npm · pdfnative-mcp
$npx -y pdfnative-mcp@1.7.0 PDFNATIVE_MCP_OUTPUT_DIR — Absolute path of a sandboxed directory where outputMode='file' may write PDFs. Unset: every tool returns base64 only (file output disabled).
PDFNATIVE_MCP_CACHE_DIR — Opt-in content-addressed response cache directory (SHA-256 keyed, 1h TTL, 256 MiB LRU, plaintext at rest). Never caches encrypt/decrypt, sign, timestamp, add_ltv, update_metadata, encrypted builds or file output.
PDFNATIVE_MCP_PORT — Serve Streamable HTTP on this loopback port instead of stdio (MCP 2026-07-28, stateless). Unauthenticated unless PDFNATIVE_MCP_HTTP_TOKEN is set.
PDFNATIVE_MCP_HTTP_TOKEN · secret — Opt-in bearer token for the HTTP transport (>= 16 chars, no whitespace). When set, /mcp requires 'Authorization: Bearer <token>' or answers 401. Never logged.
PDFNATIVE_MCP_MAX_INFLATE_BYTES — Per-stream FlateDecode decompression cap in bytes (zip-bomb mitigation; default 104857600 = 100 MiB). Integer >= 1024; an invalid value refuses to start the server.
PDFNATIVE_MCP_CREATION_DATE — ISO 8601 instant with a time zone (e.g. 2026-01-01T00:00:00Z) pinned as the creation date of every generated document: reproducible bytes on any host. A call's own creationDate still wins. An invalid value refuses to start the server.
SOURCE_DATE_EPOCH — reproducible-builds.org convention: integer seconds since the Unix epoch, used as the pinned creation date when PDFNATIVE_MCP_CREATION_DATE is unset. An invalid value refuses to start the server.
PDFNATIVE_MCP_TSA_URL — http(s) URL of the RFC 3161 timestamp authority used by sign_pdf timestamp=true and timestamp_pdf (PAdES B-T / B-LTA). Unset: those calls fail with TSA_NOT_CONFIGURED and no network request is made. Tool arguments can never supply a URL.
PDFNATIVE_MCP_TSA_AUTH · secret — Optional Authorization header value sent to the TSA (e.g. 'Basic ...' or 'Bearer ...'). Never logged or echoed.
PDFNATIVE_MCP_REVOCATION — 'ocsp', 'crl' or 'ocsp,crl': enables online revocation collection for add_ltv mode='online' (PAdES B-LT). Unset: that mode fails with REVOCATION_NOT_CONFIGURED; mode='offline' stays fully offline. Requires PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS.
PDFNATIVE_MCP_NETWORK_ALLOWED_HOSTS — Comma-separated allow-list of OCSP / CRL responder hosts ('host', 'host:port' or '*.suffix'). Mandatory when PDFNATIVE_MCP_REVOCATION is set: responder URLs found in certificates are fetched only if the host matches (http(s) only, no credentials, no redirects, internal addresses rejected unless listed verbatim).
PDFNATIVE_MCP_NETWORK_TIMEOUT_MS — Per-request timeout for TSA / OCSP / CRL calls in milliseconds, 1000-120000 (default 10000).