{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "cloudconvert",
    "name": "CloudConvert API",
    "vendor": "CloudConvert (Lunaweb GmbH)",
    "vendorUrl": "https://cloudconvert.com",
    "kind": "http-api",
    "category": "pdf-tools",
    "summary": "File conversion API from Lunaweb GmbH in Germany. Jobs chain import, convert, merge, optimise, watermark and PDF tasks across more than 200 formats, through a REST API, six SDKs, a CLI and a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/cloudconvert",
    "markdownUrl": "https://www.anchorterminal.com/tools/cloudconvert.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudconvert.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudconvert.json",
    "repo": "https://github.com/cloudconvert/cloudconvert-node",
    "license": "Proprietary service under CloudConvert's terms of service. The SDKs and the CLI on GitHub are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.cloudconvert.com/v2",
    "packages": [
      {
        "registry": "npm",
        "name": "cloudconvert"
      },
      {
        "registry": "npm",
        "name": "cloudconvert-cli"
      },
      {
        "registry": "pypi",
        "name": "cloudconvert"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve API key from the dashboard, sent as `Authorization: Bearer API_KEY`. A key takes any of six scopes chosen at creation and does not expire until revoked. OAuth 2.0 clients use the authorisation code or implicit grant at `https://cloudconvert.com/oauth/authorize`. The hosted MCP server signs in by OAuth and asks for `user.read`, `task.read` and `task.write`.",
    "pricing": "freemium",
    "pricingNotes": "Free plan with 10 conversion credits a day and no card, limited to 1 GB files, 5 minutes of processing and 5 concurrent tasks. Paid credits come as prepaid packages that never expire or as monthly subscriptions, from 500 to 1,000,000 credits. A conversion costs a base of 1 credit (2 for Office or iWork to PDF, 4 for PDF to Office) plus 1 a minute after the first, and only successful conversions are charged. The price per credit is drawn by a script and was not readable. The API page says prices start at $0.008 a file at 10,000 files. A sandbox API runs test files without credits (https://cloudconvert.com/pricing, checked 2026-10-09).",
    "priceSummary": "Freemium",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the pricing page or the terms (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 24,
    "popularity": {
      "githubStars": 192,
      "npmWeekly": 103789,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://cloudconvert.com/docs/getting-started/introduction",
    "llmsTxt": "https://cloudconvert.com/docs/llms.txt",
    "capabilities": [
      "pdf.convert",
      "pdf.merge",
      "pdf.generate",
      "docs.ocr"
    ],
    "tags": [
      "hosted",
      "mcp",
      "oauth",
      "llms-txt",
      "async-jobs",
      "webhooks",
      "sandbox",
      "cli",
      "php",
      "node",
      "python",
      "ruby",
      "java",
      "dotnet",
      "status-page",
      "iso27001",
      "eu-hosted"
    ],
    "lastRelease": "2026-09-03",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 66.4,
      "grade": "B",
      "agentReady": false,
      "rank": 291,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 71,
        "maintenance": 68,
        "payments": 35,
        "reliability": 80,
        "schema": 59,
        "security": 71,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Graded as a hosted service. Status page at status.cloudconvert.com with nine components and 90-day bars (20). Six incidents between 3 August and 8 October 2026, the longest readable ones a 23-minute slowdown in EU Central on 8 October and a six-minute multi-component alert on 7 September, with the API at 99.997 per cent over 90 days, so minor incidents only (20). Limits on creating jobs and tasks are described as dynamic, with `X-RateLimit-Limit` and `X-RateLimit-Remaining` headers and a free-plan cap of 5 concurrent tasks, but no fixed number per plan (8). A 429 carries `Retry-After` in seconds and the docs say CloudConvert retries retryable errors itself. No idempotency key (12). The terms promise 99.9 per cent monthly uptime with refunds on paid plans (10). API v2 is generally available and the MCP server carries no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 59,
          "points": 9.59,
