SubmitraX
REMOTE · MCP.SUBMITRAX.COM · SCANNED SEP 28
Form backend for static sites: create forms, manage submissions, webhooks and exports.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 57 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 1988 tokens (~34/item across 57 items; 57 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage57
- 82% of tools have a non-trivial description (not blank, and not just the tool's name).Partial
- 6% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 10 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_form" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 57 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
How do I install the SubmitraX MCP server?
SubmitraX is a hosted endpoint at https://mcp.submitrax.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.submitrax.com
claude mcp add --transport http com-submitrax-mcp 'https://mcp.submitrax.com/mcp'
{
"mcpServers": {
"com-submitrax-mcp": {
"url": "https://mcp.submitrax.com/mcp"
}
}
} {
"servers": {
"com-submitrax-mcp": {
"type": "http",
"url": "https://mcp.submitrax.com/mcp"
}
}
} [mcp_servers.com-submitrax-mcp] url = "https://mcp.submitrax.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-submitrax-mcp": {
"type": "remote",
"url": "https://mcp.submitrax.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-submitrax-mcp --url 'https://mcp.submitrax.com/mcp' --transport streamable-http
mcp_servers:
com-submitrax-mcp:
url: "https://mcp.submitrax.com/mcp" {
"McpServers": {
"com-submitrax-mcp": {
"Transport": "http",
"Url": "https://mcp.submitrax.com/mcp"
}
}
} assistant mcp add com-submitrax-mcp -t streamable-http -u 'https://mcp.submitrax.com/mcp'
{
"mcpServers": {
"com-submitrax-mcp": {
"type": "http",
"url": "https://mcp.submitrax.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 53
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://mcp.submitrax.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.submitrax.com | CN=YE2,O=Let's Encrypt,C=US | 22 Sept 2026 | 21 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 55b120b02509c4bfdf54ad76f427eb61250 |
| SANs: mcp.submitrax.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.submitrax.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| submitrax.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.submitrax.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.submitrax.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
accept_invite Accept workspace invite ~33
Accept a pending workspace invitation using its invitation token, linking it to the authenticated user.
| Name | Type | Req | Description |
|---|---|---|---|
| token | string | yes | – |
No output schema declared.
No examples provided.
add_form_webhook Add form webhook ~33
Add a notification webhook URL to a form.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| url | string | yes | – |
No output schema declared.
No examples provided.
bulk_archive_submissions Bulk archive submissions ~15
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| submissionIds | array | yes | – |
No output schema declared.
No examples provided.
bulk_delete_submissions Bulk delete submissions ~15
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| submissionIds | array | yes | – |
No output schema declared.
No examples provided.
bulk_delete_users_admin Bulk delete users (admin) ~29
Delete multiple user accounts at once. Requires super-admin.
| Name | Type | Req | Description |
|---|---|---|---|
| userIds | array | yes | – |
No output schema declared.
No examples provided.
create_checkout_session Create Stripe checkout session ~54
Start a Stripe subscription checkout for a plan ('free', 'essentials', 'pro'). Downgrades immediately if planType is 'free'.
| Name | Type | Req | Description |
|---|---|---|---|
| billingPeriod | string | – | – |
| planType | string | yes | – |
No output schema declared.
No examples provided.
create_export Create submission export ~61
Create a CSV or JSON export of a form's submissions, optionally filtered by date range (YYYY-MM-DD).
| Name | Type | Req | Description |
|---|---|---|---|
| end_date | string | – | – |
| formId | string | yes | – |
| format | string | – | – |
| start_date | string | – | – |
No output schema declared.
No examples provided.
create_form Create form ~53
Create a new form in a workspace.
| Name | Type | Req | Description |
|---|---|---|---|
| custom_html | string | – | – |
| email_to | string | – | Defaults to the authenticated user's email |
| name | string | yes | – |
| workspace_id | string | yes | – |
No output schema declared.
