# PostalForm (remote · postalform.com)

Create mail drafts, upload PDFs, browse forms, track orders, and pay via MPP or x402.

- Trust score: 64/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `postalform.com`: 64/100 (this document), [markdown](https://verifymcp.io/servers/com-postalform-postalform/postalform.md), [page](https://verifymcp.io/servers/com-postalform-postalform/postalform)

## Channel facts

- Endpoint: `https://postalform.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 74/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 37/100
  - 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 3321 tokens (~237/item across 14 items; 13 tools + 1 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 7/100
  - Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 84/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 44% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
  - Supports UI / widget rendering.

## Install

### How do I install the PostalForm MCP server?

PostalForm is a hosted endpoint at https://postalform.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-postalform-postalform 'https://postalform.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-postalform-postalform": {
      "url": "https://postalform.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-postalform-postalform": {
      "type": "http",
      "url": "https://postalform.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-postalform-postalform]
url = "https://postalform.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-postalform-postalform": {
      "type": "remote",
      "url": "https://postalform.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-postalform-postalform --url 'https://postalform.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-postalform-postalform:
    url: "https://postalform.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-postalform-postalform": {
      "Transport": "http",
      "Url": "https://postalform.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-postalform-postalform -t streamable-http -u 'https://postalform.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-postalform-postalform": {
      "type": "http",
      "url": "https://postalform.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-28 (score 63, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 63)

First indexed and scored.

## MCP tools (13)

### `postalform.list_forms` (~77 tokens)

List available forms

Use this when you need the published single-mailpiece PostalForm workflow catalog available to agents. Coordinated statutory multi-recipient workflows are excluded.

Input parameters:

- `cursor` (string): Pagination cursor (opaque string).
- `limit` (integer): Max results (default 50).
- `q` (string): Optional search query (matches slug/name).

Output parameters:

- `forms` (array)
- `next_cursor`

### `postalform.get_form_schema` (~56 tokens)

Get form schema

Use this when you need a machine-usable schema for one supported single-mailpiece PostalForm workflow (fields, groups, attachments, and dependencies).

Input parameters:

- `slug` (string, required): Workflow slug (e.g. "8822").

Output parameters:

- `agent_summary` (string)
- `aliases` (array)
- `attachments` (array)
- `attachments_max_total_size_mb` (number)
- `bulk_form`
- `category` (string)
- `certified_mail` (string)
- `checkout_flow` (string)
- `compliance_policy`
- `data_collected` (array)
- `deadline_helper`
- `description` (string)
- `fields` (array)
- `form_summary` (string)
- `groups` (array)
- `indexable` (boolean)
- `llms` (boolean)
- `multi_recipient`
- `name` (string)
- `pricing` (object)
- `publish_state` (string)
- `published_at` (string)
- `recipient` (object)
- `recipient_presets`
- `recipient_rules`
- `schema_version` (integer)
- `slug` (string)
- `topics` (array)
- `updated_at` (string)
- `workflow_version` (integer)

### `postalform.search_addresses` (~159 tokens)

Search mailing addresses

Use this to search for a mailing address and return Loqate suggestions with IDs. Pass country_code to filter by country; it defaults to US. If a suggestion has type "Container" (building/complex), call this tool again with container=<id> and a refined query to drill down to type "Address". Only type "Address" is valid for order creation.

Input parameters:

- `container` (string): Loqate container id for drilling into suggestions, if provided
- `country_code` (string): Two-letter country code to filter suggestions. Defaults to US.
- `query` (string, required): Partial address text, e.g. "123 Main St"
- `target` (string): Which address field is being searched (used for UI context).

Output parameters:

- `query` (string)
- `suggestions` (array)
- `target` (string)
- `view` (string)

### `postalform.create_pdf_upload` (~119 tokens)

Create a PDF upload

Use this when the host cannot provide a PDF file param directly. It creates a short-lived PDF upload URL and upload token (multipart/form-data, file field). Let the HTTP client generate Content-Type with its multipart boundary.

Input parameters:

- `content_length` (integer): Optional content length in bytes.
- `content_type` (string): Optional content type hint (application/pdf).
- `file_name` (string): Optional original file name.
- `request_id` (string): Optional idempotency key. Reuse the same value if retrying the call.

