Kamy
REMOTE · MCP.KAMY.DEV · SCANNED SEP 27
Document API for AI-native software: render PDFs, e-sign, PAdES-seal, and verify.
Available components
Recent critical change
Authorization (19 Aug 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (rollback_template). See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 406, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability67
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 14125 tokens (~239/item across 59 items; 59 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 59 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Kamy MCP server?
Kamy is a hosted endpoint at https://mcp.kamy.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.kamy.dev
claude mcp add --transport http dev-kamy-kamy 'https://mcp.kamy.dev/mcp'
{
"mcpServers": {
"dev-kamy-kamy": {
"url": "https://mcp.kamy.dev/mcp"
}
}
} {
"servers": {
"dev-kamy-kamy": {
"type": "http",
"url": "https://mcp.kamy.dev/mcp"
}
}
} [mcp_servers.dev-kamy-kamy] url = "https://mcp.kamy.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-kamy-kamy": {
"type": "remote",
"url": "https://mcp.kamy.dev/mcp",
"enabled": true
}
}
} openclaw mcp add dev-kamy-kamy --url 'https://mcp.kamy.dev/mcp' --transport streamable-http
mcp_servers:
dev-kamy-kamy:
url: "https://mcp.kamy.dev/mcp" {
"McpServers": {
"dev-kamy-kamy": {
"Transport": "http",
"Url": "https://mcp.kamy.dev/mcp"
}
}
} assistant mcp add dev-kamy-kamy -t streamable-http -u 'https://mcp.kamy.dev/mcp'
{
"mcpServers": {
"dev-kamy-kamy": {
"type": "http",
"url": "https://mcp.kamy.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 18 Sept 26 +3
- Stability: fail → pass ▲ security
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 19 Aug 26 0
- Authorization: partial → fail ▼ critical
- Stability: 0.77 → fail ▼ security
- Tool “generate_integration_code” was removed ▼ security
- Tool “get_api_key_instructions” was removed ▼ security
- Tool “install_sdk” was removed ▼ security
- New tool “delete_schedule”, which the server declares destructive security
- New tool “rollback_template”, which the server declares destructive security
- Tool “render_pdf” rewrote its description, which is the text the model reads security
- Tool “verify_pdf_signature” rewrote its description, which is the text the model reads security
- Schema quality: 121 → 239 ▼ functional
- Server version: 1.2.0 → 1.5.0 functional
- New tool “attest_artifact” functional
- New tool “bulk_signature_requests” functional
- New tool “convert_document” functional
- New tool “create_envelope” functional
- New tool “create_schedule” functional
- New tool “create_template” functional
- New tool “create_webhook” functional
- New tool “edit_pdf” functional
- New tool “extract_from_render” functional
- New tool “get_account” functional
- New tool “get_envelope” functional
- New tool “get_job” functional
- New tool “get_provenance_chain” functional
- New tool “get_render” functional
- New tool “get_render_pages” functional
- New tool “get_signature_request” functional
- New tool “get_signature_template” functional
- New tool “get_started” functional
- New tool “get_template_version” functional
- New tool “get_upload” functional
- New tool “list_renders” functional
- New tool “list_schedules” functional
- New tool “list_signature_templates” functional
- New tool “list_template_versions” functional
- New tool “list_webhooks” functional
- New tool “merge_pdfs” functional
- New tool “preview_field_placement” functional
- New tool “publish_template” functional
- New tool “record_agent_action” functional
- New tool “remind_signature” functional
- New tool “render_async” functional
- New tool “render_batch” functional
- New tool “render_docx” functional
- New tool “render_html” functional
- New tool “render_pptx” functional
- New tool “render_xlsx” functional
- New tool “scan_tool_description” functional
- New tool “split_pdf” functional
- New tool “test_webhook” functional
- New tool “trace_record” functional
- New tool “trace_record_batch” functional
- New tool “trace_search” functional
- New tool “update_template” functional
- New tool “upload_file” functional
- New tool “verify_attestation” functional
- New tool “verify_mcp_server” functional
- Tool “verify_pdf_signature” changed its title: Verify PDF signature → Hash a PDF and build its verify URL cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://mcp.kamy.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=kamy.dev | CN=WE1,O=Google Trust Services,C=US | 17 Aug 2026 | 15 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | a70e92a03ce9d95813506d1773ef6fba |
| SANs: kamy.dev, mcp.kamy.dev, *.mcp.kamy.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.kamy.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| kamy.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.kamy.dev/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.kamy.dev/mcp | Inconclusive | 406 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ask_kamy Ask Kamy ~74
Ask Kamy Brain a question about Kamy usage, templates, plans, or errors. Sends the question to Kamy's public assistant endpoint and returns a paragraph answer.
| Name | Type | Req | Description |
|---|---|---|---|
| question | string | yes | The question to ask Kamy about — how to render a template, why a render failed, what plan to pick, etc. |
No output schema declared.
No examples provided.
attest_artifact Attest artifact ~452
Cryptographically sign an output your agent produced — a PDF, report, code patch, dataset, email — so a third party can later confirm those exact bytes are the ones that were recorded, unmodified. Pass content_text or content_base64 and Kamy hashes the bytes for you; pass content_sha256 alone when the content itself must never leave your environment. Returns { attestation_id, content_sha256, signature, recorded_at, verify_url } — hand verify_url to whoever needs to check the artifact. This proves the bytes match what this account recorded at that time; it makes no claim about whether the content is correct. Requires a Kamy API key.
| Name | Type | Req | Description |
|---|---|---|---|
| artifact_type | string | yes | What kind of output this is, e.g. 'pdf', 'report', 'code_patch', 'dataset', 'email', 'llm_output'. Free-form label used for filtering later. |
| content_base64 | string | – | Base64-encoded artifact bytes. Use for binary output (PDF, image, archive). Supply exactly one of content_sha256, content_base64, or content_text. |
| content_sha256 | string | – | SHA-256 of the artifact bytes, when you'd rather not send the content itself. Supply exactly one of content_sha256, content_base64, or content_text. |
| content_text | string | – | UTF-8 text artifact. Convenience input: this MCP server base64-encodes it locally and sends it as content_base64 — no other transformation is applied. Supply exactly one of content_sha256, content_ba… |
| feature | string | – | Product area or pipeline name, for grouping attestations. |
| metadata | object | – | Arbitrary JSON stored alongside the attestation (model, source URL, reviewer, ...). |
| parent_sha256 | – | – | content_sha256 of the preceding record in the chain, when this artifact was derived from an earlier one. |
| run_id | string | – | Your identifier for the agent run this artifact belongs to. Pass the same run_id across attestations and agent-action records to build one provenance chain readable via get_provenance_chain. |
| tags | array | – | Up to 20 free-form labels. |
No output schema declared.
