Product2026-09-103 min read

What Self-Hosting Actually Buys You (and What It Costs)

Self-hosting PDF123 keeps uploads on your pdfx-server and exposes the same REST, MCP, and CLI catalog. You trade SaaS convenience for ops ownership costs.

PDF123 · Updated 2026-09-17

A public converter optimizes for anonymous one-offs. Self-hosting PDF123 changes the contract: uploads land on machines you operate, and every catalog tool is reachable as HTTP, not only as a browser form.

What you buy

Data locality is the first purchase. Files hit your pdfx-server, not a temp store you do not run. The second purchase is the developer surface on that same box: REST under /api/v1/…, OpenAPI at /v1/openapi.json, MCP at /mcp, and pdfx --cloud aimed at your base URL.

Docker Compose runs the Rust backend and the Next.js portal together so humans and scripts share one catalog. There is no desktop installer in that path; offline use is Compose and CLI (Self-host). Native local work uses task pdfx:dev beside the portal; Compose uses task docker:build / task docker:up (API :8080, portal :3000).

An agent or CI job with your key calls the same ops as the public site. Merge, Compress, OCR, convert, and the rest keep the same paths and parameters. That sameness is the product, not a slogan.

Ads that fund the public site are not part of a self-hosted deploy. You also skip the hosted anonymous quota story: capacity planning becomes yours, including CPU spikes during OCR or large merges. OCR still returns Markdown (text/markdown) on your box; relocating the server does not change the op contract.

What it costs

You own uptime, image upgrades, disk for temporary files, TLS, and key rotation. Compose is quick to start; keeping it healthy is ongoing. Set SECURITY_CUSTOMGLOBALAPIKEY when you want a fixed API key gate on your instance. Optional features (for example URL→PDF via SYSTEM_ENABLEURLTOPDF=true) are flags you enable deliberately, not defaults that appear because the public site has them.

Self-hosting does not add a visual “Edit PDF” canvas by flipping a flag. The surface stays form tools plus API. If you need canvas editing, you still need a different product; relocating the server does not invent that UI.

Rate limits and metering behavior follow how you configure the box. Do not assume the public site’s advertised headers and caps transplant unchanged; read the headers your instance returns when you care about budget. Dependency-heavy ops (OCR models, optional converters) fail with structured missing_dependency / unavailable problem codes if the binary or model pack is not installed on your image.

How it relates to the public site

Use hosted PDF123 for zero-setup trials. Catalog tools and anonymous /api/v1/ calls need no account there; responses advertise X-RateLimit-* and 429 responses include Retry-After (anonymous rate limiting).

Self-host when retention rules, air-gapped networks, or private automation require it. /llms.txt helps agents discover tools on whichever base URL you run; Google Search does not treat it as a ranking signal. MCP and OpenAPI stay available beside the portal on that same base.

When not to self-host yet

If you only need one merge this afternoon, the hosted form is enough. If you need private bytes tomorrow and every day after, start from Compose now rather than bolting a desktop installer onto a SaaS habit. The offline story we support is documented on Self-host, not a store listing.

Start from Self-host. Keys and OpenAPI live on Developers. For a shorter contrast with browser-only converters, see Why self-host a PDF toolkit. For why Compose is the private path instead of an .exe, see Why we skipped the desktop app.

Open tool
Process in the browser — no watermark, files removed after the job.
Open tool