Back to Browse

Pdf MCP Server

by Jztan
Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Production-ready MCP server for PDF processing with intelligent caching.

About

Production-ready MCP server for PDF processing with intelligent caching.

Security Report

5.2
Moderate5.2Moderate Risk

pdf-mcp is a well-engineered MCP server with solid security practices. Authentication is appropriately scoped for its use cases (optional token-based for HTTP mode, STDIO default), dependencies are carefully managed with security pins, and the codebase demonstrates good input validation and error handling. Some low-severity findings around broad exception handling and logging practices do not materially impact security. Supply chain analysis found 11 known vulnerabilities in dependencies (1 critical, 5 high severity). Package verification found 1 issue.

4 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

system_info

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Directory for storing PDF cache (default: ~/.cache/pdf-mcp)Optional

Environment variable: PDF_MCP_CACHE_DIR

Cache time-to-live in hours (default: 24)Optional

Environment variable: PDF_MCP_CACHE_TTL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jztan-pdf-mcp": {
      "env": {
        "PDF_MCP_CACHE_DIR": "your-pdf-mcp-cache-dir-here",
        "PDF_MCP_CACHE_TTL": "your-pdf-mcp-cache-ttl-here"
      },
      "args": [
        "-y",
        "pdf-mcp-demo-recorder"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

pdf-mcp

PyPI version Python 3.10+ License: MIT GitHub Issues CI codecov Downloads

Surgical PDF access for AI agents: search, read, and extract without flooding context.

An MCP server that lets Claude Code and other AI agents search a PDF by meaning or keyword, read only the pages that matter, and cleanly pull out tables, images, and scanned text, even from multi-column and Japanese layouts.

mcp-name: io.github.jztan/pdf-mcp

Try it in your browser

See what your AI agent sees →

Drop in any PDF, or a whole folder of them, and watch an agent triage the corpus, search across every document at once, and read only the pages that matter, using a fraction of the tokens. 100% client-side, no install required.

Why pdf-mcp?

Without pdf-mcpWith pdf-mcp
Large PDFsContext overflowRead only the pages you need
Finding contentLoad everythingHybrid search: BM25 keyword + semantic
Folders of PDFsOne document at a timeWarm, triage, and search a whole folder
Tables and chartsLost in raw textStructured rows, and (x, y) data from vector charts
Multi-column and vertical layoutsColumns interleavedCorrect reading order, including Japanese tategaki
Scanned PDFsNo text at allOCR via Tesseract, parallel across pages
Repeated accessRe-parse every timeSQLite cache that survives restarts
Hidden or injected textSilently ingestedFlagged as untrusted, nothing stripped

Installation

pip install pdf-mcp

That is the whole install: hybrid search, corpus tools, multi-column and CJK reading order all work out of the box.

OCR on scanned PDFs additionally needs system Tesseract:

brew install tesseract        # macOS
apt install tesseract-ocr     # Ubuntu/Debian
winget install Tesseract-OCR  # Windows

Quick Start

claude mcp add pdf-mcp -- pdf-mcp

Then ask Claude to read a PDF. For Claude Desktop, VS Code, Codex CLI, Kiro, or any other MCP client, see docs/clients.md.

Why this exists, and what broke along the way: Claude's 100-page PDF limit and how I got around it

Tools

13 specialized tools rather than one monolithic one. Typical pattern: pdf_info to plan, pdf_search to locate (its paragraph excerpts often answer the question outright), pdf_read_pages when you need more. For a folder, pdf_corpus_overview to triage, then pdf_corpus_search.