No examples provided.
bulk_signature_requests Send one PDF to many separate signers ~404
Fan one already-rendered PDF out to up to 100 independent signers in a single call — the 'send this NDA to everyone on the list' path. Each signer gets their own request, their own sign link and their own invitation email, but they all share one source render, so only one document is produced and stored. Choose create_envelope instead when the recipients are signing the SAME document together and you need routing, ordering and one envelope status; choose this when they are unrelated parties each signing their own copy. Duplicate signer emails within one batch are rejected up front with 422. Per-signer failures do not abort the batch: the response is { bulkId, count, successCount, failureCount, results } in input order, each row either ok with signatureId and signUrl or ok:false with a reason, and the call returns 207 when any row failed. Consumes one signature from the monthly quota PER signer (free tier: 10 per month, then per-signature billing), so a large batch can exhaust a small plan part-way through and the remaining rows come back failed. Requires a Kamy API key with the `signatures:write` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| expiresIn | integer | – | Sign-link lifetime in seconds. Min 1 hour, max 30 days. Defaults to 7 days. |
| message | string | – | Shared invite message. `{{signerName}}` is substituted per recipient. |
| position | object | – | One signature rectangle in PDF points (origin bottom-left) shared by every signer. |
| reminderCadenceHours | integer | – | Auto-reminder cadence in hours, shared across the batch. Up to 3 reminders. |
| renderId | string | yes | Render UUID every signer receives. One render, one storage object, many requests. |
| signers | array | yes | 1–100 signers. Duplicate emails are rejected up front with 422. |
No output schema declared.
No examples provided.
convert_document Convert file to PDF ~262
Convert a file you already hold — .docx, .xlsx or .csv — into a PDF, preserving its existing content. Pass the bytes base64-encoded together with the original filename, which is what the API uses to detect the input type. This is the inbound direction: it consumes an existing document, whereas render_docx / render_xlsx / render_pptx GENERATE new documents from structured data, and render_pdf builds one from a template. Returns a stored render { id, url, bytes, durationMs, name } whose id can be fed straight into merge_pdfs, split_pdf, edit_pdf, create_signature_request or create_envelope. Counts one render against the monthly quota. Files over 10 MB are refused by this tool because the bytes travel through the tool call. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| fileBase64 | string | yes | Base64-encoded bytes of the source file. |
| filename | string | yes | Source filename including its extension — the route detects the input type from it. Must end in .docx, .xlsx or .csv. |
| name | string | – | Label for the resulting render row. Defaults to the source filename. |
No output schema declared.
No examples provided.
create_envelope Send one PDF to multiple signers ~530
Send a single PDF to 2–10 signers as one envelope. This is the multi-signer counterpart to create_signature_request, which handles exactly one signer — the API rejects an envelope with fewer than two recipients, so pick the tool by signer count. routing 'parallel' (default) emails everyone at once and each signs independently; routing 'sequential' emails only the lowest-order recipient and activates the rest one at a time as each preceding signer finishes, which is what you want for approve-then-countersign chains. The source is either a render you own (renderId) or a PDF fetched from a public URL (pdfUrl) — supply exactly one. Pass preview: true to create the envelope and get every sign URL back WITHOUT sending any email and WITHOUT consuming quota; do that first if you are unsure about field placement. A real send emails the recipients immediately and consumes one signature from the monthly quota PER recipient (free tier: 10 signatures/month, then per-signature billing). Returns { envelope, recipients: [...] } with a sign_url per recipient. Requires a Kamy API key with the `signatures:write` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| ccEmails | array | – | Up to 10 observers CC'd on the invitations. Not signers. |
| expiresIn | integer | – | Sign-link lifetime in seconds. Min 1 hour, max 30 days. |
| message | string | – | Message included in every invitation email. |
| pdfUrl | string | – | Publicly fetchable PDF URL. Kamy downloads it and stores it as a render first. Supply exactly one of renderId or pdfUrl. |
| placedFields | array | – | Up to 100 sender-placed form fields for signers to complete. |
| position | object | – | Default signature placement in PDF points, origin bottom-left. |
| preview | boolean | – | When true, creates the envelope and returns every sign URL WITHOUT emailing anyone and without consuming signature quota. Use it to check placement and routing before the real send. |
| recipients | array | yes | 2–10 signers. The route rejects a single recipient — use create_signature_request for one signer. |
| renderId | string | – | UUID of a completed render owned by this account. Supply exactly one of renderId or pdfUrl. |
| routing | string | – | 'parallel' (default) emails everyone at once and each signs independently. 'sequential' emails only the lowest-order recipient; the rest are created with status 'waiting' and activated one at a time… |
No output schema declared.
No examples provided.
create_schedule Create a schedule ~456
Set up a recurring render: a cron expression, a template, and where each document goes. Use this instead of render_pdf when the user wants a document produced repeatedly on a calendar — a weekly report, a monthly invoice run — so nothing has to stay running. Delivery channel is 'email' or 'whatsapp' (recipients required) or 'download' (stored only; retrieve later with list_renders). The cron is evaluated in the given IANA timezone, and how often it may fire is plan-gated: at least 60 minutes apart on Free, 15 on Starter, 5 on Pro and above — a tighter expression is rejected with a validation error naming the limit. Every firing spends one render from the monthly quota, so a frequent schedule can exhaust a small plan on its own. Returns the created schedule including its id and next_run_at.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | yes | Where each rendered document goes. 'download' just stores it (find it later with list_renders); 'email' and 'whatsapp' require recipients. |
| data | object | – | Template data, used verbatim on every firing. Defaults to {}. |
| enabled | boolean | – | Defaults to true. Create it disabled to set it up now and start it later. |
| name | string | yes | Human label for this schedule, shown in the dashboard. |
| options | object | – | Render options passed straight through to the render, in the nested /v1/render shape, e.g. { format: 'letter', margin: { top: '20mm' } }. |
| recipients | array | – | Email addresses or phone numbers, matching the channel. Required and non-empty for email and whatsapp; ignored for download. |
| schedule | string | yes | Standard 5-field cron expression, e.g. '0 9 * * 1' for 09:00 every Monday. Rejected with a validation error if it fires more often than the plan's minimum interval. |
| template | string | yes | Template slug or UUID rendered on every firing. Same values render_pdf accepts. |
| timezone | string | – | IANA timezone the cron expression is evaluated in, e.g. 'Asia/Dubai'. Defaults to UTC. |
No output schema declared.
