# Galley Render (remote · mcp.galleyrender.com)

JSON in, PDF out. Render invoices, certificates, reports and cards from a template and a payload.

- Trust score: 68/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

> **Recent critical change**: Authorization (2026-09-18). See the changelog below before you install this server.

## Components

- remote · `mcp.galleyrender.com`: 68/100 (this document), [markdown](https://verifymcp.io/servers/com-galleyrender-galley-render/mcp.md), [page](https://verifymcp.io/servers/com-galleyrender-galley-render/mcp)

## Channel facts

- Endpoint: `https://mcp.galleyrender.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (unlink_account).
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 64/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 5052 tokens (~315/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 40/100
  - Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Galley Render MCP server?

Galley Render is a hosted endpoint at https://mcp.galleyrender.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-galleyrender-galley-render 'https://mcp.galleyrender.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-galleyrender-galley-render": {
      "url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-galleyrender-galley-render": {
      "type": "http",
      "url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-galleyrender-galley-render]
url = "https://mcp.galleyrender.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-galleyrender-galley-render": {
      "type": "remote",
      "url": "https://mcp.galleyrender.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-galleyrender-galley-render --url 'https://mcp.galleyrender.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-galleyrender-galley-render:
    url: "https://mcp.galleyrender.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-galleyrender-galley-render": {
      "Transport": "http",
      "Url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-galleyrender-galley-render -t streamable-http -u 'https://mcp.galleyrender.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-galleyrender-galley-render": {
      "type": "http",
      "url": "https://mcp.galleyrender.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 68, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-25 (score 67, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-23 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-22 (score 65, 0)

- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “create_account” rewrote its description, which is the text the model reads
- [security] Tool “create_template” rewrote its description, which is the text the model reads
- [security] Tool “get_render” rewrote its description, which is the text the model reads
- [security] Tool “link_account” rewrote its description, which is the text the model reads
- [security] Tool “render” rewrote its description, which is the text the model reads
- [security] Tool “unlink_account” rewrote its description, which is the text the model reads
- [security] Tool “usage” rewrote its description, which is the text the model reads
- [security] Tool “whoami” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 280 → 315
- [functional] Server version: 0.1.0 → 0.2.0
- [cosmetic] “upgrade” reworded the description of “plan”

### 2026-09-21 (score 65, 0)

- [security] New tool “rotate_key”, which the server declares destructive
- [security] Tool “create_account” rewrote its description, which is the text the model reads
- [security] Tool “usage” rewrote its description, which is the text the model reads

### 2026-09-20 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 64, +1)

- [critical regression] Authorization: unverified → fail
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] New tool “unlink_account”, which the server declares destructive
- [security] Tool “create_account” rewrote its description, which is the text the model reads
- [security] Tool “render” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 239 → 273
- [functional] New tool “billing_portal”
- [functional] New tool “link_account”
- [functional] New tool “upgrade”
- [functional] New tool “whoami”
- [cosmetic] “create_account” reworded the description of “email”

## MCP tools (16)

### `list_templates` (~65 tokens)

List templates

List the templates on this account, with their latest version number. Start here: rendering needs a template, and this says which ones exist. A brand-new trial account starts with the starter library (invoice, quote, receipt, og-card, certificate and more) already loaded. Free.

### `get_template` (~135 tokens)

Get a template

Fetch one template version: its JSON Schema, its default render options, an example payload and its HTML source. Read the schema before rendering — it is the contract for the `data` argument. Free.

Input parameters:

- `include_source` (boolean): Include the HTML source in the response. Default true. Set false when you only need the schema.
- `template` (string, required): Template to use: `invoice` for the latest version, or `invoice@3` to pin version 3. Pin the version in anything you ship — a new version changes the output and the cache key. Call list_templates to s…

### `create_template` (~563 tokens)

Create a template

Create a new template at version 1 from an HTML document with Liquid expressions, plus a JSON Schema for its data. Use this when nothing in list_templates fits. The name must be free on this account — publishing a change to an existing template is `update_template`, not this. Free, but each plan keeps a limited number of templates of your own (the starter library never counts): at the limit this returns `plan_required` with how many the account has, and `update_template` still works.

