quillpdf-mcp
This server provides local-first PDF manipulation tools that run entirely on your machine — no files are ever uploaded or transmitted over a network. It exposes the following capabilities:
pdf_merge: Combine two or more PDF files into a single document in a specified order.pdf_split: Split a PDF by page ranges into multiple output files, or extract specific pages into a single new PDF.pdf_rotate: Rotate all pages or a selected subset by any multiple of 90 degrees (e.g., 90°, 180°, -90°).pdf_watermark: Stamp custom text on every page with configurable font size, opacity, color, and position.pdf_bates: Add sequential Bates numbers to every page with options for prefix, starting number, zero-pad width, font size, color, and corner placement.pdf_clean_metadata: Strip sensitive metadata including title, author, subject, keywords, creator, creation/modification dates, and the XMP metadata stream.pdf_page_count: Return the total number of pages in a PDF file.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@quillpdf-mcpmerge invoice1.pdf and invoice2.pdf into combined.pdf"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
quillpdf-mcp
PDF operations for MCP. An MCP server and CLI for local PDF manipulation:
Merge, split, organize, delete pages
Rotate, crop
Watermark, Bates numbering, page numbers
Flatten forms, images → PDF
Metadata cleaning, page count
AES-256 protect / unlock
Built on pdf-lib. MIT licensed. stdio transport. No network calls — files never leave your machine.
Install
npx -p quillpdf-mcp quillpdf --help # CLI
npx quillpdf-mcp --help # MCP server (your MCP client launches it over stdio)Or globally:
npm install -g quillpdf-mcp
quillpdf --helpRequires Node.js 18+.
Related MCP server: mcp-pdf-utils
Scope
quillpdf-mcp implements structural PDF transforms and AES-256 protect/unlock. It does not perform OCR, redaction, or compression — those are available in the browser version (quillpdf.com), where processing also stays client-side. They'll ship here only when they can run fully locally.
Use it from an AI assistant (MCP)
The MCP server speaks stdio and exposes one tool per operation.
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"quillpdf": {
"command": "npx",
"args": ["-y", "quillpdf-mcp"]
}
}
}Claude Code
claude mcp add quillpdf -- npx -y quillpdf-mcpThen ask your assistant things like "merge invoice-1.pdf and invoice-2.pdf into combined.pdf" or "Bates-number discovery.pdf with prefix ABC starting at 1." The assistant supplies file paths on your machine; the server reads and writes them locally.
A ready-to-copy config lives in examples/mcp-config.json.
Tools
Tool | What it does |
| Merge 2+ PDFs into one, in order |
| Split by page ranges (one file per group) or extract specific pages into one file |
| Rotate pages by a multiple of 90° (all pages or a chosen subset) |
| Stamp text on every page (size / opacity / color / position) |
| Sequential Bates numbering (prefix, start, zero-pad, corner) |
| Strip info-dict fields + dates, and delete the XMP metadata stream |
| Count pages |
| Keep pages in the order you list — reorder, delete and duplicate in one step |
| Remove listed pages, keeping the rest in order |
| Stamp readable page numbers ( |
| Trim page margins by setting the CropBox — hides, does not remove (not redaction) |
| Paint filled form values onto the page so they can't be edited or read back as form data |
| Build a PDF from PNG/JPEG images, one per page |
| Encrypt with AES-256 so the document needs a password to open |
| Remove the password from a document you have the password for |
Use it from the command line
# Merge (order is preserved)
quillpdf merge a.pdf b.pdf c.pdf -o combined.pdf
# Split into one file per range group → out-1.pdf (pages 1-3), out-2.pdf (page 5)
quillpdf split in.pdf --ranges "1-3,5" -o out.pdf
# Extract specific pages into a single file (reordering/duplicates allowed)
quillpdf split in.pdf --pages "5,1,1" -o extract.pdf
# Rotate every page 90°, or just some pages
quillpdf rotate in.pdf --angle 90 -o rotated.pdf
quillpdf rotate in.pdf --angle 180 --pages "2,4" -o rotated.pdf
# Watermark
quillpdf watermark in.pdf --text "DRAFT" --opacity 0.15 --position center -o wm.pdf
# Bates numbering → PLT-000001, PLT-000002, …
quillpdf bates in.pdf --prefix "PLT-" --start 1 --pad 6 -o numbered.pdf
# Strip document metadata
quillpdf clean-metadata in.pdf -o clean.pdf
# Page count (prints a number)
quillpdf page-count in.pdfEvery command has --help.