No examples provided.
create_signature_request Send for e-signature ~572
Send a previously rendered PDF to a signer for e-signature when a Kamy API key is configured. Without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| authMethod | string | – | Identity-verification mode. `link` (default) — possession of the secret URL is the only check. `email_otp` — sign page renders a 6-digit OTP gate; code emailed to `signerEmail`. `sms_otp` — same gate… |
| ccEmails | array | – | Up to 10 observer addresses CC'd on the invite and the completion notice. Not signers themselves. |
| expiresIn | integer | – | How long (seconds) the sign link stays valid. Defaults to 30 days. Min 1 hour, max 30 days. |
| message | string | – | Optional message rendered in the email invitation body. |
| placedFields | array | – | Up to 100 sender-defined fillable fields stamped onto the PDF at sign time. Use for flat PDFs that don't ship AcroForm widgets. Names must be unique. |
| position | object | – | Optional sender-chosen signature placement in PDF points (72 dpi, origin bottom-left). Defaults to bottom-right of the last page sized 220×64 pt; when omitted, the signer can drag the placeholder on… |
| reminderCadenceHours | integer | – | When set (24–168), the auto-reminder cron resends the invite every N hours while the request stays pending, up to 3 reminders. Omit for no auto-reminders. |
| renderId | string | yes | Render UUID returned by render_pdf or any /v1/render call. The render's PDF is the document the signer will receive. |
| requireStamp | boolean | – | Require the signer to upload a company stamp / seal alongside their personal signature (UAE, KSA, JP, KR, IN, CN B2B workflows). Server refuses to seal without one. |
| signOnEveryPage | boolean | – | When true, the server stamps the signer's signature on every page of the source PDF instead of only the configured position. Common B2B contract pattern. |
| signatureTemplateId | string | – | Apply a signature template's defaults (placedFields, position, message, expiresIn, ccEmails). Request-level fields override the template. |
| signerEmail | string | yes | Recipient email address. |
| signerName | string | yes | Recipient full name. Must be typed verbatim by the signer to confirm intent. |
| signerPhone | string | – | E.164 phone number. Required when `authMethod` is `sms_otp`; ignored otherwise. Example: `+14155551234`. |
No output schema declared.
No examples provided.
create_template Create a template ~348
Create a new custom PDF template owned by this account: a name, a unique slug, a Handlebars/HTML body, and optional CSS and JSON Schema. The slug is what render_pdf then takes as `template`. Custom templates are a paid feature — on the Free plan this returns 403 FORBIDDEN before anything is created. The slug must be unique within the account and must not collide with a built-in system slug (invoice, receipt, quote, …); both cases come back 422, and the fix for an already-taken slug is update_template rather than a retry. A brand-new template has no published version, so it renders straight from what you supply here — publish_template only becomes necessary once you start cutting versions. Requires a Kamy API key with the `templates:write` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| css | string | – | Stylesheet applied at render time. Max 1 MB. |
| description | string | – | What this template is for. |
| html | string | yes | Handlebars/HTML body of the document. Max 5 MB. |
| isPublic | boolean | – | When true, other accounts can list and render it. Defaults to false. |
| name | string | yes | Human-readable template name. |
| schema | object | – | JSON Schema describing the data payload the template expects. Defaults to {}. |
| slug | string | yes | Stable identifier the render tools take as `template`. Unique per account, and it may not collide with a built-in system slug (invoice, receipt, quote, …) — both cases are rejected with 422. |
| tags | array | – | Up to 10 free-form labels. |
No output schema declared.
No examples provided.
create_webhook Create a webhook ~328
Register an HTTPS endpoint that Kamy POSTs to when work finishes, so a long render or an e-signature does not have to be polled. Use this when the caller owns a server that can receive callbacks; use get_job or list_renders when it cannot. The response includes a one-time signing secret used to verify delivery signatures — it is shown here and never again, so surface it to the user immediately and tell them to store it. Defaults to the render.completed and render.failed events; the full set is render.completed, render.failed, signature.signed, signature.voided, signature.expired, signature.envelope_completed, signature.envelope_voided, test.ping, and any other string is accepted so new events can be subscribed to without an upgrade. Endpoint URLs on private, loopback, link-local or cloud-metadata hosts are rejected at registration, so a localhost tunnel will not work — use a public URL.
| Name | Type | Req | Description |
|---|---|---|---|
| enabled | boolean | – | Defaults to true. Register it disabled to wire it up before switching it on. |
| events | array | – | Event names to receive. Defaults to ["render.completed", "render.failed"]. Known events: render.completed, render.failed, signature.signed, signature.voided, signature.expired, signature.envelope_com… |
| url | string | yes | HTTPS endpoint Kamy POSTs each event to. Private, loopback, link-local and cloud-metadata hosts are rejected at registration time, so localhost and 10.x/192.168.x addresses will not work. |
No output schema declared.
No examples provided.
delete_schedule Delete a schedule ~165
Permanently delete a recurring schedule so it stops firing. There is no undo and no trash — recreate it with create_schedule if it is deleted by mistake, so confirm with the user before calling this on a schedule you did not just create. If the intent is only to pause it, do not use this tool: a schedule can be switched off and back on again via its `enabled` flag on the REST endpoint (PATCH /v1/schedules/{id}), which this MCP surface does not expose. Documents already produced by past firings are unaffected and remain available through list_renders. Returns { deleted: true }, or 404 if the id does not belong to this account.
| Name | Type | Req | Description |
|---|---|---|---|
| schedule_id | string | yes | Schedule id (UUID) from create_schedule or list_schedules. |
No output schema declared.