Input parameters:

- `description` (string): One line on what this template is for. Shown in list_templates.
- `engine` (string): Rendering engine. `chromium` (default) is full HTML and CSS and is required for PDF. `satori` is a fast PNG path for simple flexbox card layouts — no page breaks, no floats, no external CSS — and cos…
- `example`: A payload that renders correctly. It is echoed back in validation errors, so include one.
- `expected_pages` (integer): How many PDF pages a typical payload renders. Default 1. This is the estimate the free tier and the spend cap are checked against before the render starts, so a template that runs to several pages mu…
- `message` (string): Change note for this version, like a commit message.
- `name` (string, required): Template name: lowercase letters, digits, dot, dash or underscore, 1-63 characters. Unique per account. Versions are separate — do not put `@1` here.
- `options` (object): Render options, merged over the template's own defaults. Options are part of the cache key, so two calls that differ only here are two different renders.
- `schema` (object): JSON Schema (2020-12) for the `data` payload this template accepts. Strongly recommended: it is what turns a bad payload into a field-level error with a path, an expected type and a working example i…
- `source` (string, required): One self-contained HTML document with inline CSS and Liquid expressions (`{{ customer.name }}`, `{% for line in line_items %}`). No file includes: everything the render needs must be in this string,…

### `update_template` (~447 tokens)

Publish a new template version

Publish a new immutable version of an existing template. Versions are never edited in place: `invoice@2` keeps rendering exactly as it did, and anything pinned to it is unaffected. Renders cached against the old version stay valid, and the new version starts with a cold cache. `engine`, `schema`, `options` and `example` are inherited from the previous version unless you send them, so a source-only change needs only `template` and `source`. Free.

Input parameters:

- `description` (string): Replaces the template description.
- `engine` (string): Engine for the new version. Inherited from the previous version when omitted.
- `example`: A payload that renders correctly under the new version. Inherited when omitted.
- `expected_pages` (integer): How many PDF pages a typical payload renders. Inherited from the previous version when omitted. This is the estimate the free tier and the spend cap are checked against before the render starts, so a…
- `message` (string): Change note for this version, like a commit message.
- `options` (object): Default render options. Inherited from the previous version when omitted.
- `schema` (object): JSON Schema for the `data` payload. Inherited from the previous version when omitted — send `{}` only if you really want a version that validates nothing.
- `source` (string, required): One self-contained HTML document with inline CSS and Liquid expressions (`{{ customer.name }}`, `{% for line in line_items %}`). No file includes: everything the render needs must be in this string,…
- `template` (string, required): Name of an existing template. A new immutable version is published; earlier versions keep rendering, so anything pinned to `name@2` is unaffected.

### `validate_data` (~156 tokens)

Validate a payload against a template

Dry-run a `data` payload against a template's JSON Schema and get back exactly the errors a render would raise — field path, expected type, what was received and a value that would be accepted. Costs nothing and renders nothing. Use it before a batch, or whenever you are assembling a payload from somewhere you do not control.

Input parameters:

- `data` (required): The payload you intend to render. Checked against the template's JSON Schema and nothing else.
- `template` (string, required): Template to use: `invoice` for the latest version, or `invoice@3` to pin version 3. Pin the version in anything you ship — a new version changes the output and the cache key. Call list_templates to s…

### `render` (~404 tokens)

Render a document

Render a template plus a JSON payload into a PDF, PNG or JPG and return a signed URL. This is the one tool most calls need.

Small jobs finish inside the call and come back `status: "succeeded"` with a `url` you can hand straight to a user. Anything with a `webhook_url`, `async: true` or a large payload comes back `status: "queued"` with an id for get_render.

