
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
GroupDocs.Signature.Mcp
Advanced tools
MCP server exposing GroupDocs.Signature for .NET — sign documents with text, QR code, barcode, image, or digital certificate signatures; search for and verify existing signatures via AI agents.
MCP server that exposes GroupDocs.Signature as AI-callable tools for Claude, Cursor, GitHub Copilot, and other MCP agents.
One-click installs pre-fill every supported setting: edit the placeholder documents folder after install (output defaults to the same folder); an empty GROUPDOCS_LICENSE_PATH runs in evaluation mode - point it at your license to lift limits.
More clients - ready-made configs for Claude Code, Codex CLI, Visual Studio 2022, Cursor, Windsurf, Cline, and JetBrains Rider live in
install/generated/.
Requires .NET 10 SDK.
Run directly with dnx (recommended — no install step):
dnx GroupDocs.Signature.Mcp --yes
Pulls the latest stable release on every invocation. To pin to a specific
version (recommended for shared configs and CI), append @<version>:
dnx GroupDocs.Signature.Mcp@26.7.2 --yes
Or install as a global dotnet tool:
dotnet tool install -g GroupDocs.Signature.Mcp
groupdocs-signature-mcp
Or run via Docker:
docker run --rm -i \
-v $(pwd)/documents:/data \
ghcr.io/groupdocs-signature/signature-net-mcp:latest
The underlying GroupDocs engine renders signature glyphs (text, QR codes,
barcodes) onto document pages via System.Drawing (GDI+). When you run the
server natively (via dnx or the global dotnet tool) on Linux or macOS,
install the native libgdiplus library and a fonts package first:
| Platform | Setup |
|---|---|
| Windows | Nothing — GDI+ is built into the OS. |
| Linux | sudo apt-get install -y libgdiplus libfontconfig1 ttf-mscorefonts-installer |
| macOS | brew install mono-libgdiplus |
| Docker | Nothing — the image already bundles libgdiplus, libfontconfig1, and ttf-mscorefonts-installer. |
Skipping this on Linux/macOS surfaces as DllNotFoundException: libgdiplus in
the tool response. The simplest zero-setup option on Linux/macOS is the
Docker image.
| Tool | Description |
|---|---|
Sign | Sign a document with a text, QR code, barcode, or digital certificate signature; saves the signed file as <name>_signed.<ext> |
Verify | Verify signatures in a document (text, QR code, barcode, digital, or all) and return a validity report |
SearchTextSignatures | Find embedded text signatures (stamps, labels, native text annotations) with optional substring filter |
SearchBarcodes | Find barcode signatures (Code39, Code128, EAN, etc.) with optional decoded-text filter and optional inline image |
SearchQrCodes | Find QR code signatures with optional decoded-text filter and optional inline image |
SearchDigitalSignatures | Find digital certificate signatures and return signer, issuer, serial number, validity status |
SearchImageSignatures | Find embedded image signatures (logos, stamp images, picture overlays) and return them as base64 PNGs |
GetDocumentInfo | Return file type, page count, size, and per-page dimensions as JSON (no modification) |
The MCP server itself is MIT; the underlying GroupDocs.Signature engine requires a license for production use. Without one the server runs in evaluation mode:
To lift the limits, point GROUPDOCS_LICENSE_PATH at your GroupDocs.Total.lic:
| Variable | Description | Default |
|---|---|---|
GROUPDOCS_MCP_STORAGE_PATH | Base folder for input and output files | current directory |
GROUPDOCS_MCP_OUTPUT_PATH | (Optional) separate folder for output files | GROUPDOCS_MCP_STORAGE_PATH |
GROUPDOCS_LICENSE_PATH | Path to GroupDocs license file | (evaluation mode) |
{
"mcpServers": {
"groupdocs-signature": {
"type": "stdio",
"command": "dnx",
"args": ["GroupDocs.Signature.Mcp", "--yes"],
"env": {
"GROUPDOCS_MCP_STORAGE_PATH": "/path/to/documents"
}
}
}
}
To pin to a specific version, replace
"GroupDocs.Signature.Mcp"with"GroupDocs.Signature.Mcp@26.7.2"inargs. Pinning is recommended for shared / committed configs to avoid surprise upgrades.
NuGet.org generates a ready-to-use mcp.json snippet on the package page.
Copy it directly into your .vscode/mcp.json.
Alternatively, add manually to .vscode/mcp.json:
{
"inputs": [
{
"type": "promptString",
"id": "storage_path",
"description": "Base folder for input and output files.",
"password": false
}
],
"servers": {
"groupdocs-signature": {
"type": "stdio",
"command": "dnx",
"args": ["GroupDocs.Signature.Mcp", "--yes"],
"env": {
"GROUPDOCS_MCP_STORAGE_PATH": "${input:storage_path}"
}
}
}
}
Same pinning rule as above — swap
"GroupDocs.Signature.Mcp"for"GroupDocs.Signature.Mcp@26.7.2"to lock to a specific release.
cd docker
docker compose up
Edit docker/docker-compose.yml to point volumes at your local documents folder.
MIT — see LICENSE
FAQs
MCP server exposing GroupDocs.Signature for .NET — sign documents with text, QR code, barcode, image, or digital certificate signatures; search for and verify existing signatures via AI agents.
We found that GroupDocs.Signature.Mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.