No examples provided.
edit_pdf Edit an existing PDF ~646
Modify an existing PDF: fill AcroForm fields by name, stamp text at absolute coordinates, or paint opaque boxes over regions. Operations apply in the order given, to either a render you own (renderId) or a PDF Kamy downloads from a public URL (pdfUrl) — supply exactly one. Use this when a document already exists and needs values or marks; use render_pdf when the document should be generated from a template instead. Nothing is overwritten: the source is untouched and the result is a NEW render whose id feeds directly into create_signature_request, create_envelope, merge_pdfs or split_pdf. Coordinates are PDF points with the origin at the BOTTOM-left. AcroForm values are flattened by default so they cannot be edited after signing. 'cover' paints an opaque rectangle over the region — it hides content visually but does NOT delete the underlying bytes, and the response carries a COVER_VISUAL_ONLY warning for every cover op. Anyone can still copy the text out from under the box. It is NOT redaction: never use it to hide secrets or personal data in a document you are about to hand out, and do not describe the result as redacted. There is no redaction operation — 'op: redact' is rejected with REDACTION_NOT_SUPPORTED. To remove sensitive data, regenerate the document without it. Returns { id, url, bytes, durationMs, name, warnings } — always read warnings, since out-of-range pages and unmatched field names are reported there rather than failing the call. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| flattenFields | boolean | – | Bake AcroForm values into the page content stream after the fill_field ops so they can no longer be edited. Leave true before e-signing. Pass false only when something downstream still needs the live… |
| name | string | – | Label for the resulting render row. |
| operations | array | yes | 1–200 operations applied in the order given. 'fill_field' writes into an AcroForm widget; 'stamp_text' draws text at an absolute position; 'cover' paints an opaque rectangle over the region — it hide… |
| pdfUrl | string | – | Publicly fetchable URL of a PDF Kamy has never seen. Kamy downloads it, applies the operations and stores only the edited result — the source does not become a separate render, and the call costs one… |
| renderId | string | – | UUID of an existing render owned by this account. Supply exactly one of renderId or pdfUrl. |
No output schema declared.
No examples provided.
extract_document Extract document (Kamy Ingest) ~149
Extract structured data from a PDF (invoice, receipt, contract, ID document, or any form). Returns the parsed JSON plus a public verify URL that proves the extraction matches the source. Use this when an agent needs to read an inbound document and act on it.
| Name | Type | Req | Description |
|---|---|---|---|
| source_base64 | string | – | Base64-encoded PDF bytes. Use when the source isn't publicly fetchable. |
| source_url | string | – | Public URL to a PDF (preferred). One of source_url or source_base64 is required. |
| template | string | yes | Predefined template id. invoice/receipt for AP and POS docs, contract for legal agreements, id_document for passports/IDs, generic_form for anything else. |
No output schema declared.
No examples provided.
extract_from_render Extract from a render ~221
Read the text or the form fields back out of a document this account already rendered, without uploading anything. Pass type='text' (the default) for per-page text plus a joined fullText string, or type='fields' for the PDF's AcroForm field names, types and current values — the latter is how you discover what edit_pdf can fill in. Choose extract_document instead when the PDF came from outside Kamy or when you need AI-structured JSON against a schema; this tool is a plain mechanical read of an existing render, spends no render quota and no extraction credits. The render must have status 'success' or the call returns 409 RENDER_NOT_READY.
| Name | Type | Req | Description |
|---|---|---|---|
| render_id | string | yes | Render id (UUID) as returned by render_pdf, render_async/get_job, or list_renders. |
| type | string | – | 'text' (default) returns { pages: [{ page, text }], fullText, pageCount }. 'fields' returns the AcroForm fields as { name, type, value }. |
No output schema declared.
No examples provided.
get_account Get account ~218
Read everything about the authenticated Kamy account in one call: profile, plan and plan status, the plan's limits (renders per month, API keys, seats, custom templates, overage pricing, priority queue), month-to-date render usage, and whether documents rendered on this plan carry Kamy's own watermark. This is the only tool that answers any of those questions — there is no separate quota tool. Call it before render_batch, create_schedule, or any long series of renders: usage.renders.remaining is how many the API will still accept, and every render tool fails with 402 QUOTA_EXCEEDED once it hits zero, a failure nothing can recover from within the same calendar month. quota and remaining are null on unmetered plans, which means unlimited, not zero. Also check watermarkPolicy.appliedToRenders before generating something the user intends to send on: it is true on the free plan and cannot be turned off per render. Read-only, spends nothing, and works with any valid API key regardless of its scopes.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_envelope Get an envelope ~148
Fetch one multi-signer envelope with every recipient in signing order — each with a live sign_url, status, recipient_order, expires_at and last_reminded_at — plus the envelope's own status and routing. This is the tool for 'who still has not signed?' after a create_envelope send; get_signature_request answers that for a single standalone request and returns no recipient list. Under sequential routing, recipients whose turn has not arrived show status 'waiting'. Read-only and spends no quota. Requires a Kamy API key with the `signatures:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| envelopeId | string | yes | Envelope ID returned by create_envelope. |
No output schema declared.
No examples provided.
get_job Get job status ~149
Poll an asynchronous render job started by render_async. Returns { jobId, status } where status is 'queued', 'processing', 'completed' or 'failed'; on 'completed' the response also carries `render` with the finished document's id, signed URL, size and duration, and on 'failed' it carries `error` with the reason. Poll every few seconds rather than in a tight loop — a typical render finishes in seconds, a heavy one can take a minute. If a job's signed URL has since expired, pass its render id to get_render for a fresh one. Read-only and spends no quota.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | The jobId render_async returned. |
No output schema declared.
No examples provided.
get_provenance_chain Get provenance chain ~141
Replay everything recorded under one run_id — artifacts from attest_artifact and calls from record_agent_action — in order, with each record's link to its parent hash. Use it to answer 'what did this agent actually do, and in what sequence?' during an incident review, a handover, or an audit. Returns { run_id, chain_intact, records: [...] }, where chain_intact is the server's verdict on whether the parent-hash links are unbroken across the run. Read-only. Requires a Kamy API key.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run_id you passed to attest_artifact / record_agent_action. |
No output schema declared.
No examples provided.
get_render Get render ~165
Fetch one previously produced document by its render id, with a freshly signed download URL valid for the next hour. This is the recovery path for an expired link: the URL is minted at read time, so calling this again on an old render always yields a working download. Use list_renders first if you do not have the id. Returns { id, name, templateId, templateName, status, bytes, durationMs, url, createdAt }, where url is null when the render failed, has not finished yet, or its file has aged out of retention — check status before assuming a download exists. Read-only and spends no quota.
| Name | Type | Req | Description |
|---|---|---|---|
| render_id | string | yes | Render id (UUID) as returned by render_pdf, render_async/get_job, or list_renders. |
No output schema declared.