          "reason": "No OpenAPI document was found in the docs or llms.txt. `GET /v2/operations` returns each operation's options with types, defaults and enum values, which is a machine-readable contract for options only. The MCP tool schemas sit behind OAuth and were not read (10 of 25). llms.txt and a Markdown twin of every docs page (10). The reference states what each endpoint does and when the synchronous variants are a poor choice, and the MCP tool list gives one line a tool (12). Task parameters are typed in the docs, but format options are found at run time through the operations endpoint and `createJob` takes an arbitrary task graph (10). Every operation has a raw request, CLI, cURL and SDK example, and the docs show 422, 429 and failed-task bodies with codes, with no full code list (11). The `/v2` prefix and pinnable engine versions, with no changelog found (6)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 71,
          "points": 11.54,
          "reason": "The MCP server lists 24 tools, the 11 to 30 band, and the API returns links and status objects with an `include` parameter for the larger parts (16). List endpoints take `per_page` (100 by default, 1,000 at most), `page`, and filters by status, tag, operation and API key (17). Errors carry a `code` and a `message`, validation errors name the field, and failed tasks report codes such as `OPEN_FAILED` (15). No idempotency key. Jobs take a `tag`, a retry endpoint creates a new task, only successful conversions are charged, and the docs ask callers not to retry automatically. MCP annotations were not read (8). A job needs three short tasks, and there are official SDKs in six languages and a CLI (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 71,
          "points": 12.43,
          "reason": "API keys are created with any of six scopes and can be revoked, and OAuth 2.0 issues tokens for third-party clients, though the implicit grant is still supported and no rotation feature is documented. Signed URLs carry an HMAC signature, not the key (27). A key limited to `task.read` is read-only, and the MCP server asks for three scopes, one of them `task.write`. No confirmation step for deletes (12). Results come back as download links, and the `metadata` and `capture-website` operations handle untrusted content. The MCP page tells users to connect only the official URL, with no prompt-injection guidance (6). The security page says all access is logged and reviewable by the customer in activity logs, and jobs can be filtered by API key (11). ISO 27001 from TÜV Süd, a valid security.txt with a disclosure policy and no formal bounty, and no public advisories found (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 35,
          "points": 4.38,
          "reason": "No x402, MPP or L402 (0). The credit cost of each conversion type is published (1, 2 or 4 credits, plus 1 a minute), and the API page says prices start at $0.008 a file at 10,000 files, but the price per credit is drawn by a script and was not read, so 15 of 20. Free plan of 10 credits a day with no card (20). A person signs up in a browser to create a key or approve OAuth (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "reason": "The MCP server was announced on 3 September 2026, 36 days before this check (20). Five SDK and CLI releases since 11 July (CLI 3.0.1, Java 1.2.4 and 1.2.5, PHP 3.4.4, Ruby 1.2.0) and the MCP launch (20). No changelog. Support is a contact form and email, and dependency pull requests on the Java and CLI repositories were merged on 5 and 6 October 2026. Issue replies were not read (8 of 15). Six official SDKs, four released in 2026. The Node.js SDK's last tag is April 2025 and the Python SDK's is March 2022, and the MCP server is not in the official registry (12). Every SDK repository has a test workflow (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 64, provenance 85",
          "reason": "Closed service with dated terms that cover API use, and MIT SDKs (18). The privacy policy of 17 April 2026 gives 24 hours for files, 72 hours for account data after deletion and 180 days for logs, which agrees with the docs' 24-hour task deletion. It says files are not read, mined or copied and that AI is used only for the docs' question box. A DPA is signed on request (25). No deprecation policy. The terms give 30 days' notice only if the whole service is discontinued, and the operations endpoint flags deprecated engine versions (5). Hosting, payment, support and AI providers are named with addresses, and regions are Germany and Virginia, with no separate sub-processor list (16)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server lists 24 tools, the 11 to 30 band, and the API returns links and status objects with an `include` parameter for the larger parts (16). List endpoints take `per_page` (100 by default, 1,000 at most), `page`, and filters by status, tag, operation and API key (17). Errors carry a `code` and a `message`, validation errors name the field, and failed tasks report codes such as `OPEN_FAILED` (15). No idempotency key. Jobs take a `tag`, a retry endpoint creates a new task, only successful conversions are charged, and the docs ask callers not to retry automatically. MCP annotations were not read (8). A job needs three short tasks, and there are official SDKs in six languages and a CLI (15).",
