A file conversion API covering documents, images, audio, video and archives, running the right tool for each format so you do not have to install any of them.
Build me a file conversion service that replaces CloudConvert: an API and a queue that runs the right tool for each format, sandboxed, on my own machine. STACK - Node 20+ with Fastify for the API - SQLite through better-sqlite3 for jobs and history, WAL mode - The converters are existing binaries, each in its own container: ffmpeg, ImageMagick, LibreOffice, Ghostscript, pandoc, qpdf, 7-zip - Docker or Podman on the host; the API never runs a converter in its own process - Caddy in front THE DATA MODEL - jobs: id, token, status, created_by, created_at, started_at, finished_at, error, priority - tasks: id, job_id, kind, engine, input_file_id, output_file_id, options_json, status, attempts, log_path, started_at, finished_at - files: id, job_id, kind, original_name, stored_path, mime_detected, mime_claimed, size_bytes, sha256, expires_at, deleted_at - engines: name, image, formats_in_json, formats_out_json, cpu_limit, memory_limit, timeout_seconds - usage: id, api_key_id, bytes_in, bytes_out, seconds_cpu, created_at - A job is a graph of tasks: import, convert, optimise, export. Chaining is the reason this is a service and not a shell script SANDBOXING, WHICH IS THE ACTUAL PRODUCT - Every conversion runs in a container with no network, a read-only root filesystem, a tmpfs for work, a memory cap, a CPU quota, a wall-clock timeout and a dropped capability set - The input is mounted read-only at a fixed path; the output directory is the only writable mount - Non-root inside the container, and a seccomp profile - File parsers are among the most reliably exploitable code in existence. Ghostscript, ImageMagick and LibreOffice have all been remote code execution in the last few years. The isolation is not caution, it is the requirement — write that in the README - The detected MIME type governs which engine runs, never the file extension and never the client's claim; a mismatch is recorded THE API - POST a job describing tasks, or use the one-shot convert endpoint for the common case - Upload directly, by URL, or with a pre-signed form; download by a signed link that expires - Poll for status, or receive a webhook signed with HMAC and retried with backoff - Errors say which task failed, with the last lines of the engine's log, sanitised of paths - Idempotency keys, so a retried request never runs the job twice - API keys with per-key limits on concurrency, file size and monthly bytes WHAT IT CONVERTS - Images: raster and vector both ways, with resize, crop, quality, colour profile handling and metadata stripping optional - Documents: office formats and PDF through LibreOffice, PDF operations through qpdf and Ghostscript, markup through pandoc - Audio and video through ffmpeg, with sensible presets rather than a hundred exposed flags - Archives, extracted with a limit on the expansion ratio and the entry count — a zip bomb is a denial of service with a two-line fix - Every format pair is declared in the engines table, so the API can answer 'what can you convert this to' from data rather than from a hard-coded list THE QUEUE - Workers pull tasks, with a concurrency cap per engine and a global one - Retries with backoff for transient failures, never for a parse failure - Priority so a small image is not stuck behind an hour of video - Progress reported where the engine reports it, and honestly absent where it does not FILES AND PRIVACY - Everything expires: a default of an hour, configurable per job, enforced by a sweeper that also deletes on disk - Deletion is real, and the row records that it happened - Optional at-rest encryption with a per-job key held only for the job's life - The README states plainly how long files live and what is logged THE INTERFACE - A page to drop a file, pick a target format, and get the result — the API with a face on it - A job list with logs for the operator - Dark and light OPERATIONS - .env: DATABASE_PATH, STORAGE_PATH, BASE_URL, SIGNING_SECRET, MAX_UPLOAD_BYTES, CONTAINER_RUNTIME - Migrations on boot, each once - Disk watchdog: refuse new jobs above a threshold rather than filling the volume - Health endpoint that converts a one-pixel PNG through the real path - Backup covers the database; the files are ephemeral by design and are not backed up WHAT MATTERS MOST The sandbox. Build the container runner with its limits and the MIME detection first, and try to break it with a malformed PDF and a zip bomb before writing a single format handler. Everything else here is calling a binary with the right arguments. Give me the repository, the container definitions, migrations, .env.example, and a README with deploy steps behind Caddy and the security assumptions stated in full.
What you lose
- Dozens of conversion tools installed, patched and sandboxed, which is the actual product
- Capacity for large files without you sizing a worker
- Sandboxing, which matters because file parsers are a common source of vulnerabilities
If you would rather not build
- Your own worker, which is what the prompt builds
What it costs
as published on their pricing page
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $9/mo | — | — |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
ffmpeg
$0Handles audio and video conversion for practically every format.
FFmpeg/FFmpegfree · open source
Stirling-PDF
$0A self-hosted toolkit for splitting, merging and converting PDFs.
Stirling-Tools/Stirling-PDFfree · open source
Why this verdict
our own opinion · changed only by a person
85/100
Verdict yes at 85. The converters are free; the work is sandboxing them properly, because file parsers are exactly where untrusted input causes harm.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about CloudConvert
answered from the record above
Is CloudConvert free?
No — the plan we track is $9 a month. From around $9/month billed monthly for a package of conversion minutes.
Can you replace CloudConvert by building your own?
YES. Replaceable in one session with an AI coding agent. Replacement score 85 out of 100, build time one session. Read what you lose before you decide.
How much does CloudConvert cost?
$9 a month on Package — $108 a year. Recorded 10 Aug 2026.
What do you lose by replacing CloudConvert?
Dozens of conversion tools installed, patched and sandboxed, which is the actual product; Capacity for large files without you sizing a worker; Sandboxing, which matters because file parsers are a common source of vulnerabilities. If any of those carry weight for you, keep paying.
Is there an open-source alternative to CloudConvert?
Yes: ffmpeg, Stirling-PDF. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

