Paperless-NGX over MCP: search, read, upload and tag documents; manage correspondents and types.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
PAPERLESS_MCP_API_TOKENAPI keyoptionalPaperless service-account token used for outbound API requests. The server refuses to start without it.
PAPERLESS_MCP_BEARER_TOKENAPI keyoptionalSingle shared bearer token; enables bearer auth unless `bearer_tokens_file` is set, which takes precedence.
PAPERLESS_MCP_OIDC_CLIENT_SECRETOAuth appoptionalOIDC client secret registered with the provider.
PAPERLESS_MCP_OIDC_JWT_SIGNING_KEYAPI keyoptionalSigning key for issued tokens; used in oidc-proxy mode only. When unset, the key is derived deterministically from `oidc_client_secret`, so tokens survive a restart. Rotating that secret then…
PAPERLESS_MCP_OIDC_VERIFY_ACCESS_TOKENAPI keyoptionalValidate the access token instead of the id token.
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge has no scan on record for this entry, so it holds no observation of its tool surface. That is an absence of evidence, not evidence that it exposes no tools.
Paperless-NGX over MCP: search, read, upload and tag documents; manage correspondents and types.
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.