          "maintenance": "The MCP server was announced on 3 September 2026, 36 days before this check (20). Five SDK and CLI releases since 11 July (CLI 3.0.1, Java 1.2.4 and 1.2.5, PHP 3.4.4, Ruby 1.2.0) and the MCP launch (20). No changelog. Support is a contact form and email, and dependency pull requests on the Java and CLI repositories were merged on 5 and 6 October 2026. Issue replies were not read (8 of 15). Six official SDKs, four released in 2026. The Node.js SDK's last tag is April 2025 and the Python SDK's is March 2022, and the MCP server is not in the official registry (12). Every SDK repository has a test workflow (8).",
          "payments": "No x402, MPP or L402 (0). The credit cost of each conversion type is published (1, 2 or 4 credits, plus 1 a minute), and the API page says prices start at $0.008 a file at 10,000 files, but the price per credit is drawn by a script and was not read, so 15 of 20. Free plan of 10 credits a day with no card (20). A person signs up in a browser to create a key or approve OAuth (0).",
          "reliability": "Graded as a hosted service. Status page at status.cloudconvert.com with nine components and 90-day bars (20). Six incidents between 3 August and 8 October 2026, the longest readable ones a 23-minute slowdown in EU Central on 8 October and a six-minute multi-component alert on 7 September, with the API at 99.997 per cent over 90 days, so minor incidents only (20). Limits on creating jobs and tasks are described as dynamic, with `X-RateLimit-Limit` and `X-RateLimit-Remaining` headers and a free-plan cap of 5 concurrent tasks, but no fixed number per plan (8). A 429 carries `Retry-After` in seconds and the docs say CloudConvert retries retryable errors itself. No idempotency key (12). The terms promise 99.9 per cent monthly uptime with refunds on paid plans (10). API v2 is generally available and the MCP server carries no beta label (10).",
          "schema": "No OpenAPI document was found in the docs or llms.txt. `GET /v2/operations` returns each operation's options with types, defaults and enum values, which is a machine-readable contract for options only. The MCP tool schemas sit behind OAuth and were not read (10 of 25). llms.txt and a Markdown twin of every docs page (10). The reference states what each endpoint does and when the synchronous variants are a poor choice, and the MCP tool list gives one line a tool (12). Task parameters are typed in the docs, but format options are found at run time through the operations endpoint and `createJob` takes an arbitrary task graph (10). Every operation has a raw request, CLI, cURL and SDK example, and the docs show 422, 429 and failed-task bodies with codes, with no full code list (11). The `/v2` prefix and pinnable engine versions, with no changelog found (6).",
          "security": "API keys are created with any of six scopes and can be revoked, and OAuth 2.0 issues tokens for third-party clients, though the implicit grant is still supported and no rotation feature is documented. Signed URLs carry an HMAC signature, not the key (27). A key limited to `task.read` is read-only, and the MCP server asks for three scopes, one of them `task.write`. No confirmation step for deletes (12). Results come back as download links, and the `metadata` and `capture-website` operations handle untrusted content. The MCP page tells users to connect only the official URL, with no prompt-injection guidance (6). The security page says all access is logged and reviewable by the customer in activity logs, and jobs can be filtered by API key (11). ISO 27001 from TÜV Süd, a valid security.txt with a disclosure policy and no formal bounty, and no public advisories found (15).",
          "transparency": "Closed service with dated terms that cover API use, and MIT SDKs (18). The privacy policy of 17 April 2026 gives 24 hours for files, 72 hours for account data after deletion and 180 days for logs, which agrees with the docs' 24-hour task deletion. It says files are not read, mined or copied and that AI is used only for the docs' question box. A DPA is signed on request (25). No deprecation policy. The terms give 30 days' notice only if the whole service is discontinued, and the operations endpoint flags deprecated engine versions (5). Hosting, payment, support and AI providers are named with addresses, and regions are Germany and Virginia, with no separate sub-processor list (16)."
