Smallpdf Pro

Offer common PDF transformations through a private self-hosted interface

KINDA · partial replacement
price $12/mosubscription / year $144estimated build time multi-dayreplaced by 0 people

The core loop is buildable, but a dependable replacement becomes a real weekend or multi-day project. For Smallpdf Pro, offer common PDF transformations through a private self-hosted interface. The hard boundary is hosted convenience, broad tools, mobile apps, signatures, ocr, and high-volume processing, plus document fidelity, identity, and compliance.

Build verification: not recorded. How we judge buildability

What you give up

  • hosted convenience, broad tools, mobile apps, signatures, OCR, and high-volume processing
  • pixel-perfect proprietary PDF engine
  • identity verification
  • qualified trust services
  • large template and integration ecosystem

Why people still pay

People still pay for Smallpdf Pro because the visible editor is reproducible, but reliable rendering and legally defensible signature workflows are not a casual side project. The recurring cost buys format edge cases, fonts, rendering, encryption, signatures, evidence, retention, storage, backups, and legal requirements, not just the visible interface.

Your build guide

The stack, security requirements, and agent rules for a focused replacement.

Before you start

  • A Python virtual environment, writable input/output directories and sufficient disk for both originals and outputs. Bind the service to localhost.
  • Implementation components: Python, FastAPI and server-rendered HTML with HTMX for a local interface. SQLite for manifests and job state, with an explicit worker process and immutable source files.
  • Scope boundary: Certified signatures and universal Office conversion are not included.
01
Python, FastAPI and server-rendered HTML with HTMX for a local interface.
02
SQLite for manifests and job state, with an explicit worker process and immutable source files.
03
Domain model: PDF inputs, requested operations, temporary workspaces, preview pages and output verification records
engineering roadmap

Implementation plan

1

Phase 1

Scope and fixtures. Implement this bounded workflow: Offer a private local interface for merge, split, rotate and size reduction, with optional OCR using an installed engine. Queue one bounded operation at a time and show before/after file information. Record prerequisites, select representative user-owned fixtures and document the unsupported features: Certified signatures and universal Office conversion are not included.

2

Phase 2

Durable model. Model PDF inputs, requested operations, temporary workspaces, preview pages and output verification records Add migrations or a versioned document format, explicit validation, stable IDs and a visible import-error report. Preserve this rule: Document contents stay local by default; temporary files have defined retention and failed jobs cannot expose partial outputs as final downloads.

3

Phase 3

Complete the first useful path. Implement the workflow's input, review and output interface, with clear controls and explicit empty/error states. Save a job manifest with input hash, parameters and state. Write to temporary outputs, then atomically finalize only successful results; resume unfinished jobs without replacing originals.

4

Phase 4

Permissions and integration failure. Bound file sizes and processing time, reject path traversal, and use argument arrays for subprocesses. Treat imported text as data and redact confidential source content from logs. Request integration credentials and permissions only for the enabled feature; show a disconnected state instead of mock results.

5

Phase 5

Portable handoff. Export sources, manifests and outputs with checksums. Keep failed-job diagnostics and allow retry into a new output path; restore the database and file directory together. Include setup, operating limits, fixture walkthrough and shutdown/restart instructions in the README.

6

Phase 6

Acceptance scenarios. Cancel a large compression job and retain the input; reopening a successful merged file confirms page count, order and readable text. Repeat the workflow after restart and with a denied permission or unavailable dependency; show recoverable failure rather than a success placeholder.

the pro prompt
download AGENTS.md
WORKING SLICE
Offer a private local interface for merge, split, rotate and size reduction, with optional OCR using an installed engine. Queue one bounded operation at a time and show before/after file information.

Build this scoped Smallpdf Pro-inspired workflow with a documented data model and visible failure states.

Architecture
- Python, FastAPI and server-rendered HTML with HTMX for a local interface.
- SQLite for manifests and job state, with an explicit worker process and immutable source files.

Prerequisites and limits
A Python virtual environment, writable input/output directories and sufficient disk for both originals and outputs. Bind the service to localhost.
Outside this release: Certified signatures and universal Office conversion are not included.

