
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
carbone-mcp
Advanced tools
Official MCP for Carbone — Document Generation, Document Conversion, and Universal Templating. Generate PDF, DOCX, XLSX, PPTX, ODT, ODS, CSV, HTML and XML documents from templates and JSON data. Convert Office documents (DOCX, XLSX, PPTX) and HTML to PDF.
Official Carbone MCP server — Turn AI assistants into document automation experts. Generate professional PDFs, invoices, reports, and more using natural language.
Give Claude, ChatGPT, and other AI assistants the power to:
{d.field} tagsGet your free API key at account.carbone.io.
All stdio-compatible MCP clients use the same config:
{
"mcpServers": {
"carbone": {
"command": "npx",
"args": ["-y", "carbone-mcp"],
"env": {
"CARBONE_API_KEY": "your_api_key_here"
}
}
}
}
| Client | Config file |
|---|---|
| Claude Desktop (macOS) | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Claude Desktop (Windows) | %APPDATA%\Claude\claude_desktop_config.json |
| Cursor (global) | ~/.cursor/mcp.json |
| Cursor (project) | .cursor/mcp.json |
| Claude Code | claude mcp add carbone-mcp -e CARBONE_API_KEY=your_key -- npx -y carbone-mcp |
VS Code uses
{ "mcp": { "servers": { ... } } }instead of{ "mcpServers": { ... } }— the inner config block is identical.
After adding the config, restart your client and try: "What can Carbone do?"
Connect directly to the hosted endpoint. Supported by VS Code, Cursor, Claude Code, and other clients that support streamable HTTP transport.
{
"mcp": {
"servers": {
"carbone": {
"type": "streamable-http",
"url": "https://mcp.carbone.io",
"headers": {
"Authorization": "Bearer your_api_key_here"
}
}
}
}
}
Authentication: The HTTP endpoint currently requires a Carbone API key passed as a Bearer token in the
Authorizationheader. OAuth2 support (for Claude Desktop, Mistral, ChatGPT, Gemini, and other clients) is planned for a future release.Cursor uses
{ "mcpServers": { ... } }instead of{ "mcp": { "servers": { ... } } }— the inner config block is identical.Claude Desktop does not support HTTP Bearer token authentication — use the stdio option above instead.
docker run -d -p 3000:3000 \
-e MCP_TRANSPORT=http \
-e CARBONE_API_KEY=your_api_key_here \
carbone/carbone-mcp
Connect your MCP client to http://your-host:3000 using the HTTP config above (replace the URL).
Docker Compose — see compose.yml:
CARBONE_API_KEY=your_key docker compose up -d
Claude Desktop with Docker (stdio) — Claude Desktop does not support HTTP transport; use the stdio mode instead:
{
"mcpServers": {
"carbone": {
"command": "docker",
"args": ["run", "-i", "--rm",
"-e", "CARBONE_API_KEY=your_api_key_here",
"-e", "MCP_TRANSPORT=stdio",
"carbone/carbone-mcp"]
}
}
}
If you run Carbone on-premise, point the MCP server at your instance — no API key required:
# Docker (HTTP)
docker run -d -p 3000:3000 \
-e CARBONE_BASE_URL=https://your-carbone-server.com \
carbone/carbone-mcp
# stdio
CARBONE_BASE_URL=https://your-carbone-server.com npx carbone-mcp
Required (stdio mode, cloud API):
CARBONE_API_KEY — Your Carbone API key (get one free →). Not required when CARBONE_BASE_URL points to your own on-premise server, or when running in HTTP mode (clients supply their own key via Authorization: Bearer).| Variable | Default | Description |
|---|---|---|
CARBONE_BASE_URL | https://api.carbone.io | Override for self-hosted or staging environments. When set to a custom URL, CARBONE_API_KEY is not required. |
CARBONE_TIMEOUT | 60000 | Request timeout in milliseconds (max: 60000) |
CARBONE_MAX_FILE_BYTES | 104857600 | Maximum size (bytes) for a resolved input file — path, URL, or base64 (100 MB default) |
MCP_TRANSPORT | stdio | Transport mode: stdio (default, for AI clients) or http (for self-hosted deployments) |
MCP_PORT | 3000 | HTTP server port (only used when MCP_TRANSPORT=http) |
MCP_PATH | / | HTTP endpoint path (only used when MCP_TRANSPORT=http) |
MCP_MAX_BODY_BYTES | 62914560 | Maximum request body size in bytes (60 MB default, matching Carbone Cloud limit) |
CARBONE_REQUIRE_CLIENT_AUTH_HEADER | false | HTTP mode only — require Authorization: Bearer <key> on every request. Leave false only if you intend a shared-key server: with a server-level CARBONE_API_KEY set, requests that carry no Bearer key fall back to it, so anyone who can reach the port can spend that Carbone account. Set to true to require each client to bring its own key. Irrelevant when no server key is set (e.g. on-premise) |
CARBONE_ALLOW_PRIVATE_NETWORK | false | Allow user-supplied URLs (templates, data, …) to resolve to private/internal addresses. Off by default to block SSRF (cloud metadata, localhost, RFC1918). Enable only on a trusted deployment with internal template hosts |
