Universal PDF coverage — inspect, extract, generate, convert, manipulate, secure, and fill in one binary.
mcp-pdf
The PDF Operating Layer for AI Agents
What it gives an agent
A purpose-built capability behind one MCP connection.
The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.
High fidelity — pdf_oxide for extraction (100% pass rate on 3,830 PDFs), printpdf for generation.
Cross-viewer compatible — all output works in Safari, Preview, Chrome, and Acrobat.
Zero system dependencies — pure Rust. No LibreOffice, no Tesseract, no pdfium required.
Local-first — no cloud calls, no API keys, no data leaves your machine.
Registry-ready — ships with mcp-server.toml for automatic ADK-Rust Enterprise onboarding.
Architecture
How mcp-pdf fits into an agent system.
The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.
ADK-Rust agent
Chooses a capability from the reviewed tool catalog.
MCP client
Discovers schemas, sends calls, and receives typed content.
mcp-pdf
Validates the request and owns 57 documented tool contracts.
Domain system
Keeps the API, data, credentials, and business rules behind the server.
From the project documentation
The server’s published architecture
Tool catalog
What can an agent ask mcp-pdf to do?
Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.
57 named tools
inspect_pdfFull structural profile (pages, fonts, forms, signatures)
see documentationclassify_pdfIdentify document type (invoice, contract, form, scan)
see documentationhealth_check_pdfDetect corruption, xref errors, broken objects
see documentationdetect_featuresReport forms, tags, signatures, JavaScript, embedded files
see documentationprofile_complexityRate extraction difficulty (1-5 scale)
see documentationget_page_countNumber of pages
see documentationget_infoQuick metadata (pages, size, version, title, author)
see documentationrepair_pdfRebuild xref, fix streams, recover corrupted PDFs
see documentationextract_textAll text from PDF
see documentationextract_page_textText from a specific page
see documentationextract_metadataTitle, author, dates, creator, producer, XMP
see documentationextract_tablesTables as JSON arrays with headers and rows
see documentationGovernance
Understand the effect of every tool.
A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.
- Encryption — AES-128 R4 with proper O/U value computation (PDF spec compliant)
- Redaction — True content removal via lopdf replace_partial_text (not visual masking)
- Sanitization — Removes JavaScript, actions, embedded files, metadata in one call
- PII scanning — Regex-based detection of emails, phones, SSNs, credit cards
MCP surface
What the current documentation declares.
MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.
Install and connect
Follow the project’s documented starting point.
Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.
cargo install mcp-pdf{
"mcpServers": {
"pdf": {
"command": "mcp-pdf"
}
}
}Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.
Official documentation
Continue with the project maintainers’ source of truth.
This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.
Keep exploring
More in data & content.
Source record
Release and repository metadata for this catalog entry.
- Version
- 3.0.0
- License
- Apache-2.0
- Tools
- 57
- Revision
- 7209969f9279
- Updated
- May 26, 2026