Data model and correctness
PDF inputs, requested operations, temporary workspaces, preview pages and output verification records
Invariant: Document contents stay local by default; temporary files have defined retention and failed jobs cannot expose partial outputs as final downloads.
Save a job manifest with input hash, parameters and state. Write to temporary outputs, then atomically finalize only successful results; resume unfinished jobs without replacing originals.

Security and privacy
Bound file sizes and processing time, reject path traversal, and use argument arrays for subprocesses. Treat imported text as data and redact confidential source content from logs.

Recovery and export
Export sources, manifests and outputs with checksums. Keep failed-job diagnostics and allow retry into a new output path; restore the database and file directory together.

Implementation order
1. Phase 1 — Scope and fixtures. Implement this bounded workflow: Offer a private local interface for merge, split, rotate and size reduction, with optional OCR using an installed engine. Queue one bounded operation at a time and show before/after file information. Record prerequisites, select representative user-owned fixtures and document the unsupported features: Certified signatures and universal Office conversion are not included.
2. Phase 2 — Durable model. Model PDF inputs, requested operations, temporary workspaces, preview pages and output verification records Add migrations or a versioned document format, explicit validation, stable IDs and a visible import-error report. Preserve this rule: Document contents stay local by default; temporary files have defined retention and failed jobs cannot expose partial outputs as final downloads.
3. Phase 3 — Complete the first useful path. Implement the workflow's input, review and output interface, with clear controls and explicit empty/error states. Save a job manifest with input hash, parameters and state. Write to temporary outputs, then atomically finalize only successful results; resume unfinished jobs without replacing originals.
4. Phase 4 — Permissions and integration failure. Bound file sizes and processing time, reject path traversal, and use argument arrays for subprocesses. Treat imported text as data and redact confidential source content from logs. Request integration credentials and permissions only for the enabled feature; show a disconnected state instead of mock results.
5. Phase 5 — Portable handoff. Export sources, manifests and outputs with checksums. Keep failed-job diagnostics and allow retry into a new output path; restore the database and file directory together. Include setup, operating limits, fixture walkthrough and shutdown/restart instructions in the README.
6. Phase 6 — Acceptance scenarios. Cancel a large compression job and retain the input; reopening a successful merged file confirms page count, order and readable text. Repeat the workflow after restart and with a denied permission or unavailable dependency; show recoverable failure rather than a success placeholder.

Acceptance
Cancel a large compression job and retain the input; reopening a successful merged file confirms page count, order and readable text.
Use real source data or clearly labeled fixtures. Explain unsupported input and provider failures; do not fabricate analytics, delivery receipts, accuracy claims or security guarantees.

Optional agent guidance
Optional external skill: [modern-python](https://github.com/trailofbits/skills/blob/main/plugins/modern-python/skills/modern-python/SKILL.md) — Set up Python projects with pyproject.toml, dependency management, linting, typing and automated checks. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Optional external skill: [sharp-edges](https://github.com/trailofbits/skills/blob/main/plugins/sharp-edges/skills/sharp-edges/SKILL.md) — Review security-sensitive APIs and configuration for dangerous defaults and easy-to-misuse interfaces. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Optional external skill: [web-design-guidelines](https://github.com/vercel-labs/agent-skills/blob/main/skills/web-design-guidelines/SKILL.md) — Review web interfaces for accessibility, keyboard focus, forms, navigation and interaction quality. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Optional external skill: [pdf](https://github.com/anthropics/skills/blob/main/skills/pdf/SKILL.md) — Process PDFs through extraction, generation, page operations, form filling and OCR workflows. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Project rule — data model: PDF inputs, requested operations, temporary workspaces, preview pages and output verification records
Project rule — preserve this invariant: Document contents stay local by default; temporary files have defined retention and failed jobs cannot expose partial outputs as final downloads.
Project rule — acceptance evidence: Cancel a large compression job and retain the input; reopening a successful merged file confirms page count, order and readable text.