| Tool | Description | Docs |
|---|---|---|
convert_document | Convert documents between 100+ formats without storing a template | → |
render_document | Generate documents from templates by merging with JSON data | → |
| Tool | Description | Docs |
|---|---|---|
list_templates | Browse your template library with filtering by category or search (tags are returned per template but not filterable server-side) | → |
list_categories | List all template categories in your account | → |
list_tags | List all tags used across your templates | → |
upload_template | Store reusable templates with versioning, categorization, and metadata | → |
update_template_metadata | Rename, categorize, tag, deploy, or expire template versions | → |
delete_template | Soft-delete templates (marked for removal, gone after ~24h) | → |
download_template | Download original template files (DOCX, XLSX, PDF, etc.) | → |
| Tool | Description | Docs |
|---|---|---|
get_api_status | Check Carbone API health and current version | |
get_capabilities | View all supported formats, features, and examples |
📖 Full API Reference → — Detailed parameters, schemas, and examples
By default, a generated or converted file is returned based on its type and transport:
| Output | stdio (local clients) | HTTP (remote / self-hosted) |
|---|---|---|
| Text — HTML, TXT, CSV, MD, XML | inline text | inline text |
| Inline images — PNG, JPG, GIF, WEBP | inline image | inline image |
| Everything else — PDF, Office, ZIP, SVG… | saved to a temp file, path returned | returned as a download attachment |
Three optional parameters on convert_document and render_document (and outputPath / asAttachment on download_template) override this:
| Parameter | Effect |
|---|---|
outputPath | stdio only — save the output to this local path instead of returning it inline (rejected in HTTP mode) |
asAttachment | return the bytes as a downloadable attachment for any format, instead of inline |
returnLink | return Carbone's public one-time download URL instead of the file — short-lived and consumed by the first download, so hand it to the user rather than fetching it yourself (works in stdio and HTTP) |
Claude Desktop: it cannot render inline binary attachments (it mishandles them as images). For PDFs and Office files, rely on the default stdio temp-file path, or use
returnLinkto get a download URL.
"Convert this Word document to PDF: /path/to/contract.docx"
"Turn my Excel spreadsheet into CSV format"
"Convert this HTML page to a PNG image"
"Convert my Markdown README to PDF"
"Convert this PPTX to PNG — use OnlyOffice for best fidelity"
"Rasterize this PDF to PNG images — one per page"
"Generate an invoice using template T123 with: {customer: 'Acme Corp', total: 1500, items: [...]}"
"Generate invoices from the data in /data/invoices.json"
"Create 500 invoices from my billing data and bundle them in a ZIP"
"Generate a French invoice for my Paris client — use EUR currency and fr-fr locale"
"Render this monthly report for each client in clients.json and ZIP them all"
"Generate invoice-{d.id}.pdf for each row in my sales data"
"Add a CONFIDENTIAL watermark to this contract before sending it"
"Convert this NDA to PDF/A format for long-term archiving"
"Generate a password-protected PDF — open password: 'secret123'"
"Create signed offer letters for each candidate using this DOCX template"
"Generate a compliance report with a DRAFT watermark, 20% opacity, rotated -45°"
"Create personalized onboarding documents for all 50 new employees in this JSON"
"Generate an employment contract for each person in new-hires.json"
"Build payslips for every employee in my payroll export"
"Create training certificates for everyone who passed this month"
"Fill out the performance review template with each employee's data"
"Generate this invoice in French, German, and Spanish from the same template"
"Render the report with timezone America/New_York so dates show in Eastern time"
"Convert all prices from EUR to USD using today's exchange rates"
"Generate the contract in fr-fr locale so numbers use European formatting"
"Convert this DOCX to a password-protected PDF"
"Add a semi-transparent DRAFT watermark to every page"
"Generate a PDF/A-1b compliant version of this document for archiving"
"Export only pages 1–5 of this presentation as a PDF"
"Convert each slide of this PPTX to a separate PDF page"
"Upload this invoice template and tag it 'sales' and 'finance'"
"What templates do I have in the 'contracts' category?"