No examples provided.
get_render_pages Get render pages as images ~206
Rasterise every page of an existing render to a PNG image and return one signed 1-hour URL per page, with pixel width and height. Use this when a page has to be looked at rather than read — thumbnails, previews, visual QA of a layout, or an image attachment — and use extract_from_render when you want the text. The render must already have status 'success'; a queued or failed one comes back as 409 RENDER_NOT_READY. Repeated calls overwrite the same page images, so it is safe to retry. Rasterisation costs no render quota. Returns { pages: [{ page, width, height, url }], count, dpi }.
| Name | Type | Req | Description |
|---|---|---|---|
| dpi | integer | – | Raster resolution. Defaults to 150 (screen quality); 300 for print-quality thumbnails. Clamped to 72-300 server-side. |
| render_id | string | yes | Render id (UUID) as returned by render_pdf, render_async/get_job, or list_renders. |
No output schema declared.
No examples provided.
get_signature_certificate Get Certificate of Completion URL ~112
Returns the authenticated download URL for a signature request's Certificate of Completion PDF — the process audit trail (invite → opened → consent → signed, with IP / user-agent) that legal teams expect. Only available after the request reaches a terminal state. Without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| signatureRequestId | string | yes | ID of the signature_request to fetch the Certificate of Completion for. Must be in a terminal state (signed / declined / delegated / voided / expired); pending requests return 409. |
No output schema declared.
No examples provided.
get_signature_request Get a signature request ~199
Fetch one signature request by id, with the detail list_signature_requests leaves out: the placed_fields layout, signed_at plus signed_ip and signed_user_agent, last_reminded_at, cc_emails, and envelope_id + recipient_order when it is part of an envelope. Use list_signature_requests to find an id and this to inspect it; use get_signature_certificate when what you actually want is the legal audit-trail PDF rather than the row. `status` is one of pending, waiting, signed, declined, delegated, voided or expired — `waiting` means a sequential envelope has not reached this signer yet, so nothing is wrong and no reminder is due. Read-only and spends no quota. Requires a Kamy API key with the `signatures:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| signatureRequestId | string | yes | ID returned by create_signature_request, bulk_signature_requests, or a list call. |
No output schema declared.
No examples provided.
get_signature_template Get a signature template ~117
Fetch one e-signature preset in full, including the placed_fields array and position that list_signature_templates omits. Use it to inspect or copy an existing field layout before applying it through create_signature_request's signatureTemplateId, or as the starting point for a preview_field_placement check against a new render. Read-only and spends no quota. Requires a Kamy API key with the `signatures:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| signatureTemplateId | string | yes | ID from list_signature_templates. |
No output schema declared.
No examples provided.
get_started Get started with Kamy ~293
Everything needed to go from nothing to a rendered document in one call: the steps to create an API key in the dashboard, and — when you name a `framework` — the install command for the Kamy SDK, the environment variable it reads, and the client-setup snippet for that stack. Add a `template` slug and it also returns a ready-to-paste route handler that renders it. Every argument is optional and each one only adds a section, so calling this with no arguments is the right move when a user has no key yet, and calling it with framework + template is the right move when they are wiring the first endpoint. This replaces the separate install_sdk, generate_integration_code and get_api_key_instructions tools removed in 1.5.0. Pure text: it makes no API call, reads no account state, and needs no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| framework | string | – | Stack being integrated. Omit to get only the API-key steps; supply it to also get the install command, the environment variable, and the client-setup snippet. |
| packageManager | string | – | Package manager for the install command. Default npm. Ignored for Python stacks. |
| template | string | – | Template slug (e.g. 'invoice') to also emit a ready-to-paste route handler that renders it. Requires `framework`. Call list_templates first if you do not know the slug. |
No output schema declared.
No examples provided.
get_template_schema Get template schema ~83
Fetch the JSON Schema (exact data shape) and a copy-pasteable sample payload for a Kamy system template by slug. Call this before render_pdf so you fill the right fields with the right types instead of guessing. No authentication required.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Template slug — e.g. 'invoice', 'receipt', 'uae-tax-invoice'. |
No output schema declared.
No examples provided.
get_template_version Get a template version ~165
Fetch one template version snapshot in full — html, css, schema, createdBy, createdAt — exactly as it was frozen when that version was cut. Use list_template_versions first to find the number. Use this to inspect what a released version actually contained, or to recover content a later draft edit overwrote; it changes nothing on its own, so pair it with rollback_template when you want that version live again. Takes a template UUID or slug. Read-only and spends no quota. Requires a Kamy API key with the `templates:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| templateId | string | yes | Template UUID or slug — every /v1/templates route resolves either. |
| version | integer | yes | Version number from list_template_versions. |
No output schema declared.
No examples provided.
get_upload Get an uploaded asset ~188
Look up a stored asset by its upload id: filename, contentType, sizeBytes, status, its `kamy://asset/<id>` reference, and a freshly signed downloadUrl valid for one hour once the bytes exist. Its main use is confirming an out-of-band transfer landed — upload_file returns uploaded:false when the file was too large to pass inline and you PUT it yourself — because this read reconciles a still-'pending' row against storage and flips it to 'uploaded' the first time it sees the object. Also the way to mint a fresh download link after an earlier signed URL expired. Read-only and spends no quota. Requires a Kamy API key with the `uploads:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| uploadId | string | yes | Upload UUID returned by upload_file. The bare UUID, not the kamy://asset/... ref. |
No output schema declared.
No examples provided.
list_renders List renders ~213
List the documents this account has already produced, newest first. This is how you find a PDF made earlier — in a previous turn, by a schedule, or by another process — when you no longer hold its URL. Download URLs returned by the render tools are signed and expire after an hour, so a link from earlier in the conversation is probably dead; find the render here, then call get_render with its id to mint a fresh one. Returns { renders: [{ id, name, templateId, templateName, status, bytes, durationMs, cost, createdAt }], total, page, pageSize, hasMore, currency }. The `name` field is whatever label was passed at render time, which is the fastest way to identify the right document. Read-only and spends no quota.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | 1-based page number. Defaults to 1 (the most recent renders). |
| page_size | integer | – | Rows per page, 1-100. Defaults to 20. |
No output schema declared.
No examples provided.
list_schedules List schedules ~148
List this account's recurring render schedules, newest first, with the id needed to delete one. Use it to answer what is already automated before creating a duplicate, and to diagnose a schedule that is not producing documents: each row carries enabled, schedule, timezone, next_run_at, and last_run_at / last_run_status / last_run_error from the most recent firing — last_run_error is where a delivery or quota failure shows up. Returns { schedules, total, limit, offset }. Read-only and spends no quota.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Rows to return, 1-100. Defaults to 50. |
| offset | integer | – | Rows to skip. Defaults to 0. |
No output schema declared.
