Skip to main content

SafeDocx · Open-source Word editing for AI

Let your AI edit Word documents like code.

Use Claude Code, Gemini CLI, Cursor, or another MCP-compatible agent. Each edit is written next to its reason in a format-preserving plain-text copy you can keep in Git, and lands in the .docx as a tracked change and comment.

  • Apache 2.0, free for commercial use
  • Runs locally
  • Tracked changes
  • ECMA-376 target subset
Monthly npm downloads for @usejunior/safe-docx
vendor-agreement.docxWord file

9. Term and Termination

9.1 Term. This Agreement begins on the Effective Date and continues until all Order Forms have expired or been terminated.

9.2 Termination for Breach. Either party may terminate this Agreement immediately upon written notice if the other party materially breaches this Agreement.

9.3 Effect of Termination. On termination, Customer will pay all fees accrued through the termination date.

10. Warranties

10.1 Authority. Each party represents that it has full power and authority to enter into this Agreement.

10.2 Performance. Vendor warrants that the Services will perform materially as described in the Documentation.

11. Limitation of Liability

11.1 Liability Cap. Each party's total liability under this Agreement will not exceed the fees paid by Customer in the twelve (12) months before the claim.

11.2 Excluded Damages. Neither party is liable for indirect, incidental, special or consequential damages, or lost profits.

LLegal team
LLegal team
Converting to plain textEdit lands as a tracked changeReason lands as a comment
vendor-agreement.mdocDSL (domain-specific language)

Illustrative example. You approve every change and every comment.

Why a plain-text copy

Your edits live in code, not inside a zip file.

A .docx is a compressed package, so Git can only see it as a binary. SafeDocx gives your agent a plain-text projection of the document to edit instead, and writes the result back into the original file.

Reasons stay with the edits

Each change is paired with its rationale in one file. External-facing reasons become Word comments; internal ones stay with your team.

Contracts in Git

Pin the counterparty's original, then commit each round of edits as readable text. Review the history the way you review code.

Formatting stays pinned

Styles, numbering and run formatting stay attached to the tags, so an edit only ever touches the words.

Checked before it lands

The before text is matched against the file, and each change applies whole. What you wrote is exactly what appears as a tracked change.

Built for document review

Change the wording. Keep the review trail.

Revise without rebuilding

Replace text and insert paragraphs in existing Word files while preserving their structure and formatting.

Make changes easy to inspect

Produce tracked replacements or compare versions so reviewers can see what changed before accepting it.

Keep the discussion with the text

Add and update comments so questions and explanations stay attached to the passage under review.

Keep mechanics out of the prompt

Let the agent describe the edit. Let the engine handle Word.

Splitting runs and chasing numbering references competes for the same context window as the work users actually care about.

  1. 1InstructionThe user describes the intended change.
  2. 2AgentSearches context and chooses a typed operation.
  3. 3SafeDocxResolves OOXML structure and applies the mutation.
  4. 4Word outputReturns a reviewable file with revisions or comments.

Agent context

Intent, clause meaning, business constraints, reviewer instructions.

Engine boundary

Runs, relationships, numbering, revision markup, comments, and package integrity.

Inspectable evidence

A result is more useful when you can see how it was scored.

The existing open benchmark runs shared task fixtures through small adapters and checks the resulting document. Scenario outcomes do not imply that every adapter implements the benchmark's full operation surface.

See the compatibility results
Task fixtureInput document + expected invariant
Adapter operationProduces an output DOCX
Structural and visual checksCompare the result with the task invariant
PassPass-divergentUnsupported

Start locally

Add SafeDocx to your coding agent.

The MCP server runs on your machine. Your AI client and model provider remain separate parts of the data path.

Choose your coding agent

Install for Claude Code

You’ll need Node.js/npm and Claude Code installed.

  1. Run this command in your terminal:

    claude mcp add safe-docx -- npx -y @usejunior/safe-docx
  2. Confirm the server is registered:

    claude mcp get safe-docx
  3. Start a new Claude Code session in your document’s folder. Ask it to use SafeDocx to read a Word file, then review the result.

Install for Codex CLI

You’ll need Node.js/npm and the Codex CLI installed.

  1. Run this command in your terminal:

    codex mcp add safe-docx -- npx -y @usejunior/safe-docx
  2. Confirm the server is registered:

    codex mcp get safe-docx
  3. Start a new Codex session in your document’s folder. Ask it to use SafeDocx to read a Word file, then review the result.

These commands register the local MCP server and use npx to fetch and run the npm package when your agent starts it.

Common questions

SafeDocx FAQ

Can Claude read and edit DOCX files?

Yes, with safe-docx as the bridge. Claude can read text from .docx files natively and generate new ones via its file-creation tool. For surgical edits to an existing document that preserve formatting, tracked changes, and comments, safe-docx is the open-source MCP server that adds that capability. After claude mcp add safe-docx -- npx -y @usejunior/safe-docx, your Claude agent has typed tool calls for replacing text, adding comments, comparing versions, and extracting tracked changes.

Is there an MCP server for editing Word documents?

Yes - safe-docx is an Apache-2.0-licensed Model Context Protocol server specifically for editing existing Microsoft Word .docx files. It exposes 26 typed tools across 8 categories (structural inspection, text editing, controlled batches, comment and footnote management, tracked-change controls, comparison, and export). It runs locally via npx and works with any MCP-compatible client (Claude Code, Gemini CLI, Cursor).

Does safe-docx preserve tracked changes?

Yes. safe-docx round-trips OOXML <w:ins> and <w:del> elements, the associated <w:rPr> formatting on revision marks, and comment ranges (<w:commentRangeStart> / <w:commentRangeEnd>). When the agent makes an edit, you can choose to wrap that edit in a tracked-change marker so Word's Track Changes view shows the agent's revisions alongside any human ones already in the document.

How is safe-docx different from python-docx?

python-docx is a Python library focused on generating new .docx files programmatically. safe-docx is a TypeScript-native MCP server purpose-built for editing existing documents AI agents need to work with - surgical text replacement, comment manipulation, comparison, and revision extraction, all preserving the original formatting. See the feature-by-feature comparison for specifics on tracked-change handling, OOXML coverage, and round-trip fidelity.

Where does safe-docx run, and does it send my documents anywhere?

safe-docx runs entirely on your local machine as an MCP server process started by your AI client (Claude Code, Gemini CLI, etc.). It reads and writes .docx files on your local filesystem. safe-docx does not send document content to any UseJunior server, third-party server, or cloud service. Network access is required only for the initial npm install and for updates.

Important nuance: safe-docx itself is local-only, but your AI client may upload prompt content (including text extracted from the document) to its own model provider as part of how it processes your request. That data flow is governed by your AI client's terms (Anthropic, Google, etc.), not by safe-docx. If you need a fully air-gapped workflow, pair safe-docx with a local model.

Does safe-docx work with Gemini CLI?

Yes. safe-docx is an MCP server, so any MCP-compatible client can use it. For Gemini CLI: gemini extensions install https://github.com/UseJunior/safe-docx. See Quick install for Claude Code and Cursor.

Is safe-docx open source? What's the license?

Apache-2.0. Source on GitHub at UseJunior/safe-docx, npm package @usejunior/safe-docx. Contributions welcome.

What do I need to get started, and does SafeDocx cost anything?

SafeDocx is free and Apache-2.0 licensed; no SafeDocx account or subscription is required. Install Node.js/npm and use an MCP-compatible agent, then follow Quick install. Your AI client or model provider may charge separately. Start with a copy of a document and review the output in Word.

Will SafeDocx work with every Word document?

SafeDocx targets a subset of the Word document standard. Check the compatibility results for the scenarios you need, try a copy of your document, and inspect the output in Word.

Your first edit

Give your agent a Word file. Get a change you can review.

Start with a copy, ask for a tracked replacement or reviewer comment, and inspect the output in Word.