Existing files are never silently replaced. If the -o path already
exists, the command stops with an error instead of clobbering it — add
--force (or force: true on the MCP tools) to replace it deliberately.
Privacy & security notes
Local only. All PDF processing happens in-process via
pdf-lib. The server communicates over stdio and never opens a network connection. (The MCP SDK bundles optional HTTP/SSE transports innode_modules, but this server only ever uses stdio, so none of that code runs.)Password-protected PDFs are refused, not silently unlocked. Every operation except
unlockstops with a clear message rather than stripping the password for you.unlockdecrypts only with a password you supply — it does not recover, guess, or brute-force one.Encryption engine.
protectandunlockrun QPDF (Apache-2.0) compiled to WebAssembly, in-process and offline like everything else.pdf-libcannot encrypt at all, and the community forks that add it are unmaintained — encryption is the one operation where a subtle bug means a document you believe is locked isn't, so this uses the reference implementation instead.AES-256 only.
protectemits PDF 2.0 encryption revision 6. The 40-bit and 128-bit modes are deliberately not exposed: QPDF classes both as weak crypto, and shipping a "protected" file that isn't meaningfully protected is worse than shipping nothing.Permission flags are a request, not a guarantee.
--no-print/--no-copy/--no-modifyset bits that a well-behaved reader honours; they are not enforced by the encryption. The password is the part that actually protects the file. (Extraction for accessibility stays permitted even with--no-copy, so screen readers keep working.)Cropping is not redaction.
cropsets the CropBox, so trimmed content is hidden but still present in the file and fully recoverable. Do not use it to remove sensitive material.clean-metadatascope. It clears the title, author, subject, keywords, and creator fields plus the CreationDate/ModDate in the document information dictionary, and deletes the document-level XMP metadata stream — the copy Acrobat, Word, InDesign, and LibreOffice write, which is often the authoritative one. Note thatpdf-librewrites the/Producerfield with its own signature on save, so that one field is replaced rather than emptied. It does not scrub page-level annotations, embedded file attachments, or the text/image content of pages.
Not here yet (roadmap)
These need a Node image backend or an OCR engine and are planned for a later release — they are not in this package today:
compress(image re-encode) — needs an image codec such assharppdf-to-image(render pages to PNG) — needs a rasterizer (pdfjs-dist+ canvas)redact(true rasterize-on-redact removal) — needs the same rasterizerocr(searchable-text layer) — needstesseract.js
Each would roughly quadruple this package's dependency surface, which is the whole reason they're held back: the pitch here is a small, local, no-network tool. They'll ship only when they can run fully locally without giving that up.
Philosophy
Keep the server small, local, and easy to audit. Most "PDF API" tools answer document work with "upload it to us" — for legal discovery, medical records, or financials, the upload is the problem. This runs where you are; the bytes stay on your disk.
Development
npm install
npm run build # tsc → dist/
npm test # builds, then runs the unit suite (node:test)The engine (src/core.ts) is pure: bytes in, bytes out, no I/O. The CLI (src/cli.ts) and MCP server (src/server.ts) are thin front-ends over it.
License
MIT © Purple Directive. See LICENSE.
Learn more at quillpdf.com.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceA comprehensive tool server for reading, merging, and extracting content from PDF files via local paths or direct URLs. It enables metadata retrieval, regex searching, and page-specific text extraction with built-in caching and workspace-restricted security.9MIT
- AlicenseAqualityDmaintenanceAn MCP server for local PDF manipulation including merging, splitting, rotating, watermarking, and text extraction. It works with various MCP-compatible clients and processes PDFs entirely on-device without cloud services.1113MIT
- Alicense-qualityAmaintenanceThe local PDF workflow for Claude Desktop and MCP hosts: fill, sign, merge, split, extract, and analyze PDFs without sending files to a web app.2150MIT
- Alicense-qualityBmaintenancePrivacy-first file tools for AI agents, enabling operations like PDF merge/split, image compression/convert, metadata stripping, and background removal without storing files.36MIT
Related MCP Connectors
EPUB/PDF tools: merge, split, compress, convert, edit metadata, validate ebooks.
Turn a description into a shareable, editable PDF — invoices, certificates, reports, resumes.
PDF accessibility checks (veraPDF PDF/UA-1), auto-fix and Markdown conversion. EU-hosted.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/PurpleDirective/quillpdf-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server