Renders are deterministic and cached: the same template version, data and options return the stored object with `cached: true`, free and instant. Billing is per PNG or JPG and per PDF page; cache hits are never billed.

No API key needed to start — the first call mints a trial of 10 PDF pages or 10 images and returns its token.

Input parameters:

- `async` (boolean): Force the queued path even for a small job. Default false: small jobs finish inside the call and come back with a URL already.
- `data` (required): The JSON payload for the template, matching its schema. Call get_template for the schema, or validate_data to dry-run a payload for free.
- `format` (string): Output format. Defaults to `pdf` for chromium templates and `png` for satori ones. `webp` is not supported in v1.
- `options` (object): Render options, merged over the template's own defaults. Options are part of the cache key, so two calls that differ only here are two different renders.
- `template` (string, required): Template to use: `invoice` for the latest version, or `invoice@3` to pin version 3. Pin the version in anything you ship — a new version changes the output and the cache key. Call list_templates to s…
- `webhook_url` (string): Absolute https URL to POST the finished render to. Supplying one forces the queued path: the call returns immediately with status `queued`.

### `get_render` (~141 tokens)

Get a render

Fetch a render by id: its status, and a freshly signed URL once it has succeeded. Use it to poll a queued render, or to re-sign a URL that has expired — signed URLs last an hour, the stored file lasts until the render's `expires_at` (the plan's retention). Past `expires_at` the file is deleted and this returns `retention_expired` (410) with the render and the template version to render again. Free, and never re-renders.

Input parameters:

- `render_id` (string, required): Render id from a previous render call, e.g. `rnd_…`. Returns the status and a fresh signed URL.

### `list_renders` (~74 tokens)

List recent renders

Recent renders on this account, newest first, with status, template version and a signed URL for each that succeeded. Useful for finding a render whose id you lost, or checking what a batch did. Free.

Input parameters:

- `limit` (integer): How many to return, newest first. 1-100, default 25.

### `usage` (~71 tokens)

Usage and limits

What this account has spent this period and what is left: renders, billable units by format, cost, the free-tier allowance, the monthly spend cap and — on a keyless trial — how much of the trial's 10 PDF pages or 10 images remains. Check it before a large batch. Free.

### `upgrade` (~462 tokens)

Upgrade to a paid plan

Get a Stripe Checkout link for a paid plan, for a human to open.

\**This tool cannot subscribe anybody.** It returns a `url`; a person has to open it and enter a card on Stripe's own page. Hand the URL to the human you are working for and say what it costs. Nothing is charged, and no plan changes, until they finish on that page — at which point Stripe tells Galley and the new plan is live within a second or two. Confirm with `usage`.

Use it when a render was refused with `quota_exceeded`, or with `plan_required` because the account is on Free and asked for webhooks or cloud delivery. The error body names the plan that would have worked.

The account needs a verified email address first — invoices and receipts go to it — so call `create_account` before this if you are on the keyless trial. Changing or cancelling an existing plan is `billing_portal`, never this. Free.

\**If billing is not enabled on the deployment this is pointed at, the call is refused with `billing_unavailable` (503) rather than answered with a link.** That is deliberate: the alternative is a URL on a domain that does not resolve, which you cannot tell apart from a real one. On that error, say so and point the human at https://galleyrender.com/pricing. Do not construct a checkout URL yourself and do not retry.

Input parameters:

- `interval` (string): Billing interval. Default `month`. `year` is ten months for twelve on every plan.
- `plan` (string, required): Which paid plan to subscribe to. Solo $5/mo (200 PDF pages or 500 images, webhooks, cloud delivery), Starter $19/mo (2,000 PDF pages or 5,000 images), Growth $79/mo (12,000 PDF pages or 30,000 images…

### `billing_portal` (~189 tokens)

Open the billing portal

Get a link to the Stripe customer portal, for a human to open: change plan, update the card, download invoices, or cancel.

