Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Galley Render

REMOTE · MCP.GALLEYRENDER.COM · SCANNED SEP 28

JSON in, PDF out. Render invoices, certificates, reports and cards from a template and a payload.

+3 this week 68 Trust /100

Recent critical change

Authorization (18 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability64
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 5052 tokens (~315/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
  • Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Galley Render MCP server?

Galley Render is a hosted endpoint at https://mcp.galleyrender.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.galleyrender.com

# add to Claude Code
claude mcp add --transport http com-galleyrender-galley-render 'https://mcp.galleyrender.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-galleyrender-galley-render": {
      "url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-galleyrender-galley-render": {
      "type": "http",
      "url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-galleyrender-galley-render]
url = "https://mcp.galleyrender.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-galleyrender-galley-render": {
      "type": "remote",
      "url": "https://mcp.galleyrender.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-galleyrender-galley-render --url 'https://mcp.galleyrender.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-galleyrender-galley-render:
    url: "https://mcp.galleyrender.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-galleyrender-galley-render": {
      "Transport": "http",
      "Url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-galleyrender-galley-render -t streamable-http -u 'https://mcp.galleyrender.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-galleyrender-galley-render": {
      "type": "http",
      "url": "https://mcp.galleyrender.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 23 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 22 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “create_account” rewrote its description, which is the text the model reads security
    • Tool “create_template” rewrote its description, which is the text the model reads security
    • Tool “get_render” rewrote its description, which is the text the model reads security
    • Tool “link_account” rewrote its description, which is the text the model reads security
    • Tool “render” rewrote its description, which is the text the model reads security
    • Tool “unlink_account” rewrote its description, which is the text the model reads security
    • Tool “usage” rewrote its description, which is the text the model reads security
    • Tool “whoami” rewrote its description, which is the text the model reads security
    • Schema quality: 280 → 315 ▼ functional
    • Server version: 0.1.0 → 0.2.0 functional
    • “upgrade” reworded the description of “plan” cosmetic
  • 21 Sept 26 0
    • New tool “rotate_key”, which the server declares destructive security
    • Tool “create_account” rewrote its description, which is the text the model reads security
    • Tool “usage” rewrote its description, which is the text the model reads security
  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1
    • Authorization: unverified → fail ▼ critical
    • The server rewrote its instructions, which are the text every model session reads security
    • New tool “unlink_account”, which the server declares destructive security
    • Tool “create_account” rewrote its description, which is the text the model reads security
    • Tool “render” rewrote its description, which is the text the model reads security
    • Schema quality: 239 → 273 ▼ functional
    • New tool “billing_portal” functional
    • New tool “link_account” functional
    • New tool “upgrade” functional
    • New tool “whoami” functional
    • “create_account” reworded the description of “email” cosmetic
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Probed https://mcp.galleyrender.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.galleyrender.com CN=WE1,O=Google Trust Services,C=US 16 Sept 2026 15 Dec 2026 ECDSA 256 ECDSA-SHA256 b913ca648fa6c7a2132c2e4cddeb32b6
SANs: mcp.galleyrender.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.galleyrender.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
galleyrender.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.galleyrender.com/mcp Verified 200
http (plaintext) http://mcp.galleyrender.com/mcp HTTPS enforced 301 https://mcp.galleyrender.com/mcp
MCP tools · 16 exposed · ~4,502 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
billing_portal ~189

Get a link to the Stripe customer portal, for a human to open: change plan, update the card, download invoices, or cancel. This is the only way any of those happen. Galley's API cannot change or cancel a subscription and cannot issue a refund — deliberately — so if you are asked to downgrade or cancel, the answer is this link and a human on the other end of it. The link is single-use and short-lived, so fetch a fresh one rather than storing it. Only works once the account has subscribed at least once; before that, use `upgrade`. Free. **If billing is not enabled on the deployment this is pointed at, the call is refused with `billing_unavailable` (503) rather than answered with a link.** Say so and point the human at support@galleyrender.com. Do not construct a portal URL yourself and do not retry.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

