Paperless NGXSAFE
An MCP (Model Context Protocol) server for interacting with a Paperless-NGX API server. This server provides tools for managing documents, tags, correspondents, and document types in your Paperless-NGX instance.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server for interacting with a Paperless-NGX API server. This server provides tools for managing documents, tags, correspondents, and document types in your Paperless-NGX instance.
Quick Start
Installation
- Install the MCP server:
npm install -g paperless-mcp
- Add it to your Claude's MCP configuration:
For VSCode extension, edit ~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json:
{
"mcpServers": {
"paperless": {
"command": "npx",
"args": ["paperless-mcp", "http://your-paperless-instance:8000", "your-api-token"]
}
}
}For Claude desktop app, edit ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"paperless": {
"command": "npx",
"args": ["paperless-mcp", "http://your-paperless-instance:8000", "your-api-token"]
}
}
}- Get your API token:
- Log into your Paperless-NGX instance
- Click your username in the top right
- Select "My Profile"
- Click the circular arrow button to generate a new token
- Replace the placeholders in your MCP config:
http://your-paperless-instance:8000with your Paperless-NGX URLyour-api-tokenwith the token you just generated
That's it! Now you can ask Claude to help you manage your Paperless-NGX documents.
Example Usage
Here are some things you can ask Claude to do:
- "Show me all documents tagged as 'Invoice'"
- "Search for documents containing 'tax return'"
- "Create a new tag called 'Receipts' with color #FF0000"
- "Download document #123"
- "List all correspondents"
- "Create a new document type called 'Bank Statement'"
Available Tools
Document Operations
list_documents
Get a paginated list of all documents.
Parameters:
- page (optional): Page number
- page_size (optional): Number of documents per page
list_documents({966577e2c447OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add paperless-mcp --env API_KEY=${API_KEY} -- npx -y @nloui/[email protected]{
"mcpServers": {
"paperless-mcp": {
"command": "npx",
"args": [
"-y",
"@nloui/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}"
}
}
}
}Exposed tools (16)
6 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bulk_edit_correspondents | write | Perform bulk operations on multiple correspondents: set permissions to control who can assign them to documents, or permanently delete multiple correspondents. Use with caution as deletion affects all associated documents. |
bulk_edit_document_types | write | Perform bulk operations on multiple document types: set permissions to control who can assign them to documents, or permanently delete multiple types. Use with caution as deletion affects all associated documents. |
bulk_edit_documents | write | Perform bulk operations on multiple documents simultaneously: set correspondent/type/tags, delete, reprocess, merge, split, rotate, or manage permissions. Efficient for managing large document collections. |
bulk_edit_tags | write | Perform bulk operations on multiple tags: set permissions to control access or permanently delete multiple tags at once. Efficient for managing large tag collections. |
create_correspondent | write | Create a new correspondent (person, company, or organization) for tracking document senders and receivers. Can include automatic matching patterns for smart assignment to incoming documents. |
create_document_type | write | Create a new document type for categorizing documents by their purpose or format (e.g., Invoice, Receipt, Contract). Can include automatic matching rules for smart classification. |
create_tag | write | Create a new tag for labeling and organizing documents. Tags can have colors for visual identification and automatic matching rules for smart assignment. |
delete_tag | destructive | Permanently delete a tag from the system. This removes the tag from all documents that currently use it. Use with caution as this action cannot be undone. |
download_document | read | Download a document file as base64-encoded data. Choose between original uploaded file or processed/archived version with OCR improvements. |
get_document | read | Get complete details for a specific document including full metadata, content preview, tags, correspondent, and document type information. |
list_correspondents | read | Retrieve all available correspondents (people, companies, organizations that send/receive documents). Returns names and automatic matching patterns for document assignment. |
list_document_types | read | Retrieve all available document types for categorizing documents by purpose or format (Invoice, Receipt, Contract, etc.). Returns names and automatic matching rules. |
list_tags | read | Retrieve all available tags for labeling and organizing documents. Returns tag names, colors, and matching rules for automatic assignment. |
post_document | write | Upload a new document to Paperless-NGX with metadata. Supports PDF, images (PNG/JPG/TIFF), and text files. Automatically processes for OCR and indexing. |
search_documents | read | |
update_tag | write | Modify an existing tag |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
delete_tag
@modelcontextprotocol/sdk, express, typescript, zod, @types/node, ts-node
Gates applied: no_behavioural_pass, no_license.
966577e2c447full audit observations/trust-audit/mcp-server/nloui__paperless-ngx.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 966577e2c447 | SAFE | B | 89 | first audit |
Questions
What is the Paperless NGX MCP server?
An MCP (Model Context Protocol) server for interacting with a Paperless-NGX API server. This server provides tools for managing documents, tags, correspondents, and document types in your Paperless-NGX instance.
What tools does Paperless NGX expose?
16 in total: 6 read-only, 9 that write, and 1 that can delete or overwrite (delete_tag). Every one is listed on this page with its risk.
Is Paperless NGX safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Paperless NGX need?
It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Paperless NGX run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @nloui/paperless-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (966577e2c447), read on 2026-10-06. The repository is watched and re-audited when it changes.