{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "foxit-pdf-services",
    "name": "Foxit PDF Services API",
    "vendor": "Foxit Software Incorporated",
    "vendorUrl": "https://developer-api.foxit.com",
    "kind": "http-api",
    "category": "pdf-tools",
    "summary": "Foxit's cloud REST API for PDF work. It converts Office files, HTML, Markdown and web pages to PDF and back, merges, splits, compresses, protects, redacts, fills forms and runs OCR. An official MCP server wraps it.",
    "url": "https://www.anchorterminal.com/tools/foxit-pdf-services",
    "markdownUrl": "https://www.anchorterminal.com/tools/foxit-pdf-services.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/foxit-pdf-services.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/foxit-pdf-services.json",
    "repo": "https://github.com/foxitsoftware/foxit-pdf-api-mcp-server",
    "license": "Proprietary service under the Foxit API Service Agreement. The MCP server is MIT per its package.json, with no licence file in the repository",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://na1.fusion.foxit.com/pdf-services",
    "packages": [
      {
        "registry": "npm",
        "name": "@foxitsoftware/foxit-pdf-api-mcp-server"
      }
    ],
    "auth": "oauth",
    "authNotes": "Self-serve. Sign up at app.developer-api.foxit.com with an email address and the dashboard shows a client ID and client secret for a default application. Exchange them at `https://na1.fusion.foxit.com/oauth/token` (client credentials, HTTP Basic recommended) for a Bearer token that lasts about 24 hours, with no refresh token and no scopes. An account holds up to 10 applications on the free plan and 50 on paid plans, each in sandbox or production mode. The MCP server sends the client ID and secret as `client_id` and `client_secret` headers on every call.",
    "pricing": "freemium",
    "pricingNotes": "Free Developer plan with 500 credits a year, renewed yearly, and the sign-up page asks only for an email address. Startup is $1,750 a year for 5,000 credits and Business $4,500 a year for 15,000, with Volume by quote. A PDF Services request costs 1 credit when it returns 2xx, whatever the page count. Failed requests, uploads, task polling and downloads are free. Credits are shared with the eSign (5 an envelope) and Document Generation APIs and do not roll over (https://app.developer-api.foxit.com/pricing, checked 2026-10-08).",
    "priceSummary": "$0.35 / call",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the OpenAPI file, the reference guides or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 42,
    "popularity": {
      "githubStars": 12,
      "npmWeekly": 47,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://app.developer-api.foxit.com/reference/tag/pdf-services-overview",
    "openapi": "https://app.developer-api.foxit.com/documentation/foxit-apis.yaml",
    "registryName": "io.github.foxitsoftware/foxit-pdf-api-mcp-server",
    "capabilities": [
      "pdf.convert",
      "pdf.merge",
      "pdf.forms",
      "pdf.generate",
      "pdf.extract",
      "docs.ocr"
    ],
    "tags": [
      "hosted",
      "mcp",
      "oauth",
      "openapi",
      "async-jobs",
      "free-tier",
      "typescript",
      "status-page"
    ],
    "lastRelease": "2026-07-13",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 48.3,
      "grade": "D",
      "agentReady": false,
      "rank": 727,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 49,
        "maintenance": 38,
        "payments": 40,
        "reliability": 47,
        "schema": 62,
        "security": 40,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 47,
          "points": 9.4,
          "reason": "Read with the hosted lines. status.foxit.com keeps 90-day component history for Foxit's cloud products, but has no component for the API gateway at na1.fusion.foxit.com or for PDF Services (8 of 20). With no component there is no readable incident history for this API (5). Rate limits are published as 15 requests a minute in sandbox mode and 100 in production mode, per application, over a rolling 60 seconds (15). The limits guide asks for exponential backoff on 429 and the credits guide says a retried request is not charged twice, but no Retry-After header is documented and 429 also signals an exhausted credit quota (9 of 15). The trust centre states an aim of 99.99 per cent uptime, and the API Service Agreement gives no availability warranty, so no SLA (0). PDF Services is generally available, with structural extraction marked trial (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 62,
          "points": 10.07,
          "reason": "A public OpenAPI 3.1 file, version 2.3.0, describes 38 PDF Services operations, and the MCP server's tools carry typed zod schemas (25). No llms.txt on either portal host and no Markdown twins. The reference pages are drawn by script from the OpenAPI file (0). Operation descriptions state purpose, use cases and limits, and MCP descriptions give the upload, operate and poll order, but none says when not to use a tool (13 of 20). Enums cover compression levels, permissions, ciphers and rotations and required fields are marked, while page ranges are pattern-free strings (11 of 15). The PDF Services paths carry 235 examples and coded 400 and 500 bodies, but 401 and 429 are not declared on those operations (10 of 15). The file has a version number, paths are unversioned and no changelog was found (3 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 49,
          "points": 7.96,
          "reason": "The MCP server at 1.1.2 has 42 tools in about 89 KB of source with no toolsets, the more-than-30 band (5). The API returns a document ID, not the file, and takes page ranges, so responses stay small (15). We averaged the two to 10 because the listing covers both. Page ranges, extract types and image DPI limit output, and nothing lists or pages stored documents (12 of 20). Errors are JSON with a code and a message that names the valid values, and a failed task reports its error (14 of 20). Credits are deduplicated by a `request_id`, but no header for a client to set one is documented, and the MCP tools carry no `readOnlyHint` or `destructiveHint` (6 of 20). Most operations need only `documentId`. No official SDK package was found beyond the MCP server (7 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 40,
          "points": 7,
          "reason": "OAuth 2.0 client credentials per application, with a Bearer token of about 24 hours, no scopes and no refresh token. Secrets can be rotated and the docs forbid credentials in query parameters (20 of 30). No read-only mode. Sandbox mode is the only separation. The MCP server has no annotations or confirmation step, `delete_document` is permanent, `upload_document` reads any `file://` path, `download_document` writes to any absolute path, and the HTTP stream transport binds 0.0.0.0 by default with no authentication in the source (2 of 20). Extracted text, Markdown and HTML, and pages fetched by URL, are untrusted content with no injection guidance (0). The dashboard shows credits used and remaining. No per-call log is documented (4 of 15). A disclosure policy with safe harbour, CVE numbering authority status, security bulletins and SOC 2 Type II for the cloud PDF APIs, with an expired security.txt and no bounty (14 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). The price per unit is public without a login. One credit per successful request, at $1,750 a year for 5,000 credits or $4,500 for 15,000 (20). The Developer plan gives 500 credits a year and the sign-up page asks only for an email address. We did not go past that page, so a later card step is unchecked (20). A person signs up in a browser to get the client ID and secret (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 38,
          "points": 3.33,
          "reason": "The MCP server's last npm release is 1.1.2 on 13 July 2026, 87 days before this check. The API itself has no dated release notes (20 of 30). One release in the last 90 days and no dated changelog entries (0). On GitHub, two bug reports of 27 August 2026 and a fix submitted on 29 August are still open, and the newest topics on the developer forum have no replies. Support runs through a case form (6 of 25). The server is in the official MCP registry under io.github.foxitsoftware, but the entry lists 0.2.3 from December 2025 (10 of 15). The repository has no CI workflow, no tests and no licence file, and its source stops at 0.2.3 while npm carries 1.1.2 (2 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 44, provenance 81",
          "reason": "A closed service under a dated API Service Agreement (30 June 2025). The MCP server is MIT per package.json with no licence file (17 of 30). The agreement says uploaded documents are deleted within 30 days. The privacy policy says uploads are deleted when processing completes and outputs typically within a day, and it states an effective date of 10 May 2022. It says customer documents are not used to train AI models. No DPA was found (14 of 30). The agreement promises prior notice of changes with no period, and there is no deprecation policy (4 of 20). Server locations are named as the United States, Germany, Canada, Australia and Japan, the API host is a single na1 address, and no sub-processor list for the API was found (9 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP server at 1.1.2 has 42 tools in about 89 KB of source with no toolsets, the more-than-30 band (5). The API returns a document ID, not the file, and takes page ranges, so responses stay small (15). We averaged the two to 10 because the listing covers both. Page ranges, extract types and image DPI limit output, and nothing lists or pages stored documents (12 of 20). Errors are JSON with a code and a message that names the valid values, and a failed task reports its error (14 of 20). Credits are deduplicated by a `request_id`, but no header for a client to set one is documented, and the MCP tools carry no `readOnlyHint` or `destructiveHint` (6 of 20). Most operations need only `documentId`. No official SDK package was found beyond the MCP server (7 of 15).",
          "maintenance": "The MCP server's last npm release is 1.1.2 on 13 July 2026, 87 days before this check. The API itself has no dated release notes (20 of 30). One release in the last 90 days and no dated changelog entries (0). On GitHub, two bug reports of 27 August 2026 and a fix submitted on 29 August are still open, and the newest topics on the developer forum have no replies. Support runs through a case form (6 of 25). The server is in the official MCP registry under io.github.foxitsoftware, but the entry lists 0.2.3 from December 2025 (10 of 15). The repository has no CI workflow, no tests and no licence file, and its source stops at 0.2.3 while npm carries 1.1.2 (2 of 10).",
          "payments": "No x402, MPP or L402 (0). The price per unit is public without a login. One credit per successful request, at $1,750 a year for 5,000 credits or $4,500 for 15,000 (20). The Developer plan gives 500 credits a year and the sign-up page asks only for an email address. We did not go past that page, so a later card step is unchecked (20). A person signs up in a browser to get the client ID and secret (0).",
          "reliability": "Read with the hosted lines. status.foxit.com keeps 90-day component history for Foxit's cloud products, but has no component for the API gateway at na1.fusion.foxit.com or for PDF Services (8 of 20). With no component there is no readable incident history for this API (5). Rate limits are published as 15 requests a minute in sandbox mode and 100 in production mode, per application, over a rolling 60 seconds (15). The limits guide asks for exponential backoff on 429 and the credits guide says a retried request is not charged twice, but no Retry-After header is documented and 429 also signals an exhausted credit quota (9 of 15). The trust centre states an aim of 99.99 per cent uptime, and the API Service Agreement gives no availability warranty, so no SLA (0). PDF Services is generally available, with structural extraction marked trial (10).",
          "schema": "A public OpenAPI 3.1 file, version 2.3.0, describes 38 PDF Services operations, and the MCP server's tools carry typed zod schemas (25). No llms.txt on either portal host and no Markdown twins. The reference pages are drawn by script from the OpenAPI file (0). Operation descriptions state purpose, use cases and limits, and MCP descriptions give the upload, operate and poll order, but none says when not to use a tool (13 of 20). Enums cover compression levels, permissions, ciphers and rotations and required fields are marked, while page ranges are pattern-free strings (11 of 15). The PDF Services paths carry 235 examples and coded 400 and 500 bodies, but 401 and 429 are not declared on those operations (10 of 15). The file has a version number, paths are unversioned and no changelog was found (3 of 15).",
          "security": "OAuth 2.0 client credentials per application, with a Bearer token of about 24 hours, no scopes and no refresh token. Secrets can be rotated and the docs forbid credentials in query parameters (20 of 30). No read-only mode. Sandbox mode is the only separation. The MCP server has no annotations or confirmation step, `delete_document` is permanent, `upload_document` reads any `file://` path, `download_document` writes to any absolute path, and the HTTP stream transport binds 0.0.0.0 by default with no authentication in the source (2 of 20). Extracted text, Markdown and HTML, and pages fetched by URL, are untrusted content with no injection guidance (0). The dashboard shows credits used and remaining. No per-call log is documented (4 of 15). A disclosure policy with safe harbour, CVE numbering authority status, security bulletins and SOC 2 Type II for the cloud PDF APIs, with an expired security.txt and no bounty (14 of 20).",
          "transparency": "A closed service under a dated API Service Agreement (30 June 2025). The MCP server is MIT per package.json with no licence file (17 of 30). The agreement says uploaded documents are deleted within 30 days. The privacy policy says uploads are deleted when processing completes and outputs typically within a day, and it states an effective date of 10 May 2022. It says customer documents are not used to train AI models. No DPA was found (14 of 30). The agreement promises prior notice of changes with no period, and there is no deprecation policy (4 of 20). Server locations are named as the United States, Germany, Canada, Australia and Japan, the API host is a single na1 address, and no sub-processor list for the API was found (9 of 20)."
        },
        "sources": [
          {
            "what": "developer portal home",
            "url": "https://developer-api.foxit.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "PDF Services product page with the MCP section",
            "url": "https://developer-api.foxit.com/pdf-services/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing and plans",
            "url": "https://app.developer-api.foxit.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "sign-up page",
            "url": "https://app.developer-api.foxit.com/sign-up",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI file named in the reference page's configuration, with the guides for credits, limits and authentication",
            "url": "https://app.developer-api.foxit.com/documentation/foxit-apis.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "credits guide",
            "url": "https://app.developer-api.foxit.com/reference/tag/credits-explained",
            "seen": "2026-10-08"
          },
          {
            "what": "limits guide",
            "url": "https://app.developer-api.foxit.com/reference/tag/limits",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication guide",
            "url": "https://app.developer-api.foxit.com/reference/tag/authentication-guide",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server repository, shallow clone",
            "url": "https://github.com/foxitsoftware/foxit-pdf-api-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package metadata and the 1.1.2 tarball source, read and not run",
            "url": "https://registry.npmjs.org/@foxitsoftware/foxit-pdf-api-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=foxit",
            "seen": "2026-10-08"
          },
          {
            "what": "Foxit API Service Agreement",
            "url": "https://www.foxit.com/api/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "General Terms of Service",
            "url": "https://www.foxit.com/product/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.foxit.com/company/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "API security and compliance page",
            "url": "https://www.foxit.com/api/api-security-compliance/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://www.foxit.com/trust-center/",
            "seen": "2026-10-08"
          },
          {
            "what": "vulnerability disclosure policy",
            "url": "https://www.foxit.com/support/responsible-disclosure-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.foxit.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "status page and history",
            "url": "https://status.foxit.com/history",
            "seen": "2026-10-08"
          },
          {
            "what": "developer blog feed",
            "url": "https://developer-api.foxit.com/feed/",
            "seen": "2026-10-08"
          },
          {
            "what": "developer forum, latest topics",
            "url": "https://developerforums.foxit.com/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for foxit.com",
            "url": "https://rdap.verisign.com/com/v1/domain/foxit.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The lead's docs link, docs.developer-api.foxit.com, is a Postman collection page. The current reference is at app.developer-api.foxit.com/reference and the API host is na1.fusion.foxit.com",
          "The MCP server is a local package that calls the hosted API. No hosted MCP endpoint was found",
          "The OpenAPI file's address was taken from the reference page's own configuration block, which also sets a YAML download. No other page links it",
          "The official MCP server authenticates with `client_id` and `client_secret` headers, while the reference documents only a Bearer token from `/oauth/token`. Whether the header scheme stays supported is not stated",
          "The PDF Services page claims ISO 27001. The trust centre and the API security page name SOC 2 Type II only",
          "unchecked: whether the free plan asks for a card after the email step",
          "unchecked: how a client sets the `request_id` that the credits guide says deduplicates retries",
          "unchecked: whether a DPA or a sub-processor list for the APIs exists. None was linked from the pages read",
          "unchecked: official SDK packages. A July 2025 forum post mentions a soft launch and none is linked from the reference",
          "unchecked: the Postman documentation at docs.developer-api.foxit.com, which is drawn by script",
          "The last few pages were fetched shortly after midnight on 9 October 2026 by the machine's clock. Dates here follow the batch date of 8 October"
        ]
      },
      "negative": 0,
      "verdict": "One credit per successful request, with failed calls, uploads, polling and downloads free, and a 500-credit yearly free plan. Access has no scopes, and the official MCP server reads and writes any local path. The status page has no component for the API, and no changelog was found.",
      "bestFor": "An agent that needs conversion, page operations, protection, redaction, forms and OCR at a flat per-request price with free failures.",
      "strengths": [
        "Public OpenAPI 3.1 file covering 38 PDF Services operations, with request examples and coded error bodies",
        "Flat price of 1 credit per successful request. Failed requests, uploads, task polling and downloads are not billed",
        "Free Developer plan with 500 credits a year, and paid plans published at $1,750 and $4,500 a year",
        "Rate limits published as 15 requests a minute in sandbox mode and 100 in production, per application",
        "Vulnerability disclosure policy with safe harbour, and Foxit assigns its own CVE IDs as a CNA"
      ],
      "weaknesses": [
        "OAuth client credentials carry no scopes, so every application credential can convert, delete and download",
        "status.foxit.com has no component for the API gateway at na1.fusion.foxit.com or for PDF Services",
        "No API changelog or deprecation policy found, and no llms.txt. The reference pages are drawn by script",
        "MCP server 1.1.2 has 42 tools with no annotations, and its public repository still holds 0.2.3",
        "The API agreement says uploads are deleted within 30 days. The privacy policy says on completion, with outputs kept about a day"
      ],
      "agentNotes": [
        "Exchange the client ID and secret at `https://na1.fusion.foxit.com/oauth/token` and cache the Bearer token. `expires_in` is about 24 hours and there is no refresh token",
        "Upload first with `POST /pdf-services/api/documents/upload`, start the operation, poll `GET /pdf-services/api/tasks/{task-id}` until `COMPLETED`, then download `resultDocumentId`",
        "Read the body of a 429. It means either the rate limit (15 a minute in sandbox, 100 in production) or `QUOTA_EXCEEDED` when credits run out",
        "Keep uploads under 100 MB, and delete documents with `DELETE /pdf-services/api/documents/{document-id}` when done. Deletion is permanent",
        "With the MCP server, pass only paths the task needs. `upload_document` reads any `file://` path and `download_document` writes to any absolute path"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 48.3
        }
      ],
      "editorialScores": {
        "ergonomics": 49,
        "maintenance": 38,
        "payments": 40,
        "reliability": 47,
        "schema": 62,
        "security": 40,
        "transparency": 44
      },
      "provenanceScore": 81
    },
    "connect": {
      "install": "npx @foxitsoftware/foxit-pdf-api-mcp-server",
      "http": "curl --request POST 'https://na1.fusion.foxit.com/oauth/token' \\\n  --user 'YOUR_CLIENT_ID:YOUR_CLIENT_SECRET' \\\n  --header 'Content-Type: application/x-www-form-urlencoded' \\\n  --data 'grant_type=client_credentials'",
      "config": {
        "mcpServers": {
          "foxit-pdf": {
            "args": [
              "-y",
              "@foxitsoftware/foxit-pdf-api-mcp-server"
            ],
            "command": "npx",
            "env": {
              "FOXIT_CLOUD_API_CLIENT_ID": "your_client_id",
              "FOXIT_CLOUD_API_CLIENT_SECRET": "your_client_secret",
              "FOXIT_CLOUD_API_HOST": "https://na1.fusion.foxit.com/pdf-services"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/pdf.convert",
      "tool": "https://letme.dev/foxit-pdf-services"
    },
    "notable": [
      "One OpenAPI 3.1 file (version 2.3.0) describes 68 operations on na1.fusion.foxit.com, 38 of them PDF Services, 27 eSign and 2 Document Generation (https://app.developer-api.foxit.com/documentation/foxit-apis.yaml)",
      "A PDF Services request is billed 1 credit only when it returns 2xx on a processing endpoint. Uploads, task polling and downloads are free (https://app.developer-api.foxit.com/reference/tag/credits-explained)",
      "Rate limits are per application, 15 requests a minute in sandbox mode and 100 in production mode (https://app.developer-api.foxit.com/reference/tag/limits)",
      "The MCP server on npm is 1.1.2 (13 July 2026) with 42 tools. The public repository's last commit is 23 January 2026 at 0.2.3 with 32 tools, and the MCP registry entry lists 0.2.3 (https://github.com/foxitsoftware/foxit-pdf-api-mcp-server)",
      "The API Service Agreement says a user must not disparage or adversely affect Foxit or its API products, and caps liability at $500 for trial use and $1,000 for paid use (https://www.foxit.com/api/terms-of-service/)",
      "The General Terms of Service bar data mining or similar data gathering and extraction methods in connection with the services (https://www.foxit.com/product/terms-of-service/)",
      "The PDF Services page names SOC 2 and ISO 27001. The trust centre and the API security page list SOC 2 Type II and not ISO 27001 (https://developer-api.foxit.com/pdf-services/, https://www.foxit.com/trust-center/)"
    ],
    "area": "web-data",
    "details": [
      {
        "label": "API",
        "value": "REST at https://na1.fusion.foxit.com/pdf-services, 38 operations in an OpenAPI 3.1 file (version 2.3.0) shared with the eSign and Document Generation APIs. Processing calls answer 202 with a `taskId`"
      },
      {
        "label": "Operations",
        "value": "Create PDF from Word, Excel, PowerPoint, HTML, URL, text, image and Markdown. Convert PDF to Word, Excel, PowerPoint, HTML, text, image and Markdown. Combine, split, extract, compress, linearise, flatten, manipulate pages, watermark, search and replace, protect, remove password, redact, compare, OCR, properties, auto-tag, form data import and export"
      },
      {
        "label": "Structural extraction",
        "value": "`POST /pdf-services/api/documents/pdf-structural-extract` returns a ZIP with JSON layout, tables and images. Marked trial in the reference"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 client credentials per application, no scopes, no refresh token. Up to 10 applications on the free plan and 50 on paid plans, each in sandbox or production mode"
      },
      {
        "label": "Rate limits",
        "value": "15 requests a minute per application in sandbox mode, 100 in production mode, over a rolling 60 seconds. Every HTTP method counts"
      },
      {
        "label": "Limits",
        "value": "100 MB per uploaded file. URL to PDF allows 30 seconds of JavaScript and 60 seconds of page load"
      },
      {
        "label": "Billing",
        "value": "1 credit per 2xx response on a processing endpoint. 4xx, 5xx, uploads, task polling and downloads are free. Credits reset yearly and do not roll over"
      },
      {
        "label": "Errors",
        "value": "JSON `code` and `message`, such as `VALIDATION_ERROR`, `MAX_UPLOAD_SIZE_EXCEEDED` and `QUOTA_EXCEEDED`. Task status is PENDING, IN_PROGRESS, COMPLETED or FAILED"
      },
      {
        "label": "MCP server",
        "value": "Official, `@foxitsoftware/foxit-pdf-api-mcp-server` 1.1.2 on npm (13 July 2026), MIT per package.json, 42 tools, stdio by default and HTTP stream on 0.0.0.0:8080 when asked. Authenticates with `client_id` and `client_secret` headers"
      },
      {
        "label": "Data retention",
        "value": "The API Service Agreement says uploaded documents are deleted within 30 days. The privacy policy says uploads are deleted when processing completes and outputs typically within a day"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II for the cloud-hosted PDF APIs per foxit.com/api/api-security-compliance. TLS 1.2 or higher in transit and AES-256 at rest per the same page"
      },
      {
        "label": "Status",
        "value": "status.foxit.com lists eSign, Admin Console, PDF Editor Cloud, accounts, AI Assistant, the websites and Smart Redact. No component for the API gateway"
      }
    ],
    "unitPrices": [
      {
        "item": "PDF Services request, Startup plan",
        "unit": "call",
        "usd": 0.35,
        "note": "$1,750 a year for 5,000 credits, 1 credit per successful request"
      },
      {
        "item": "PDF Services request, Business plan",
        "unit": "call",
        "usd": 0.3,
        "note": "$4,500 a year for 15,000 credits, 1 credit per successful request"
      },
      {
        "item": "Startup",
        "unit": "month",
        "usd": 168,
        "note": "Billed monthly. $1,750 billed yearly, 5,000 credits a year"
      },
      {
        "item": "Business",
        "unit": "month",
        "usd": 431,
        "note": "Billed monthly. $4,500 billed yearly, 15,000 credits a year"
      }
    ],
    "provenance": {
      "legalEntity": "Foxit Software Incorporated",
      "domain": "foxit.com",
      "domainRegistered": "2004-01-04",
      "endpointOnVendorDomain": true,
      "terms": "https://www.foxit.com/api/terms-of-service/",
      "privacy": "https://www.foxit.com/company/privacy-policy/",
      "statusPage": "https://status.foxit.com",
      "changelog": "",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The Foxit API Service Agreement (effective 30 June 2025) applies to the API services and is read with the General Terms of Service (effective 27 June 2025) and the Foxit Software Privacy Policy.",
        "The API answers at na1.fusion.foxit.com, a foxit.com subdomain. The developer portal is developer-api.foxit.com and the reference is app.developer-api.foxit.com.",
        "www.foxit.com/.well-known/security.txt carries `Expires: 2025-01-01T100:00:00.000Z`, which is past and not a valid timestamp. It names security-ml@foxit.com and the disclosure policy.",
        "status.foxit.com has no component for the API gateway or PDF Services. Its only entry naming the developer portal is an outage record of 9 December 2025 whose single update reads Testing.",
        "The privacy policy states it is effective as of 10 May 2022, and also carries later sections on AI model training and server locations.",
        "No API changelog was found on the developer portal, in the reference or in the MCP repository.",
        "RDAP for foxit.com gives a registration date of 2004-01-04."
      ],
      "score": 81,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Foxit Software Incorporated",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "foxit.com, registered 2004-01-04 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "na1.fusion.foxit.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.foxit.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.foxit.com/api/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-06-30",
          "words": 1296,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective as of June 30, 2025",
              "says": "Last updated 2025-06-30"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "For trial services, Foxit's total liability arising from or related to the services shall be capped at USD 500;"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "4.1 You may terminate your use of Foxit API Services at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "4.2 Subject to applicable laws, Foxit may terminate this Agreement for any reason upon 10 business days written notice.",
              "says": "Gives 10 business days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Moreover, you must not disparage or adversely affect Foxit or Foxit API products in any way while exercising the rights under this Agreement."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "The updated Agreement becomes effective upon publication and supersedes previous versions.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "4.2 Subject to applicable laws, Foxit may terminate this Agreement for any reason upon 10 business days written notice."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability for paid services is capped at the lesser of 1,000 US dollars or the amount paid in the preceding 12 months, and at 500 US dollars for trial services.",
              "quote": "For trial services, Foxit's total liability arising from or related to the services shall be capped at USD 500; for paid services, it shall not exceed the lesser of (a) USD 1,000 or (b) the total amount You paid for Foxit API Services in the 12 months preceding the event giving rise to the claim."
            },
            {
              "date": "2026-10-08",
              "text": "Documents uploaded to enable API functions are deleted within 30 days, subject to further instructions on the product page.",
              "quote": "Documents uploaded for such purposes will be deleted within 30 days, subject to further instructions on the product page."
            },
            {
              "date": "2026-10-08",
              "text": "The customer must not disparage or adversely affect Foxit or its API products while exercising rights under the agreement.",
              "quote": "Moreover, you must not disparage or adversely affect Foxit or Foxit API products in any way while exercising the rights under this Agreement."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.foxit.com/company/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 11623,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The data we collect is processed by us for the following purposes:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "The data for the interaction with our e-mails are stored pseudonym for 30 days and then completely anonymized.",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Join our managed service provider program to bundle, deploy, and support Foxit across your client base."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Clicking “Do Not Sell or Share My Personal Information” in our cookie banner.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "…the categories of recipients to whom your data has been disclosed, the planned retention period, the right to rectification, deletion, limitation of processing or opposition, the existence of the right to complain, the source of their data, if not collected from us, and the existence of automated decision-making inclu…"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For any questions about privacy in connection with our products and services or the use of our website, you can always contact our data protection officer.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "We rely on the European Commission's Standard Contractual Clauses (SCCs) and the Data Privacy Framework to ensure a high level of protection for your personal data.",
              "says": "Relies on standard contractual clauses and the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "For users reside in the U.S., our use of Meta Pixel may be considered targeted advertising or the “sharing” of personal information."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Text prompts, queries and responses in the AI Assistant are processed by Microsoft through Azure OpenAI.",
              "quote": "You acknowledge and agree that Microsoft will process the text prompts, queries and responses."
            },
            {
              "date": "2026-10-08",
              "text": "Chat contents from AI services may be collected and stored automatically on cloud servers, and the user can choose whether histories are stored.",
              "quote": "When you use our AI features/services, we may automatically collect and store the contents of your chat interactions on secure cloud servers."
            },
            {
              "date": "2026-10-08",
              "text": "Chat histories are not used to train or improve AI models without explicit consent.",
              "quote": "We will not use your chat histories to train or improve AI models unless you have given us explicit consent."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/foxit-pdf-services.json",
    "live": {
      "slug": "foxit-pdf-services",
      "probe": {
        "target": "https://na1.fusion.foxit.com/pdf-services",
        "method": "get",
        "lastAt": "2026-10-09T09:26:50.619122091Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 209,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 138,
        "p95ms24h": 315,
        "samples24h": 20,
        "samples30d": 20,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 20,
            "ok": 20
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.foxit.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:57:56.42451441Z"
      },
      "updatedAt": "2026-10-09T09:26:50.619122091Z"
    }
  }
}
