# SubmitraX (remote · mcp.submitrax.com)

Form backend for static sites: create forms, manage submissions, webhooks and exports.

- Trust score: 53/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `mcp.submitrax.com`: 53/100 (this document), [markdown](https://verifymcp.io/servers/com-submitrax-mcp/mcp.md), [page](https://verifymcp.io/servers/com-submitrax-mcp/mcp)

## Channel facts

- Endpoint: `https://mcp.submitrax.com/mcp`
- Transports: `streamable-http`
- Auth: `required`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 57 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 65/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 1988 tokens (~34/item across 57 items; 57 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 57/100
  - 82% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 6% of tool parameters carry a description.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 10 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_form" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 57 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the SubmitraX MCP server?

SubmitraX is a hosted endpoint at https://mcp.submitrax.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-submitrax-mcp 'https://mcp.submitrax.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-submitrax-mcp": {
      "url": "https://mcp.submitrax.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-submitrax-mcp": {
      "type": "http",
      "url": "https://mcp.submitrax.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-submitrax-mcp]
url = "https://mcp.submitrax.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-submitrax-mcp": {
      "type": "remote",
      "url": "https://mcp.submitrax.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-submitrax-mcp --url 'https://mcp.submitrax.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-submitrax-mcp:
    url: "https://mcp.submitrax.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-submitrax-mcp": {
      "Transport": "http",
      "Url": "https://mcp.submitrax.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-submitrax-mcp -t streamable-http -u 'https://mcp.submitrax.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-submitrax-mcp": {
      "type": "http",
      "url": "https://mcp.submitrax.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 53)

First indexed and scored.

## MCP tools (57)

### `set_auth_token` (~50 tokens)

Set auth token

Set the bearer token (JWT from login/register, or a workspace API token starting with sk_) used to authenticate subsequent tool calls.

Input parameters:

- `token` (string, required): JWT or workspace API token (sk_...)

### `get_auth_status` (~21 tokens)

Get auth status

Check whether an auth token is currently configured for this session.

### `register` (~47 tokens)

Register

Register a new SubmitraX user account. Stores the returned token for subsequent authenticated tool calls.

Input parameters:

- `email` (string, required)
- `name` (string)
- `password` (string, required)

### `login` (~38 tokens)

Login

Log in with email and password. Stores the returned token for subsequent authenticated tool calls.

Input parameters:

- `email` (string, required)
- `password` (string, required)

### `login_with_google` (~43 tokens)

Login with Google

Log in or register using a Google Sign-In ID token credential. Stores the returned token for subsequent authenticated tool calls.

Input parameters:

- `credential` (string, required): Google ID token credential

### `get_current_user` (~18 tokens)

Get current user

Get the profile of the currently authenticated user.

### `accept_invite` (~33 tokens)

Accept workspace invite

Accept a pending workspace invitation using its invitation token, linking it to the authenticated user.

Input parameters:

- `token` (string, required)

### `upgrade_user_plan` (~31 tokens)

Upgrade user plan

Change the authenticated user's plan (defaults to 'pro' if not specified).

Input parameters:

- `plan` (string)

### `get_public_form_html` (~41 tokens)

Get public form HTML

Fetch the rendered public HTML (custom or default template) for a form by its form key. No authentication required.

Input parameters:

- `formKey` (string, required)

### `list_forms` (~34 tokens)

List forms

List forms across the user's workspaces, or within one workspace if workspace_id is given.

Input parameters:

- `workspace_id` (string)

### `create_form` (~53 tokens)

Create form

Create a new form in a workspace.

Input parameters:

- `custom_html` (string)
- `email_to` (string): Defaults to the authenticated user's email
- `name` (string, required)
- `workspace_id` (string, required)

### `get_form` (~25 tokens)

Get form

Get a single form by id or form key.

Input parameters:

- `id` (string, required)

### `update_form` (~97 tokens)

Update form

Update a form's settings (name, notification email, Slack webhook, redirect URL, custom HTML, active state, or arbitrary settings).

Input parameters:

- `custom_html` (string)
- `email_to` (string)
- `id` (string, required)
- `is_active` (boolean)
- `name` (string)
- `redirect_url` (string)
- `settings` (object)
- `slack_webhook` (string)

### `delete_form` (~19 tokens)

Delete form

Delete a form.

Input parameters:

- `id` (string, required)

### `list_form_webhooks` (~34 tokens)

List form webhooks

List the notification webhook URLs (Slack, Discord, generic) configured on a form.

