Atlas / MCP servers / baruchiro / Paperless NGX

Paperless NGXSAFE

mcp/baruchiro/paperless-ngx-1

An MCP (Model Context Protocol) server for interacting with a Paperless-NGX API server. This server provides tools for managing documents, tags, correspondents, and document types in your Paperless-NGX instance.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
44 19r · 19w · 6d
Transport
sse · stdio · streamable-http
License
ISC
Stars
146
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server for interacting with a Paperless-NGX API server. This server provides tools for managing documents, tags, correspondents, and document types in your Paperless-NGX instance.

Quick Start

[](https://cursor.com/install-mcp?name=paperless&config=eyJjb21tYW5kIjoibnB4IC15IEBiYXJ1Y2hpcm8vcGFwZXJsZXNzLW1jcEBsYXRlc3QiLCJlbnYiOnsiUEFQRVJMRVNTX1VSTCI6Imh0dHA6Ly95b3VyLXBhcGVybGVzcy1pbnN0YW5jZTo4MDAwIiwiUEFQRVJMRVNTX0FQSV9LRVkiOiJ5b3VyLWFwaS10b2tlbiJ9fQ%3D%3D)

Installation

Add these to your MCP config file:

// STDIO mode (recommended for local or CLI use)

"paperless": {
"command": "npx",
"args": [
"-y",
"@baruchiro/paperless-mcp@latest",
],
"env": {
"PAPERLESS_URL": "http://your-paperless-instance:8000",
"PAPERLESS_API_KEY": "your-api-token",
"PAPERLESS_PUBLIC_URL": "https://your-public-domain.com"
}
}

// HTTP mode (recommended for Docker or remote use)

"paperless": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/baruchiro/paperless-mcp:latest",
],
"env": {
"PAPERLESS_URL": "http://your-paperless-instance:8000",
"PAPERLESS_API_KEY": "your-api-token",
"PAPERLESS_PUBLIC_URL": "https://your-public-domain.com"
}
}
  1. Get your API token:
  2. Log into your Paperless-NGX instance
  3. Click your username in the top right
  4. Select "My Profile"
  5. Click the circular arrow button to generate a new token
  1. Replace the pl
Read from source at commit 112a4d9f157dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add paperless-mcp --env PAPERLESS_API_KEY=${PAPERLESS_API_KEY} --env PAPERLESS_TOKEN=${PAPERLESS_TOKEN} -- npx -y @baruchiro/[email protected]
claude-desktop
{
  "mcpServers": {
    "paperless-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@baruchiro/[email protected]"
      ],
      "env": {
        "PAPERLESS_API_KEY": "${PAPERLESS_API_KEY}",
        "PAPERLESS_TOKEN": "${PAPERLESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (44)

