
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@bigapi/mcp
Advanced tools
MCP server for bigapi.dev – the output layer for AI agents: render HTML/Markdown to PDF, merge/split/compress PDFs, convert images. One cent per operation.
MCP server for bigapi.dev – deterministic file operations for AI agents.
Gives Claude Desktop, Cursor, Cline, Windsurf and any MCP-capable agent the file operations an LLM cannot do itself – over plain HTTPS, with one key, nothing to install server-side:
| Tool | What it does |
|---|---|
render | HTML / Markdown / URL → PDF or PNG via server-side Chromium (reports, invoices, offers, documentation) |
screenshot | Any public URL, real device presets (desktop / laptop / tablet / mobile), full page |
ocr | Scanned PDF or photo → searchable PDF, plain text, or per-page JSON (deu, eng, deu+eng, …) |
office_to_pdf | DOCX, XLSX, PPTX, ODT, RTF, CSV, TXT → PDF via server-side LibreOffice |
pdf_to_pdfa | PDF → archival PDF/A-2b with embedded fonts (long-term storage, compliance) |
pdf_merge · pdf_split · pdf_rotate · pdf_compress | The PDF basics |
pdf_to_images | PDF pages → JPEG/PNG, e.g. to look at a document with a vision model |
image_process | Resize, crop, rotate, convert (webp/avif/…), compress, strip EXIF, watermark – one call |
image_info | Format, dimensions, color space, EXIF/ICC presence |
get_access | Free API key, instantly, no signup – 100 free operations that never expire |
get_balance · get_usage · set_monthly_cap · get_pricing | Account |
$0.01 per operation. 100 free. Free operations and balance never expire. Failed calls are free. Servers in Germany, GDPR, files deleted after delivery.
Also listed in the official MCP Registry as dev.bigapi/mcp.
Requires Node 18+. No API key needed up front – the agent can call get_access itself.
claude_desktop_config.json (Settings → Developer → Edit Config):
{
"mcpServers": {
"bigapi": {
"command": "npx",
"args": ["-y", "@bigapi/mcp"]
}
}
}
Restart Claude Desktop. Then: "Get bigapi access and render this text as a PDF on my Desktop."
Same block in the respective MCP settings (.cursor/mcp.json, ~/.codeium/windsurf/mcp_config.json, Cline → MCP Servers → Configure).
"bigapi": { "command": "npx", "args": ["-y", "@bigapi/mcp"], "env": { "BIGAPI_KEY": "bigapi_..." } }
Inputs are local paths (/Users/me/report.pdf, C:\Users\me\scan.pdf). Outputs are written to output_path if given, otherwise to a temp folder (BIGAPI_OUTPUT_DIR to change). Every result includes the cost, what it was charged from, and the remaining balance.
Flat $0.01 per operation (per page for ocr and office_to_pdf, $0.05 for pdf_to_pdfa). Prepaid from $5 – no subscription, no signup, balance never expires, failed calls are free. Machine-readable: get_pricing or GET /v1/pricing.
| Variable | Default | Purpose |
|---|---|---|
BIGAPI_KEY | – | Use this key instead of the stored one |
BIGAPI_CONFIG_DIR | ~/.bigapi | Where get_access stores the key (config.json, mode 600) |
BIGAPI_OUTPUT_DIR | OS temp dir | Default output folder |
BIGAPI_URL | https://api.bigapi.dev | API base (for self-hosting / testing) |
Plain HTTP works everywhere (n8n, Make, Zapier, LangChain, your code):
curl -X POST https://api.bigapi.dev/v1/keys # → key
curl -o out.pdf https://api.bigapi.dev/v1/render \
-H "Authorization: Bearer $KEY" -H "content-type: application/json" \
-d '{"markdown":"# Hello from an agent"}'
OpenAPI: https://api.bigapi.dev/openapi.json · Docs: https://api.bigapi.dev/docs · Guides: https://bigapi.dev/guides/ · llms.txt: https://api.bigapi.dev/llms.txt
MIT
FAQs
MCP server for bigapi.dev - the output layer for AI agents: turn what an agent produced into a finished file, and read files back in. $0.01 per operation.
The npm package @bigapi/mcp receives a total of 109 weekly downloads. As such, @bigapi/mcp popularity was classified as not popular.
We found that @bigapi/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.