Output parameters:

- `expires_at` (string)
- `max_bytes` (integer)
- `required_headers` (object)
- `upload_token` (string)
- `upload_url` (string)

### `postalform.create_order_draft` (~646 tokens)

Create a mail order draft

Prepare an existing PDF for mailing and return the order ID, total, hosted checkout URL, and checkout session. After buyer approval, a compatible client can pass a Stripe shared payment token to complete_checkout; otherwise present the hosted checkout URL. To prepare for MPP, set payment_protocol=mpp and buyer_email; receive a PDF preview, hosted checkout_url fallback and MPP challenge, then use postalform.pay_order with the order_id after buyer approval. Draft creation never pays. For x402, use postalform.create_machine_order.

Input parameters:

- `buyer_email` (string): Required for MPP receipt delivery.
- `buyer_name` (string): Receipt name; defaults to sender_name for MPP.
- `certified` (boolean): Whether to add proof mail: USPS Certified Mail for US destinations, Canada Post Registered Mail through PostGrid for Canadian destinations, or PinGen registered mail for supported European destinatio…
- `certified_return_receipt` (boolean): Add Electronic Return Receipt for US Certified Mail. Ignored for Canada Post Registered Mail and PinGen registered-mail destinations (default: false).
- `color` (boolean): Whether to print in color (default: false).
- `double_sided` (boolean): Whether to print double-sided (default: true).
- `file_name` (string): Optional display file name.
- `mail_class` (string): Mail service level (standard, priority, express).
- `payment_protocol` (string): Optional payment path. Defaults to hosted checkout. Choose mpp to return a payment challenge for this same prepared order; buyer_email is required. Draft creation never pays.
- `pdf` (required): The PDF to mail. Accepts attachment objects ({ download_url, file_id }). Fallbacks: upload_token from postalform.create_pdf_upload, data:application/pdf;base64,..., or a public HTTPS download URL.
- `recipient_address_id` (string): Loqate address id for the recipient (required when recipient_address_type is Address).
- `recipient_address_manual` (object): Recipient manual address fields (required when recipient_address_type is Manual).
- `recipient_address_text` (string): Human-readable recipient address preview (required when recipient_address_type is Address; optional for Manual).
- `recipient_address_type` (string, required): Address suggestion type for the recipient (from postalform.search_addresses). Use Manual to pass a structured address with countryCode when outside the US.
- `recipient_name` (string, required): Recipient's name.
- `request_id` (string): Optional idempotency key. Reuse the same value if retrying the call.
- `sender_address_id` (string): Loqate address id for the sender (required when sender_address_type is Address).
- `sender_address_manual` (object): Sender manual address fields (required when sender_address_type is Manual).
- `sender_address_text` (string): Human-readable sender address preview (required when sender_address_type is Address; optional for Manual).
- `sender_address_type` (string, required): Address suggestion type for the sender (from postalform.search_addresses). Use Manual to pass a structured address with countryCode when outside the US.
- `sender_name` (string, required): Sender's name (return address).

Output parameters:

- `checkout_session` (object)
- `checkout_url`
- `order_id` (string)
- `page_count`
- `payment` (object)
- `payment_protocol` (string)
- `preview_url`
- `price_usd`
- `recipient_address_text` (string)
- `recipient_name` (string)
- `sender_address_text` (string)
- `sender_name` (string)
- `view` (string)

### `postalform.preview_letter_order_draft` (~193 tokens)

Preview a mail order draft from letter text

Use this to prepare a non-writing preview for a mailed letter before creating checkout. It renders the letter, validates the addresses, and returns a widget with a create-draft action.