        },
        "sources": [
          {
            "what": "llms.txt",
            "url": "https://cloudconvert.com/docs/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API introduction, authentication, errors and rate limiting",
            "url": "https://cloudconvert.com/docs/raw/getting-started/introduction.md",
            "seen": "2026-10-09"
          },
          {
            "what": "jobs reference",
            "url": "https://cloudconvert.com/docs/raw/api-reference/jobs.md",
            "seen": "2026-10-09"
          },
          {
            "what": "tasks reference",
            "url": "https://cloudconvert.com/docs/raw/api-reference/tasks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "operations reference",
            "url": "https://cloudconvert.com/docs/raw/api-reference/operations.md",
            "seen": "2026-10-09"
          },
          {
            "what": "webhooks reference",
            "url": "https://cloudconvert.com/docs/raw/api-reference/webhooks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "PDF operations",
            "url": "https://cloudconvert.com/docs/raw/operations/pdf-operations.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server docs",
            "url": "https://cloudconvert.com/docs/raw/integrations/mcp-server.md",
            "seen": "2026-10-09"
          },
          {
            "what": "signed URLs",
            "url": "https://cloudconvert.com/docs/raw/integrations/signed-urls.md",
            "seen": "2026-10-09"
          },
          {
            "what": "import and export tasks",
            "url": "https://cloudconvert.com/docs/raw/import-export/export-files.md",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://cloudconvert.com/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "API product page",
            "url": "https://cloudconvert.com/apis/file-conversion",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service",
            "url": "https://cloudconvert.com/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://cloudconvert.com/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "security page",
            "url": "https://cloudconvert.com/security",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://cloudconvert.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "about and imprint",
            "url": "https://cloudconvert.com/about",
            "seen": "2026-10-09"
          },
          {
            "what": "blog",
            "url": "https://cloudconvert.com/blog",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.cloudconvert.com",
            "seen": "2026-10-09"
          },
          {
            "what": "incident history",
            "url": "https://status.cloudconvert.com/incidents",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://mcp.cloudconvert.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-09"
          },
          {
            "what": "SDK and CLI repositories, tags and workflows",
            "url": "https://github.com/cloudconvert",
            "seen": "2026-10-09"
          },
          {
            "what": "npm downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/cloudconvert",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=cloudconvert",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP",
            "url": "https://rdap.verisign.com/com/v1/domain/cloudconvert.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the price per credit for packages and subscriptions. The pricing page draws it by script, and only the $0.008 a file starting figure on the API page was read",
          "unchecked: the MCP server's tool schemas and annotations, which need an OAuth sign-in to list",
          "unchecked: issue response times on the SDK repositories, and PyPI download counts",
          "unchecked: the ISO 27001 certificate itself. The security page links it and names TÜV Süd",
          "No OpenAPI document, changelog or deprecation policy was found in the docs, llms.txt or site footer",
          "The terms forbid offering a stand-alone raw file conversion service on the API, which a general-purpose agent operator should read before reselling conversions"
        ]
      },
      "negative": 0,
      "verdict": "API keys and OAuth tokens carry six scopes, the terms promise 99.9 per cent monthly uptime with refunds, and uploaded files are deleted within 24 hours. No OpenAPI document or changelog was found, and the per-credit price is drawn by a script on the pricing page.",
      "bestFor": "An agent that converts between many file formats, merges to PDF, or needs OCR, PDF/A, encryption and page operations in one job, with storage on S3, Azure or Google Cloud.",
      "strengths": [
        "API keys are created with any of six scopes (`user.read`, `user.write`, `task.read`, `task.write`, `webhook.read`, `webhook.write`) and can be revoked",
        "The terms of service promise 99.9 per cent monthly uptime, with 1 per cent of the last invoice refunded per 10 minutes of unavailability",