No examples provided.
list_signature_requests List signature requests ~52
List signature requests created by the configured Kamy account, newest first. Without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Default 50. |
| offset | integer | – | Default 0. |
No output schema declared.
No examples provided.
list_signature_templates List signature templates ~183
List this account's reusable e-signature presets — saved field placements, default invite message, default link lifetime and CC list — newest first. These are signing presets, NOT the document catalog: list_templates is what render_pdf draws from. Rows here carry only id, name, description, expires_in and cc_emails; call get_signature_template for the placed_fields and position. Pass an id as create_signature_request's signatureTemplateId to apply a preset instead of re-specifying the layout every time. Returns { templates, total, limit, offset }. Read-only and spends no quota. Requires a Kamy API key with the `signatures:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Page size, 1–100. Default 50. |
| offset | integer | – | Rows to skip. Default 0. |
No output schema declared.
No examples provided.
list_template_versions List template versions ~136
List a template's immutable version snapshots, newest first, as { id, version, createdAt }. This is where the version number that publish_template and rollback_template take comes from. Bodies are deliberately not included — call get_template_version when you need one snapshot's html, css and schema. Works on system and public templates as well as your own, by UUID or slug. Read-only and spends no quota. Requires a Kamy API key with the `templates:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| templateId | string | yes | Template UUID or slug — every /v1/templates route resolves either. |
No output schema declared.
No examples provided.
list_templates List templates ~20
List Kamy's public system PDF templates. No authentication required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_webhooks List webhooks ~106
List the webhook endpoints registered on this account, with the id needed to test one. Each row carries url, events, enabled, and lastDeliveryAt / lastStatus from the most recent delivery — lastStatus is the HTTP code the caller's own server returned, so this is where a silently broken endpoint shows up as a 4xx or 5xx. Signing secrets are never returned here; they are shown only once, by create_webhook. Read-only and spends no quota.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
merge_pdfs Merge renders into one PDF ~205
Concatenate 2–20 existing renders into a single new PDF, in exactly the order the ids are given. Both the inputs and the output are Kamy render ids, so this is the composition step after several render_pdf / convert_document / edit_pdf calls — it cannot merge arbitrary URLs or raw bytes, and every id must belong to this account and point at a completed render or the whole call fails. The source renders are left untouched. Returns a new render { id, url, bytes, durationMs }. Billed as one additional render. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | – | Label for the merged render, e.g. 'Q3 statement bundle'. |
| renderIds | array | yes | 2–20 render UUIDs owned by this account, in the page order you want. Any id that isn't yours, or whose render didn't complete, fails the whole call. |
No output schema declared.
No examples provided.
pki_sign_pdf PKI-sign PDF ~248
Cryptographically sign an existing render with PAdES when a Kamy API key is configured. Without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| location | string | – | Optional /Sig dictionary Location. |
| reason | string | – | Optional /Sig dictionary Reason — surfaced in Acrobat's signature panel. ASCII-coerced server-side. |
| renderId | string | yes | Render UUID returned by render_pdf or any /v1/render call. The PDF will be sealed with a Kamy-issued X.509 leaf certificate. |
| signerEmail | string | – | Override the signer email. Defaults to the account's email. |
| signerName | string | – | Override the signer display name. Defaults to the account's full_name. |
| withRevocationInfo | boolean | – | When false, skip embedding the Kamy CA CRL into the PKCS#7 SignedData (PAdES-B-T instead of B-LT). Online verifiers can still fetch the CRL via the Distribution Point on the leaf cert. Default: true. |
| withTimestamp | boolean | – | When false, skip the RFC 3161 timestamp call (PAdES-B-B instead of B-T). Default: true. |
No output schema declared.
No examples provided.
preview_field_placement Preview signature field placement ~331
Check a placedFields layout against a real render's page geometry before anything is sent: no signature request is created, no email goes out, and no signature quota is spent. It accepts exactly what create_signature_request accepts — all seven field types, `options`, and anchor-positioned fields — so anything that previews clean will send. Returns each page's true width and height, so a sender UI can draw a preview at the right aspect ratio, plus per field valid / issues / the resolved coordinates the request would actually be stored with, after sourcePage scaling and anchor substitution. Issues are PAGE_OUT_OF_RANGE, OFF_PAGE_RIGHT, OFF_PAGE_TOP, DUPLICATE_NAME, ANCHOR_NOT_FOUND (the anchor text is not on that page, so the field falls back to the raw x/y) and OPTIONS_REQUIRED. None of these make create_signature_request fail — that is the point of checking here, because a field that lands off the page is accepted and emailed. The source render must have status 'success'; if its PDF has aged out of storage the call returns 410 and the fix is to re-render. Read-only. Requires a Kamy API key with the `signatures:read` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| placedFields | array | yes | Up to 100 fields to validate. Exactly the shape create_signature_request takes — same seven types, same `anchor` and `options` support — so a layout that previews clean is a layout that sends. |
| renderId | string | yes | Render UUID whose real page sizes the fields are checked against. |
No output schema declared.
No examples provided.
publish_template Publish a template version ~219
Make a template version live for rendering. Called with no `version`, it snapshots the current draft into a new version and points published_version at it — this is how you ship an edit made with update_template. Called with an existing `version`, it republishes that earlier snapshot and leaves the draft alone. Reach for rollback_template instead when you are reverting a bad release: only that tool offers the concurrency fence and the option to restore the draft as well. Takes a template UUID or slug, same as every other /v1/templates route. Returns { templateId, publishedVersion, publishedVersionId, latestVersion, publishedAt }. Requires a Kamy API key with the `templates:write` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| templateId | string | yes | Template UUID or slug — every /v1/templates route resolves either. |
| version | integer | – | Omit to snapshot the current draft into a new version and publish that. Supply an existing version number to republish a known-good earlier snapshot, leaving the draft untouched. |
No output schema declared.
No examples provided.
record_agent_action Record agent action ~284
Append one signed tool_call -> tool_result pair to a tamper-evident ledger. Call it after any consequential tool invocation — a payment, an outbound email, a write into a customer system — so there is a hash-chained record of what the agent asked for and what came back, signed at write time. Pass a stable run_id to keep an entire agent run in one chain, and parent_sha256 to link records explicitly; read the result back with get_provenance_chain. Returns { record_id, content_sha256, signature, recorded_at, verify_url }. Requires a Kamy API key.
| Name | Type | Req | Description |
|---|---|---|---|
| latency_ms | integer | – | Wall-clock duration of the call. |
| parent_sha256 | string | – | content_sha256 of the previous record in this run, to link the chain explicitly. |
| run_id | string | – | Your identifier for this agent run. Reuse it across records to build one chain. |
| server | string | yes | Identifier of the MCP server (or tool provider) the call went to, e.g. 'kamy'. |
| status | string | – | Outcome of the call. Defaults to ok. |
| tool | string | yes | Name of the tool that was invoked. |
| tool_call | – | – | The request you sent — typically the arguments object, verbatim. |
| tool_result | – | – | The result you received back, verbatim. |
No output schema declared.
