MCP低风险未认领
pdfnative MCP — PDF/A & PDF/X-4 generation, PAdES signing & introspection
PDF MCP: generate PDF/A & PDF/X-4, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools
Nizokanizoka/pdfnative-mcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.Nizoka/pdfnative-mcp",
"description": "PDF MCP: generate PDF/A & PDF/X-4, sign & verify PAdES (LTV), forms, merge, split, encrypt. 28 tools",
"title": "pdfnative MCP — PDF/A & PDF/X-4 generation, PAdES signing & introspection",
"repository": {
"url": "https://github.com/Nizoka/pdfnative-mcp",
"source": "github"
},
"version": "1.7.0",
"websiteUrl": "https://github.com/Nizoka/pdfnative-mcp#readme",
"packages": [
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "pdfnative-mcp",
"version": "1.7.0",
"runtimeHint": "npx",
"transport": {
"type": "stdio"
},
"runtimeArguments": [
{
"value": "-y",
"type": "positional",
"valueHint": "skip-confirm"
},
{
"value": "pdfnative-mcp",
"type": "positional",
"valueHint": "package"
}
],
"environmentVariables": [
{
"description": "Absolute path of a sandboxed directory where outputMode='file' may write PDFs. Unset: every tool returns base64 only (file output disabled).",
"format": "filepath",
"name": "PDFNATIVE_MCP_OUTPUT_DIR"
},
{
"description": "Opt-in content-addressed response cache directory (SHA-256 keyed, 1h TTL, 256 MiB LRU, plaintext at rest). Never caches encrypt/decrypt, sign, timestamp, add_ltv, update_metadata, encrypted builds or file output.",
"format": "filepath",
"name": "PDFNATIVE_MCP_CACHE_DIR"
},
{
"description": "Serve Streamable HTTP on this loopback port instead of stdio (MCP 2026-07-28, stateless). Unauthenticated unless PDFNATIVE_MCP_HTTP_TOKEN is set.",
"format": "number",
"name": "PDFNATIVE_MCP_PORT"
},
{
"description": "Opt-in bearer token for the HTTP transport (>= 16 chars, no whitespace). When set, /mcp requires 'Authorization: Bearer <token>' or answers 401. Never logged.",
"isSecret": true,
"name": "PDFNATIVE_MCP_HTTP_TOKEN"
},
{
"description": "Per-stream FlateDecode decompression cap in bytes (zip-bomb mitigation; default 104857600 = 100 MiB). Integer >= 1024; an invalid value refuses to start the server.",
"format": "number",
"name": "PDFNATIVE_MCP_MAX_INFLATE_BYTES"
},
{
"description": "ISO 8601 instant with a time zone (e.g. 2026-01-01T00:00:00Z) pinned as the creation date of every generated document: reproducible bytes on any host. A call's own creationDate still wins. An invalid value refuses to start the server.",
"name": "PDFNATIVE_MCP_CREATION_DATE"
},
{
"description": "reproducible-builds.org convention: integer seconds since the Unix epoch, used as the pinned creation date when PDFNATIVE_MCP_CREATION_DATE is unset. An invalid value refuses to start the server.",
"format": "number",
"name": "SOURCE_DATE_EPOCH"
},
{
"description": "http(s) URL of the RFC 3161 timestamp authority used by sign_pdf timestamp=true and timestamp_pdf (PAdES B-T / B-LTA). Unset: those calls fail with TSA_NOT_CONFIGURED and no network request is made. Tool arguments can never supply a URL.",
"name": "PDFNATIVE_MCP_TSA_URL"
},
{
"description": "Optional Authorization header value sent to the TSA (e.g. 'Basic ...' or 'Bearer ...'). Never logged or echoed.",
"isSecret": true,
"name": "PDFNATIVE_MCP_TSA_AUTH"
},
{
"description": "'ocsp', 'crl' or 'ocsp,crl': enables online revocation collection for add_ltv mode='online' (PAdES B-LT). Unset: that mode fails with REVOCATION_NOT_CONFIGURED; mode='offline' stays fully offline. Requires PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS.",
"choices": [
"ocsp",
"crl",
"ocsp,crl"
],
"name": "PDFNATIVE_MCP_REVOCATION"
},
{
"description": "Comma-separated allow-list of OCSP / CRL responder hosts ('host', 'host:port' or '*.suffix'). Mandatory when PDFNATIVE_MCP_REVOCATION is set: responder URLs found in certificates are fetched only if the host matches (http(s) only, no credentials, no redirects, internal addresses rejected unless listed verbatim).",
"name": "PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS"
},
{
"description": "Per-request timeout for TSA / OCSP / CRL calls in milliseconds, 1000-120000 (default 10000).",
"format": "number",
"name": "PDFNATIVE_MCP_NETWORK_TIMEOUT_MS"
}
]
}
],
"_meta": {
"io.modelcontextprotocol.registry/publisher-provided": {
"com.github": {
"serverDisplayName": "pdfnative MCP"
},
"io.github.nizoka.publisher": {
"engine": "pdfnative@1.8",
"keywords": [
"pdf",
"pdf-a",
"pdf-ua",
"pdf-x-4",
"pades",
"digital-signature",
"rfc3161",
"ocsp",
"crl",
"acroform",
"merge-pdf",
"split-pdf",
"encrypt-pdf",
"barcode",
"qrcode",
"svg",
"factur-x",
"zugferd",
"cmyk",
"typography",
"reproducible-builds",
"source-date-epoch",
"unicode"
],
"license": "MIT",
"mcpProtocol": "2026-07-28",
"network": "none by default (opt-in RFC 3161 TSA, OCSP/CRL)",
"promptCount": 7,
"releaseHighlights": [
"PDF/X-4 output and validation",
"typography options on 9 document tools",
"CMYK colours everywhere",
"27 Unicode scripts",
"reproducible creation date via PDFNATIVE_MCP_CREATION_DATE / SOURCE_DATE_EPOCH",
"new typography prompt"
],
"standards": [
"PDF/A",
"PDF/UA-1",
"PDF/X-4",
"PAdES B-B to B-LTA",
"ISO 32000-1"
],
"tool": "mcp-publisher",
"toolCount": 28,
"toolVersion": "1.7.9",
"transports": [
"stdio",
"streamable-http"
]
}
}
}
}权限
声明检测
运行代码—
node安装—
npm:pdfnative-mcp@1.7.0安装时运行脚本—无
网络无无
需要的凭据
PDFNATIVE_MCP_HTTP_TOKENPDFNATIVE_MCP_TSA_AUTHPDFNATIVE_MCP_HTTP_TOKENPDFNATIVE_MCP_TSA_AUTH工作区外的路径—无
智能体工具—无
检查
低风险 · 没有发现需要提醒的地方。
未经人工审核 · 已做规则检查;模型审核尚未开启。
版本
- #11.7.0最新2026年10月7日
pdfnative MCP — PDF/A & PDF/X-4 generation, PAdES signing & introspection在 Codeg 中打开