        "Hosted MCP server at `https://mcp.cloudconvert.com` since 3 September 2026, with 24 tools and OAuth sign-in instead of a pasted key",
        "Files are deleted after 24 hours at the latest, and regional endpoints keep processing in Germany or in Virginia",
        "A 429 answer carries `Retry-After`, and the rate-limited endpoints return `X-RateLimit-Limit` and `X-RateLimit-Remaining`"
      ],
      "weaknesses": [
        "No OpenAPI document and no API changelog were found. The blog has one post since August 2024",
        "The price per credit is drawn by a script on the pricing page, so no price table is readable without a browser",
        "Rate limits are described as dynamic, with no fixed number per plan",
        "No idempotency key. The docs ask callers not to retry failed tasks automatically",
        "MCP tools take input files only as HTTP or HTTPS URLs, so local attachments fail in clients that do not turn uploads into links",
        "The terms forbid using the API to run a stand-alone raw file conversion service"
      ],
      "agentNotes": [
        "Build each job from an import task, one or more processing tasks and an `export/url` task, then read the download links from the export task's `result.files`",
        "Call `GET /v2/operations` with `include=options` to find the options a format pair accepts before creating a `convert` task",
        "Do not retry a failed task automatically. CloudConvert retries retryable errors itself, and a retry endpoint creates a new task",
        "Download output within 24 hours. Tasks, files and export URLs are deleted after that",
        "Use `https://sandbox.api.cloudconvert.com/v2` for tests. It consumes no credits and accepts only a fixed set of approved test files"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 66.4
        }
      ],
      "editorialScores": {
        "ergonomics": 71,
        "maintenance": 68,
        "payments": 35,
        "reliability": 80,
        "schema": 59,
        "security": 71,
        "transparency": 64
      },
      "provenanceScore": 85
    },
    "connect": {
      "install": "npm install -g cloudconvert-cli",
      "http": "curl -X POST \"https://api.cloudconvert.com/v2/jobs\" \\\n  -H \"Authorization: Bearer API_KEY\" \\\n  -H \"Content-type: application/json\" \\\n  -d '{\"tasks\":{\"import-my-file\":{\"operation\":\"import/url\",\"url\":\"https://my.url/file.docx\"},\"convert-my-file\":{\"operation\":\"convert\",\"input\":\"import-my-file\",\"output_format\":\"pdf\"},\"export-my-file\":{\"operation\":\"export/url\",\"input\":\"convert-my-file\"}}}'"
    },
    "letme": {
      "capability": "https://letme.dev/pdf.convert",
      "tool": "https://letme.dev/cloudconvert"
    },
    "notable": [
      "The hosted MCP server at `https://mcp.cloudconvert.com` was announced on 3 September 2026. It uses Streamable HTTP and OAuth 2.0 and lists 24 tools, eight of them PDF operations (https://cloudconvert.com/docs/raw/integrations/mcp-server.md)",
      "PDF operations are `pdf/a`, `pdf/x`, `pdf/ocr`, `pdf/encrypt`, `pdf/decrypt`, `pdf/split-pages`, `pdf/extract-pages` and `pdf/rotate-pages`, beside `convert`, `merge`, `optimize`, `watermark` and `capture-website` (https://cloudconvert.com/docs/raw/operations/pdf-operations.md)",
      "The terms of service (12 April 2022) promise 99.9 per cent monthly uptime and refund 1 per cent of the last invoice per 10 minutes of unavailability, on a claim with request logs (https://cloudconvert.com/terms)",
      "The terms require the API to be an integral component of software that adds significant value, and forbid a stand-alone raw file conversion service built on it (https://cloudconvert.com/terms)",
      "Lunaweb GmbH holds ISO 27001 certification from TÜV Süd, per its security page, and each conversion runs in its own isolated container (https://cloudconvert.com/security)",
      "Files are deleted after 24 hours at the latest, account data within 72 hours of account deletion and log data after 180 days (https://cloudconvert.com/privacy)",
      "The status page lists six incidents between 3 August and 8 October 2026 and shows 99.997 per cent uptime for the API over 90 days (https://status.cloudconvert.com/incidents)"
    ],
    "area": "web-data",
    "details": [
      {
        "label": "Surfaces",
        "value": "REST API v2 at `https://api.cloudconvert.com/v2`, a synchronous host at `https://sync.api.cloudconvert.com/v2`, a hosted MCP server at `https://mcp.cloudconvert.com`, signed URLs, a Socket.io feed, and a CLI"
      },
      {
        "label": "Operations",
        "value": "`convert`, `optimize`, `watermark`, `capture-website`, `thumbnail`, `merge`, `archive`, `metadata`, `command` (FFmpeg, ImageMagick, GraphicsMagick) and eight `pdf/` operations for PDF/A, PDF/X, OCR, encrypt, decrypt, split, extract and rotate"
      },
      {
        "label": "Formats",
        "value": "212 formats in 11 groups per the home page, 23 of them document formats"
      },
      {
        "label": "Import and export",
