# Cofferdock (remote · api.cofferdock.com)

Real files for AI assistants: HTML to image/PDF, screenshots, QR, charts, PDF tools, validators.

- Trust score: 38/100 (low)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-03

## Components

- remote · `api.cofferdock.com`: 38/100 (this document), [markdown](https://verifymcp.io/servers/com-cofferdock-cofferdock/api.md), [page](https://verifymcp.io/servers/com-cofferdock-cofferdock/api)

## Channel facts

- Endpoint: `https://api.cofferdock.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-03.

- **Endpoint Security**: 94/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the Cofferdock MCP server?

Cofferdock is a hosted endpoint at https://api.cofferdock.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-cofferdock-cofferdock 'https://api.cofferdock.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-cofferdock-cofferdock": {
      "url": "https://api.cofferdock.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-cofferdock-cofferdock": {
      "type": "http",
      "url": "https://api.cofferdock.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-cofferdock-cofferdock]
url = "https://api.cofferdock.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-cofferdock-cofferdock": {
      "type": "remote",
      "url": "https://api.cofferdock.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-cofferdock-cofferdock --url 'https://api.cofferdock.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-cofferdock-cofferdock:
    url: "https://api.cofferdock.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-cofferdock-cofferdock": {
      "Transport": "http",
      "Url": "https://api.cofferdock.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-cofferdock-cofferdock -t streamable-http -u 'https://api.cofferdock.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-cofferdock-cofferdock": {
      "type": "http",
      "url": "https://api.cofferdock.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 38, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 38, 0)

- [security regression] Endpoint reachability: reachable → behind authorisation

### 2026-09-26 (score 38)

First indexed and scored.

## MCP tools (26)

### `get_status` (~56 tokens)

Check your plan and remaining credits

Check your plan and remaining credits. Returns your plan, the monthly limit, how many credits you have used and how many are left. Free: does not cost a credit. Useful at the start of a workflow to decide whether to continue.

### `html_to_image` (~301 tokens)

HTML to image (PNG, JPEG or WebP)

HTML to image (PNG, JPEG or WebP). Renders HTML (with inline CSS; fonts and images from the internet are allowed, JavaScript is not executed) into an image. Ideal for social cards, certificates, tickets, OG images or any design you can describe in HTML. Send either html, or template + data to use a ready-made design.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `data` (object): Texts for the template, e.g. { "name": "Jane Doe", "course": "n8n basics" } for "certificate". Plain text only: everything is escaped. Fields you leave out keep the example text.
- `format` (string)
- `full_page` (boolean): Capture the whole content height instead of the viewport.
- `height` (integer)
- `html` (string): The HTML to render (max 5 MB). Put the CSS inline or in a <style> tag. Required unless you use template.
- `lang` (string): Language of the example texts of the template.
- `quality` (integer): For jpeg and webp.
- `template` (string): Use one of our ready-made designs instead of sending html. Fields, example texts and sizes: https://cofferdock.com/templates.json
- `wait_ms` (integer): Extra wait before the snapshot.
- `width` (integer)

### `html_to_pdf` (~267 tokens)

HTML to PDF

HTML to PDF. Renders HTML into a PDF (invoices, reports, tickets, contracts). Same rendering engine as /capture: inline CSS, web fonts and images allowed, no JavaScript. Send either html, or template + data (the "invoice" template works well as a PDF).

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `data` (object): Texts for the template, e.g. { "name": "Jane Doe", "course": "n8n basics" } for "certificate". Plain text only: everything is escaped. Fields you leave out keep the example text.
- `format` (string): Paper size.
- `html` (string): The HTML to render (max 5 MB). Required unless you use template.
- `landscape` (boolean)
- `lang` (string): Language of the example texts of the template.
- `margin` (integer): Margin in millimetres, same on all four sides.
- `print_background` (boolean): Print background colours and images.
- `scale` (number)
- `template` (string): Use one of our ready-made designs instead of sending html. Fields, example texts and sizes: https://cofferdock.com/templates.json

### `screenshot_url` (~119 tokens)

Screenshot of a public web page

Screenshot of a public web page. Loads a public URL in a real browser (JavaScript enabled) and takes a screenshot. Private networks and internal addresses are blocked.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `format` (string)
- `full_page` (boolean)
- `height` (integer)
- `quality` (integer): JPEG only.
- `url` (string, required): Public http(s) URL to capture.
- `wait_ms` (integer)
- `width` (integer)

### `generate_qr` (~136 tokens)

QR code (PNG or SVG)

QR code (PNG or SVG). Turns a link or any text (max 1500 characters) into a QR code.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `dark` (string): Colour of the dots.
- `data` (string, required): The link or text to encode. "url" and "text" are accepted as aliases.
- `ecc` (string): Error correction level.
- `format` (string)
- `light` (string): Background colour.
- `margin` (integer): Quiet zone, in modules.
- `size` (integer): Side in pixels.

