You can ask an AI agent such as Claude, Cursor or GitHub Copilot to sign a document and have it done locally, on your own machine, with the file and the certificate never leaving it. The agent decides what to sign and how; the GroupDocs.Signature.Mcp server applies the signature through its sign tool. Everything below starts from prompts like this one:
Sign contract.pdf digitally using signing-cert.pfx.
The step-by-step version with config and troubleshooting is in the documentation: How to sign documents with AI agents using MCP.
What does “sign” mean when you ask an AI agent?
It can mean a visual mark or a cryptographic signature, and the difference matters before anything is automated. The sign tool accepts four values for type: text, qrcode, barcode and digital. The first three place a visual mark on the page. Only digital applies a certificate-backed cryptographic signature that records who signed and lets anyone detect later changes to the file.
Language models do not make this distinction on their own. If a prompt says only “sign this”, the agent has to guess which one you mean, so name the type. The three ways below are ordered from the lightest mark to the strongest.
Way 1: Stamp the page with a text signature
Use a text signature when a person or process only needs to see that a document was handled: a name, a date, an approval label.
Add a text signature with my name and today’s date to report.docx.
The agent calls sign with type: "text" and the text you gave it. The server writes a signed copy to the output folder and leaves the original untouched. This is a mark, not proof: it shows a label on the page and says nothing about who put it there or whether the file changed afterwards.
Way 2: Add a QR code or barcode that carries a reference
Use a code when a machine, not a person, will read the signature later. A QR code can hold structured text, and a barcode (the Code39, Code128 and EAN family) suits scan-line workflows.
Sign contract.pdf with a QR code containing ORDER-2026-0418.
The agent calls sign with type: "qrcode" and text: "ORDER-2026-0418". Give the text explicitly in every prompt that asks for a code, and read the value back with search_qr_codes before you rely on it. Like a text stamp, a code is a visual mark: it proves the mark is present, not who applied it.
Way 3: Apply a certificate-based digital signature
Use a digital signature when you need to show who signed and that the file has not changed since. The agent passes the certificate file and its password to sign:
Sign contract.pdf digitally using signing-cert.pfx.
The call uses type: "digital", certificate and certificatePassword. Both are read from local disk by the local server process, and the signing happens in-process. There is no signing service involved, so neither the key nor the password is transmitted anywhere. Keep the password in an environment variable rather than in a committed client configuration.
Order matters here. Visual marks rewrite the file, so any text stamp or code added after a digital signature invalidates it. Apply every visual mark first and the digital signature last, and say so in the prompt whenever the agent is chaining signatures.
Example session (abridged)
You: Sign contract.pdf with a QR code containing ORDER-2026-0418.
Agent: [sign] file=contract.pdf, type=qrcode, text="ORDER-2026-0418"
-> Signed contract.pdf with qrcode signature
The signed copy was saved to the output folder.
The original contract.pdf was not modified.
Illustrative output: the file name and the QR value are invented. The tool returns the fields described above.
What can an AI agent not sign for you?
An agent can apply a signature; it cannot make that signature legally binding. This server is not a hosted e-signature service or a qualified trust service provider. It applies a signature with the certificate you provide, on one machine, for one client process.
Whether the result satisfies a given legal regime, such as an eIDAS qualified signature, depends on the certificate and the process around it, not on this server. If a dispute is plausible, ask which certificate and which process apply before you automate.
Evaluation limits you should know about
Without a license the server runs in evaluation mode: only the first 2 pages are processed, and a trial badge is stamped on every page. A signature meant for page 5 of a contract will not be placed, and no error tells you so. Before any signing run that matters, ask:
What is the license status of the signature server?
The agent calls get_license_status, which reports the mode (evaluation, licensed or metered) without touching a document.
FAQ
Can AI sign documents for me?
An agent can apply a text, QR code, barcode or certificate-based signature to a document through the sign tool, locally. Whether that signature carries legal weight depends on the certificate and your jurisdiction, not on the agent.
Can Claude sign a PDF without uploading it anywhere? Yes. The MCP server runs as a child process of the client over stdio, with no inbound ports, no external endpoints and no telemetry. The path is agent, local server, local filesystem.
Which clients does this work with?
Claude Desktop, Claude Code, VS Code with GitHub Copilot, Visual Studio 2022 (17.14+), Cursor, Windsurf, Cline, Codex CLI and JetBrains Rider. Install with dnx GroupDocs.Signature.Mcp --yes or the Docker image ghcr.io/groupdocs-signature/signature-net-mcp.
Go deeper
- Documentation, canonical how-to: How to sign documents with AI agents using MCP
- Documentation hub: GroupDocs.Signature MCP Server
- Next: Why an AI Agent Should Not Just Say a Document Is Verified
- Next: Enforce Signing Policy with Automated AI Sweeps over MCP
- Next: From Barcode to Record: Document Intake Automation with AI Agents
- On-premise and security model: 3 architectures for AI document processing, and the one that keeps files inside your network
- Questions: GroupDocs Signature forum
- Source: GroupDocs.Signature.Mcp on GitHub