This is the only way any of those happen. Galley's API cannot change or cancel a subscription and cannot issue a refund — deliberately — so if you are asked to downgrade or cancel, the answer is this link and a human on the other end of it. The link is single-use and short-lived, so fetch a fresh one rather than storing it.

Only works once the account has subscribed at least once; before that, use `upgrade`. Free.

\**If billing is not enabled on the deployment this is pointed at, the call is refused with `billing_unavailable` (503) rather than answered with a link.** Say so and point the human at support@galleyrender.com. Do not construct a portal URL yourself and do not retry.

### `whoami` (~162 tokens)

Which account am I, and how did I get here

The account this connection is acting on: its id, its plan, how many PDF pages or images its trial or free tier has left (`renders_remaining`, one per page or image), and — the part no other tool answers — **how this request authenticated**: `header` (a key on the HTTP connection), `binding` (this client was linked with `link_account`), or `trial` (the keyless trial).

Call it before a batch, and call it the moment anything about quota surprises you. A `quota_exceeded` that quotes a limit you do not recognise almost always means `trial`: the key never reached this server, and the renders are coming out of a throwaway account rather than yours. Free, and it renders nothing.

### `link_account` (~530 tokens)

Link this client to an existing account

Point this MCP client at an account you already have, so header-less calls from it stop spending the keyless trial.

\**This is for clients that cannot set HTTP headers** — Claude.ai custom connectors and ChatGPT apps. If your client *can* set a header, prefer that: it is per-connection, it is not tied to a network address, and it needs no tool call at all.

\**Only a client with an identity of its own can be linked.** A connector added with the shared URL and no client id is recognised by its IP address and User-Agent, and every user of a hosted connector shares those: they call from their vendor's servers. Linking that would link all of them, so it is refused. Add this server with a personal URL instead — `https://mcp.galleyrender.com/mcp/c/<id>`, with a random `<id>` of your own (https://galleyrender.com/docs/connect makes one) — or send `X-Galley-Client-Id` with at least 128 random bits, then link.

Two ways to prove the account is yours. `api_key`, if you have the key to hand. Or `link_code`, the one-time code mailed to the account's own address — call `create_account` with that address to have one sent, and nobody has to paste a key into a chat window.

Either way the credential is used once, checked, and dropped: what is stored is the account id and a key minted for this client, which `unlink_account` revokes.

\**Whoever has the client id acts as the account.** A personal connector URL or a client id header is a credential once linked: keep it like a key, and `unlink_account` when you are done on a machine that is not yours. Free.

Input parameters:

- `api_key` (string): A Galley API key, starting `glr_sk_`. It is checked against the API and then discarded — the binding that is stored is by account id, and this server keeps no copy of the key. Give either this or `li…
- `link_code` (string): The one-time code mailed to the account's address, like `GLR-4F7K-9QX2`. Ten minutes, one use. Ask for one by calling `create_account` with the address: if it already has an account, a code is what c…

### `unlink_account` (~107 tokens)

Unlink this client from its account

Undo `link_account`. The binding is deleted and the key that was minted for this client is revoked, so the client can no longer reach the account. Your own API key is untouched — this disconnects a client, it does not close an account.

Do this on any machine that is not yours, and whenever a personal connector URL or a client id may have been seen by somebody else. Calls afterwards fall back to the keyless trial. Safe to call when nothing is linked. Free.

### `rotate_key` (~382 tokens)

Mint a new API key and retire the old one

Get a fresh API key for the account this connection is already acting on — the answer to a key that has been lost, leaked, pasted into a chat window, or left on a machine that is not yours.

\**Two calls, on purpose.** `rotate_key({})` mints the new key and shows it **once**; it revokes nothing, so whatever is running on the old key keeps running. Give the new key to the person, wait until they tell you it is saved, then call `rotate_key({ confirm_saved: true, revoke_key_id: "…" })` with the id from `other_live_keys` to kill the old one. Revoking first would take their integration down between the two calls, and revoking without asking would do it without them knowing why.

