paperless-ngx-mcp

MCPattested
v3.2.1Oliver FueckertISCUpdated todaynpmGitHub

Model Context Protocol (MCP) server for Paperless-NGX. Lets AI assistants manage documents and their versions, tags, correspondents, document types, custom fields, saved views, storage paths, workflows, mail accounts and rules, share links and bundles, no

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
6GitHub stars
3Forks
todayLast update
Needs 1 credential before it runs
  • PAPERLESS_API_KEYAPI keyrequired

    Paperless-ngx API token (My Profile → generate token)

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
AuthorOliver Fueckert
LicenseISC
Version3.2.1
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · fdb24b6
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface40 tools · 8 privileged
Security scan✓ Cleanv3.2.1 · todayHow well does this scan work?
EvalsNone
IndexedSep 24, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 8 privileged
Statically extracted from the published packagev3.2.1 · 6h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

list_correspondentsList all correspondents with optional filtering and pagination. Correspondents represent entities that send or receive documents.

List all correspondents with optional filtering and pagination. Correspondents represent entities that send or receive documents.

No input schema was published for this tool.

get_correspondentGet a specific correspondent by ID with full details including matching rules.

Get a specific correspondent by ID with full details including matching rules.

No input schema was published for this tool.

create_correspondentCreate a new correspondent with optional matching pattern and algorithm for automatic document assignment.

Create a new correspondent with optional matching pattern and algorithm for automatic document assignment.

No input schema was published for this tool.

update_correspondentUpdate fields on ONE correspondent (PATCH — only fields you supply are changed). Editable fields: name, match (matching pattern), matching_algorithm, is_insensitive. To assign this correspondent to documents, use edit_documents_bulk with method 'set_correspondent' or update_document instead.

Update fields on ONE correspondent (PATCH — only fields you supply are changed). Editable fields: name, match (matching pattern), matching_algorithm, is_insensitive. To assign this correspondent to documents, use edit_documents_bulk with method 'set_correspondent' or update_document instead.

No input schema was published for this tool.

delete_correspondentprivileged⚠️ DESTRUCTIVE: Permanently delete a correspondent from the entire system. This will affect ALL documents that use this correspondent.

⚠️ DESTRUCTIVE: Permanently delete a correspondent from the entire system. This will affect ALL documents that use this correspondent.

No input schema was published for this tool.

list_custom_fieldsList all custom fields. IMPORTANT: When a user query may refer to a custom field, you should fetch all custom fields up front (with a large enough page_size), cache them for the session, and search locally for matches by name before making further API calls. This reduces redundant requests and hand…

List all custom fields. IMPORTANT: When a user query may refer to a custom field, you should fetch all custom fields up front (with a large enough page_size), cache them for the session, and search locally for matches by name before making further API calls. This reduces redundant requests and hand…

No input schema was published for this tool.

get_custom_fieldGet a specific custom field by ID with full details including data type and extra configuration.

Get a specific custom field by ID with full details including data type and extra configuration.

No input schema was published for this tool.

create_custom_fieldCreate a new custom field with a specified data type (string, url, date, boolean, integer, float, monetary, documentlink, or select). For monetary fields, values must use currency code prefix format (e.g., USD10.00, GBP123.45) — NOT trailing symbol format (e.g., 10.00$).

Create a new custom field with a specified data type (string, url, date, boolean, integer, float, monetary, documentlink, or select). For monetary fields, values must use currency code prefix format (e.g., USD10.00, GBP123.45) — NOT trailing symbol format (e.g., 10.00$).

No input schema was published for this tool.

update_custom_fieldUpdate fields on ONE custom field definition (PATCH — only fields you supply are changed). Editable fields: name, data_type, extra_data. ⚠️ Changing data_type on a field that already has values on documents may render those values invalid or unreadable — change data_type only on unused fields. To s…

Update fields on ONE custom field definition (PATCH — only fields you supply are changed). Editable fields: name, data_type, extra_data. ⚠️ Changing data_type on a field that already has values on documents may render those values invalid or unreadable — change data_type only on unused fields. To s…

No input schema was published for this tool.

delete_custom_fieldprivileged⚠️ DESTRUCTIVE: Permanently delete a custom field from the entire system. This will remove the field from ALL documents that use it.

⚠️ DESTRUCTIVE: Permanently delete a custom field from the entire system. This will remove the field from ALL documents that use it.