### `data_to_chart` (~116 tokens)

Data to chart image (bar, line, pie, doughnut, radar)

Data to chart image (bar, line, pie, doughnut, radar). Turns labels and numeric series into a chart image, without a browser. Pie and doughnut accept 1 series only.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `format` (string)
- `height` (integer)
- `labels` (array, required)
- `series` (array, required)
- `title` (string)
- `type` (string, required)
- `width` (integer)

### `transform_image` (~156 tokens)

Resize, convert or compress an image

Resize, convert or compress an image. Resizes (with a fit mode), converts between JPEG/PNG/WebP/AVIF and/or compresses ONE image. Provide at least one of width, height, format or quality. Input formats: PNG, JPEG, WebP, AVIF, GIF, TIFF.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `file` (string, required): The image, base64-encoded.
- `fit` (string): How to fit when both width and height are given.
- `format` (string): Output format (default: same as input).
- `height` (integer)
- `quality` (integer)
- `width` (integer)

### `merge_pdfs` (~71 tokens)

Merge 2 to 20 PDFs into one

Merge 2 to 20 PDFs into one. Joins several PDFs in the order given. One credit regardless of how many files.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `files` (array, required): The PDFs, base64-encoded, in order.

### `split_pdf` (~135 tokens)

Split a PDF by page ranges

Split a PDF by page ranges. Creates one PDF per range. Ranges use 1-indexed pages: "1-3,5,7-9" gives three files. For one file per page, list every page: "1,2,3". One credit regardless of how many files come out.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `file` (string, required): The PDF, base64-encoded.
- `ranges` (string, required): Required. e.g. "1-3,5,7-9" (one output file per comma-separated group).

### `rotate_pdf` (~121 tokens)

Rotate pages of a PDF

Rotate pages of a PDF. Rotates all pages, or only the ones in `pages`, by 90, 180 or 270 degrees (added to the rotation each page already has).

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `angle` (integer)
- `file` (string, required): The PDF, base64-encoded.
- `pages` (string): Pages to act on, 1-indexed, e.g. "1-3,5,7-9". Default: all pages.

### `watermark_pdf` (~212 tokens)

Add a text or image watermark to a PDF

Add a text or image watermark to a PDF. Overlays a text (max 200 characters) OR a PNG/JPEG image on every page (or on `pages`). Image watermarks need the JSON body.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `color` (string): Text only.
- `file` (string, required): The PDF, base64-encoded.
- `font_size` (number): Text only.
- `image` (string): Watermark image (PNG or JPEG), base64.
- `opacity` (number)
- `pages` (string): Pages to act on, 1-indexed, e.g. "1-3,5,7-9". Default: all pages.
- `position` (string)
- `rotation` (number): Degrees.
- `scale` (number): Image only: width as a fraction of the page width.
- `text` (string): Watermark text. Provide text or image, not both.

### `fill_pdf_form` (~158 tokens)

Fill a PDF form (or list its fields)

Fill a PDF form (or list its fields). Fills the fields of an existing PDF form (AcroForm) with the values in `data`. Without `data` (or with inspect=true) it returns the list of fields instead, so you know their names. Set flatten=true to make the result non-editable.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `data` (object): Field values: { "fieldName": "value", "checkbox": true }. As a query parameter it must be a JSON string.
- `file` (string, required): The PDF, base64-encoded.
- `flatten` (boolean)
- `inspect` (boolean): Only list the fields.

### `extract_pdf_text` (~79 tokens)

Extract the text of a PDF

Extract the text of a PDF. Returns the text of a PDF (not scanned images: there is no OCR). Set pages=true to also get the text page by page.

Costs 1 credit per call.

Input parameters:

- `file` (string, required): The PDF, base64-encoded.
- `pages` (boolean): Also return the text split by page.

### `add_pdf_page_numbers` (~172 tokens)

Add page numbers to a PDF

Add page numbers to a PDF. Stamps a page number on every page (or on `pages`). The `format` text must contain {n}; it can also use {total}.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `color` (string)
- `file` (string, required): The PDF, base64-encoded.
- `font_size` (number)
- `format` (string): e.g. "Page {n} of {total}".
- `margin` (number): Points.
- `pages` (string): Pages to act on, 1-indexed, e.g. "1-3,5,7-9". Default: all pages.
- `position` (string)
- `start` (integer)

### `pdf_metadata` (~138 tokens)

Read or write PDF metadata

Read or write PDF metadata. With no metadata fields it READS title, author, subject, keywords, creator, producer and dates. With any field given it WRITES them and returns the PDF.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `author` (string)
- `creation_date` (string)
- `creator` (string)
- `file` (string, required): The PDF, base64-encoded.
- `keywords` (array)
- `modification_date` (string)
- `producer` (string)
- `subject` (string)
- `title` (string)

### `images_to_pdf` (~99 tokens)

Images to PDF (one image per page)

