# ShipMyForm (remote · shipmyform.com)

Create form endpoints for any site, get paste-ready markup, and read submission stats.

- Trust score: 61/100 (medium)
- Change this week: +28
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-30

## Components

- remote · `shipmyform.com`: 61/100 (this document), [markdown](https://verifymcp.io/servers/com-shipmyform-shipmyform/api-mcp.md), [page](https://verifymcp.io/servers/com-shipmyform-shipmyform/api-mcp)

## Channel facts

- Endpoint: `https://shipmyform.com/api/mcp`
- Transports: `streamable-http`
- Auth: `required`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-30.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 29 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 2017 tokens (~69/item across 29 items; 29 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 77/100
  - 90% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 52% of tool parameters carry a description.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "revoke_api_key" implies "revoke" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 30 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

**Unverified: 1 category.** A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the ShipMyForm MCP server?

ShipMyForm is a hosted endpoint at https://shipmyform.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-shipmyform-shipmyform 'https://shipmyform.com/api/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-shipmyform-shipmyform": {
      "url": "https://shipmyform.com/api/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-shipmyform-shipmyform": {
      "type": "http",
      "url": "https://shipmyform.com/api/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-shipmyform-shipmyform]
url = "https://shipmyform.com/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-shipmyform-shipmyform": {
      "type": "remote",
      "url": "https://shipmyform.com/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-shipmyform-shipmyform --url 'https://shipmyform.com/api/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-shipmyform-shipmyform:
    url: "https://shipmyform.com/api/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-shipmyform-shipmyform": {
      "Transport": "http",
      "Url": "https://shipmyform.com/api/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-shipmyform-shipmyform -t streamable-http -u 'https://shipmyform.com/api/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-shipmyform-shipmyform": {
      "type": "http",
      "url": "https://shipmyform.com/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-30 (score 61, +28)

- [security regression] Authorization: fail → unverified
- [security improvement] Transport: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [functional improvement] Tool coverage: unverified → 90
- [functional improvement] MCP protocol: unverified → pass
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: 0
- [functional] First check of Schema quality: pass
- [functional] First check of Tool coverage: 52
- [functional] First check of Schema quality: good

### 2026-09-28 (score 33, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 33, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-21 (score 33)

First indexed and scored.

## MCP tools (29)

### `sign_up` (~169 tokens)

Create an account

Start a ShipMyForm account from an email address, with no browser. A 6-digit code is emailed to the address; verify_account with { email, code } then returns the API key. Works without authentication. Also works for an existing account (the code approves API access).

Input parameters:

- `agent` (string): Your name, e.g. 'Claude Code', shown in the verification email.
- `email` (string, required): The user's email address. Ask for it; never invent one.
- `preset` (string): Named scope bundle: full (everything), wiring (forms only, no submission access), readonly, triage
- `scopes` (array): Explicit scopes, instead of a preset. Ignored where it would exceed the calling key's own scopes.
- `workspaceName` (string)

### `verify_account` (~135 tokens)

Verify the account email

Prove the address with the 6-digit code emailed by sign_up. Without a key on the connection, pass the email too: on success this returns the API key (shown once). Turns on email notifications.

Input parameters:

- `agent` (string)
- `code` (string, required)
- `email` (string): Required when not yet connected with a key
- `preset` (string): Named scope bundle: full (everything), wiring (forms only, no submission access), readonly, triage
- `scopes` (array): Explicit scopes, instead of a preset. Ignored where it would exceed the calling key's own scopes.

### `resend_verification_code` (~24 tokens)

Resend the verification code

Email a fresh 6-digit verification code to the account's address.

### `get_account` (~25 tokens)

Get account

The account's email, verification state, plan, limits, usage and dashboard URL.

### `create_api_key` (~115 tokens)

Create an API key

Mint another API key for this workspace (shown once), optionally narrower than this one. A key can never grant scopes it does not itself hold, so this is the safe way to hand a limited key to another agent.

Input parameters:

- `name` (string, required)
- `preset` (string): Named scope bundle: full (everything), wiring (forms only, no submission access), readonly, triage
- `scopes` (array): Explicit scopes, instead of a preset. Ignored where it would exceed the calling key's own scopes.

### `list_api_keys` (~18 tokens)

List API keys

API keys on this workspace (metadata only).

### `revoke_api_key` (~35 tokens)

Revoke an API key

Revoke a key by id. The key in use on this connection cannot revoke itself.

Input parameters:

- `keyId` (string, required)

### `start_upgrade` (~55 tokens)

Start a paid plan

Get a hosted checkout URL for the Starter or Pro plan. Payment is completed by a person on that page; the plan activates automatically afterwards (check with get_account).

Input parameters:

- `period` (string)
- `plan` (string, required)

### `get_billing_portal` (~27 tokens)

Billing portal link

A self-service billing portal URL: change plan, update the card, cancel.

### `list_forms` (~18 tokens)

List forms

The workspace's forms with their public endpoint URLs.

### `create_form` (~100 tokens)

Create a form

Create a form and get its endpoint plus a paste-ready HTML snippet. Email notifications to the account owner are set up automatically. Works on every plan.

Input parameters:

- `allowedDomains` (array): Sites allowed to submit, e.g. ['example.com']. Empty = any.
- `name` (string, required): Human-readable form name, e.g. 'Contact form'
- `purpose` (string): What the form is for, in a sentence. Helps the spam classifier.

### `get_form` (~38 tokens)

Get form

A form's full configuration, connectors and hosted-page status.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123

### `update_form` (~196 tokens)

Update form settings

Change any subset of a form's settings: name, purpose, allowedDomains, redirectUrl, spamMode, active, storeSubmissions, validation rules, blocklist, autoResponder (Pro).