Input parameters:

- `certified` (boolean)
- `certified_return_receipt` (boolean)
- `color` (boolean)
- `double_sided` (boolean)
- `letter` (object, required)
- `mail_class` (string)
- `recipient_address_id` (string)
- `recipient_address_manual` (object)
- `recipient_address_text` (string)
- `recipient_address_type` (string, required)
- `recipient_name` (string, required)
- `request_id` (string)
- `sender_address_id` (string)
- `sender_address_manual` (object)
- `sender_address_text` (string)
- `sender_address_type` (string, required)
- `sender_name` (string, required)

Output parameters:

- `draft_request` (object)
- `page_count` (integer)
- `price_usd` (number)
- `recipient_address_text` (string)
- `recipient_name` (string)
- `sender_address_text` (string)
- `sender_name` (string)
- `view` (string)

### `postalform.create_letter_order_draft` (~356 tokens)

Create a mail order draft from letter text

Prepare letter text for mailing and return the order ID, total, hosted checkout URL, and checkout session. Accepts text directly; no PDF upload or browser is needed. Letter drafts may include typed or drawn signatures. After buyer approval, a compatible client can use complete_checkout with a Stripe shared payment token; otherwise present the hosted checkout URL. To prepare for MPP, set payment_protocol=mpp and buyer_email; receive a PDF preview, hosted checkout_url fallback and MPP challenge, then use postalform.pay_order with the order_id after buyer approval. Draft creation never pays. For x402, use postalform.create_machine_order.

Input parameters:

- `buyer_email` (string): Required for MPP receipt delivery.
- `buyer_name` (string): Receipt name; defaults to sender_name for MPP.
- `certified` (boolean)
- `certified_return_receipt` (boolean)
- `color` (boolean)
- `double_sided` (boolean)
- `letter` (object, required)
- `mail_class` (string)
- `payment_protocol` (string): Optional payment path. Defaults to hosted checkout. Choose mpp to return a payment challenge for this same prepared order; buyer_email is required. Draft creation never pays.
- `recipient_address_id` (string)
- `recipient_address_manual` (object)
- `recipient_address_text` (string)
- `recipient_address_type` (string, required)
- `recipient_name` (string, required)
- `request_id` (string)
- `sender_address_id` (string)
- `sender_address_manual` (object)
- `sender_address_text` (string)
- `sender_address_type` (string, required)
- `sender_name` (string, required)

Output parameters:

- `checkout_session` (object)
- `checkout_url`
- `order_id` (string)
- `page_count`
- `payment` (object)
- `payment_protocol` (string)
- `preview_url`
- `price_usd`
- `recipient_address_text` (string)
- `recipient_name` (string)
- `sender_address_text` (string)
- `sender_name` (string)
- `view` (string)

### `postalform.create_form_order_draft` (~378 tokens)

Create a mail order draft from a workflow form submission

Prepare a supported workflow form for mailing and return the order ID, total, hosted checkout URL, and checkout session. After buyer approval, a compatible client can use complete_checkout with a Stripe shared payment token; otherwise present the hosted checkout URL. To prepare for MPP, set payment_protocol=mpp and buyer_email; receive a PDF preview, hosted checkout_url fallback and MPP challenge, then use postalform.pay_order with the order_id after buyer approval. Draft creation never pays. For x402, use postalform.create_machine_order.

Input parameters:

- `attachments` (array)
- `buyer_email` (string): Required for MPP receipt delivery.
- `buyer_name` (string): Receipt name; defaults to sender_name for MPP.
- `certified` (boolean)
- `certified_return_receipt` (boolean)
- `color` (boolean)
- `double_sided` (boolean)
- `fields` (object)
- `mail_class` (string)
- `payment_protocol` (string): Optional payment path. Defaults to hosted checkout. Choose mpp to return a payment challenge for this same prepared order; buyer_email is required. Draft creation never pays.
- `recipient_address_id` (string)
- `recipient_address_manual` (object)
- `recipient_address_text` (string)
- `recipient_address_type` (string)
- `recipient_name` (string)
- `request_id` (string)
- `sender_address_id` (string)
- `sender_address_manual` (object)
- `sender_address_text` (string)
- `sender_address_type` (string, required)
- `sender_name` (string, required)
- `slug` (string, required)
- `use_workflow_recipient` (boolean): Deprecated compatibility field. Predefined and computed workflow recipients are always enforced and cannot be overridden.

