PDF.net
by PDF.net
Generate, edit, merge, split, convert and organize PDFs in a cloud document library from an AI agent. Anthropic lists 20 tools; PDF.net publishes capabilities, not tool names. OAuth sign-in with one service-wide scope, and one tool permanently deletes.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Connect PDF.net via MCP
https://mcp.pdf.net/mcpWorks in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.
PDF.net Tools & Capabilities (20)
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
Limits
- One scope covers everything. The server's RFC 9728 descriptor advertises
pdfnet.mcpandoffline_access, and its authorization server metadata repeats the same pair. Neither names a verb or an object. No boundary falls between listing your library and deleting a folder from it — the one place a scope split would have mattered on this surface. - PDF.net publishes no tool list. The 20 names come from Anthropic's directory. The vendor's documentation describes nine capabilities in prose and prints no tool name, so the two enumerations can only be matched semantically and a rename would not be detectable.
- We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so no parameter-level detail is published here, and the read/write split is our classification rather than the server's declaration.
delete_resourceis ambiguous about its target. The name says resource; PDF.net's capability table groups documents and folders together under Organize. A single call may remove a folder.- Nothing restores. No tool empties or recovers from the recycle bin. Undoing an agent's deletion is a web-app action within the thirty-day window.
- No retention control exists in the surface. PDF.net documents no per-document expiry, and no tool sets one. A processed contract persists for as long as the account does.
- The MCP app widget was not audited. The directory marks
has_mcp_app: true; the bundle is served over the authenticated session and we could not read it. Treat the click-driven surface as unknown. - Whether a download link is public is unresolved. PDF.net documents
download_pdf_documentreturning a direct link and does not state whether it is session-scoped, time-limited or openable by anyone. We did not call the tool. - Four capabilities are excluded by the vendor. E-signing, annotations, form filling and password protection are unavailable through the connector; requests for them return a link into the web app instead.
- No usage or plan tool exists.
get_profileis the only account-reading tool and PDF.net does not document it exposing quota or plan state. - No published rate limits. We found no PDF.net documentation of request-rate limits, retry behaviour or
429handling for the MCP server or its API. - No compliance certifications are published. PDF.net's security page describes encryption, access controls and subprocessors but names no SOC 2, ISO 27001 or HIPAA attestation, and mentions a Data Processing Agreement without linking a resolvable copy.
- Trials auto-renew and cancellation is not self-service. PDF.net's Terms of Use state a trial converts to a recurring monthly subscription unless cancelled by phone or email.
Frequently asked questions
It works on documents already there, and it can bring in more. Every tool acts on your PDF.net cloud library rather than your disk. Two tools add to it: import_file_from_url fetches a URL server-side, and generate_pdf_document writes a new file. PDF.net states documents are encrypted at rest with AES-256 and are not used to train models.
Indefinitely, until you delete it. PDF.net's retention policy states documents are retained while the account is active and the user has not deleted them. Deleting moves a file to a recycle bin recoverable for thirty days, then permanent erasure. There is no automatic expiry for documents in an active account, and no tool sets a retention period.
It can delete them; recovery is a separate step you take yourself. delete_resource is the one destructive tool among the twenty and its name does not say whether it hits a folder or a file. PDF.net's policy puts deleted documents in a recycle bin for thirty days, so an agent's mistake is recoverable — but only from the web app, since no tool restores.
Not from the connector, on the evidence available. download_pdf_document returns a download link, and PDF.net's help article says the assistant gives you one. No tool carries a share verb, and PDF.net's separate Share PDF product, whose links open without an account, is not represented in the tool list. Whether a download link authenticates was not established.
No, not today. PDF.net states the MCP connector is available on all plans including free, and that the MCP server is free to use today. No tool name contains credit, balance, usage, quota or billing, so nothing observes spend either. The word today is PDF.net's own, so treat free as current policy rather than a commitment.
One service-wide permission and a refresh token. The server's RFC 9728 descriptor advertised pdfnet.mcp and offline_access on 2026-08-23. Neither names a verb or an object, so no boundary falls between listing your library and deleting a folder from it. Consent is all-or-nothing across every document in the account.
Twenty, according to Anthropic's directory, which is the only enumeration that exists. PDF.net's help article publishes a nine-row capability table describing what the connector does, and never prints a single tool name. So there is no second list of names to diff, and a rename between the two would be invisible.
E-signing, annotations, form filling and password protection. PDF.net's own troubleshooting section names those four as unavailable through the connector, and states the assistant will instead hand you a link to open the document in the web editor. Two tools, open_in_web_editor and open_pdf_document_manager, appear to be that handoff path.
Yes, and that is worth pricing in before approving it. list_document_tree walks the library and find_in_documents searches across documents, so an agent that can call either sees everything in the account, not only the file you named. PDF.net states the connector reaches your library only, and never another user's account.
Sources
- PDF.net MCP help article, "Connect pdf.net to your ChatGPT or Claude (MCP)" (retrieved 2026-08-23). This is the vendor's capability table, example prompts, exclusions and troubleshooting; last updated by PDF.net on 2026-08-20. · retrieved 2026-08-23
- PDF.net MCP server product page (retrieved 2026-08-23, via its documented
.mdtwin). Source of the "free to use today" statement. · retrieved 2026-08-23 - PDF.net Data Retention and Deletion Policy (retrieved 2026-08-23) · retrieved 2026-08-23
- PDF.net Security (retrieved 2026-08-23) · retrieved 2026-08-23
- PDF.net Privacy Policy (retrieved 2026-08-23) · retrieved 2026-08-23
- PDF.net Terms of Use (retrieved 2026-08-23) · retrieved 2026-08-23
- PDF.net Share PDF product page (retrieved 2026-08-23). The separate share product whose links open without an account. · retrieved 2026-08-23
- PDF.net machine-readable site index,
llms.txt(retrieved 2026-08-23). PDF.net'srobots.txtcarriesContent-Signal: search=yes, ai-train=yes, ai-input=yes, expressly permitting this synthesis. · retrieved 2026-08-23 - Live authentication check — anonymous
initializeagainsthttps://mcp.pdf.net/mcpreturned HTTP 401 with awww-authenticatechallenge naming scopepdfnet.mcp offline_access(2026-08-23). No tool was called. · retrieved 2026-08-23 - Live OAuth posture check — RFC 9728 metadata at
https://mcp.pdf.net/.well-known/oauth-protected-resourceand authorization server metadata athttps://mcp.pdf.net/.well-known/oauth-authorization-server(2026-08-23). A control request to a non-existent sibling path returned 404, so these 200s are genuine rather than a catch-all. · retrieved 2026-08-23 - Anthropic Connectors Directory entry — , read from our directory snapshot dated 2026-08-23 · retrieved 2026-08-23
- PDF.net support — <mailto:support+mcp@pdf.net> · Privacy
Use in Agentman
Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.
Open in Agentman StudioServer Info
- Category
- Productivity
- Developer
- PDF.net
- Tools
- 20
- Domain
- mcp.pdf.net
Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.