Input parameters:

- `id` (string, required)

### `add_form_webhook` (~33 tokens)

Add form webhook

Add a notification webhook URL to a form.

Input parameters:

- `id` (string, required)
- `url` (string, required)

### `delete_form_webhook` (~33 tokens)

Delete form webhook

Remove a notification webhook URL from a form.

Input parameters:

- `id` (string, required)
- `url` (string, required)

### `submit_form` (~64 tokens)

Submit form

Submit data to a public form endpoint, as an end user would. No authentication required.

Input parameters:

- `data` (object, required): Form field values, e.g. { "name": "Jane", "email": "jane@example.com" }
- `formKey` (string, required)

### `submit_demo` (~40 tokens)

Submit demo

Trigger a demo submission email for marketing/demo purposes. No authentication required, rate-limited.

Input parameters:

- `data` (object)
- `email` (string, required)

### `list_form_submissions` (~26 tokens)

List form submissions

List all submissions for a specific form.

Input parameters:

- `formId` (string, required)

### `list_submissions` (~35 tokens)

List submissions

List submissions across the user's workspaces, or within one workspace if workspace_id is given.

Input parameters:

- `workspace_id` (string)

### `mark_submission_read` (~13 tokens)

Mark submission as read

Input parameters:

- `id` (string, required)

### `toggle_submission_archived` (~24 tokens)

Toggle submission archived

Flip a submission's archived state.

Input parameters:

- `id` (string, required)

### `toggle_submission_spam` (~24 tokens)

Toggle submission spam

Flip a submission's spam state.

Input parameters:

- `id` (string, required)

### `resend_submission_email` (~25 tokens)

Resend submission email

Resend the email notification for a submission.

Input parameters:

- `id` (string, required)

### `delete_submission` (~12 tokens)

Delete submission

Input parameters:

- `id` (string, required)

### `delete_all_form_submissions` (~27 tokens)

Delete all form submissions

Delete every submission belonging to a form.

Input parameters:

- `formId` (string, required)

### `bulk_archive_submissions` (~15 tokens)

Bulk archive submissions

Input parameters:

- `submissionIds` (array, required)

### `bulk_delete_submissions` (~15 tokens)

Bulk delete submissions

Input parameters:

- `submissionIds` (array, required)

### `list_workspaces` (~21 tokens)

List workspaces

List workspaces owned by or shared with the authenticated user.

### `create_workspace` (~12 tokens)

Create workspace

Input parameters:

- `name` (string, required)

### `get_workspace` (~12 tokens)

Get workspace

Input parameters:

- `id` (string, required)

### `update_workspace` (~26 tokens)

Update workspace

Input parameters:

- `id` (string, required)
- `name` (string)
- `settings` (object)

### `delete_workspace` (~33 tokens)

Delete workspace

Delete a workspace along with all its forms and submissions. Only the owner may do this.

Input parameters:

- `id` (string, required)

### `redeem_voucher` (~38 tokens)

Redeem voucher

Redeem a voucher code to add submission quota to a workspace's owner.

Input parameters:

- `code` (string, required)
- `id` (string, required)

### `generate_workspace_api_token` (~44 tokens)

Generate workspace API token

Generate (or reset) a long-lived API token (sk_...) scoped to a single workspace, for use with public API integrations.

Input parameters:

- `id` (string, required)

### `list_workspace_members` (~30 tokens)

List workspace members

List members and pending invitations of a workspace, including its owner.

Input parameters:

- `workspaceId` (string, required)

### `invite_workspace_member` (~58 tokens)

Invite workspace member

Invite a new member to a workspace by email. Requires admin access to the workspace.

Input parameters:

- `theirEmail` (string, required)
- `theirName` (string, required)
- `workspaceId` (string, required)
- `yourName` (string, required)

### `update_member_role` (~29 tokens)

Update member role

Input parameters:

- `memberId` (string, required)
- `role` (string, required)
- `workspaceId` (string, required)

### `remove_workspace_member` (~22 tokens)

Remove workspace member

Input parameters:

- `memberId` (string, required)
- `workspaceId` (string, required)

### `list_templates` (~34 tokens)

List default templates

List default templates available to all users, optionally filtered by type ('form' or 'email').

Input parameters:

- `type` (string)

### `list_all_templates_admin` (~42 tokens)

List all templates (admin)

Paginated list of every template. Requires super-admin.

Input parameters:

- `limit` (number)
- `page` (number)
- `type` (string)

### `create_template_admin` (~61 tokens)

Create template (admin)

Create a new template. Requires super-admin.

Input parameters:

- `content` (string, required)
- `description` (string)
- `is_default` (boolean)
- `name` (string, required)
- `slug` (string)
- `type` (string, required)

### `update_template_admin` (~67 tokens)

Update template (admin)

Update a template. Requires super-admin.

Input parameters:

- `content` (string)
- `description` (string)
- `id` (string, required)
- `is_default` (boolean)
- `name` (string)
- `slug` (string)
- `type` (string)

### `delete_template_admin` (~24 tokens)

Delete template (admin)

Delete a template. Requires super-admin.

Input parameters:

- `id` (string, required)

### `create_checkout_session` (~54 tokens)

Create Stripe checkout session

Start a Stripe subscription checkout for a plan ('free', 'essentials', 'pro'). Downgrades immediately if planType is 'free'.

Input parameters:

- `billingPeriod` (string)
- `planType` (string, required)

### `list_admin_users` (~37 tokens)

List all users (admin)

Paginated list of all users with plan stats. Requires super-admin.

Input parameters:

- `limit` (number)
- `page` (number)

### `update_user_role_admin` (~40 tokens)

Update user admin role

Grant or revoke super-admin status for a user. Requires super-admin.

Input parameters:

- `id` (string, required)
- `is_super_admin` (boolean, required)

### `update_user_plan_admin` (~44 tokens)

Update user plan (admin)

Set a user's plan ('free' or 'pro') and its associated quota. Requires super-admin.

Input parameters:

- `id` (string, required)
- `plan` (string, required)

### `update_user_quota_admin` (~38 tokens)

Update user quota (admin)

Set a user's submission quota directly. Requires super-admin.

Input parameters:

- `id` (string, required)
- `submission_quota` (number, required)

### `delete_user_admin` (~26 tokens)

Delete user (admin)

Delete a single user account. Requires super-admin.

Input parameters:

- `id` (string, required)

### `bulk_delete_users_admin` (~29 tokens)

Bulk delete users (admin)

Delete multiple user accounts at once. Requires super-admin.

Input parameters:

- `userIds` (array, required)

### `generate_ai_content` (~59 tokens)

Generate AI content

Proxy a request to the configured n8n AI generation webhook (e.g. for AI-assisted form/HTML generation). Requires the server to have AI generation configured.

Input parameters:

- `payload` (object, required): Arbitrary JSON payload forwarded to the AI generation webhook

### `create_export` (~61 tokens)

Create submission export

Create a CSV or JSON export of a form's submissions, optionally filtered by date range (YYYY-MM-DD).

Input parameters:

- `end_date` (string)
- `formId` (string, required)
- `format` (string)
- `start_date` (string)

### `list_form_exports` (~14 tokens)

List form exports

Input parameters:

- `formId` (string, required)

### `download_export` (~43 tokens)

Download export

Download the contents of a previously created export file (CSV or JSON text).

Input parameters:

- `filename` (string, required): The export filename, as returned by create_export or list_form_exports

### `health_check` (~20 tokens)

Health check

Check whether the SubmitraX API is reachable and running.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-submitrax-mcp/mcp#diagnostics

## Score history

- 2026-09-28: 53

## Common questions

### What is the SubmitraX MCP server?

SubmitraX is an MCP server listed in the public MCP registry as com.submitrax/mcp. Form backend for static sites: create forms, manage submissions, webhooks and exports. This page covers its hosted endpoint (https://mcp.submitrax.com/mcp).

### Is the SubmitraX MCP server safe to use?

SubmitraX scores 53 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the SubmitraX MCP server expose?

SubmitraX exposes 57 tools: set_auth_token, get_auth_status, register, login, login_with_google, and 52 more. Their descriptions and schemas cost roughly 1,988 tokens of context every time the server is loaded.

### Does the SubmitraX MCP server require authentication?

No. We connected to SubmitraX without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the SubmitraX MCP server still maintained?

SubmitraX is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.submitrax.com/mcp
- Authorisation metadata: https://mcp.submitrax.com/.well-known/oauth-protected-resource/mcp
- Website: https://submitrax.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-submitrax-mcp/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-submitrax-mcp/mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-submitrax-mcp/mcp