\**The key is shown once and cannot be recovered.** Hand it over immediately and do not repeat it in any later message, summary, log or file.

Needs a key on the connection or a linked client — it cannot help somebody holding nothing. That case starts at `create_account` with the account's verified address, which mails a one-time code for `link_account`. Free, and it renders nothing.

Input parameters:

- `confirm_saved` (boolean): Leave this off for the first call: it mints the new key and shows it once, and revokes nothing. Set it to `true` — together with `revoke_key_id` — only after the human has told you they have saved th…
- `revoke_key_id` (string): The id of the key to revoke, taken from `other_live_keys` in the first call's answer. Required with `confirm_saved`. Never guess one: revoking the wrong key takes down whatever was using it.

### `create_account` (~614 tokens)

Create an account and get an API key

Turn the keyless trial into a real account and get a permanent API key.

Call it once with an email. A link is mailed to that address and the tool returns `status: "pending_verification"` with a four-character `request_code`. **Tell the person the code.** The link opens a page that names who asked, when, and the code, and nothing happens until the person answers it: they confirm the request only if it shows the code you gave them. After they confirm, call this again with the same email, from this same client, and it returns the API key, once. The key goes only to the client whose request was confirmed, and that client is then bound to the account, so a connector that cannot send headers is connected from then on.

\**A client with no identity of its own can't be handed the key** (`can_receive_key: false`). That is any client that sent no key and no client id — every hosted connector added with the shared URL, because they all call from their vendor's servers. Its person verifies the address on the page and sees the key there, once. To use the account from such a connector afterwards, add it with a personal URL (`https://mcp.galleyrender.com/mcp/c/<id>`).

If the person says the request wasn't theirs, it is cancelled, this returns `status: "declined"`, and the address can't be asked about again from this client for a day.

\**If that address already has an account, no second one is made, and no key comes back.** You get `status: "existing_account"`, `verified: false`, `existing_account: true`, and a one-time code in the post — hand that code to `link_account` and this client is connected to the account that already exists. Use this rather than inventing a second address: two accounts means two free tiers and two sets of templates, and the renders anyone is waiting for are on the first one. A key on the connection changes this only if it is a live key for that same account.

When the person confirms this client's request, this client's trial is upgraded in place, so te…

Input parameters:

- `email` (string, required): Where to send the verification link. Use the address of the person who owns this project — not a made-up one; the key is only released after the link is clicked. If this address already has a Galley…
- `name` (string): Account name. Defaults to the local part of the email.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-galleyrender-galley-render/mcp#diagnostics

## Score history

- 2026-09-28: 68
- 2026-09-27: 68
- 2026-09-26: 67
- 2026-09-25: 67
- 2026-09-24: 66
- 2026-09-23: 66
- 2026-09-22: 65
- 2026-09-21: 65
- 2026-09-20: 65
- 2026-09-19: 64
- 2026-09-18: 64
- 2026-09-17: 63
- 2026-09-16: 63

## Common questions

### What is the Galley Render MCP server?

Galley Render is an MCP server listed in the public MCP registry as com.galleyrender/galley-render. JSON in, PDF out. Render invoices, certificates, reports and cards from a template and a payload. This page covers its hosted endpoint (https://mcp.galleyrender.com/mcp).

### Is the Galley Render MCP server safe to use?

Galley Render scores 68 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Galley Render MCP server expose?

Galley Render exposes 16 tools: list_templates, get_template, create_template, update_template, validate_data, and 11 more. Their descriptions and schemas cost roughly 4,502 tokens of context every time the server is loaded.

### Does the Galley Render MCP server require authentication?

No. We connected to Galley Render without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Galley Render MCP server still maintained?

Galley Render is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.galleyrender.com/mcp
- Website: https://galleyrender.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-galleyrender-galley-render/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-galleyrender-galley-render/mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-galleyrender-galley-render/mcp