Input parameters:

- `active` (boolean)
- `allowedDomains` (array)
- `autoResponder` (object)
- `blocklist` (array): Emails, @domains or keywords that mark a submission as spam
- `formId` (string, required): Form id, e.g. frm_abc123
- `name` (string)
- `purpose`
- `redirectUrl`: Absolute URL visitors are sent to after submitting
- `spamMode` (string)
- `storeSubmissions` (boolean)
- `validation`: Server-side rules by field, e.g. { "email": { "required": true, "type": "email" }, "message": { "minLength": 10 } }. null clears.

### `delete_form` (~36 tokens)

Delete form

Delete a form; its endpoint stops accepting submissions.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123

### `get_form_snippet` (~61 tokens)

Get form snippet

A copy-paste form snippet for a framework (html, react, vue, or fetch) wired to the form's endpoint.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123
- `framework` (string)

### `get_submission_stats` (~48 tokens)

Get submission stats

Delivered / spam-held / flagged counts for a form, plus workspace quota usage. Works on every plan.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123

### `list_connector_types` (~29 tokens)

List connector types

Every destination submissions can be routed to, with the config fields each needs and which plan it requires.

### `list_connectors` (~39 tokens)

List a form's connectors

Connectors on a form with their status and last error.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123

### `add_connector` (~111 tokens)

Add a connector

Route a form's submissions somewhere: email, webhook, Slack, Discord, Airtable, HubSpot, Telegram and more. Get the config fields from list_connector_types. OAuth connectors (Google Sheets, Notion) must be added in the dashboard.

Input parameters:

- `config` (object, required): Field values keyed by the config field names
- `formId` (string, required): Form id, e.g. frm_abc123
- `type` (string, required): Connector type from list_connector_types, e.g. 'slack'

### `test_connector` (~28 tokens)

Test a connector

Send a test delivery through a connector and report the result.

Input parameters:

- `connectorId` (string, required)

### `set_connector_active` (~21 tokens)

Enable or disable a connector

Input parameters:

- `active` (boolean, required)
- `connectorId` (string, required)

### `remove_connector` (~13 tokens)

Remove a connector

Input parameters:

- `connectorId` (string, required)

### `publish_hosted_page` (~70 tokens)

Publish a hosted form page

Publish a standalone page for the form on shipmyform.com (no website needed) and get its URL plus an embed script. Uses the designed page if one exists, otherwise a default email + message form.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123

### `unpublish_hosted_page` (~26 tokens)

Unpublish the hosted page

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123

### `list_submissions` (~170 tokens)

List submissions

Read submissions across the workspace or for one form, with filters (status, date range, text search, country, attachments, failed deliveries) and paging. Spam is excluded unless status is 'spam'. Requires a paid plan.

Input parameters:

- `countries` (array): ISO 3166 alpha-2 codes
- `deliveryFailed` (boolean)
- `formId` (string): Form id, e.g. frm_abc123
- `hasFiles` (boolean)
- `limit` (integer)
- `offset` (integer)
- `q` (string): Free-text search across field values
- `since` (string): ISO date; received on/after
- `sort` (string)
- `status` (string)
- `until` (string): ISO date; received before

### `get_submission` (~25 tokens)

Get a submission

One submission with spam signals and delivery history.

Input parameters:

- `submissionId` (string, required)

### `label_submissions` (~68 tokens)

Classify submissions

Mark submissions as spam, ok (not spam) or flagged. spam/ok also teach the classifier, so your judgement improves future filtering. This is how you triage in your own environment: list, decide, label.

Input parameters:

- `ids` (array, required)
- `label` (string, required)

### `delete_submissions` (~25 tokens)

Delete submissions

Permanently delete submissions (and their files).

Input parameters:

- `ids` (array, required)

### `export_submissions` (~57 tokens)

Export submissions as CSV

All of a form's submissions (up to 2,000) as CSV text, optionally filtered by status.

Input parameters:

- `formId` (string, required): Form id, e.g. frm_abc123
- `status` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-shipmyform-shipmyform/api-mcp#diagnostics

## Score history

- 2026-09-30: 61
- 2026-09-29: 33
- 2026-09-28: 33
- 2026-09-27: 33
- 2026-09-26: 33
- 2026-09-25: 33
- 2026-09-24: 33
- 2026-09-23: 33
- 2026-09-22: 33
- 2026-09-21: 33

## Common questions

### What is the ShipMyForm MCP server?

ShipMyForm is an MCP server listed in the public MCP registry as com.shipmyform/shipmyform. Create form endpoints for any site, get paste-ready markup, and read submission stats. This page covers its hosted endpoint (https://shipmyform.com/api/mcp).

### Is the ShipMyForm MCP server safe to use?

ShipMyForm scores 61 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the ShipMyForm MCP server expose?

ShipMyForm exposes 29 tools: sign_up, verify_account, resend_verification_code, get_account, create_api_key, and 24 more. Their descriptions and schemas cost roughly 1,782 tokens of context every time the server is loaded.

### Does the ShipMyForm MCP server require authentication?

No. We connected to ShipMyForm without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the ShipMyForm MCP server still maintained?

ShipMyForm is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://shipmyform.com/api/mcp
- Authorisation metadata: https://shipmyform.com/.well-known/oauth-protected-resource/api/mcp
- Website: https://shipmyform.com/docs/mcp
- Changelog RSS feed: https://verifymcp.io/servers/com-shipmyform-shipmyform/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-shipmyform-shipmyform/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-shipmyform-shipmyform/api-mcp
