An AI agent can watermark documents on your own machine, with no upload: you ask in plain language, the agent calls the GroupDocs.Watermark.Mcp server, and a marked copy appears next to the original. This works in Claude Desktop, Claude Code, Cursor, VS Code with GitHub Copilot and Windsurf. A typical first request, run locally:

Add a diagonal CONFIDENTIAL watermark to contract.pdf.

The step-by-step version with config and troubleshooting is in the documentation: How to watermark documents with AI agents using MCP.

Why should documents made with an LLM carry a label?

Once an LLM drafts, summarises or reformats documents, files circulate without any sign of how they were produced. Asking the model to “add a note at the top” changes the content itself, and a model that rewrites a document can change more than the note. A watermark is applied by the engine as a separate object on a saved copy, so the text underneath is not regenerated. The server writes every result as a new file; the original is left alone. The mark is plain text or an image that you choose; the server does not detect whether a document was AI-generated and embeds no provenance metadata. That makes labelling a policy you can state in one sentence: every document that leaves this folder carries a mark.

A watermark is a deterrent, not an access control. It makes provenance visible and casual reuse awkward. It does not stop copying and it can be removed by someone who wants to. If you need tamper evidence, use a digital signature instead.

Way 1: Stamp a status as text

Use add_watermark when the label is a word or a short phrase: DRAFT, CONFIDENTIAL, a date, “Generated with AI”.

Add a diagonal AI-GENERATED watermark to summary.docx.

The agent calls add_watermark with text, an optional fontSize (default 36) and rotation (default -45, the classic diagonal). Expected result: a message of the form Added text watermark "AI-GENERATED" to "summary.docx" and the path of the new file in your output folder.

Way 2: Mark the source with an image

Use add_image_watermark when the label is a logo, a stamp or a scanned signature. The image can be PNG, JPG, BMP or TIFF and is resolved by name from the same storage folder as the document.

Put approved-stamp.png on every page of report.pdf at 30% opacity.

opacity runs from 0.0 to 1.0 with a default of 0.5. Values between 0.2 and 0.4 usually read as a label rather than an obstruction.

Way 3: Combine a status and a source mark

Use two calls when one mark is not enough, for example the source logo plus a status. Chain them and say so:

Add the logo at 30% opacity, then add a DRAFT text watermark to that result.

Each call writes a new file. Without “to that result” the second call starts from the original and only the DRAFT mark survives.

How do you check that the label is there?

Use search_watermarks to ask what a document carries. It returns a JSON object with count and a watermarks array; each entry has type (text or image), text, page, x, y, width, height and rotateAngle.

Does proposal.pdf already have a watermark, and what does it say?

Run it before a labelling pass and a file that already shows CONFIDENTIAL is not stamped twice at two angles. Run it after a pass and you have evidence that the mark is there.

Example session (abridged)

You:    Add a diagonal CONFIDENTIAL watermark to contract.pdf, then
        check that it is there.
Agent:  [add_watermark: text "CONFIDENTIAL", rotation -45]
        Added text watermark "CONFIDENTIAL" to "contract.pdf"
Agent:  [search_watermarks on the new copy]
        count: 1 - type: text, text: "CONFIDENTIAL", page: 1
        The copy carries one text watermark. contract.pdf is unchanged.

How do you set it up?

With the .NET 10 SDK installed, the server starts with one command, and your client launches it for you once it is registered:

dnx GroupDocs.Watermark.Mcp --yes

Set GROUPDOCS_MCP_STORAGE_PATH to the folder that holds your documents. Registration blocks exist for Claude Desktop, Claude Code, Cursor, VS Code with GitHub Copilot, Windsurf, Cline and Codex CLI; the exact config for each is in the documentation hub linked below.

What are the limits?

The first limit is licensing. The server starts in evaluation mode, where, per the server’s licensing page, output carries evaluation limitations; the exact limits are on the library’s licensing page. For a watermarking tool this matters: a copy produced in evaluation mode is a draft, not something to distribute. Ask the agent to call get_license_status first; it returns mode (evaluation, licensed or metered) without touching a document.

FAQ

Can Claude watermark a PDF without uploading it? Yes. The server runs as a local process that your client starts, and the data path is agent, local server, local filesystem. The model sees your prompt and the server’s text replies; the document files stay on disk.

Which formats can an AI agent watermark? PDF, Word, Excel, PowerPoint, images and 50+ more document and image formats, with the same two tools for all of them.

How do I label many files at once? Name the folder in the prompt; the agent calls the tool per file. A full walkthrough is in the batch post linked below.

Go deeper