Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Kamy

REMOTE · MCP.KAMY.DEV · SCANNED SEP 28

Document API for AI-native software: render PDFs, e-sign, PAdES-seal, and verify.

Available components

0 this week 72 Trust /100

Recent critical change

Authorization (19 Aug 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability67
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 14125 tokens (~239/item across 59 items; 59 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 97% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 59 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Kamy MCP server?

Kamy is a hosted endpoint at https://mcp.kamy.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.kamy.dev

# add to Claude Code
claude mcp add --transport http dev-kamy-kamy 'https://mcp.kamy.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-kamy-kamy": {
      "url": "https://mcp.kamy.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-kamy-kamy": {
      "type": "http",
      "url": "https://mcp.kamy.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-kamy-kamy]
url = "https://mcp.kamy.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-kamy-kamy": {
      "type": "remote",
      "url": "https://mcp.kamy.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-kamy-kamy --url 'https://mcp.kamy.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-kamy-kamy:
    url: "https://mcp.kamy.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-kamy-kamy": {
      "Transport": "http",
      "Url": "https://mcp.kamy.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-kamy-kamy -t streamable-http -u 'https://mcp.kamy.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-kamy-kamy": {
      "type": "http",
      "url": "https://mcp.kamy.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 18 Sept 26 +3
    • Stability: fail → pass ▲ security
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 19 Aug 26 0
    • Authorization: partial → fail ▼ critical
    • Stability: 0.77 → fail ▼ security
    • Tool “generate_integration_code” was removed ▼ security
    • Tool “get_api_key_instructions” was removed ▼ security
    • Tool “install_sdk” was removed ▼ security
    • New tool “delete_schedule”, which the server declares destructive security
    • New tool “rollback_template”, which the server declares destructive security
    • Tool “render_pdf” rewrote its description, which is the text the model reads security
    • Tool “verify_pdf_signature” rewrote its description, which is the text the model reads security
    • Schema quality: 121 → 239 ▼ functional
    • Server version: 1.2.0 → 1.5.0 functional
    • New tool “attest_artifact” functional
    • New tool “bulk_signature_requests” functional
    • New tool “convert_document” functional
    • New tool “create_envelope” functional
    • New tool “create_schedule” functional
    • New tool “create_template” functional
    • New tool “create_webhook” functional
    • New tool “edit_pdf” functional
    • New tool “extract_from_render” functional
    • New tool “get_account” functional
    • New tool “get_envelope” functional
    • New tool “get_job” functional
    • New tool “get_provenance_chain” functional
    • New tool “get_render” functional
    • New tool “get_render_pages” functional
    • New tool “get_signature_request” functional
    • New tool “get_signature_template” functional
    • New tool “get_started” functional
    • New tool “get_template_version” functional
    • New tool “get_upload” functional
    • New tool “list_renders” functional
    • New tool “list_schedules” functional
    • New tool “list_signature_templates” functional
    • New tool “list_template_versions” functional
    • New tool “list_webhooks” functional
    • New tool “merge_pdfs” functional
    • New tool “preview_field_placement” functional
    • New tool “publish_template” functional
    • New tool “record_agent_action” functional
    • New tool “remind_signature” functional
    • New tool “render_async” functional
    • New tool “render_batch” functional
    • New tool “render_docx” functional
    • New tool “render_html” functional
    • New tool “render_pptx” functional
    • New tool “render_xlsx” functional
    • New tool “scan_tool_description” functional
    • New tool “split_pdf” functional
    • New tool “test_webhook” functional
    • New tool “trace_record” functional
    • New tool “trace_record_batch” functional
    • New tool “trace_search” functional
    • New tool “update_template” functional
    • New tool “upload_file” functional
    • New tool “verify_attestation” functional
    • New tool “verify_mcp_server” functional
    • Tool “verify_pdf_signature” changed its title: Verify PDF signature → Hash a PDF and build its verify URL cosmetic
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Probed https://mcp.kamy.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=kamy.dev CN=WE1,O=Google Trust Services,C=US 17 Aug 2026 15 Nov 2026 ECDSA 256 ECDSA-SHA256 a70e92a03ce9d95813506d1773ef6fba
SANs: kamy.dev, mcp.kamy.dev, *.mcp.kamy.dev
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.kamy.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
kamy.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.kamy.dev/mcp Verified 200
http (plaintext) http://mcp.kamy.dev/mcp Inconclusive 406
MCP tools · 59 exposed · ~14,125 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
trace_record ~366