Images to PDF (one image per page). Turns 1 to 20 PNG/JPEG images into a PDF. page_size "auto" makes each page the size of its image; A4, A3, A5, Letter, Legal or Tabloid fit the image inside.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `images` (array, required)
- `page_size` (string)

### `pdf_to_images` (~122 tokens)

PDF pages to PNG images

PDF pages to PNG images. Renders each page (or the ones in `pages`) as a PNG. `scale` 1 is 72 dpi; 2 is 144 dpi.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `file` (string, required): The PDF, base64-encoded.
- `pages` (string): Pages to act on, 1-indexed, e.g. "1-3,5,7-9". Default: all pages.
- `scale` (number)

### `protect_pdf` (~75 tokens)

Add a password to a PDF

Add a password to a PDF. Encrypts the PDF so it asks for the password when opened. The PDF must not be protected already.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `file` (string, required): The PDF, base64-encoded.
- `password` (string, required)

### `unprotect_pdf` (~87 tokens)

Remove the password of a PDF (you must know it)

Remove the password of a PDF (you must know it). Returns an unencrypted copy of a password-protected PDF. It does not crack passwords: the current one is required.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `file` (string, required): The PDF, base64-encoded.
- `password` (string, required): The current password.

### `create_zip` (~70 tokens)

Create a zip from up to 50 files

Create a zip from up to 50 files. Packs files of any type into a .zip. Names can include folders ("reports/january.pdf"). Default output is the zip binary.

Costs 1 credit per call.

Returns a temporary download link (valid 15 minutes).

Input parameters:

- `files` (array, required)

### `validate_email` (~68 tokens)

Validate an email address

Validate an email address. Checks the format and, by default, that the domain has a real mail server (MX record). An invalid email is still a successful call (valid=false).

Costs 1 credit per call.

Input parameters:

- `check_mx` (boolean)
- `email` (string, required)

### `validate_phone` (~98 tokens)

Validate and format a phone number

Validate and format a phone number. Validates an international phone number and returns it in E.164 and international formats, with its country and type (mobile, fixed line...). Give `country` (2-letter code) for numbers without the + prefix.

Costs 1 credit per call.

Input parameters:

- `country` (string): ISO 3166-1 alpha-2, e.g. "ES", "GB".
- `phone` (string, required)

### `validate_iban` (~49 tokens)

Validate an IBAN

Validate an IBAN. Checks the IBAN checksum (ISO 7064) and returns the country and the formatted IBAN.

Costs 1 credit per call.

Input parameters:

- `iban` (string, required)

### `generate_uuid` (~47 tokens)

Generate UUIDs (v4)

Generate UUIDs (v4). Returns 1 to 100 random UUIDs. One credit per call regardless of count.

Costs 1 credit per call.

Input parameters:

- `count` (integer)

### `slugify` (~83 tokens)

Text to URL slug

Text to URL slug. Lowercases, removes accents and keeps only letters and digits separated by `separator`. "Año Nuevo 2026!" becomes "ano-nuevo-2026".

Costs 1 credit per call.

Input parameters:

- `separator` (string): 1 to 3 characters: lowercase letters, digits, underscore or hyphen.
- `text` (string, required)

### `hash` (~85 tokens)

Hash a text or a file (md5, sha1, sha256, sha512)

Hash a text or a file (md5, sha1, sha256, sha512). Returns the hash of a text (JSON) or of a file (raw bytes, max 25 MB). Useful for checksums and deduplication.

Costs 1 credit per call.

Input parameters:

- `algorithm` (string)
- `encoding` (string)
- `text` (string, required)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-cofferdock-cofferdock/api#diagnostics

## Score history

- 2026-10-03: 38
- 2026-10-02: 38
- 2026-10-01: 38
- 2026-09-30: 38
- 2026-09-29: 38
- 2026-09-28: 38
- 2026-09-27: 38
- 2026-09-26: 38

## Common questions

### What is the Cofferdock MCP server?

Cofferdock is an MCP server listed in the public MCP registry as com.cofferdock/cofferdock. Real files for AI assistants: HTML to image/PDF, screenshots, QR, charts, PDF tools, validators. This page covers its hosted endpoint (https://api.cofferdock.com/mcp).

### Is the Cofferdock MCP server safe to use?

Cofferdock scores 38 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Cofferdock MCP server expose?

Cofferdock exposes 26 tools: get_status, html_to_image, html_to_pdf, screenshot_url, generate_qr, and 21 more. Their descriptions and schemas cost roughly 3,120 tokens of context every time the server is loaded.

### Does the Cofferdock MCP server require authentication?

Yes. Cofferdock asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the Cofferdock MCP server still maintained?

Cofferdock is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://api.cofferdock.com/mcp
- Website: https://cofferdock.com/ai
- Changelog RSS feed: https://verifymcp.io/servers/com-cofferdock-cofferdock/api.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-cofferdock-cofferdock/api.json
- HTML version of this page: https://verifymcp.io/servers/com-cofferdock-cofferdock/api
