---
name: "pdf123-show-javascript"
description: "Extract and display any embedded JavaScript in a PDF. Runs the PDF123 \"Show Javascript\" tool (pdf123.xyz) over its REST API with curl, no account needed. Use when the user wants this done to their file. Also known as: 查看 JavaScript, Ver JavaScript, JavaScript देखें, عرض JavaScript, Lihat JavaScript, Afficher le JavaScript, Показать JavaScript, JavaScriptの表示, JavaScript anzeigen, JavaScript 보기, Xem JavaScript, JavaScript'i göster, Mostra JavaScript, ดู JavaScript, Pokaż JavaScript, Показати JavaScript, JavaScript tonen, Tunjuk JavaScript, Visa JavaScript, Προβολή JavaScript, Преглед на JavaScript, Onyesha JavaScript."
compatibility: "Needs curl 7.76+ and outbound HTTPS to pdf123.xyz, or PDFX_API_BASE pointing at a self-hosted pdfx-server."
---

# Show Javascript (PDF123)

Extract and display any embedded JavaScript in a PDF.

Web version: https://pdf123.xyz/show-javascript · All tools: https://pdf123.xyz/skills/pdf123.md

## When to use

- Inspect OpenAction before opening a file in a trusting viewer
- Copy embedded scripts for review
- Confirm a form has no catalog JS the walker can see

## Run it

Replace the sample file names and values with the user's, then run:

```bash
API="${PDFX_API_BASE:-https://pdf123.xyz}"
curl -sS --fail-with-body -X POST "$API/api/v1/misc/show-javascript" \
  -F "fileInput=@input.pdf" \
  --output-dir "pdf123-output/$(date +%Y%m%d-%H%M%S)" --create-dirs -OJ -w '%{filename_effective} %{content_type}\n'
```

## Inputs

Everything is `multipart/form-data`. The command above already sends each field with its default; keep them all and change only the values the user asked for, since some endpoints reject a missing optional field.

| Field | Type | Required | Default | Notes |
| --- | --- | --- | --- | --- |
| `fileInput` | file | yes | | .pdf (one file) |

## Result

curl saves the result in a new `pdf123-output/<timestamp>/` directory under the server's file name and prints its path and content type. Several output files come back as one ZIP. Tell the user where the file is.

## Limits

- Not an executor
- Scripts in unusual objects or XFA forms can be missed
- Not a cleaner
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.

## Errors

- A non-zero curl exit means the request failed. The saved file then holds `application/problem+json`; read it and report its `detail` to the user instead of retrying blindly.
- `413`: the upload exceeds 100 MiB. `429`: wait for `Retry-After` seconds, then retry once.
- Send `X-API-KEY: $PDFX_API_KEY` only if the user has a PDF123 API key; anonymous calls work without it.

## Privacy

Files are uploaded to the API host, processed, and deleted once the response is sent. For confidential files, ask before uploading, or use a self-hosted server via `PDFX_API_BASE`.