19 read · 19 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bulk_edit_correspondentswriteBulk edit correspondents. ⚠️ WARNING:
bulk_edit_custom_fieldswriteBulk edit custom fields. ⚠️ WARNING:
bulk_edit_document_typeswriteBulk edit document types. ⚠️ WARNING:
bulk_edit_documentswritePerform bulk operations on multiple documents. Note:
bulk_edit_tagswriteBulk edit tags. ⚠️ WARNING:
create_correspondentwriteCreate a new correspondent with optional matching pattern and algorithm for automatic document assignment.
create_custom_fieldwriteCreate a new custom field with a specified data type (string, url, date, boolean, integer, float, monetary, documentlink, or select). For monetary fields, values must use currency code prefix format (e.g., USD10.00, GBP123.45) — NOT trailing symbol format (e.g., 10.00$).
create_document_notewriteAdd a note to a document. Use this to record an audit trail or progress note directly on the document. Returns the document
create_document_typewriteCreate a new document type with optional matching pattern and algorithm for automatic document classification.
create_mail_rulewriteCreate a Paperless mail rule. Use list_mail_accounts first to choose account. Prefer attachment-only rules for invoices unless the full mail must be archived.
create_tagwriteCreate a new tag with optional color, matching pattern, and matching algorithm for automatic document tagging.
delete_correspondentdestructive⚠️ DESTRUCTIVE: Permanently delete a correspondent from the entire system. This will affect ALL documents that use this correspondent.
delete_custom_fielddestructive⚠️ DESTRUCTIVE: Permanently delete a custom field from the entire system. This will remove the field from ALL documents that use it.
delete_document_notedestructive⚠️ DESTRUCTIVE: Permanently delete a single note from a document by its note ID. This operation is irreversible. Returns the document
delete_document_typedestructive⚠️ DESTRUCTIVE: Permanently delete a document type from the entire system. This will affect ALL documents that use this type.
delete_mail_ruledestructiveDelete one Paperless mail rule. This changes future mail ingestion behavior but does not delete documents.
delete_tagdestructive⚠️ DESTRUCTIVE: Permanently delete a tag from the entire system. This will remove the tag from ALL documents that use it. Use with extreme caution.
download_documentreadDownload a document file by ID. Returns a paperless:// resource URI; read the resource to fetch the file content.
get_correspondentreadGet a specific correspondent by ID with full details including matching rules.
get_custom_fieldreadGet a specific custom field by ID with full details including data type and extra configuration.
get_documentreadGet a specific document by ID with full details including correspondent, document type, tags, and custom fields. Note: Document content is excluded from results by default. Use
get_document_contentreadGet the text content of a specific document by ID. Use this when you need to read or analyze the actual document text.
get_document_thumbnailreadGet a document thumbnail (image preview) by ID. Returns a paperless:// resource URI; read the resource to fetch the image content.
get_document_typereadGet a specific document type by ID with full details including matching rules.
get_mail_accountreadGet one Paperless mail account by ID. Password/token fields are redacted if the server returns them.
get_mail_rulereadGet one Paperless mail rule by ID.
list_correspondentsreadList all correspondents with optional filtering and pagination. Correspondents represent entities that send or receive documents.
list_custom_fieldsread
list_document_notesreadList all notes attached to a document. Notes are free-text comments on a document and are the natural place for an audit trail (e.g. \
list_document_typesread
list_documentsreadList and filter documents with pagination and common Paperless filters such as title search, correspondent, document type, tag, storage path, creation date, archive serial number, and simple custom field filters. Use
list_mail_accountsreadList Paperless mail accounts for selecting the account ID needed by mail rules. Does not expose account passwords.
list_mail_rulesreadList Paperless mail rules with optional pagination.
list_tagsread
post_documentwriteUpload a new document to Paperless-NGX with optional metadata like title, correspondent, document type, tags, and custom fields. Provide either
process_mail_accountwriteManually run Paperless mail processing for one account. This can consume matching mails according to enabled Paperless mail rules.
query_documentsread
search_documentsreadDeprecated compatibility wrapper for full-text document search. Use
update_correspondentwriteUpdate an existing correspondent
update_custom_fieldwriteUpdate an existing custom field
update_documentwriteUpdate a specific document with new values (title, correspondent, document type, storage path, tags, custom fields, and more). Top-level fields you omit are left unchanged. IMPORTANT: custom_fields is the exception — see its parameter description; it replaces the document
update_document_typewriteUpdate an existing document type
update_mail_rulewritePatch an existing Paperless mail rule. Only supplied fields are changed.
update_tagwriteUpdate an existing tag
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_correspondent, delete_custom_field, delete_document_note, delete_document_type, delete_mail_rule, delete_tag
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/mocks/paperlessApi.ts:1
import { PaperlessAPI } from "../../api/PaperlessAPI";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/mocks/paperlessApi.ts:2
import { Document } from "../../api/types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/utils/matchingAlgorithm.ts:5
} from "../../api/types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/utils/selectFields.test.ts:3
import { PaperlessAPI } from "../../api/PaperlessAPI";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/utils/selectFields.test.ts:4
import { CustomField } from "../../api/types";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/docker-publish.yml:88
code=$(curl -s --max-time 2 -o /dev/null -w "%{http_code}" http://127.0.0.1:3000/mcp || true)
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:11
[![Install MCP Server](https://cursor.com/deeplink/mcp-install-light.svg)](https://cursor.com/install-mcp?name=paperless&config=eyJjb21tYW5kIjoibnB4IC15IEBiYXJ1Y2hpcm8vcGFwZXJsZXNzLW1jcEBsYXRlc3QiLCJl
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, express, form-data, zod, @anthropic-ai/dxt, @changesets/cli, @types/express
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:94
- 6f8aada: Allow `post_document` to upload from an absolute server-side `file_path` instead of base64 `file`, avoiding base64 overhead for large files. Reads are validated (absolute path, regular file
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:752
TOKEN=$(curl -s -X POST http://localhost:8000/api/token/ \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 112a4d9f157dfull audit observations/trust-audit/mcp-server/baruchiro__paperless-ngx-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07112a4d9f157dSAFEB89first audit
06

Questions

What is the Paperless NGX MCP server?

An MCP (Model Context Protocol) server for interacting with a Paperless-NGX API server. This server provides tools for managing documents, tags, correspondents, and document types in your Paperless-NGX instance.

What tools does Paperless NGX expose?

44 in total: 19 read-only, 19 that write, and 6 that can delete or overwrite (delete_correspondent, delete_custom_field, delete_document_note, delete_document_type, delete_mail_rule). Every one is listed on this page with its risk.

Is Paperless NGX safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Paperless NGX need?

It reads PAPERLESS_API_KEY and PAPERLESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Paperless NGX run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @baruchiro/paperless-mcp at 2.2.1.

How current is this page?

The grade is for one exact copy of the source (112a4d9f157d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement