{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "nutrient-dws-processor",
    "name": "Nutrient DWS Processor API",
    "vendor": "Nutrient (PSPDFKit GmbH)",
    "vendorUrl": "https://www.nutrient.io",
    "kind": "http-api",
    "category": "pdf-tools",
    "summary": "Hosted REST API from Nutrient (formerly PSPDFKit) that generates, converts, merges, OCRs, redacts, watermarks and signs PDF and Office documents. Agents call it with a Bearer key or through a local stdio MCP server.",
    "url": "https://www.anchorterminal.com/tools/nutrient-dws-processor",
    "markdownUrl": "https://www.anchorterminal.com/tools/nutrient-dws-processor.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nutrient-dws-processor.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nutrient-dws-processor.json",
    "repo": "https://github.com/PSPDFKit/nutrient-dws-mcp-server",
    "license": "Proprietary service under the Nutrient DWS API licence agreement. The MCP server and the TypeScript and Python clients are MIT",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://api.nutrient.io",
    "packages": [
      {
        "registry": "npm",
        "name": "@nutrient-sdk/dws-mcp-server"
      },
      {
        "registry": "npm",
        "name": "@nutrient-sdk/dws-client-typescript"
      },
      {
        "registry": "pypi",
        "name": "nutrient-dws"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. A person signs up at dashboard.nutrient.io and copies a live key, sent as `Authorization: Bearer \u003ckey\u003e`. Keys can be scoped to one DWS product. `POST /tokens` issues a JWT limited to named operations and origins, valid for one hour by default and at most 24, and revocable with `DELETE /tokens`. The MCP server uses OAuth in a browser (PKCE, dynamic client registration, scopes such as `product:processor`) or `NUTRIENT_DWS_API_KEY` for headless use. Test keys need Support to enable them.",
    "pricing": "freemium",
    "pricingNotes": "Free plan of 50 credits a month, no card, with watermarked output. Paid plans are Starter $75 a month for 1,000 credits, Growth $275 for 5,000 and Pro $445 for 10,000, with 10 per cent off billed yearly and custom plans above that. Most tools cost a fixed number of credits per use, from 0.5 to 10, and AI redaction is priced per page. Pay-as-you-go overage has a spending cap, and on the free plan starts with a $25 wallet load. The per-credit overage rate was not readable (https://www.nutrient.io/api/pricing/processor-api/, checked 2026-10-08).",
    "priceSummary": "$75 / mo",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the guides, the OpenAPI document, the pricing page or the MCP server README (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 8,
    "popularity": {
      "githubStars": 71,
      "npmWeekly": 2701,
      "pypiWeekly": 2214,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.nutrient.io/guides/dws-processor/",
    "llmsTxt": "https://www.nutrient.io/guides/dws-processor/llms.txt",
    "openapi": "https://cdn.cloud.nutrient.io/dws/assets/specs/public@1.19.0-ec566a84de4ef6c97fd9b586262ddcc4.yml",
    "registryName": "io.github.PSPDFKit/nutrient-dws-mcp-server",
    "capabilities": [
      "pdf.convert",
      "pdf.merge",
      "pdf.forms",
      "pdf.generate",
      "pdf.extract",
      "docs.ocr",
      "docs.tables"
    ],
    "tags": [
      "hosted",
      "mcp",
      "oauth",
      "openapi",
      "llms-txt",
      "typescript",
      "python",
      "async-jobs",
      "free-tier",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-08-27",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.7,
      "grade": "B",
      "agentReady": false,
      "rank": 197,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 84,
        "maintenance": 78,
        "payments": 40,
        "reliability": 68,
        "schema": 84,
        "security": 66,
        "transparency": 73
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 68,
          "points": 13.6,
          "reason": "Graded with the hosted lines. Status page at www.nutrientstatus.com on Better Stack with a Processor API component and 90 days of daily history (20). The JSON feed shows DWS Platform, the routing layer in front of the API, down for 3,679 seconds (61 minutes) on 13 July 2026, and the Processor API monitor down on five days from 23 July to 23 August, the longest 715 seconds. We read the 13 July figure as one major outage (10). No written incident reports could be read. The pricing guide gives 100 requests a minute per key on all plans and 10 a minute for test keys (15). It recommends exponential backoff, async admission returns `Retry-After`, and `Idempotency-Key` covers async builds only, so 13 of 15. The product page mentions guaranteed SLAs on custom plans, but no SLA document is published and the terms disclaim availability (0). GA, at spec version 1.19.0 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 84,
          "points": 13.65,
          "reason": "A public OpenAPI 3.1.0 document, version 1.19.0, with 17 operations and 203 schemas, loaded by the reference page from Nutrient's CDN. The eight MCP tools have typed Zod inputs (25). llms.txt at site and product level with topic indexes, and a Markdown twin of each guide (10). Tag descriptions explain the Build API, async jobs and authorisation at length, and the MCP `document_processor` description sends extraction work to `parse_document` (15). 102 of 203 schemas use enums and build actions are discriminated by `type`. The MCP schema has one free-form record (13). Guides carry samples in six languages, and the errors guide and async tables document the response bodies (14). The spec is versioned and the MCP server keeps a changelog, but no public API changelog was found (7)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 84,
          "points": 13.65,
          "reason": "Eight MCP tools, in the ten-or-fewer band, though the schema source is 35 KB. API responses are files or `json-content` with switches for plain text, structured text, key-value pairs and tables (20). Page ranges per part, output switches, and MCP tools that write large output to a file and return a summary. Nothing to paginate (15). Errors carry `failingPaths` in JSONPath form, a `requestId`, and `error.reason` codes with recommended handling for async jobs (18). `Idempotency-Key` on async `/build` only, and all eight MCP tools carry the four annotations (17). Single-purpose endpoints such as `/processor/generate_pdf` need one file, `/build` chains actions, and official clients exist for TypeScript (3.0.0) and Python (3.1.0) (14)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 66,
          "points": 11.55,
          "reason": "OAuth at api.nutrient.io with PKCE (S256), dynamic client registration, a revocation endpoint and per-product scopes such as `product:processor`. Live keys can be scoped, and `POST /tokens` issues JWTs limited to named operations and origins, expiring within 24 hours and revocable. The base key can only be regenerated. No query-string credential is documented (28). Scoped keys, operation-limited JWTs, read-only annotations and an optional sandbox directory, but no confirmation step, and without `SANDBOX_PATH` the MCP server has no path restriction (13). Document text comes back as untrusted content. Large output goes to a file by design, and no prompt-injection guidance was found (4). Each response reports credit cost and remaining credits with a request id, and a usage endpoint exists. No audit log was found (6). SOC 2 Type 2 and SOC 3 per the trust centre, annual penetration testing by Prescient Security, and a vulnerability disclosure policy with a report page. security.txt is a 404 and no bounty was established (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Plans are public at $75, $275 and $445 a month for 1,000, 5,000 and 10,000 credits, with 10 per cent off for yearly billing, and the pricing page gives the credit cost of twelve tools, from 0.5 for HTML to PDF to 10 for a digital signature (20). The free plan gives 50 credits a month with no card and watermarked output (20). The OAuth server supports dynamic client registration and a device flow, but a person still signs in or signs up in a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "reason": "MCP server v0.1.3 tagged 27 August 2026, 42 days before this check, and the TypeScript client 3.0.0 on 23 August (20). Four MCP releases since 10 July (0.1.0, 0.1.1, 0.1.2, 0.1.3) plus the client release (20). On GitHub, issue 35 was fixed the day it was filed, while issue 29 has been open since 8 June with no reply and pull request 42 since 28 August. Support answers through a form with a stated target of one business day (15 of 25). The MCP server is in the official registry as `io.github.PSPDFKit/nutrient-dws-mcp-server` at 0.1.3 (15). CI runs lint, build and tests with actions pinned to commit hashes (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "note": "editorial 62, provenance 84",
          "reason": "The API is closed under a dated licence agreement (September 2026) naming PSPDFKit GmbH, and the MCP server and both clients are MIT, so between the two bands (20). The privacy policy has a Processor API section, the terms carry data processing terms in section 9, and files are deleted within 24 hours on plans without retention. Plans with retention enabled let Nutrient keep files and train models on them, and no public page says which plans those are (20). No deprecation policy. The terms allow changes at any time with reasonable efforts at notice, and the one deprecated endpoint in the spec has no removal date (4). The trust centre lists 51 sub-processors with locations, updated 8 September 2026, and the status page names Frankfurt and Oregon processing regions (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Eight MCP tools, in the ten-or-fewer band, though the schema source is 35 KB. API responses are files or `json-content` with switches for plain text, structured text, key-value pairs and tables (20). Page ranges per part, output switches, and MCP tools that write large output to a file and return a summary. Nothing to paginate (15). Errors carry `failingPaths` in JSONPath form, a `requestId`, and `error.reason` codes with recommended handling for async jobs (18). `Idempotency-Key` on async `/build` only, and all eight MCP tools carry the four annotations (17). Single-purpose endpoints such as `/processor/generate_pdf` need one file, `/build` chains actions, and official clients exist for TypeScript (3.0.0) and Python (3.1.0) (14).",
          "maintenance": "MCP server v0.1.3 tagged 27 August 2026, 42 days before this check, and the TypeScript client 3.0.0 on 23 August (20). Four MCP releases since 10 July (0.1.0, 0.1.1, 0.1.2, 0.1.3) plus the client release (20). On GitHub, issue 35 was fixed the day it was filed, while issue 29 has been open since 8 June with no reply and pull request 42 since 28 August. Support answers through a form with a stated target of one business day (15 of 25). The MCP server is in the official registry as `io.github.PSPDFKit/nutrient-dws-mcp-server` at 0.1.3 (15). CI runs lint, build and tests with actions pinned to commit hashes (8).",
          "payments": "No x402, MPP or L402 (0). Plans are public at $75, $275 and $445 a month for 1,000, 5,000 and 10,000 credits, with 10 per cent off for yearly billing, and the pricing page gives the credit cost of twelve tools, from 0.5 for HTML to PDF to 10 for a digital signature (20). The free plan gives 50 credits a month with no card and watermarked output (20). The OAuth server supports dynamic client registration and a device flow, but a person still signs in or signs up in a browser (0).",
          "reliability": "Graded with the hosted lines. Status page at www.nutrientstatus.com on Better Stack with a Processor API component and 90 days of daily history (20). The JSON feed shows DWS Platform, the routing layer in front of the API, down for 3,679 seconds (61 minutes) on 13 July 2026, and the Processor API monitor down on five days from 23 July to 23 August, the longest 715 seconds. We read the 13 July figure as one major outage (10). No written incident reports could be read. The pricing guide gives 100 requests a minute per key on all plans and 10 a minute for test keys (15). It recommends exponential backoff, async admission returns `Retry-After`, and `Idempotency-Key` covers async builds only, so 13 of 15. The product page mentions guaranteed SLAs on custom plans, but no SLA document is published and the terms disclaim availability (0). GA, at spec version 1.19.0 (10).",
          "schema": "A public OpenAPI 3.1.0 document, version 1.19.0, with 17 operations and 203 schemas, loaded by the reference page from Nutrient's CDN. The eight MCP tools have typed Zod inputs (25). llms.txt at site and product level with topic indexes, and a Markdown twin of each guide (10). Tag descriptions explain the Build API, async jobs and authorisation at length, and the MCP `document_processor` description sends extraction work to `parse_document` (15). 102 of 203 schemas use enums and build actions are discriminated by `type`. The MCP schema has one free-form record (13). Guides carry samples in six languages, and the errors guide and async tables document the response bodies (14). The spec is versioned and the MCP server keeps a changelog, but no public API changelog was found (7).",
          "security": "OAuth at api.nutrient.io with PKCE (S256), dynamic client registration, a revocation endpoint and per-product scopes such as `product:processor`. Live keys can be scoped, and `POST /tokens` issues JWTs limited to named operations and origins, expiring within 24 hours and revocable. The base key can only be regenerated. No query-string credential is documented (28). Scoped keys, operation-limited JWTs, read-only annotations and an optional sandbox directory, but no confirmation step, and without `SANDBOX_PATH` the MCP server has no path restriction (13). Document text comes back as untrusted content. Large output goes to a file by design, and no prompt-injection guidance was found (4). Each response reports credit cost and remaining credits with a request id, and a usage endpoint exists. No audit log was found (6). SOC 2 Type 2 and SOC 3 per the trust centre, annual penetration testing by Prescient Security, and a vulnerability disclosure policy with a report page. security.txt is a 404 and no bounty was established (15).",
          "transparency": "The API is closed under a dated licence agreement (September 2026) naming PSPDFKit GmbH, and the MCP server and both clients are MIT, so between the two bands (20). The privacy policy has a Processor API section, the terms carry data processing terms in section 9, and files are deleted within 24 hours on plans without retention. Plans with retention enabled let Nutrient keep files and train models on them, and no public page says which plans those are (20). No deprecation policy. The terms allow changes at any time with reasonable efforts at notice, and the one deprecated endpoint in the spec has no removal date (4). The trust centre lists 51 sub-processors with locations, updated 8 September 2026, and the status page names Frankfurt and Oregon processing regions (18)."
        },
        "sources": [
          {
            "what": "llms.txt for the Processor API",
            "url": "https://www.nutrient.io/guides/dws-processor/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "getting started guide",
            "url": "https://www.nutrient.io/guides/dws-processor/getting-started.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference",
            "url": "https://www.nutrient.io/api/reference/public/",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.1 document, version 1.19.0",
            "url": "https://cdn.cloud.nutrient.io/dws/assets/specs/public@1.19.0-ec566a84de4ef6c97fd9b586262ddcc4.yml",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication guide",
            "url": "https://www.nutrient.io/guides/dws-processor/developer-guides/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "errors guide",
            "url": "https://www.nutrient.io/guides/dws-processor/developer-guides/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing guide with rate limits",
            "url": "https://www.nutrient.io/guides/dws-processor/pricing.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://www.nutrient.io/api/pricing/processor-api/",
            "seen": "2026-10-08"
          },
          {
            "what": "product page and FAQ",
            "url": "https://www.nutrient.io/api/processor-api/",
            "seen": "2026-10-08"
          },
          {
            "what": "test mode guide",
            "url": "https://www.nutrient.io/guides/dws-processor/test-mode.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security guide",
            "url": "https://www.nutrient.io/guides/dws-processor/security.md",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy guide",
            "url": "https://www.nutrient.io/guides/dws-processor/privacy.md",
            "seen": "2026-10-08"
          },
          {
            "what": "DWS API licence agreement",
            "url": "https://www.nutrient.io/legal/cloud-terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.nutrient.io/legal/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre and sub-processor list",
            "url": "https://trust.nutrient.io/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.nutrient.io/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://www.nutrientstatus.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status page JSON feed",
            "url": "https://www.nutrientstatus.com/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth server metadata",
            "url": "https://api.nutrient.io/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server repository, source, tags and changelog",
            "url": "https://github.com/PSPDFKit/nutrient-dws-mcp-server",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=nutrient",
            "seen": "2026-10-08"
          },
          {
            "what": "npm, TypeScript client",
            "url": "https://registry.npmjs.org/@nutrient-sdk/dws-client-typescript",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI, Python client",
            "url": "https://pypi.org/pypi/nutrient-dws/json",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for nutrient.io",
            "url": "https://rdap.identitydigital.services/rdap/domain/nutrient.io",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.nutrient.io/.well-known/security.txt",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the pay-as-you-go price per credit on each plan. The pricing page draws it by script and our read showed a placeholder",
          "unchecked: which plans have data retention enabled. The terms say it is indicated for each subscription plan, and the public pricing page does not say",
          "unchecked: written incident reports. The status page's updates view returned an empty body, so the incident record is read from per-day downtime seconds in the JSON feed",
          "unchecked: the per-tool credit table in the dashboard, which is behind a sign-in. The Markdown twin of the per-tool pricing guide has empty credit cells, so costs come from the twelve tools shown on the pricing page",
          "unchecked: the date of OpenAPI version 1.19.0. No public API changelog was found",
          "unchecked: the vulnerability disclosure policy and SOC 2 report in the trust centre, which need an access request",
          "The lead called the MCP server a way to use the API. It is a local stdio package, not a hosted endpoint, and it also wraps the separate Data Extraction API"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "2026-10-08. The product page FAQ says the API runs without strict rate limits or hard caps, while the pricing guide sets 100 requests a minute per key on every plan. The MCP product page also invites users to start on a free test key, which the test-mode guide says Support must enable first. Two points (https://www.nutrient.io/api/processor-api/, https://www.nutrient.io/guides/dws-processor/pricing.md)."
      ],
      "verdict": "A public OpenAPI 3.1 document, JSONPath-level error bodies and OAuth or operation-limited tokens make the API easy for an agent to call, and 50 free credits a month need no card. The status feed shows 61 minutes of platform downtime on 13 July 2026, and the terms let plans with data retention train models on submitted files.",
      "bestFor": "An agent that must change or produce documents (merge, convert, OCR, redact, sign, fill forms) in one chained request with predictable per-use cost.",
      "strengths": [
        "OpenAPI 3.1 document (version 1.19.0) for 17 operations, with llms.txt indexes and a Markdown twin of every guide",
        "Errors return `failingPaths` in JSONPath form, a `requestId`, and machine-readable `error.reason` codes for async jobs",
        "OAuth with PKCE, dynamic client registration and per-product scopes, plus JWTs limited by operation, origin and expiry of up to 24 hours",
        "All eight MCP tools carry `readOnlyHint`, `destructiveHint`, `idempotentHint` and `openWorldHint`, and file access can be confined to a sandbox directory",
        "Free plan of 50 credits a month with no card, and the vendor says failed requests (4xx or 5xx) cost no credits"
      ],
      "weaknesses": [
        "The status feed records 61 minutes of DWS Platform downtime on 13 July 2026 and five days with Processor API downtime since 23 July",
        "Plans with data retention enabled let Nutrient keep files and train models on them, and no public page says which plans those are",
        "The product page says there are no strict rate limits, while the pricing guide sets 100 requests a minute per key on every plan",
        "No public API changelog or deprecation policy was found, and the terms allow changes to the API at any time",
        "`Idempotency-Key` works only on async `/build` requests, and free-plan output is watermarked"
      ],
      "agentNotes": [
        "Send `Authorization: Bearer \u003ckey\u003e` to `https://api.nutrient.io`. Use `POST /build` with an `instructions` JSON part to chain several actions in one charged request",
        "Call `POST /analyze_build` first to get the credit cost of a build. The call is free",
        "Stay under 100 requests a minute per key and back off exponentially on 429. Test keys allow 10 a minute and 5 MB",
        "For long jobs send `Prefer: respond-async` with an `Idempotency-Key`, then poll the `Location` URL with `X-Async-Job-Token` after `Retry-After`",
        "Set `SANDBOX_PATH` for the MCP server. Without it the server reads and writes any path the user account can reach"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.7
        }
      ],
      "editorialScores": {
        "ergonomics": 84,
        "maintenance": 78,
        "payments": 40,
        "reliability": 68,
        "schema": 84,
        "security": 66,
        "transparency": 62
      },
      "provenanceScore": 84
    },
    "connect": {
      "install": "npm install @nutrient-sdk/dws-client-typescript",
      "http": "curl -X POST 'https://api.nutrient.io/build' \\\n  -H 'Authorization: Bearer YOUR_API_KEY' \\\n  -F 'index.html=@index.html' \\\n  -F 'instructions={\"parts\":[{\"html\":\"index.html\"}]}' \\\n  -o hello.pdf",
      "config": {
        "mcpServers": {
          "nutrient-dws": {
            "args": [
              "-y",
              "@nutrient-sdk/dws-mcp-server"
            ],
            "command": "npx",
            "env": {
              "SANDBOX_PATH": "/your/sandbox/directory"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/pdf.convert",
      "tool": "https://letme.dev/nutrient-dws-processor"
    },
    "notable": [
      "`POST /build` takes an `instructions` JSON part that assembles a document from files, URLs, HTML or blank pages and chains actions such as OCR, watermark, rotate, flatten and redact in one request (https://www.nutrient.io/api/reference/public/)",
      "`POST /analyze_build` returns the credit cost of a build without running it, free of charge (https://www.nutrient.io/guides/dws-processor/pricing/calculate-credit-usage.md)",
      "Async builds use `Prefer: respond-async`, accept an `Idempotency-Key` and return a job URL plus a `jat_` job access token (https://www.nutrient.io/api/reference/public/)",
      "Rate limit of 100 requests a minute per API key on every plan, and 10 a minute with a 5 MB cap for test keys (https://www.nutrient.io/guides/dws-processor/pricing.md)",
      "For plans with data retention enabled the terms grant Nutrient a licence to keep submitted files and outputs and train models on them. Other plans delete files within 24 hours (https://www.nutrient.io/legal/cloud-terms/)",
      "The free tier is closed to commercial use by organisations with more than 20 employees or over $1 million in yearly revenue (https://www.nutrient.io/legal/cloud-terms/)",
      "The MCP server is a local stdio package with eight tools, and it also wraps the separate Data Extraction API (https://github.com/PSPDFKit/nutrient-dws-mcp-server)",
      "The status page runs on Better Stack and lists DWS Platform, Processor API and two processing regions, Frankfurt and Oregon (https://www.nutrientstatus.com/)"
    ],
    "area": "web-data",
    "details": [
      {
        "label": "Endpoints",
        "value": "17 operations in OpenAPI 1.19.0. `/build`, `/analyze_build`, `/sign`, `/ai/redact`, `/process_office_template`, six `/processor/*` shortcuts (convert_to_pdf, generate_pdf, ocr, redact, watermark, md_to_pdf), async job status and result, `/tokens`, and account usage"
      },
      {
        "label": "Operations",
        "value": "HTML, Markdown, Office, image and URL to PDF, PDF to Office, HTML, Markdown and images, merge, split, rotate, page edits, watermark, OCR, redaction and AI redaction, form filling by Instant JSON, XFDF import, flatten, passwords and permissions, optimisation, linearisation, PDF/A and PDF/UA, digital signatures, text, table and key-value extraction"
      },
      {
        "label": "Free tier",
        "value": "50 credits a month, no card, output watermarked. Not for commercial use by organisations over 20 employees or $1 million in revenue"
      },
      {
        "label": "Credit costs",
        "value": "Fixed per use for most tools. HTML to PDF 0.5, image to PDF 0.5, PDF to image 0.5, merge 1, compress 1, watermark 1, redaction 1, Office to PDF 1, PDF to Office 1, OCR 2, text extraction 3, digital signature 10. AI redaction is per page"
      },
      {
        "label": "Rate limits",
        "value": "100 requests a minute per API key on all plans. Test keys 10 a minute, 5 MB request and result size, no AI tools"
      },
      {
        "label": "Errors",
        "value": "JSON body with `details`, `status`, `requestId` and `failingPaths` (JSONPath plus message). Async jobs add `error.reason` codes. `/build` documents 400, 401, 402, 403, 408, 409, 413, 422, 429, 500 and 503"
      },
      {
        "label": "Async and retries",
        "value": "`Prefer: respond-async` on `/build` returns 202 with `Location`, `Retry-After` and a job access token. `Idempotency-Key` up to 255 bytes, async only"
      },
      {
        "label": "Credentials",
        "value": "Live API key (global or scoped), JWT from `POST /tokens` with allowed operations, origins and expiry up to 24 hours, or OAuth with PKCE and dynamic client registration"
      },
      {
        "label": "MCP server",
        "value": "Official, local stdio, `npx -y @nutrient-sdk/dws-mcp-server`, MIT, v0.1.3. Eight tools (document_processor, document_signer, ai_redactor, check_credits, parse_document, extract_fields, sandbox_file_tree, directory_tree) and five prompts. All tools annotated"
      },
      {
        "label": "SDKs",
        "value": "TypeScript `@nutrient-sdk/dws-client-typescript` 3.0.0 (23 August 2026) and Python `nutrient-dws` 3.1.0 (27 May 2026), both MIT. Samples for Java, C#, PHP and shell"
      },
      {
        "label": "Data retention",
        "value": "Plans without retention delete uploads and results within 24 hours and store only MIME type and page count. Plans with retention keep files and outputs and use them to train models"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2 and SOC 3 per trust.nutrient.io, annual penetration testing by Prescient Security, vulnerability disclosure policy"
      },
      {
        "label": "Status",
        "value": "www.nutrientstatus.com on Better Stack. Processor API 99.981 per cent and DWS Platform 99.950 per cent over 90 days, as the page reports"
      },
      {
        "label": "Billing",
        "value": "Paddle is merchant of record. Responses carry `x-pspdfkit-request-cost` and `x-pspdfkit-remaining-credits`. The vendor says 4xx and 5xx responses cost no credits"
      }
    ],
    "unitPrices": [
      {
        "item": "Starter",
        "unit": "month",
        "usd": 75,
        "note": "1,000 credits. $67 a month billed yearly"
      },
      {
        "item": "Growth",
        "unit": "month",
        "usd": 275,
        "note": "5,000 credits. $247 a month billed yearly"
      },
      {
        "item": "Pro",
        "unit": "month",
        "usd": 445,
        "note": "10,000 credits. $399 a month billed yearly"
      },
      {
        "item": "Credit on Starter",
        "unit": "credit",
        "usd": 0.075,
        "note": "Worked out from $75 for 1,000 credits. Merge costs 1 credit, OCR 2, a digital signature 10"
      }
    ],
    "provenance": {
      "legalEntity": "PSPDFKit GmbH",
      "domain": "nutrient.io",
      "domainRegistered": "2019-12-03",
      "endpointOnVendorDomain": true,
      "terms": "https://www.nutrient.io/legal/cloud-terms/",
      "privacy": "https://www.nutrient.io/legal/privacy/",
      "statusPage": "https://www.nutrientstatus.com",
      "changelog": "https://github.com/PSPDFKit/nutrient-dws-mcp-server/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The DWS API licence agreement (last updated September 2026) names PSPDFKit GmbH, doing business as Nutrient, Kaiserstrasse 117/17, 1070 Vienna, Austria, and applies Austrian law. Section 9 and Schedule 1 are the data processing terms.",
        "The privacy policy has a Nutrient API section naming PSPDFKit GmbH as controller, with a Processor API subsection.",
        "The API answers at https://api.nutrient.io. An unauthenticated request returned 401 with a JSON error and request id.",
        "The status page is on a separate domain, www.nutrientstatus.com, run on Better Stack.",
        "The changelog link is the MCP server's. No public changelog for the API itself was found.",
        "www.nutrient.io/.well-known/security.txt returns 404. Reports go through www.nutrient.io/security/report-vulnerability/.",
        "RDAP for nutrient.io gives a registration date of 2019-12-03.",
        "robots.txt carries `Content-Signal: search=yes, ai-input=yes, ai-train=yes` for every user agent."
      ],
      "score": 84,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "PSPDFKit GmbH",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "nutrient.io, registered 2019-12-03 (6 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.nutrient.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "www.nutrientstatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.nutrient.io/legal/cloud-terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 6776,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "…with Nutrient as data exporter and you as data importer, the optional Clause 7 omitted, and the laws of Austria and the courts of Vienna, Austria selected under Clauses 17 and 18.",
              "says": "The law of Austria, with disputes in the courts of Vienna, Austria"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT SHALL WE, OUR AFFILIATES, OUR SUBSIDIARIES, AND/OR OUR SUPPLIERS BE LIABLE TO YOU, YOUR AFFILIATES, AND/OR YOUR END-USERS FOR ANY DAMAGES OF ANY TYPE, WHETHER DIRECT OR INDIRECT, CONSEQUENTIAL, INCIDENTAL, OR SPECIAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST REVENUES, LOST PROFITS, LOSSES RESULTING FROM…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The term (“Term”) of the license granted under this Agreement shall continue until terminated, as set forth herein."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You further agree that if you do not acknowledge and agree with all terms set forth in this Agreement, you may not and will not use or access the API."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "In all cases, you may exercise your data-subject rights, including the right to object and the right to deletion, as described in our Privacy Policy."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "On plans with data retention enabled, Nutrient may keep and use de-identified and anonymised derivatives of submitted content without limitation, and these survive termination.",
              "quote": "to create de-identified and anonymized derivatives, which Nutrient may retain and use without limitation and which survive termination."
            },
            {
              "date": "2026-10-08",
              "text": "Nutrient may list and disclose the customer's name, company and products that include the API on its website and related material.",
              "quote": "8.2. We (or any future maintainer of the API) shall be permitted to list and disclose your name and/or company and your products that include the API on our website and related material."
            },
            {
              "date": "2026-10-08",
              "text": "Commercial use of the API by organisations exceeding 20 employees or 1 million US dollars in annual revenue is a material breach unless covered by a paid subscription.",
              "quote": "Any commercial use of the API by organizations exceeding 20 employees or $1 million USD in annual revenue constitutes a material breach of this Agreement unless covered by a paid subscription."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.nutrient.io/legal/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 9998,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Data we may collect and how we use it"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will store your data as long as it is required for our business purposes and/or as required by law (e.g.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Google may disclose this data to third parties if this is required by law or if third parties process this data on behalf of Google."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "In the event that we buy or sell any business or asset, we may disclose Personal Data to the prospective seller or buyer of such business or assets."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You may also have the right to object to this processing, to request erasure, and to access your data, and to lodge a complaint with your supervisory authority."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions or concerns regarding this Privacy Policy, please contact us by email at legal@nutrient.io or by postal mail to Nutrient, 4509 Creedmoor Road, Suite 503, Raleigh, NC 27612, USA.",
              "says": "legal@nutrient.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Data Privacy Frameworks (“DPF”) and the UK Extension to the EU-U.S.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "You can ask us to stop using your files and to delete them at any time by contacting us at legal@nutrient.io."
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We may share Personal Data and Other Data to advisors, advertisers, and investors for the purpose of conducting general business analysis or other business purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "On retention-enabled plans Nutrient keeps an internal copy for improvement and training that is not removed when a run expires or is deleted from the customer's history.",
              "quote": "Separately, on retention-enabled plans we keep an internal copy to improve and train our services; that internal copy is retained for as long as it remains useful for those purposes, subject to periodic review, and is not removed simply because a run expires or is deleted from your history."
            },
            {
              "date": "2026-10-08",
              "text": "Information uploaded to a demo or with a technical support request is treated as consented to public disclosure unless the licence agreement says otherwise.",
              "quote": "On the basis of this information, you consent to public disclosure of the information you upload to a demo of our Services or as part of your technical support request, unless your license agreement with us provides otherwise."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/nutrient-dws-processor.json",
    "live": {
      "slug": "nutrient-dws-processor",
      "probe": {
        "target": "https://api.nutrient.io",
        "method": "get",
        "lastAt": "2026-10-09T10:14:22.215147159Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 172,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 175,
        "p95ms24h": 254,
        "samples24h": 28,
        "samples30d": 28,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 28,
            "ok": 28
          }
        ]
      },
      "vendorStatus": {
        "page": "https://www.nutrientstatus.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:13.620346657Z"
      },
      "updatedAt": "2026-10-09T10:14:22.215147159Z"
    }
  }
}
