PDF.net MCP server icon

PDF.net

by PDF.net

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity20 tools

Generate, edit, merge, split, convert and organize PDFs in a cloud document library from an AI agent. Anthropic lists 20 tools; PDF.net publishes capabilities, not tool names. OAuth sign-in with one service-wide scope, and one tool permanently deletes.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect PDF.net via MCP

https://mcp.pdf.net/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

PDF.net Tools & Capabilities (20)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • One scope covers everything. The server's RFC 9728 descriptor advertises pdfnet.mcp and offline_access, and its authorization server metadata repeats the same pair. Neither names a verb or an object. No boundary falls between listing your library and deleting a folder from it — the one place a scope split would have mattered on this surface.
  • PDF.net publishes no tool list. The 20 names come from Anthropic's directory. The vendor's documentation describes nine capabilities in prose and prints no tool name, so the two enumerations can only be matched semantically and a rename would not be detectable.
  • We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so no parameter-level detail is published here, and the read/write split is our classification rather than the server's declaration.
  • delete_resource is ambiguous about its target. The name says resource; PDF.net's capability table groups documents and folders together under Organize. A single call may remove a folder.
  • Nothing restores. No tool empties or recovers from the recycle bin. Undoing an agent's deletion is a web-app action within the thirty-day window.
  • No retention control exists in the surface. PDF.net documents no per-document expiry, and no tool sets one. A processed contract persists for as long as the account does.
  • The MCP app widget was not audited. The directory marks has_mcp_app: true; the bundle is served over the authenticated session and we could not read it. Treat the click-driven surface as unknown.
  • Whether a download link is public is unresolved. PDF.net documents download_pdf_document returning a direct link and does not state whether it is session-scoped, time-limited or openable by anyone. We did not call the tool.
  • Four capabilities are excluded by the vendor. E-signing, annotations, form filling and password protection are unavailable through the connector; requests for them return a link into the web app instead.
  • No usage or plan tool exists. get_profile is the only account-reading tool and PDF.net does not document it exposing quota or plan state.
  • No published rate limits. We found no PDF.net documentation of request-rate limits, retry behaviour or 429 handling for the MCP server or its API.
  • No compliance certifications are published. PDF.net's security page describes encryption, access controls and subprocessors but names no SOC 2, ISO 27001 or HIPAA attestation, and mentions a Data Processing Agreement without linking a resolvable copy.
  • Trials auto-renew and cancellation is not self-service. PDF.net's Terms of Use state a trial converts to a recurring monthly subscription unless cancelled by phone or email.

Frequently asked questions

It works on documents already there, and it can bring in more. Every tool acts on your PDF.net cloud library rather than your disk. Two tools add to it: import_file_from_url fetches a URL server-side, and generate_pdf_document writes a new file. PDF.net states documents are encrypted at rest with AES-256 and are not used to train models.

Indefinitely, until you delete it. PDF.net's retention policy states documents are retained while the account is active and the user has not deleted them. Deleting moves a file to a recycle bin recoverable for thirty days, then permanent erasure. There is no automatic expiry for documents in an active account, and no tool sets a retention period.

It can delete them; recovery is a separate step you take yourself. delete_resource is the one destructive tool among the twenty and its name does not say whether it hits a folder or a file. PDF.net's policy puts deleted documents in a recycle bin for thirty days, so an agent's mistake is recoverable — but only from the web app, since no tool restores.

Not from the connector, on the evidence available. download_pdf_document returns a download link, and PDF.net's help article says the assistant gives you one. No tool carries a share verb, and PDF.net's separate Share PDF product, whose links open without an account, is not represented in the tool list. Whether a download link authenticates was not established.

No, not today. PDF.net states the MCP connector is available on all plans including free, and that the MCP server is free to use today. No tool name contains credit, balance, usage, quota or billing, so nothing observes spend either. The word today is PDF.net's own, so treat free as current policy rather than a commitment.

One service-wide permission and a refresh token. The server's RFC 9728 descriptor advertised pdfnet.mcp and offline_access on 2026-08-23. Neither names a verb or an object, so no boundary falls between listing your library and deleting a folder from it. Consent is all-or-nothing across every document in the account.

Twenty, according to Anthropic's directory, which is the only enumeration that exists. PDF.net's help article publishes a nine-row capability table describing what the connector does, and never prints a single tool name. So there is no second list of names to diff, and a rename between the two would be invisible.

E-signing, annotations, form filling and password protection. PDF.net's own troubleshooting section names those four as unavailable through the connector, and states the assistant will instead hand you a link to open the document in the web editor. Two tools, open_in_web_editor and open_pdf_document_manager, appear to be that handoff path.

Yes, and that is worth pricing in before approving it. list_document_tree walks the library and find_in_documents searches across documents, so an agent that can call either sees everything in the account, not only the file you named. PDF.net states the connector reaches your library only, and never another user's account.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
PDF.net
Tools
20
Domain
mcp.pdf.net

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.