create_account ~614

Turn the keyless trial into a real account and get a permanent API key. Call it once with an email. A link is mailed to that address and the tool returns `status: "pending_verification"` with a four-character `request_code`. **Tell the person the code.** The link opens a page that names who asked, when, and the code, and nothing happens until the person answers it: they confirm the request only if it shows the code you gave them. After they confirm, call this again with the same email, from this same client, and it returns the API key, once. The key goes only to the client whose request was confirmed, and that client is then bound to the account, so a connector that cannot send headers is connected from then on. **A client with no identity of its own can't be handed the key** (`can_receive_key: false`). That is any client that sent no key and no client id — every hosted connector added with the shared URL, because they all call from their vendor's servers. Its person verifies the address on the page and sees the key there, once. To use the account from such a connector afterwards, add it with a personal URL (`https://mcp.galleyrender.com/mcp/c/<id>`). If the person says the request wasn't theirs, it is cancelled, this returns `status: "declined"`, and the address can't be asked about again from this client for a day. **If that address already has an account, no second one is made, and no key comes back.** You get `status: "existing_account"`, `verified: false`, `existing_account: true`, and a one-time code in the post — hand that code to `link_account` and this client is connected to the account that already exists. Use this rather than inventing a second address: two accounts means two free tiers and two sets of templates, and the renders anyone is waiting for are on the first one. A key on the connection changes this only if it is a live key for that same account. When the person confirms this client's request, this client's trial is upgraded in place, so te…

NameTypeReqDescription
emailstringyesWhere to send the verification link. Use the address of the person who owns this project — not a made-up one; the key is only released after the link is clicked. If this address already has a Galley…
namestring–Account name. Defaults to the local part of the email.

No output schema declared.

No examples provided.

create_template ~563

Create a new template at version 1 from an HTML document with Liquid expressions, plus a JSON Schema for its data. Use this when nothing in list_templates fits. The name must be free on this account — publishing a change to an existing template is `update_template`, not this. Free, but each plan keeps a limited number of templates of your own (the starter library never counts): at the limit this returns `plan_required` with how many the account has, and `update_template` still works.

NameTypeReqDescription
descriptionstring–One line on what this template is for. Shown in list_templates.
enginestring–Rendering engine. `chromium` (default) is full HTML and CSS and is required for PDF. `satori` is a fast PNG path for simple flexbox card layouts — no page breaks, no floats, no external CSS — and cos…
example––A payload that renders correctly. It is echoed back in validation errors, so include one.
expected_pagesinteger–How many PDF pages a typical payload renders. Default 1. This is the estimate the free tier and the spend cap are checked against before the render starts, so a template that runs to several pages mu…
messagestring–Change note for this version, like a commit message.
namestringyesTemplate name: lowercase letters, digits, dot, dash or underscore, 1-63 characters. Unique per account. Versions are separate — do not put `@1` here.
optionsobject–Render options, merged over the template's own defaults. Options are part of the cache key, so two calls that differ only here are two different renders.
schemaobject–JSON Schema (2020-12) for the `data` payload this template accepts. Strongly recommended: it is what turns a bad payload into a field-level error with a path, an expected type and a working example i…
sourcestringyesOne self-contained HTML document with inline CSS and Liquid expressions (`{{ customer.name }}`, `{% for line in line_items %}`). No file includes: everything the render needs must be in this string,…

No output schema declared.

No examples provided.

get_render ~141

Fetch a render by id: its status, and a freshly signed URL once it has succeeded. Use it to poll a queued render, or to re-sign a URL that has expired — signed URLs last an hour, the stored file lasts until the render's `expires_at` (the plan's retention). Past `expires_at` the file is deleted and this returns `retention_expired` (410) with the render and the template version to render again. Free, and never re-renders.

NameTypeReqDescription
render_idstringyesRender id from a previous render call, e.g. `rnd_…`. Returns the status and a fresh signed URL.

No output schema declared.

No examples provided.

get_template ~135

Fetch one template version: its JSON Schema, its default render options, an example payload and its HTML source. Read the schema before rendering — it is the contract for the `data` argument. Free.

NameTypeReqDescription
include_sourceboolean–Include the HTML source in the response. Default true. Set false when you only need the schema.
templatestringyesTemplate to use: `invoice` for the latest version, or `invoice@3` to pin version 3. Pin the version in anything you ship — a new version changes the output and the cache key. Call list_templates to s…

No output schema declared.

No examples provided.

link_account ~530

Point this MCP client at an account you already have, so header-less calls from it stop spending the keyless trial. **This is for clients that cannot set HTTP headers** — Claude.ai custom connectors and ChatGPT apps. If your client *can* set a header, prefer that: it is per-connection, it is not tied to a network address, and it needs no tool call at all. **Only a client with an identity of its own can be linked.** A connector added with the shared URL and no client id is recognised by its IP address and User-Agent, and every user of a hosted connector shares those: they call from their vendor's servers. Linking that would link all of them, so it is refused. Add this server with a personal URL instead — `https://mcp.galleyrender.com/mcp/c/<id>`, with a random `<id>` of your own (https://galleyrender.com/docs/connect makes one) — or send `X-Galley-Client-Id` with at least 128 random bits, then link. Two ways to prove the account is yours. `api_key`, if you have the key to hand. Or `link_code`, the one-time code mailed to the account's own address — call `create_account` with that address to have one sent, and nobody has to paste a key into a chat window. Either way the credential is used once, checked, and dropped: what is stored is the account id and a key minted for this client, which `unlink_account` revokes. **Whoever has the client id acts as the account.** A personal connector URL or a client id header is a credential once linked: keep it like a key, and `unlink_account` when you are done on a machine that is not yours. Free.