No input schema was published for this tool.

edit_custom_fields_bulkprivilegedManage custom field definitions themselves (permissions, delete). ⚠️ This does NOT modify custom field values on documents — use edit_documents_bulk with method 'modify_custom_fields' for that. WARNING: 'delete' permanently removes custom fields from the entire system.

Manage custom field definitions themselves (permissions, delete). ⚠️ This does NOT modify custom field values on documents — use edit_documents_bulk with method 'modify_custom_fields' for that. WARNING: 'delete' permanently removes custom fields from the entire system.

No input schema was published for this tool.

edit_documents_bulkprivilegedNo description published

This tool published no description. Forge does not invent one.

post_documentUpload a new document file (PDF, image, etc.) to Paperless-NGX with optional metadata. Upload is asynchronous: by default returns a task UUID (use list_tasks to track consumer progress) — the actual document ID is assigned only after the consumer has processed the file. Set poll=true to wait for th…

Upload a new document file (PDF, image, etc.) to Paperless-NGX with optional metadata. Upload is asynchronous: by default returns a task UUID (use list_tasks to track consumer progress) — the actual document ID is assigned only after the consumer has processed the file. Set poll=true to wait for th…

No input schema was published for this tool.

list_documentsNo description published

This tool published no description. Forge does not invent one.

get_documentNo description published

This tool published no description. Forge does not invent one.

get_document_contentGet the text content of a specific document by ID. Use this when you need to read or analyze the actual document text. For long documents, read a slice with max_chars (and offset to continue) — e.g. max_chars: 2000 is usually enough to identify a document. Paperless stores the text without page bou…

Get the text content of a specific document by ID. Use this when you need to read or analyze the actual document text. For long documents, read a slice with max_chars (and offset to continue) — e.g. max_chars: 2000 is usually enough to identify a document. Paperless stores the text without page bou…

No input schema was published for this tool.

search_documentsRanked full-text search through Paperless's search index (content, title and metadata). mode 'query' (default) takes advanced syntax — AND/OR/NOT, "quoted phrases", field:value, wildcards*; 'text' takes plain words with no syntax; 'title' searches titles only. The index is updated in the background…

Ranked full-text search through Paperless's search index (content, title and metadata). mode 'query' (default) takes advanced syntax — AND/OR/NOT, "quoted phrases", field:value, wildcards*; 'text' takes plain words with no syntax; 'title' searches titles only. The index is updated in the background…

No input schema was published for this tool.

download_documentDownload a document file by ID. Returns the document as a base64-encoded resource.

Download a document file by ID. Returns the document as a base64-encoded resource.

No input schema was published for this tool.

get_document_thumbnailGet a document thumbnail (image preview) by ID. Returns the thumbnail as a base64-encoded WebP image resource.

Get a document thumbnail (image preview) by ID. Returns the thumbnail as a base64-encoded WebP image resource.

No input schema was published for this tool.

update_documentNo description published

This tool published no description. Forge does not invent one.

email_documentSend a document via email to one or more recipients.

Send a document via email to one or more recipients.

No input schema was published for this tool.

get_document_historyGet the change history / audit log for a document, showing who changed what and when.

Get the change history / audit log for a document, showing who changed what and when.

No input schema was published for this tool.

get_document_previewGet a full-page preview image of a document. Returns the preview as a base64-encoded image resource.

Get a full-page preview image of a document. Returns the preview as a base64-encoded image resource.

No input schema was published for this tool.

list_document_typesList all document types. IMPORTANT: When a user query may refer to a document type or tag, you should fetch all document types and all tags up front (get_filing_options returns both, plus correspondents and storage paths, in one call), cache them for the session, and search locally for matches by n…

List all document types. IMPORTANT: When a user query may refer to a document type or tag, you should fetch all document types and all tags up front (get_filing_options returns both, plus correspondents and storage paths, in one call), cache them for the session, and search locally for matches by n…

No input schema was published for this tool.

get_document_typeGet a specific document type by ID with full details including matching rules.

Get a specific document type by ID with full details including matching rules.

No input schema was published for this tool.

create_document_typeCreate a new document type with optional matching pattern and algorithm for automatic document classification.

Create a new document type with optional matching pattern and algorithm for automatic document classification.

No input schema was published for this tool.

update_document_typeUpdate fields on ONE document type (PATCH — only fields you supply are changed). Editable fields: name, match (matching pattern), matching_algorithm, is_insensitive. To assign this document type to documents, use edit_documents_bulk with method 'set_document_type' or update_document instead.