No examples provided.
create_template_admin Create template (admin) ~61
Create a new template. Requires super-admin.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | yes | – |
| description | string | – | – |
| is_default | boolean | – | – |
| name | string | yes | – |
| slug | string | – | – |
| type | string | yes | – |
No output schema declared.
No examples provided.
create_workspace Create workspace ~12
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | – |
No output schema declared.
No examples provided.
delete_all_form_submissions Delete all form submissions ~27
Delete every submission belonging to a form.
| Name | Type | Req | Description |
|---|---|---|---|
| formId | string | yes | – |
No output schema declared.
No examples provided.
delete_form Delete form ~19
Delete a form.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
delete_form_webhook Delete form webhook ~33
Remove a notification webhook URL from a form.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| url | string | yes | – |
No output schema declared.
No examples provided.
delete_submission Delete submission ~12
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
delete_template_admin Delete template (admin) ~24
Delete a template. Requires super-admin.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
delete_user_admin Delete user (admin) ~26
Delete a single user account. Requires super-admin.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
delete_workspace Delete workspace ~33
Delete a workspace along with all its forms and submissions. Only the owner may do this.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
download_export Download export ~43
Download the contents of a previously created export file (CSV or JSON text).
| Name | Type | Req | Description |
|---|---|---|---|
| filename | string | yes | The export filename, as returned by create_export or list_form_exports |
No output schema declared.
No examples provided.
generate_ai_content Generate AI content ~59
Proxy a request to the configured n8n AI generation webhook (e.g. for AI-assisted form/HTML generation). Requires the server to have AI generation configured.
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object | yes | Arbitrary JSON payload forwarded to the AI generation webhook |
No output schema declared.
No examples provided.
generate_workspace_api_token Generate workspace API token ~44
Generate (or reset) a long-lived API token (sk_...) scoped to a single workspace, for use with public API integrations.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_auth_status Get auth status ~21
Check whether an auth token is currently configured for this session.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_current_user Get current user ~18
Get the profile of the currently authenticated user.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_form Get form ~25
Get a single form by id or form key.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_public_form_html Get public form HTML ~41
Fetch the rendered public HTML (custom or default template) for a form by its form key. No authentication required.
| Name | Type | Req | Description |
|---|---|---|---|
| formKey | string | yes | – |
No output schema declared.
No examples provided.
get_workspace Get workspace ~12
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
health_check Health check ~20
Check whether the SubmitraX API is reachable and running.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
invite_workspace_member Invite workspace member ~58
Invite a new member to a workspace by email. Requires admin access to the workspace.
| Name | Type | Req | Description |
|---|---|---|---|
| theirEmail | string | yes | – |
| theirName | string | yes | – |
| workspaceId | string | yes | – |
| yourName | string | yes | – |
No output schema declared.
No examples provided.
list_admin_users List all users (admin) ~37
Paginated list of all users with plan stats. Requires super-admin.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| page | number | – | – |
No output schema declared.
No examples provided.
list_all_templates_admin List all templates (admin) ~42
Paginated list of every template. Requires super-admin.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | – |
| page | number | – | – |
| type | string | – | – |
No output schema declared.
No examples provided.
list_form_exports List form exports ~14
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| formId | string | yes | – |
No output schema declared.
No examples provided.
list_form_submissions List form submissions ~26
List all submissions for a specific form.
| Name | Type | Req | Description |
|---|---|---|---|
| formId | string | yes | – |
No output schema declared.
No examples provided.
list_form_webhooks List form webhooks ~34
List the notification webhook URLs (Slack, Discord, generic) configured on a form.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
list_forms List forms ~34
List forms across the user's workspaces, or within one workspace if workspace_id is given.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace_id | string | – | – |
No output schema declared.
No examples provided.
list_submissions List submissions ~35
List submissions across the user's workspaces, or within one workspace if workspace_id is given.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace_id | string | – | – |
No output schema declared.