        "value": "URL, upload, Base64 or raw string in. S3, Azure Blob Storage, Google Cloud Storage, OpenStack and SFTP both ways. `export/url` links last 24 hours"
      },
      {
        "label": "MCP tools",
        "value": "24. Ten file tools, eight PDF tools, and `getUser`, `getOperations`, `createJob`, `getJobs`, `getJob`, `getTask`. Input files must be HTTP or HTTPS URLs"
      },
      {
        "label": "Credentials",
        "value": "API keys with six scopes, revocable, no expiry. OAuth 2.0 authorisation code and implicit grants. Webhooks and signed URLs are signed with HMAC SHA-256"
      },
      {
        "label": "Rate limits",
        "value": "Dynamic limits on creating jobs and tasks, with `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `Retry-After` on 429. Free plan runs 5 concurrent tasks"
      },
      {
        "label": "Regions",
        "value": "`eu-central` (Germany) and `us-east` (Virginia), chosen by nearest IP, by region host or by account setting"
      },
      {
        "label": "Sandbox",
        "value": "`https://sandbox.api.cloudconvert.com/v2`, unlimited jobs with no credits, for a fixed set of approved test files"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent monthly uptime on packages, subscriptions and enterprise plans, per the terms and the pricing table"
      },
      {
        "label": "SDKs",
        "value": "PHP 3.4.4 (29 July 2026), Java 1.2.5 and Ruby 1.2.0 (24 August 2026), .NET 1.4.2 (30 April 2026), Node.js 3.0.0 (24 April 2025), Python 2.1.0, plus a Laravel package and CLI 3.0.1 (21 July 2026), all MIT"
      },
      {
        "label": "Data retention",
        "value": "Files and tasks deleted after 24 hours at the latest, or at once on delete. Account data within 72 hours of account deletion. Logs 180 days"
      },
      {
        "label": "Hosting",
        "value": "Amazon Web Services, OVH and Hetzner in Germany, and OVH US for US traffic, per the privacy policy of 17 April 2026"
      },
      {
        "label": "Certification",
        "value": "ISO 27001 for Lunaweb GmbH's ISMS from TÜV Süd, per the security page. DPA signed on request for paid plans"
      }
    ],
    "provenance": {
      "legalEntity": "Lunaweb GmbH",
      "domain": "cloudconvert.com",
      "domainRegistered": "2008-10-02",
      "endpointOnVendorDomain": true,
      "terms": "https://cloudconvert.com/terms",
      "privacy": "https://cloudconvert.com/privacy",
      "statusPage": "https://status.cloudconvert.com",
      "changelog": "",
      "securityTxt": "valid",
      "checked": "2026-10-09",
      "notes": [
        "The imprint names Lunaweb GmbH, Nördliche Münchner Straße 47, 82031 Grünwald, Germany, commercial register Amtsgericht München HRB 238086.",
        "The terms of service are dated 12 April 2022 and say they apply to the entire website and any API usage. They incorporate the privacy policy, dated 17 April 2026.",
        "security.txt names a contact address, expires on 8 April 2027 and says there is no formal bug bounty.",
        "RDAP for cloudconvert.com gives a registration date of 2008-10-02.",
        "No API changelog was found. The blog carries product announcements, one of them since August 2024.",
        "The status page runs on Better Stack."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Lunaweb GmbH",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "cloudconvert.com, registered 2008-10-02 (18 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.cloudconvert.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.cloudconvert.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://cloudconvert.com/terms",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 1184,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Don't be evil and do bad things with our service."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The credits of your package will not expire as long as you do not terminate your account."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We reserve the right to close your account with 30 days notice if it does not make sense for us to continue business with you for commercial reasons.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You agree not to bypass these policies by any means (e.g., creating multiple accounts)."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "We will use commercially reasonable efforts to make each service available with a monthly uptime percentage of at least 99.9%.",
              "says": "Names 99.9% availability"
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "For greater certainty, you agree to not offer a raw file conversion service as stand-alone product using the CloudConvert API.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "CloudConvert says it makes no backups of customer files and is not liable for damages caused by using the service.",
              "quote": "We do not make backups of your files for data protection reasons. We are not liable for damages caused by using our service."
