io.github.MLTCorp/convertfilefast
REMOTE · MCP.CONVERTFILEFAST.COM · 3 COMPONENTS · SCANNED SEP 20
Convert files, run PDF/image tools, create billing links, and report feedback.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 17 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability78
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1276 tokens (~75/item across 17 items; 17 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "merge_pdfs" implies "merge" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.MLTCorp/convertfilefast MCP server?
io.github.MLTCorp/convertfilefast is a hosted endpoint at https://mcp.convertfilefast.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.convertfilefast.com
claude mcp add --transport http mltcorp-convertfilefast 'https://mcp.convertfilefast.com/mcp'
{
"mcpServers": {
"mltcorp-convertfilefast": {
"url": "https://mcp.convertfilefast.com/mcp"
}
}
} {
"servers": {
"mltcorp-convertfilefast": {
"type": "http",
"url": "https://mcp.convertfilefast.com/mcp"
}
}
} [mcp_servers.mltcorp-convertfilefast] url = "https://mcp.convertfilefast.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"mltcorp-convertfilefast": {
"type": "remote",
"url": "https://mcp.convertfilefast.com/mcp",
"enabled": true
}
}
} openclaw mcp add mltcorp-convertfilefast --url 'https://mcp.convertfilefast.com/mcp' --transport streamable-http
mcp_servers:
mltcorp-convertfilefast:
url: "https://mcp.convertfilefast.com/mcp" {
"McpServers": {
"mltcorp-convertfilefast": {
"Transport": "http",
"Url": "https://mcp.convertfilefast.com/mcp"
}
}
} assistant mcp add mltcorp-convertfilefast -t streamable-http -u 'https://mcp.convertfilefast.com/mcp'
{
"mcpServers": {
"mltcorp-convertfilefast": {
"type": "http",
"url": "https://mcp.convertfilefast.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 23 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- The server no longer declares the “experimental” capability functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.convertfilefast.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.convertfilefast.com | CN=YR2,O=Let's Encrypt,C=US | 29 Aug 2026 | 27 Nov 2026 | RSA 4096 | SHA256-RSA | 53f15ab8d39f757e7335fe309d794cbd09a |
| SANs: mcp.convertfilefast.com | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.convertfilefast.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| convertfilefast.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| referrer-policy | no-referrer |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.convertfilefast.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.convertfilefast.com/mcp | HTTPS enforced | 301 | https://mcp.convertfilefast.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compress_image ~104
Compress an image to reduce file size, optionally capping dimensions.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded image. |
| format | – | – | Output format (jpeg, png, webp, ...). Defaults to source format. |
| max_height | – | – | Optionally cap the height in pixels. |
| max_width | – | – | Optionally cap the width in pixels. |
| quality | integer | – | Compression quality 1-100. |
| source_url | – | – | Public URL of the image. |
Structured output declared, but exposes no named fields.
No examples provided.
compress_pdf ~63
Reduce the file size of a PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded PDF. |
| quality | string | – | Compression preset. |
| remove_metadata | boolean | – | Strip PDF metadata to reduce size further. |
| source_url | – | – | Public URL of the PDF. |
Structured output declared, but exposes no named fields.
No examples provided.
convert_file ~159
Convert a document, spreadsheet, presentation, image, PDF, or data file.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded source file. Use only when there is no URL. |
| filename | – | – | Original filename (with extension); used to detect the source format and name the output. |
| source_format | – | – | Source format token (e.g. 'docx', 'pdf', 'png', 'html', 'url'). Inferred from filename/URL if omitted. |
| source_url | – | – | Public URL to the source file or webpage (preferred). For a webpage to PDF, point at the page and use target_format='pdf'. |
| target_format | string | yes | Desired output format, e.g. 'pdf', 'csv', 'png'. |
Structured output declared, but exposes no named fields.
No examples provided.
create_billing_portal_link ~25
Create a Stripe Billing Portal link for payment method and subscription management.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
create_credit_pack_checkout ~55
Create a Stripe-hosted checkout link for one-time extra credits.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | – | Preferred checkout currency. |
| pack_id | string | yes | Credit pack to buy: pack_1000 or pack_10000. |
Structured output declared, but exposes no named fields.
No examples provided.
create_subscription_checkout ~62
Create a Stripe-hosted checkout link for a Pro or Scale subscription.
| Name | Type | Req | Description |
|---|---|---|---|
| annual | boolean | – | Use annual billing instead of monthly. |
| currency | string | – | Preferred checkout currency. |
| plan_id | string | yes | Plan to subscribe to: pro or scale. |
Structured output declared, but exposes no named fields.
