PDF Blocks documentation
Where to start for each integration, the action catalog, the concepts that cut across every action, and the security and legal documentation.
Every action follows one model: send a document, name what to do with it, and get the finished document straight back. There is no SDK to install and no state to manage, and nothing is kept once the response is sent.
Start with the way you plan to call it, or search every page from the header
(⌘K, or Ctrl K on Windows).
Choose your integration
For writing code, in any language.
One authenticated HTTPS call per action: multipart/form-data in, a PDF back.
Every action is available, and each output is a valid input to the next.
For building a flow in Power Automate.
Our certified connector, with all eighteen actions as flow steps. Documents move between steps as file content, so no intermediate storage is needed.
For wiring apps together without code.
The most common actions as Zap steps, taking files from the apps you already connect. Start here for the file-field rules that trip up most Zaps.
Try one request
Put a PDF named input.pdf in your working directory, swap in your key, and run
this. It stamps a watermark across the document and writes the result to
watermarked.pdf.
curl https://api.pdfblocks.com/v1/add_text_watermark \
-H 'X-API-Key: your_api_key' \
-F file=@input.pdf \
-F line_1='CONFIDENTIAL' \
-o watermarked.pdfThe answer is 200 OK with application/pdf and the finished document as the
body. Every single-output action follows that same shape, so swapping the action
name is most of the work of adopting the next one. The
Quickstart has the same call in Python, Node.js, PHP,
Ruby, and more, plus how to get a key.
What you can do
Seventeen actions, grouped by capability. Each group links into the full catalog, where every action has its own reference page.
Combine an ordered list of documents, or break one apart by page count, at a page, by file size, or into groups you define.
Stamp text or an image across the pages, with control over placement, rotation, opacity, and which pages are covered.
Add or remove a password, apply or lift permission restrictions, and strip existing signatures.
Extract, remove, rotate, reverse, and reorder pages, all sharing one range syntax.
Core concepts
These cut across every action, and they are where most integration questions are actually answered.
- Authentication: how API keys work, what to send on each request, and how to keep a key safe.
- Working with files: how to send documents, the size limits, and what comes back.
- Selecting pages: the
pagesrange syntax shared by every page-level action. - Chaining actions: feeding one action’s output into the next without ever touching disk.
- Response formats: content negotiation, and how actions that produce several documents answer.
- Errors: the error body, and what each status code means.
- Rate limits and usage: what counts as a request, and what happens when you reach a limit.
- Regions and data residency: the regional endpoints, and where each one processes documents.
- Versioning and stability: what can change under a running integration, and what cannot.
Security and compliance
Two structural facts shape most review questions: documents are never stored, and no LLM ever reads them. Each file is processed in memory and returned in the same response.
The Trust section has the detail: the security overview with a SOC 2 control mapping, HIPAA and BAA terms, the subprocessor list, and the legal set (Terms, Privacy Policy, and DPA).
Reference and support
Every change to the API, newest first.
The machine-readable spec, for generating a client or importing into your tools.
What exists per language, and why there is no SDK to install.
How to reach us, what to include, and where to check current status.