NameTypeReqDescription
api_keystring–A Galley API key, starting `glr_sk_`. It is checked against the API and then discarded — the binding that is stored is by account id, and this server keeps no copy of the key. Give either this or `li…
link_codestring–The one-time code mailed to the account's address, like `GLR-4F7K-9QX2`. Ten minutes, one use. Ask for one by calling `create_account` with the address: if it already has an account, a code is what c…

No output schema declared.

No examples provided.

list_renders ~74

Recent renders on this account, newest first, with status, template version and a signed URL for each that succeeded. Useful for finding a render whose id you lost, or checking what a batch did. Free.

NameTypeReqDescription
limitinteger–How many to return, newest first. 1-100, default 25.

No output schema declared.

No examples provided.

list_templates ~65

List the templates on this account, with their latest version number. Start here: rendering needs a template, and this says which ones exist. A brand-new trial account starts with the starter library (invoice, quote, receipt, og-card, certificate and more) already loaded. Free.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

render ~404

Render a template plus a JSON payload into a PDF, PNG or JPG and return a signed URL. This is the one tool most calls need. Small jobs finish inside the call and come back `status: "succeeded"` with a `url` you can hand straight to a user. Anything with a `webhook_url`, `async: true` or a large payload comes back `status: "queued"` with an id for get_render. Renders are deterministic and cached: the same template version, data and options return the stored object with `cached: true`, free and instant. Billing is per PNG or JPG and per PDF page; cache hits are never billed. No API key needed to start — the first call mints a trial of 10 PDF pages or 10 images and returns its token.

NameTypeReqDescription
asyncboolean–Force the queued path even for a small job. Default false: small jobs finish inside the call and come back with a URL already.
data–yesThe JSON payload for the template, matching its schema. Call get_template for the schema, or validate_data to dry-run a payload for free.
formatstring–Output format. Defaults to `pdf` for chromium templates and `png` for satori ones. `webp` is not supported in v1.
optionsobject–Render options, merged over the template's own defaults. Options are part of the cache key, so two calls that differ only here are two different renders.
templatestringyesTemplate to use: `invoice` for the latest version, or `invoice@3` to pin version 3. Pin the version in anything you ship — a new version changes the output and the cache key. Call list_templates to s…
webhook_urlstring–Absolute https URL to POST the finished render to. Supplying one forces the queued path: the call returns immediately with status `queued`.

No output schema declared.

No examples provided.

rotate_key ~382

Get a fresh API key for the account this connection is already acting on — the answer to a key that has been lost, leaked, pasted into a chat window, or left on a machine that is not yours. **Two calls, on purpose.** `rotate_key({})` mints the new key and shows it **once**; it revokes nothing, so whatever is running on the old key keeps running. Give the new key to the person, wait until they tell you it is saved, then call `rotate_key({ confirm_saved: true, revoke_key_id: "…" })` with the id from `other_live_keys` to kill the old one. Revoking first would take their integration down between the two calls, and revoking without asking would do it without them knowing why. **The key is shown once and cannot be recovered.** Hand it over immediately and do not repeat it in any later message, summary, log or file. Needs a key on the connection or a linked client — it cannot help somebody holding nothing. That case starts at `create_account` with the account's verified address, which mails a one-time code for `link_account`. Free, and it renders nothing.

NameTypeReqDescription
confirm_savedboolean–Leave this off for the first call: it mints the new key and shows it once, and revokes nothing. Set it to `true` — together with `revoke_key_id` — only after the human has told you they have saved th…
revoke_key_idstring–The id of the key to revoke, taken from `other_live_keys` in the first call's answer. Required with `confirm_saved`. Never guess one: revoking the wrong key takes down whatever was using it.

No output schema declared.

No examples provided.

unlink_account ~107

Undo `link_account`. The binding is deleted and the key that was minted for this client is revoked, so the client can no longer reach the account. Your own API key is untouched — this disconnects a client, it does not close an account. Do this on any machine that is not yours, and whenever a personal connector URL or a client id may have been seen by somebody else. Calls afterwards fall back to the keyless trial. Safe to call when nothing is linked. Free.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

update_template ~447

Publish a new immutable version of an existing template. Versions are never edited in place: `invoice@2` keeps rendering exactly as it did, and anything pinned to it is unaffected. Renders cached against the old version stay valid, and the new version starts with a cold cache. `engine`, `schema`, `options` and `example` are inherited from the previous version unless you send them, so a source-only change needs only `template` and `source`. Free.