No examples provided.
extract_pdf_text ~76
Extract text and optional tables from a PDF as structured JSON.
| Name | Type | Req | Description |
|---|---|---|---|
| extract_tables | boolean | – | Whether to extract tables too. |
| file_base64 | – | – | Base64-encoded PDF. |
| pages | – | – | Optional pages/ranges to extract, e.g. '1-5'. |
| source_url | – | – | Public URL of the PDF. |
Structured output declared, but exposes no named fields.
No examples provided.
get_billing_status ~21
Return current plan, subscription status, and remaining credits.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
images_to_pdf ~100
Combine multiple images into one multi-page PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| filenames | – | – | Optional filenames matching files_base64, with extensions. |
| files_base64 | – | – | Base64-encoded image files to combine, in order. |
| output_name | string | – | Name for the output PDF. |
| page_size | string | – | Page size: fit, A4, or letter. |
| source_urls | – | – | Public image URLs to combine into a multi-page PDF, in order. |
Structured output declared, but exposes no named fields.
No examples provided.
list_supported_conversions ~20
List every conversion slug supported by the MCP server.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
merge_pdfs ~83
Merge multiple PDFs into a single PDF, preserving the given order.
| Name | Type | Req | Description |
|---|---|---|---|
| files_base64 | – | – | Base64-encoded PDFs to merge, in order (minimum 2). Use when there are no URLs. |
| output_name | string | – | Name for the merged PDF. |
| source_urls | – | – | Public URLs of the PDFs to merge, in order (minimum 2). |
Structured output declared, but exposes no named fields.
No examples provided.
protect_pdf ~55
Add password protection (encryption) to a PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded PDF. |
| password | string | yes | Password to set on the PDF. |
| source_url | – | – | Public URL of the PDF. |
Structured output declared, but exposes no named fields.
No examples provided.
report_feedback ~88
Report a bug, missing conversion, or quality issue to the ConvertFileFast team.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Feedback category. |
| context | – | – | Extra detail: error message, input format, expected vs actual. |
| summary | string | yes | Short description of what went wrong or what is missing. |
| tool | – | – | Tool or conversion involved, e.g. 'convert_file pdf-to-docx'. |
Structured output declared, but exposes no named fields.
No examples provided.
resize_image ~94
Resize an image to the given width/height.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded image. |
| fit | string | – | How to fit within width/height. |
| format | – | – | Output format (jpeg, png, webp, ...). Defaults to source format. |
| height | – | – | Target height in pixels. |
| source_url | – | – | Public URL of the image. |
| width | – | – | Target width in pixels. |
Structured output declared, but exposes no named fields.
No examples provided.
rotate_pdf ~77
Rotate pages in a PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| angle | integer | yes | Rotation in degrees (clockwise). |
| file_base64 | – | – | Base64-encoded PDF. |
| pages | – | – | Pages to rotate, e.g. '1,3,5-7'. Omit to rotate all pages. |
| source_url | – | – | Public URL of the PDF. |
Structured output declared, but exposes no named fields.
No examples provided.
split_pdf ~70
Extract specific pages/ranges from a PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded PDF. |
| pages | string | yes | Pages/ranges to extract, e.g. '1,3,5-7' or '1-5'. |
| source_url | – | – | Public URL of the PDF. |
Structured output declared, but exposes no named fields.
No examples provided.
unlock_pdf ~50
Remove password protection from a PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| file_base64 | – | – | Base64-encoded PDF. |
| password | string | yes | Current password of the PDF. |
| source_url | – | – | Public URL of the PDF. |
Structured output declared, but exposes no named fields.
No examples provided.
What is the io.github.MLTCorp/convertfilefast MCP server?
io.github.MLTCorp/convertfilefast is an MCP server listed in the public MCP registry as io.github.MLTCorp/convertfilefast. Convert files, run PDF/image tools, create billing links, and report feedback. This page covers its hosted endpoint (https://mcp.convertfilefast.com/mcp).
Is the io.github.MLTCorp/convertfilefast MCP server safe to use?
io.github.MLTCorp/convertfilefast scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.MLTCorp/convertfilefast MCP server expose?
io.github.MLTCorp/convertfilefast exposes 17 tools: list_supported_conversions, convert_file, images_to_pdf, merge_pdfs, split_pdf, and 12 more. Their descriptions and schemas cost roughly 1,202 tokens of context every time the server is loaded.
Does the io.github.MLTCorp/convertfilefast MCP server require authentication?
No. We connected to io.github.MLTCorp/convertfilefast without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.MLTCorp/convertfilefast MCP server still maintained?
io.github.MLTCorp/convertfilefast is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.