No examples provided.
remind_signature Remind a signer or an envelope ~249
Resend the signature invitation email. Pass signatureRequestId to nudge one signer, or envelopeId to nudge every currently-pending recipient of an envelope — supply exactly one; there is no separate envelope-reminder tool. This sends real email to third parties. Each recipient is capped at one reminder per hour: the single-request form returns 429 REMIND_TOO_SOON with a Retry-After header, while the envelope form silently skips capped recipients and reports skipped_reason per row, so read the per-recipient results rather than assuming everyone was mailed. Only pending recipients are reminded — signed, voided and expired requests return 409, and sequential recipients still in 'waiting' are skipped because it is not their turn. A manual nudge also counts toward the three-reminder auto-cadence cap. Requires a Kamy API key with the `signatures:write` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| envelopeId | string | – | Nudge every currently-pending recipient of this envelope. Supply exactly one of signatureRequestId or envelopeId. |
| signatureRequestId | string | – | Nudge this one signer. Supply exactly one of signatureRequestId or envelopeId. |
No output schema declared.
No examples provided.
render_async Render PDF asynchronously ~376
Queue one PDF render and return immediately with { jobId, status: 'queued' } instead of waiting for the document. Choose this over render_pdf when blocking is not acceptable — a heavy template, a large data set, or a turn where you have other work to do — and poll get_job with the returned jobId until status is 'completed' (the finished render, including its download URL, arrives on the job) or 'failed'. Choose render_pdf when a single document is small enough that waiting a few seconds is fine and you want the URL in one call, and render_batch when you have many documents to make at once. Same template, data and page options as render_pdf, and the same one render from the monthly quota — the quota is checked when the job is accepted, so an over-quota call fails here with 402 rather than silently queueing.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | Data used to populate the template. |
| format | string | – | Paper size. Defaults to a4. |
| margin | object | – | CSS lengths, e.g. { top: '20mm', bottom: '20mm' }. |
| metadata | object | – | PDF document properties written into the file's metadata dictionary. |
| name | string | – | Your own label for this document. Echoed back on the job result and stored on the render, so list_renders can be grepped by it later. |
| pdf_a | string | – | Convert the output to a PDF/A archival conformance level. |
| template | string | yes | Template slug (e.g. 'invoice') or template UUID. Same values render_pdf accepts. |
| watermark | object | – | Draws your own diagonal watermark over every page. Unrelated to the free-plan Kamy watermark, which is applied regardless — see get_account.watermarkPolicy. |
No output schema declared.
No examples provided.
render_batch Render a batch of PDFs ~241
Render up to 100 documents in a single blocking call, each from its own template, HTML or URL, and get every result back in one response. Choose this over calling render_pdf in a loop whenever you have more than a couple of documents — it is one round trip, one quota reservation and one rate-limit charge. It does block: items render sequentially inside a 300-second budget, so expect to wait, and reach for render_async instead when you cannot. Returns { results: [...] } in request order, where each entry is either a finished render or an { error: { code, message } } — a partial batch is normal and successful items are still yours. The whole batch's quota is reserved up front, so a batch that would cross the monthly quota is rejected in full with 402 and nothing is rendered; call get_account first if you are near the limit. Items that would overrun the time budget come back as SERVICE_UNAVAILABLE having been neither rendered nor billed — retry just those in a smaller batch.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | 1-100 documents to render, in order. Results come back in this same order. |
No output schema declared.
No examples provided.
render_docx Render Word document ~270
Render an editable Word (.docx) document from a Kamy template and data. Takes the same { template, data } payload as render_pdf but produces a different container — reach for it when the recipient has to EDIT the document (legal redlines, Word-based intake, corporate templates) rather than receive a fixed artifact. Only five slugs have a Word implementation — invoice, receipt, quote, contract, agreement — and any other template is rejected with a validation error; use render_pdf for those. Returns { id, url, bytes, durationMs, format: 'docx' }, where url is a signed download link valid for one hour and id is a normal render id. Counts one render against the monthly quota. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | – | Template data, identical in shape to the render_pdf payload for the same slug — call get_template_schema first to get the exact fields. |
| name | string | – | Label stored on the render row so the document is identifiable in the dashboard. |
| template | string | yes | Which built-in document to build. These five are the only slugs with a Word implementation; custom templates and other system templates are PDF-only (use render_pdf). |
No output schema declared.
No examples provided.
render_html Render template to HTML ~276
Compile a Kamy template — or raw Handlebars source you pass inline — against a data payload and get the rendered HTML string back. No browser runs, no PDF is produced and no file is stored, so this is the tool for piping a template into a transactional email provider, or for inspecting the markup before committing to render_pdf. Use render_pdf instead whenever the output has to be a paginated, printable artifact. Supply exactly one of template or html. Returns { format: 'html', html, bytes }. Paid-tier system templates are refused on the free plan. Counts one render against the monthly quota, since the compile step is the shared cost. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | – | Values substituted into the template's Handlebars expressions. |
| direction | string | – | Force the document's lang/dir attributes for RTL/bidi mail clients. 'auto' (default) leaves the template's own <html lang> untouched. |
| html | string | – | Raw Handlebars/HTML source to compile instead of a stored template. Supply exactly one of template or html. |
| template | string | – | Template slug or UUID — a Kamy system template or one of your own. Supply exactly one of template or html. |
No output schema declared.
No examples provided.
render_pdf Render PDF ~201
Render a PDF from a Kamy template and data, and wait for it. This is the default document tool: it blocks until the file exists and hands back { id, url, bytes, durationMs, templateId, createdAt } in one call, where url is a signed download link valid for one hour and id is the render id every later tool takes. Reach for render_async instead when waiting is not acceptable, and render_batch when several documents are wanted at once. Call get_template_schema first if you are unsure what fields the template expects. Counts one render against the monthly quota — get_account tells you what is left before this fails with 402. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | Data to populate the template |
| format | string | – | – |
| template | string | yes | Template slug (e.g., 'invoice') or template UUID |
No output schema declared.