ToolWhat it does
pdf_infoPage count, metadata, TOC summary, scanned-page detection. Call first.
pdf_searchHybrid search (keyword + semantic), page or section granularity, paragraph or context-window excerpts with source coordinates
pdf_read_pagesRead specific pages or ranges, with OCR on demand, tables, and embedded images
pdf_read_allRead a whole document in one call, byte-capped
pdf_get_tocFull table of contents for documents with many bookmarks
pdf_render_pagesRender pages as PNG for vision models: diagrams, handwriting, scans
pdf_extract_chartChart data as exact (x, y) tables, read from plot geometry
pdf_corpus_warmWarm a folder of PDFs into the cache within a time budget
pdf_corpus_overviewPer-document triage cards for a folder
pdf_corpus_searchSearch across a folder, with document and page provenance; excerpt_style="auto" picks the excerpt unit per query
pdf_cache_statsPer-document cache breakdown and total size
pdf_cache_clearClear expired or all cache entries
server_infoWhich optional features and config are active

Text returned by any of these is untrusted content extracted from a PDF. pdf_info(content_trust=True) reports hidden text a human reader cannot see, and the read tools flag it per page.

Example prompts:

"Read the PDF at /path/to/document.pdf"
"Which pages discuss supply chain risks?"
"Find sections about the training process"
"Show me what page 5 looks like"
"OCR pages 3-5 of the scanned PDF"

Full reference, every parameter and response shape: docs/tool-reference.md. Embedding model selection: docs/embedding-models.md.

Example Workflow

For a large document (e.g., a 200-page annual report):

User: "Summarize the risk factors in this annual report"

Agent workflow:
1. pdf_info("report.pdf")
   → 200 pages, TOC shows "Risk Factors" on page 89

2. pdf_search("report.pdf", "risk factors")
   → Matches with structural paragraph excerpts: each excerpt
     is the bullet, paragraph, or heading that matched, not a
     fixed-width window. Often enough to answer directly.

3. If excerpts are sufficient → synthesize answer

4. If more context needed:
   pdf_read_pages("report.pdf", "89-95")
   → Full page text for deeper reading

Remote / HTTP transport

STDIO is the default and is what every example above uses. pdf-mcp-http serves the same tools over HTTP, for clients that cannot spawn a process (the Anthropic API MCP connector, claude.ai custom connectors) and for a warm corpus shared by several clients.

export PDF_MCP_AUTH_TOKEN="$(openssl rand -hex 32)"
pdf-mcp-http

Paths resolve on the server, so an HTTP agent reads what is already there: files under an allow-listed root, or a URL the server fetches. It cannot hand over a file from its own machine. It is single-tenant and fails closed: with no auth token and no [paths] allow list, the process exits rather than serving an open endpoint.

Docker images are published to GHCR for amd64 and arm64, with everything baked in, so every tool works on the first request:

./deploy.sh              # token, image, start, health-check
cp your.pdf documents/   # this folder is the server's /data/pdfs

Read docs/remote-access.md for the trust boundary and threat model before deploying, and docs/configuration.md for setup, client config, and token rotation.

Configuration

pdf-mcp works out of the box. To restrict which paths and URL hosts the server may touch, tune cache and worker settings, or add your own content-trust phrases, see docs/configuration.md.

Roadmap

See ROADMAP.md for planned features and release history.

Contributing

Contributions are welcome. See docs/contributing.md for setup, checks, the coherence eval harness, and quality-loop guidelines.

Contributors

Thank you to everyone who has helped improve this project through code, reviews, testing, and feature requests:

@Summer907 · @ebbsanchez · @VooDisss · @DerDennisOP · @deepdmk

Per-release contributor credits are listed in the Changelog.

Security

Found a vulnerability? See SECURITY.md for the threat model, reporting channel, and expected response timeline. Please do not open a public GitHub issue for unpatched security reports.

License

MIT. See LICENSE.

Links

Blog posts

The story behind the releases. Building pdf-mcp keeps surprising me: benchmarks that go the wrong way, formats that break everything, features I had to remove. I write about that thinking in The Dispatch. Come along if that's your kind of thing.

Background, benchmarks, and design notes from building pdf-mcp:

Getting started

Corpus & multi-document search

Search & retrieval

Engineering & security

Reviews

No reviews yet

Be the first to review this server!