Output parameters:

- `checkout_session` (object)
- `checkout_url`
- `order_id` (string)
- `page_count`
- `payment` (object)
- `payment_protocol` (string)
- `preview_url`
- `price_usd`
- `recipient_address_text` (string)
- `recipient_name` (string)
- `sender_address_text` (string)
- `sender_name` (string)
- `view` (string)

### `postalform.create_machine_order` (~683 tokens)

Create or pay a machine order

Create a single PDF, letter, workflow-form order, or bulk letter campaign and pay through MPP or x402 after buyer approval. For bulk, provide exactly one of bulk.csv_content or bulk.recipients (JSON address objects with optional merge_fields), plus a shared PDF or text/HTML template. Omit top-level recipient fields and review campaign_url, recipient count and total. Bulk MPP orders can also use postalform.pay_order after fetching its challenge. The unpaid response also includes checkout_url and status_url for this same order. Without an available compatible wallet, give the buyer checkout_url and poll status_url; never recreate the order to change payment paths. Single-recipient clients with a Stripe shared payment token can instead use a draft tool followed by complete_checkout; other clients should present the hosted checkout URL.

Input parameters:

- `bulk` (object): Bulk letter campaign: exactly one of csv_content or recipients (JSON list), plus shared PDF or text/HTML template. Omit single-recipient fields, letter, form, and postcard options. color and double_s…
- `buyer_email` (string, required): Buyer email for receipts.
- `buyer_name` (string, required): Buyer name for receipts.
- `certified` (boolean)
- `certified_return_receipt` (boolean)
- `color` (boolean)
- `double_sided` (boolean)
- `file_name` (string)
- `form` (object): Workflow form payload from postalform.get_form_schema. Provide exactly one of pdf, letter, or form.
- `letter` (object): Letter text to render and mail. Provide exactly one of pdf, letter, or form. Optional format may be text, html, markdown, or rtf; default is text. Optional signature may be a typed string or drawn si…
- `mail_class` (string)
- `mailpiece_type` (string)
- `payment_authorization` (string): MPP retry value after paying with Link CLI/Link MCP. Pass the full Authorization header value, usually "Payment ...".
- `payment_protocol` (string): Direct machine payment protocol. Use mpp for Link CLI/Link MCP or Stripe SPT; use x402 for x402 wallet clients. Defaults to mpp.
- `payment_signature` (string): x402 retry value after paying the PAYMENT-REQUIRED challenge.
- `pdf`: Existing PDF to mail. For a single recipient, provide exactly one of pdf, letter, or form. For bulk.content_mode=pdf, this PDF is sent to every CSV or JSON recipient. Prefer upload_token from postalf…
- `postcard_size` (string)
- `recipient_address_id` (string)
- `recipient_address_manual` (object)
- `recipient_address_text` (string)
- `recipient_address_type` (string)
- `recipient_name` (string): Required for a single recipient. Omit when bulk supplies the recipient list.
- `request_id` (string): Idempotency key. Reuse the same value and same order fields after a payment challenge.
- `sender_address_id` (string)
- `sender_address_manual` (object)
- `sender_address_text` (string)
- `sender_address_type` (string)
- `sender_name` (string, required)
- `signature_required` (boolean)

Output parameters:

- `bulk` (object)
- `campaign_url` (string)
- `checkout_url`
- `currency`
- `endpoint` (string)
- `is_paid` (boolean)
- `mailpiece_type` (string)
- `next_action` (string)
- `next_step` (string)
- `order_complete_url`
- `order_id` (string)
- `page_count`
- `payment`
- `payment_options` (array)
- `payment_status` (string)
- `postcard_size`
- `preview_url`
- `price_usd`
- `protocol` (string)
- `request_id` (string)
- `status` (string)
- `status_url` (string)
- `view` (string)

### `postalform.pay_order` (~167 tokens)

Pay a prepared order with MPP

Get an MPP challenge or pay an existing MPP PDF, letter, workflow-form order, or bulk letter campaign after buyer approval. Use the order_id returned by any draft tool with payment_protocol=mpp or by create_machine_order. When switching from create_machine_order, omit the credential first to get this payment endpoint’s challenge. Review the preview or campaign_url, recipient count and total. No document or addresses are resubmitted. Without payment_authorization this only returns a challenge; with it, this can pay and send real mail. Reuse the same order_id on retries and follow the returned payment status.

Input parameters:

- `order_id` (string, required)
- `payment_authorization` (string): Buyer-approved MPP Authorization header, usually Payment ... . Omit to retrieve the challenge.