No examples provided.
list_templates List default templates ~34
List default templates available to all users, optionally filtered by type ('form' or 'email').
| Name | Type | Req | Description |
|---|---|---|---|
| type | string | – | – |
No output schema declared.
No examples provided.
list_workspace_members List workspace members ~30
List members and pending invitations of a workspace, including its owner.
| Name | Type | Req | Description |
|---|---|---|---|
| workspaceId | string | yes | – |
No output schema declared.
No examples provided.
list_workspaces List workspaces ~21
List workspaces owned by or shared with the authenticated user.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
login Login ~38
Log in with email and password. Stores the returned token for subsequent authenticated tool calls.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | – | |
| password | string | yes | – |
No output schema declared.
No examples provided.
login_with_google Login with Google ~43
Log in or register using a Google Sign-In ID token credential. Stores the returned token for subsequent authenticated tool calls.
| Name | Type | Req | Description |
|---|---|---|---|
| credential | string | yes | Google ID token credential |
No output schema declared.
No examples provided.
mark_submission_read Mark submission as read ~13
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
redeem_voucher Redeem voucher ~38
Redeem a voucher code to add submission quota to a workspace's owner.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | – |
| id | string | yes | – |
No output schema declared.
No examples provided.
register Register ~47
Register a new SubmitraX user account. Stores the returned token for subsequent authenticated tool calls.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | – | |
| name | string | – | – |
| password | string | yes | – |
No output schema declared.
No examples provided.
remove_workspace_member Remove workspace member ~22
No description provided.
| Name | Type | Req | Description |
|---|---|---|---|
| memberId | string | yes | – |
| workspaceId | string | yes | – |
No output schema declared.
No examples provided.
resend_submission_email Resend submission email ~25
Resend the email notification for a submission.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
set_auth_token Set auth token ~50
Set the bearer token (JWT from login/register, or a workspace API token starting with sk_) used to authenticate subsequent tool calls.
| Name | Type | Req | Description |
|---|---|---|---|
| token | string | yes | JWT or workspace API token (sk_...) |
No output schema declared.
No examples provided.
submit_demo Submit demo ~40
Trigger a demo submission email for marketing/demo purposes. No authentication required, rate-limited.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | – | – |
| string | yes | – |
No output schema declared.
No examples provided.
submit_form Submit form ~64
Submit data to a public form endpoint, as an end user would. No authentication required.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | Form field values, e.g. { "name": "Jane", "email": "jane@example.com" } |
| formKey | string | yes | – |
No output schema declared.
No examples provided.
toggle_submission_archived Toggle submission archived ~24
Flip a submission's archived state.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
toggle_submission_spam Toggle submission spam ~24
Flip a submission's spam state.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
update_form Update form ~97
Update a form's settings (name, notification email, Slack webhook, redirect URL, custom HTML, active state, or arbitrary settings).
| Name | Type | Req | Description |
|---|---|---|---|
| custom_html | string | – | – |
| email_to | string | – | – |
| id | string | yes | – |
| is_active | boolean | – | – |
| name | string | – | – |
| redirect_url | string | – | – |
| settings | object | – | – |
| slack_webhook | string | – | – |
No output schema declared.
No examples provided.
What is the SubmitraX MCP server?
SubmitraX is an MCP server listed in the public MCP registry as com.submitrax/mcp. Form backend for static sites: create forms, manage submissions, webhooks and exports. This page covers its hosted endpoint (https://mcp.submitrax.com/mcp).
Is the SubmitraX MCP server safe to use?
SubmitraX scores 53 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the SubmitraX MCP server expose?
SubmitraX exposes 57 tools: set_auth_token, get_auth_status, register, login, login_with_google, and 52 more. Their descriptions and schemas cost roughly 1,988 tokens of context every time the server is loaded.
Does the SubmitraX MCP server require authentication?
No. We connected to SubmitraX without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the SubmitraX MCP server still maintained?
SubmitraX is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.