicit TTL.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_TTL_MAX_S","description":"Ceiling in seconds a caller-requested link TTL is clamped to.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_GRACE_TTL_S","description":"Post-success grace window in seconds: a served token's TTL shrinks to this so a stalled transfer can retry within it.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_LEASE_S","description":"Crashed-handler reclaim window in seconds for an in-flight reservation.","format":"number","required":false,"secret":false},{"name":"PAPERLESS_MCP_TRANSFER_MAX_UPLOAD_BYTES","description":"Maximum size in bytes of a single upload.","format":"number","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
Source: MCP-Register · collected on 2026-09-22 · self-declared
Embed this badge

Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.

tracevero: number of measured values and date of collection for this registry entry

[![tracevero: number of measured values and date of collection for this registry entry](https://tracevero.com/badge/mcp/io-github-pvliesdonk-paperless-mcp.svg)](https://tracevero.com/mcp/io-github-pvliesdonk-paperless-mcp)

The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.

Changes

Changes
2026-09-22Declared version: 2.1.0 → 3.0.0
2026-09-22Last changed in the registry (raw): 2026-09-19 → 2026-09-21
2026-09-22First listed in the registry (raw): 2026-09-19 → 2026-09-21

These are the 3 most recent changes to this entry. Full history

tracevero · https://tracevero.com/mcp/io-github-pvliesdonk-paperless-mcp