Update fields on ONE document type (PATCH — only fields you supply are changed). Editable fields: name, match (matching pattern), matching_algorithm, is_insensitive. To assign this document type to documents, use edit_documents_bulk with method 'set_document_type' or update_document instead.

No input schema was published for this tool.

delete_document_typeprivileged⚠️ DESTRUCTIVE: Permanently delete a document type from the entire system. This will affect ALL documents that use this type.

⚠️ DESTRUCTIVE: Permanently delete a document type from the entire system. This will affect ALL documents that use this type.

No input schema was published for this tool.

upload_document_versionprivilegedAdd a new file version to an EXISTING document instead of creating a new document — e.g. a corrected scan, a signed copy, or an unlocked PDF. The new file becomes the current version: content, search and downloads follow it, and earlier versions stay listed in the document's `versions` (see get_doc…

Add a new file version to an EXISTING document instead of creating a new document — e.g. a corrected scan, a signed copy, or an unlocked PDF. The new file becomes the current version: content, search and downloads follow it, and earlier versions stay listed in the document's `versions` (see get_doc…

No input schema was published for this tool.

update_document_versionRename a version of a document (change its version_label). Version IDs are listed in get_document's `versions`.

Rename a version of a document (change its version_label). Version IDs are listed in get_document's `versions`.

No input schema was published for this tool.

delete_document_versionprivileged⚠️ DESTRUCTIVE: Permanently delete one non-root version of a document. The root (original) version can't be deleted — delete the document instead.

⚠️ DESTRUCTIVE: Permanently delete one non-root version of a document. The root (original) version can't be deleted — delete the document instead.

No input schema was published for this tool.

merge_documents_as_versions⚠️ Fold other documents into one document as its versions: each document in merge_documents stops existing as a separate document and becomes a version of root_document_id. Use it when the same paper arrived twice (e.g. a scan and a later emailed copy). Runs asynchronously.

⚠️ Fold other documents into one document as its versions: each document in merge_documents stops existing as a separate document and becomes a version of root_document_id. Use it when the same paper arrived twice (e.g. a scan and a later emailed copy). Runs asynchronously.

No input schema was published for this tool.

list_mail_accountsList the IMAP accounts Paperless fetches mail from. Passwords are always masked.

List the IMAP accounts Paperless fetches mail from. Passwords are always masked.

No input schema was published for this tool.

get_mail_accountGet one mail account by ID (password masked).

Get one mail account by ID (password masked).

No input schema was published for this tool.

create_mail_accountCreate an IMAP account for Paperless to fetch mail from. Nothing is fetched until a mail rule uses the account (create_mail_rule). Check the connection first with test_mail_account.

Create an IMAP account for Paperless to fetch mail from. Nothing is fetched until a mail rule uses the account (create_mail_rule). Check the connection first with test_mail_account.

No input schema was published for this tool.

update_mail_accountUpdate fields on ONE mail account (PATCH — only fields you supply are changed). Omit password to keep the stored one.

Update fields on ONE mail account (PATCH — only fields you supply are changed). Omit password to keep the stored one.

No input schema was published for this tool.

delete_mail_accountprivileged⚠️ DESTRUCTIVE: Permanently delete a mail account and stop fetching from it. Mail rules using it are deleted too. Already-imported documents are not affected.

⚠️ DESTRUCTIVE: Permanently delete a mail account and stop fetching from it. Mail rules using it are deleted too. Already-imported documents are not affected.

No input schema was published for this tool.

test_mail_accountNo description published

This tool published no description. Forge does not invent one.

process_mail_accountFetch mail for one account now and run its rules, instead of waiting for the schedule. Runs in the background; see list_tasks with task_type mail_fetch.

Fetch mail for one account now and run its rules, instead of waiting for the schedule. Runs in the background; see list_tasks with task_type mail_fetch.

No input schema was published for this tool.

list_mail_rulesNo description published

This tool published no description. Forge does not invent one.

34 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Model Context Protocol (MCP) server for Paperless-NGX. Lets AI assistants manage documents and their versions, tags, correspondents, document types, custom fields, saved views, storage paths, workflows, mail accounts and rules, share links and bundles, no

Keywords
mcppaperless-ngxdocument-managementaiclaudemodel-context-protocolpaperless
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-01 — observed resolution, not a publisher declaration.

60 packages resolved · 5 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

69 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+57 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.

Topics

Related in documents & pdfs