No examples provided.
render_pptx Render PowerPoint deck ~309
Build a PowerPoint (.pptx) deck from a slide spec: an ordered array of slides, each tagged with one of five fixed layouts (title, bullets, two-column, table, quote). This is NOT a template renderer like render_pdf / render_docx — there is no template slug and no free-form layout, so content has to be shaped into those five. It also converts nothing; use convert_document to turn a file you already have into a PDF. Returns a stored render { id, url, bytes, durationMs, format } where url is a signed download link valid for one hour; the deck is a .pptx, so feed the id to convert_document if the next step needs a PDF (merge_pdfs, split_pdf and the signature tools take PDFs only). Counts one render against the monthly quota. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | WIDE = 16:9 (default), STANDARD = 4:3. |
| slides | array | yes | Ordered slides. Each carries a `layout` discriminator: 'title', 'bullets', 'two-column', 'table' or 'quote'. There is no free-form layout — content that doesn't fit one of the five should be reshaped… |
| theme | object | – | – |
| title | string | – | Deck title — used as document metadata and as the returned filename stem. |
No output schema declared.
No examples provided.
render_xlsx Render Excel workbook ~237
Build an Excel (.xlsx) workbook from a sheet spec: columns with keys, row objects keyed to those columns, optional Excel number formats and a formula-aware total row (bare 'SUM' / 'AVG' / 'COUNT' / 'MIN' / 'MAX' expands into a real formula over the column's data range). Choose this over render_pdf when the recipient will sort, filter or recompute the numbers, and over render_docx when the content is tabular rather than prose. Returns a stored render { id, url, bytes, durationMs, format } where url is a signed download link valid for one hour; the workbook is a .xlsx, so feed the id to convert_document if the next step needs a PDF. Header rows are always bold on a tinted fill — there is no flag for it. Counts one render against the monthly quota. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| sheets | array | yes | One or more sheets, in tab order. |
| title | string | – | Workbook title — document metadata and the returned filename stem. |
No output schema declared.
No examples provided.
rollback_template Roll a template back to an earlier version ~344
Revert a template after a bad release: repoints published_version at the version you name, so every subsequent render immediately serves that snapshot again. Prefer this over publish_template's `version` argument whenever you are reverting, because only this tool takes expectedPublishedVersion — an optimistic fence that rejects with 409 VERSION_CONFLICT if someone moved the pointer since you read it — and only this tool can restore the working draft too. restoreDraft: true overwrites the draft html/css/schema with that version's content, auto-snapshotting the existing draft into a fresh version first so unsaved work is recoverable; it defaults to false. Destructive: it changes what production renders, and there is no undo beyond rolling forward again. Takes a template UUID or slug. Requires a Kamy API key with the `templates:write` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| expectedPublishedVersion | integer | – | Optimistic fence: the published_version you believe is live (0 if never published). The call is rejected with 409 VERSION_CONFLICT if someone moved the pointer in the meantime. Pass it whenever you r… |
| restoreDraft | boolean | – | When true, also overwrite the working draft (html/css/schema) with that version's content. The current draft is auto-snapshotted into a new version first, unless it is already byte-identical. Default… |
| templateId | string | yes | Template UUID or slug — every /v1/templates route resolves either. |
| version | integer | yes | The known-good version to make live again. Get it from list_template_versions. |
No output schema declared.
No examples provided.
scan_tool_description Scan tool description for prompt injection ~224
Heuristic pattern scan of MCP tool description text for prompt-injection tells — instructions addressed at the reading model, data-exfiltration hints, attempts to override your system prompt or hide content. Run it on descriptions from third-party MCP servers before you act on what they say. Returns risk 'low' | 'medium' | 'high' and the matched findings with excerpts. This is a heuristic aid, NOT a security boundary: a 'low' verdict is not evidence that a tool is safe, and an injection phrased to avoid the patterns will score low. Do not treat any result here as clearance to trust an untrusted tool — keep your own judgement and human review in the loop. Read-only: it analyses only the text you pass in and fetches nothing. Requires a Kamy API key.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | A single tool description to scan. Supply description, tools, or both. |
| tools | array | – | Several tools at once — e.g. the entries of a `tools/list` result. Supply description, tools, or both. |
No output schema declared.
No examples provided.
split_pdf Split a render into page ranges ~199
Extract page ranges from one existing render into separate new PDFs — the inverse of merge_pdfs. Each range you pass produces its own render, returned in the same order, so one call can both halve a contract and peel off single pages. Omit a range's `to` to run to the end of the document; a range starting past the last page fails the entire call. The source render is left untouched. Returns { renders: [...], count }, each entry a normal render object usable with merge_pdfs, edit_pdf or the signature tools. Requires a Kamy API key with the `render` scope; without a key, returns dashboard setup instructions.
| Name | Type | Req | Description |
|---|---|---|---|
| ranges | array | yes | 1–50 page ranges; each produces one output render, returned in this order. A range that starts past the last page fails the whole call. |
| renderId | string | yes | UUID of the completed render to split. Must belong to this account. |
No output schema declared.
No examples provided.
test_webhook Test a webhook ~149
Send a real test.ping event to a registered webhook endpoint — an actual outbound HTTP POST to whatever URL the user configured, signed like a genuine delivery. Use it to prove an endpoint is reachable and that signature verification works before relying on it. Delivery is dispatched in the background, so the { message: 'Test ping dispatched' } you get back means accepted for sending, not that the endpoint answered: wait a few seconds and call list_webhooks to read lastStatus and lastDeliveryAt for the real outcome. The ping is delivered regardless of which events the endpoint subscribes to.
| Name | Type | Req | Description |
|---|---|---|---|
| webhook_id | string | yes | Webhook endpoint id (UUID) from create_webhook or list_webhooks. |
No output schema declared.
No examples provided.
What is the Kamy MCP server?
Kamy is an MCP server listed in the public MCP registry as dev.kamy/kamy. Document API for AI-native software: render PDFs, e-sign, PAdES-seal, and verify. This page covers its hosted endpoint (https://mcp.kamy.dev/mcp).
Is the Kamy MCP server safe to use?
Kamy scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Kamy MCP server expose?
Kamy exposes 59 tools: list_templates, get_template_schema, create_template, update_template, publish_template, and 54 more. Their descriptions and schemas cost roughly 14,125 tokens of context every time the server is loaded.
Does the Kamy MCP server require authentication?
No. We connected to Kamy without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Kamy MCP server still maintained?
Kamy is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.