$ open in your agent (prompt prefilled, you press enter), copy the prompt or copy or download AGENTS.md · generated from this app's build plan

share on X ↗

Alternatives to building your own

Stirling PDFThe credible self-hosted Smallpdf replacement: a large transformation toolbox, local control, and no artificial per-day rationing.89kaug 2026open source↗

no votes, no pay-to-list · just what's real

Smallpdf Pro pricing

planmonthlyannual (per mo)what you get
free$0/user$0/user2 Sign.com documents/month; AI files up to 50 MB and 25–35k words; PDF downloads/tasks and mobile access have daily limits but Smallpdf does not publish the numbers
pro$15/user$12/userUnlimited use of 30+ tools, downloads, mobile app and Sign.com Premium; AI files up to 50 MB and 100k wordsThe live official pricing index exposes $15/month and $12/month on annual billing; annual total is $144.
team$15/user$12/user2–19 seats; Pro features plus centralized billing, member management and priority support; AI files up to 50 MB and 100k wordsThe 2-seat live calculator shows $30 reduced to $24/month on annual billing, i.e. $12/seat/month.
business——20+ seats; custom pricing and payment terms; dedicated support; unlimited Sign.com Premium per member

free tier2 Sign.com documents/month; AI files up to 50 MB and 25–35k words; PDF task/download and mobile caps are daily but no numeric count is published

billingmonthly + annual; 7-day free trial requiring cancellation before expiry to avoid billing

hidden costsTeam starts at 2 paid seats and Business at 20. The free plan repeatedly says 'daily limit' without publishing the count, so the practical PDF-task ceiling cannot be stated numerically from the official page.

pricing sources checked 2026-08-13 · pricing source ↗

Questions about Smallpdf Pro

Can you build your own Smallpdf Pro with AI?

Partly. The core loop is buildable, but a dependable replacement becomes a real weekend or multi-day project. For Smallpdf Pro, offer common PDF transformations through a private self-hosted interface. The hard boundary is hosted convenience, broad tools, mobile apps, signatures, ocr, and high-volume processing, plus document fidelity, identity, and compliance.

What does the Smallpdf Pro build prompt cover?

The prompt starts with this scope: Offer a private local interface for merge, split, rotate and size reduction, with optional OCR using an installed engine. Queue one bounded operation at a time and show before/after file information. Full-product capabilities excluded from the comparison include: hosted convenience, broad tools, mobile apps, signatures, OCR, and high-volume processing; pixel-perfect proprietary PDF engine; identity verification. Follow the implementation plan and its prerequisites before expanding the build.

How do I use the prompt, AGENTS.md and agent skills?

Start with the Smallpdf Pro prerequisites and stack, then copy the prompt into your coding agent. Save the project rules as AGENTS.md in the project root. Linked skills are optional packages or source instructions for specific tasks; review their current contents and install only those matching the chosen stack. A skill does not supply API credentials or verify the finished app.

How long will this Smallpdf Pro project take?

The catalogue estimate is multi-day for the limited scope. Setup, integration approvals, debugging, deployment and ongoing maintenance can add time. This is an estimate, not a delivery guarantee.

What would I give up by replacing Smallpdf Pro?

hosted convenience, broad tools, mobile apps, signatures, OCR, and high-volume processing; pixel-perfect proprietary PDF engine; identity verification; qualified trust services; large template and integration ecosystem. People still pay for Smallpdf Pro because the visible editor is reproducible, but reliable rendering and legally defensible signature workflows are not a casual side project. The recurring cost buys format edge cases, fonts, rendering, encryption, signatures, evidence, retention, storage, backups, and legal requirements, not just the visible interface.

What price is this guide comparing against?

The recorded Pro plan is $12/mo (monthly), checked 2026-07-31. Check the linked pricing source before buying. Building your own also has hosting, API and maintenance costs; the recorded amount is not a guaranteed saving.

What can I use instead of building Smallpdf Pro?

Stirling PDF: The credible self-hosted Smallpdf replacement: a large transformation toolbox, local control, and no artificial per-day rationing. Check each option's license, hosting needs and feature limits.

Every week, more subscriptions die.

New verdicts, new prompts, the week's most-doomed apps.
One email. Unsubscribe in one click.

last week:100 Questions · KINDA1of10 · KINDA1Password · KINDA+1090 more

free forever · no scanner spam · the prompt stays on the site, the deaths come to you

$weekly: what got a verdict, what died.