Output parameters:

- `bulk` (object)
- `campaign_url` (string)
- `checkout_url`
- `currency`
- `endpoint` (string)
- `is_paid` (boolean)
- `mailpiece_type` (string)
- `next_action` (string)
- `next_step` (string)
- `order_complete_url`
- `order_id` (string)
- `page_count`
- `payment`
- `payment_options` (array)
- `payment_status` (string)
- `postcard_size`
- `preview_url`
- `price_usd`
- `protocol` (string)
- `request_id` (string)
- `status` (string)
- `status_url` (string)
- `view` (string)

### `complete_checkout` (~133 tokens)

Pay a prepared checkout

After the buyer approves the prepared order and total, pay its existing checkout session using a compatible Stripe payment token, including a shared payment token (spt_...). Pass the order ID as checkout_session_id; do not resend the document or addresses. On an interrupted request, retry the same checkout and token. Existing authorized, processing, or paid payments are reused; follow the returned status and messages.

Input parameters:

- `buyer` (required): Buyer identity details for the approved checkout.
- `checkout_session_id` (string, required): The checkout session id to finalize.
- `payment_data` (object, required): Buyer-authorized payment token details. Use provider=stripe.

Output parameters:

- `buyer` (object)
- `currency` (string)
- `fulfillment_address` (object)
- `fulfillment_option_id` (string)
- `fulfillment_options` (array)
- `id` (string)
- `line_items` (array)
- `links` (array)
- `messages` (array)
- `order` (object)
- `status` (string)
- `totals` (array)

### `postalform.get_order_status` (~101 tokens)

Get order status

Read payment, processing, stored mailing/carrier status, the latest 50 public tracking events, and electronic return receipt availability. Bulk orders also return campaign_url, recipient count and per-status counts; use the campaign dashboard for individual recipients. Missing carrier evidence is null; processing or a tracking number alone does not prove mailing or delivery. This read does not pay, mail, or acquire receipts.

Input parameters:

- `order_id` (string, required): PostalForm order id.

Output parameters:

- `bulk` (object)
- `campaign_url` (string)
- `carrier`
- `checkout_url`
- `current_step`
- `delivery_status`
- `delivery_status_detail`
- `electronic_return_receipt` (object)
- `error`
- `estimated_delivery_at`
- `found` (boolean)
- `is_paid` (boolean)
- `mailing_status`
- `mailing_status_normalized`
- `next_action` (string)
- `order_id` (string)
- `page_count`
- `payment_options` (array)
- `payment_status` (string)
- `signed_by`
- `status_url` (string)
- `tracking_events` (array)
- `tracking_number`
- `tracking_updated_at`
- `view` (string)

### `postalform.ping` (~28 tokens)

Ping PostalForm

Use this when you want a quick health check that the PostalForm MCP server is reachable.

Output parameters:

- `message` (string)
- `title` (string)
- `view` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-postalform-postalform/postalform#diagnostics

## Score history

- 2026-09-29: 64
- 2026-09-28: 63
- 2026-09-27: 63

## Common questions

### What is the PostalForm MCP server?

PostalForm is an MCP server listed in the public MCP registry as com.postalform/postalform. Create mail drafts, upload PDFs, browse forms, track orders, and pay via MPP or x402. This page covers its hosted endpoint (https://postalform.com/mcp).

### Is the PostalForm MCP server safe to use?

PostalForm scores 64 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the PostalForm MCP server expose?

PostalForm exposes 13 tools: postalform.list_forms, postalform.get_form_schema, postalform.search_addresses, postalform.create_pdf_upload, postalform.create_order_draft, and 8 more. Their descriptions and schemas cost roughly 3,096 tokens of context every time the server is loaded.

### Does the PostalForm MCP server require authentication?

No. We connected to PostalForm without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the PostalForm MCP server still maintained?

PostalForm is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://postalform.com/mcp
- Website: https://postalform.com/developers
- Changelog RSS feed: https://verifymcp.io/servers/com-postalform-postalform/postalform.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-postalform-postalform/postalform.json
- HTML version of this page: https://verifymcp.io/servers/com-postalform-postalform/postalform