            },
            {
              "date": "2026-10-08",
              "text": "With Auto Refill enabled, the chosen package is charged automatically once 95 per cent of the previous package is consumed.",
              "quote": "By enabling the \"Auto Refill\" option, you agree to be charged your chosen package automatically, if your previous package is consumed by 95%."
            },
            {
              "date": "2026-10-08",
              "text": "Prepaid package credits do not expire as long as the account is not terminated.",
              "quote": "The credits of your package will not expire as long as you do not terminate your account."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://cloudconvert.com/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 5933,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect only the minimum amount of necessary data."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "All log data (IP address, user agent, referrer) is deleted after 180 days.",
              "says": "Names a period of 180 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "By contacting us via e-mail, the data processed is transferred to the service provider:"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "The data protection officer of the data controller is:",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Part of the order processing contract with Freshworks are so-called EU standard contractual clauses ((Art.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "CloudConvert says it uses AI only for the Ask AI feature of its documentation and does not use AI to process uploaded files.",
              "quote": "We use AI solely to power the \"Ask AI\" feature of our documentation. We do not use AI to process your uploaded files."
            },
            {
              "date": "2026-10-08",
              "text": "CloudConvert says it does not read, look into or mine data from uploaded files and makes no copies of them.",
              "quote": "We do not read, look into, or mine any data from your files, and we do not make any copies of them."
            },
            {
              "date": "2026-10-08",
              "text": "When an account is deleted, all personal data is permanently deleted within 72 hours.",
              "quote": "If you delete your account, all your personal data will be permanently deleted within 72 hours."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudconvert.json",
    "live": {
      "slug": "cloudconvert",
      "probe": {
        "target": "https://api.cloudconvert.com/v2",
        "method": "get",
        "lastAt": "2026-10-10T01:37:47.985576022Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 63,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 49,
        "p95ms24h": 128,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.cloudconvert.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-10T00:50:14.754320673Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "cloudconvert/cloudconvert-node",
          "version": "3.0.0",
          "released": "2025-04-24",
          "seenAt": "2026-10-09T16:45:56.322350445Z"
        },
        {
          "registry": "npm",
          "name": "cloudconvert",
          "version": "3.0.0",
          "seenAt": "2026-10-09T16:45:53.861394323Z"
        },
        {
          "registry": "npm",
          "name": "cloudconvert-cli",
          "version": "3.0.1",
          "seenAt": "2026-10-09T16:45:54.924682633Z"
        },
        {
          "registry": "pypi",
          "name": "cloudconvert",
          "version": "2.1.0",
          "released": "2022-03-30",
          "seenAt": "2026-10-09T16:45:56.121976508Z"
        }
      ],
      "githubStars": 192,
      "npmWeekly": 103789,
      "pypiWeekly": 152991,
      "pages": [
        {
          "url": "https://cloudconvert.com/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-09T18:33:56.706849483Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "05f0d28019ec"
        },
        {
          "url": "https://cloudconvert.com/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:34:00.208661298Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "618055db1cbe"
        },
        {
          "url": "https://cloudconvert.com/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:34:00.730376469Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ef7bfd5d6f7a"
        }
      ],
      "updatedAt": "2026-10-10T01:37:47.985576022Z"
    }
  }
}