"Show me all templates tagged 'hr'"
"Download template T456 so I can edit it locally"
"Deploy version V789 as the active version without deleting the others"
"Schedule this old template for deletion in 30 days"
Test and debug the server interactively:
npx @modelcontextprotocol/inspector npx carbone-mcp
Or from a local build:
npx @modelcontextprotocol/inspector node dist/index.js
Open http://localhost:5173 to view all tools, test calls, and inspect request/response JSON — no AI inference needed.
# macOS — Claude Desktop logs
tail -f ~/Library/Logs/Claude/mcp*.log
# Windows
Get-Content "$env:APPDATA\Claude\logs\mcp*.log" -Wait -Tail 50
Look for:
Carbone MCP Server v1.x.x started (stdio)When running in HTTP mode, the server exposes a health endpoint:
curl http://localhost:3000/health
{
"mcp": { "version": "1.2.2" },
"carbone": { "version": "5.x.x" }
}
The carbone field shows backend connectivity:
{ "version": "..." } — reachable and authenticated{ "error": "unauthorized", "message": "..." } — reachable but no/invalid API key{ "error": "unreachable", "message": "..." } — network error, timeout, or unexpected response⚠️ File and URL inputs (SSRF / local files)
Tools accept a local path, an HTTPS URL, or base64 for file / template and the by-reference JSON params (data, complement, …). Two guards apply:
169.254.169.254), CGNAT or reserved addresses — and every redirect hop is re-checked. Set CARBONE_ALLOW_PRIVATE_NETWORK=true only on a trusted deployment that needs internal template hosts.⚠️ Sharing a server-level API key (HTTP mode)
If you set CARBONE_API_KEY on an HTTP server and leave CARBONE_REQUIRE_CLIENT_AUTH_HEADER=false (the default), requests without a Bearer key fall back to that key — anyone who can reach the port can spend that Carbone account. Set it to true to require each client to bring its own key, or only expose the port on a trusted network. (Not applicable when no server key is set, e.g. on-premise Carbone without authentication.)
⚠️ Prompt Injection Connecting an AI assistant to any external service carries inherent risks. A malicious document or template could contain instructions that trick the AI into performing unintended actions (e.g. exfiltrating data, deleting templates). Always review what your AI client is about to do before confirming tool calls.
⚠️ API Key Protection
CARBONE_API_KEY to version control⚠️ Template Safety
⚠️ Data Privacy
CARBONE_BASE_URL to point to a self-hosted instance for maximum controlDesign templates in Word, Excel, LibreOffice, or HTML with {d.field} tags:
Dear {d.customer.name},
Your invoice total is {d.total:formatC(EUR)}.
Items:
{d.items[i].description} {d.items[i].quantity}x {d.items[i].price:formatC(EUR)}
{d.items[i+1]}
Guides & best practices:
| Category | Formats |
|---|---|
| Documents | PDF, DOCX, XLSX, PPTX, ODT, ODS, ODP, ODG, RTF, EPUB |
| Images | PNG, JPG, WEBP, SVG, TIFF, BMP, GIF |
| Web / Text | HTML, TXT, CSV, MD, XML |
Full conversion matrix: carbone.io/documentation
We welcome contributions:
See CONTRIBUTING.md for guidelines.
npm run dev # Run with tsx (no build needed)
npm run build # Compile TypeScript → dist/
npm test # Run the test suite (integration tests run only with CARBONE_TEST_API_KEY)
npm run test:watch # Watch mode
npm run test:integration # Real API tests (requires CARBONE_TEST_API_KEY)
npm run test:coverage # Coverage report
Apache 2.0 — see LICENSE
FAQs
Official MCP for Carbone — Document Generation, Document Conversion, and Universal Templating. Generate PDF, DOCX, XLSX, PPTX, ODT, ODS, CSV, HTML and XML documents from templates and JSON data. Convert Office documents (DOCX, XLSX, PPTX) and HTML to PDF.
The npm package carbone-mcp receives a total of 149 weekly downloads. As such, carbone-mcp popularity was classified as not popular.
We found that carbone-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.