NameTypeReqDescription
descriptionstring–Replaces the template description.
enginestring–Engine for the new version. Inherited from the previous version when omitted.
example––A payload that renders correctly under the new version. Inherited when omitted.
expected_pagesinteger–How many PDF pages a typical payload renders. Inherited from the previous version when omitted. This is the estimate the free tier and the spend cap are checked against before the render starts, so a…
messagestring–Change note for this version, like a commit message.
optionsobject–Default render options. Inherited from the previous version when omitted.
schemaobject–JSON Schema for the `data` payload. Inherited from the previous version when omitted — send `{}` only if you really want a version that validates nothing.
sourcestringyesOne self-contained HTML document with inline CSS and Liquid expressions (`{{ customer.name }}`, `{% for line in line_items %}`). No file includes: everything the render needs must be in this string,…
templatestringyesName of an existing template. A new immutable version is published; earlier versions keep rendering, so anything pinned to `name@2` is unaffected.

No output schema declared.

No examples provided.

upgrade ~462

Get a Stripe Checkout link for a paid plan, for a human to open. **This tool cannot subscribe anybody.** It returns a `url`; a person has to open it and enter a card on Stripe's own page. Hand the URL to the human you are working for and say what it costs. Nothing is charged, and no plan changes, until they finish on that page — at which point Stripe tells Galley and the new plan is live within a second or two. Confirm with `usage`. Use it when a render was refused with `quota_exceeded`, or with `plan_required` because the account is on Free and asked for webhooks or cloud delivery. The error body names the plan that would have worked. The account needs a verified email address first — invoices and receipts go to it — so call `create_account` before this if you are on the keyless trial. Changing or cancelling an existing plan is `billing_portal`, never this. Free. **If billing is not enabled on the deployment this is pointed at, the call is refused with `billing_unavailable` (503) rather than answered with a link.** That is deliberate: the alternative is a URL on a domain that does not resolve, which you cannot tell apart from a real one. On that error, say so and point the human at https://galleyrender.com/pricing. Do not construct a checkout URL yourself and do not retry.

NameTypeReqDescription
intervalstring–Billing interval. Default `month`. `year` is ten months for twelve on every plan.
planstringyesWhich paid plan to subscribe to. Solo $5/mo (200 PDF pages or 500 images, webhooks, cloud delivery), Starter $19/mo (2,000 PDF pages or 5,000 images), Growth $79/mo (12,000 PDF pages or 30,000 images…

No output schema declared.

No examples provided.

usage ~71

What this account has spent this period and what is left: renders, billable units by format, cost, the free-tier allowance, the monthly spend cap and — on a keyless trial — how much of the trial's 10 PDF pages or 10 images remains. Check it before a large batch. Free.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

validate_data ~156

Dry-run a `data` payload against a template's JSON Schema and get back exactly the errors a render would raise — field path, expected type, what was received and a value that would be accepted. Costs nothing and renders nothing. Use it before a batch, or whenever you are assembling a payload from somewhere you do not control.

NameTypeReqDescription
data–yesThe payload you intend to render. Checked against the template's JSON Schema and nothing else.
templatestringyesTemplate to use: `invoice` for the latest version, or `invoice@3` to pin version 3. Pin the version in anything you ship — a new version changes the output and the cache key. Call list_templates to s…

No output schema declared.

No examples provided.

whoami ~162

The account this connection is acting on: its id, its plan, how many PDF pages or images its trial or free tier has left (`renders_remaining`, one per page or image), and — the part no other tool answers — **how this request authenticated**: `header` (a key on the HTTP connection), `binding` (this client was linked with `link_account`), or `trial` (the keyless trial). Call it before a batch, and call it the moment anything about quota surprises you. A `quota_exceeded` that quotes a limit you do not recognise almost always means `trial`: the key never reached this server, and the renders are coming out of a throwaway account rather than yours. Free, and it renders nothing.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the Galley Render MCP server?

Galley Render is an MCP server listed in the public MCP registry as com.galleyrender/galley-render. JSON in, PDF out. Render invoices, certificates, reports and cards from a template and a payload. This page covers its hosted endpoint (https://mcp.galleyrender.com/mcp).

Is the Galley Render MCP server safe to use?

Galley Render scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Galley Render MCP server expose?

Galley Render exposes 16 tools: list_templates, get_template, create_template, update_template, validate_data, and 11 more. Their descriptions and schemas cost roughly 4,502 tokens of context every time the server is loaded.

Does the Galley Render MCP server require authentication?

No. We connected to Galley Render without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Galley Render MCP server still maintained?

Galley Render is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.