Record one LLM call — prompt, output, provider, model, tokens, latency — into Kamy Trace, a signed retention ledger. Each record is hashed and signed at write time, so it can be produced later without the 'you could have edited this' objection. Reach for it when model calls need a reviewable history: regulated workflows, customer-facing generations, anything you may have to explain months later. Set status 'flagged' with status_detail on calls a human should revisit. Returns { id, content_sha256, signature, recorded_at, verify_url }. Requires a Kamy API key with the trace:record scope; each call consumes monthly Trace quota.

NameTypeReqDescription
featurestring–Product area the call belongs to, e.g. 'support_reply'. Filterable in trace_search.
input_tokensinteger–Prompt tokens billed.
latency_msinteger–Wall-clock duration of the call.
modelstringyesModel identifier exactly as the provider reports it, e.g. 'claude-sonnet-4-6'.
output––The model's response, verbatim. Any JSON value.
output_tokensinteger–Completion tokens billed.
prompt––The prompt / request you sent, verbatim. Any JSON value (string, array, object).
providerstringyesWhich model vendor served the call. Use 'custom' for anything self-hosted.
statusstring–Outcome. 'flagged' marks a call you want a human to review later. Defaults to 'ok'.
status_detailstring–Why the call was flagged or failed. Free text.
tagsarray–Up to 20 free-form labels. trace_search can filter on any one of them.

No output schema declared.

No examples provided.

trace_record_batch ~180

Write up to 100 Kamy Trace records in one call. Reach for this over trace_record whenever you have more than a couple of buffered LLM calls to persist — it is one auth, one quota check and one round trip instead of N. Each element takes exactly the shape trace_record takes. The whole batch is counted against the monthly Trace quota up front, so a batch that would cross the plan cap is rejected in full with 402 and nothing is stored; split it or upgrade rather than retrying. Returns { records: [{ id, content_sha256, signature, recorded_at, verify_url }] } in input order. Requires a Kamy API key with the `trace:record` scope; without a key, returns dashboard setup instructions.

NameTypeReqDescription
recordsarrayyes1–100 records, each exactly the shape trace_record takes.

No output schema declared.

No examples provided.

trace_search ~239

Query this account's Kamy Trace records, newest first, filtered by feature, status, provider, tag, or time window. Returns record metadata — model, tokens, latency, status, content hash, recorded_at — plus next_cursor for paging; it does not return the stored prompt and output bodies. Use it to answer questions like 'how many flagged calls last week?' or to locate a specific record's id before opening it in the dashboard. Read-only. Requires a Kamy API key with the trace:read scope.

NameTypeReqDescription
cursorstring–Pass the `next_cursor` from the previous response to fetch the next page.
featurestring–Exact-match filter on the feature label.
limitinteger–Page size, 1-100. Default 25.
providerstring–Exact-match filter on provider.
sincestring–ISO-8601 timestamp, inclusive lower bound.
statusstring–Exact-match filter on outcome.
tagstring–Return records whose tags array contains this tag.
untilstring–ISO-8601 timestamp, exclusive upper bound.

No output schema declared.

No examples provided.

update_template ~221

Edit an existing custom template's DRAFT — name, html, css, schema, tags, visibility — addressed by UUID or slug. Only the fields you pass are changed. Crucially, this does not change what renders once the template has been published even once: while published_version is set, render_pdf serves that frozen snapshot and your edits stay invisible until publish_template moves the pointer, so an edit that appears to do nothing usually needs a publish. System templates, and templates belonging to another account, return 403. Requires a Kamy API key with the `templates:write` scope; without a key, returns dashboard setup instructions.

NameTypeReqDescription
cssstring–Replaces the draft CSS entirely.
descriptionstring––
htmlstring–Replaces the draft HTML entirely.
isPublicboolean––
namestring––
schemaobject–Replaces the draft JSON Schema entirely.
tagsarray––
templatestringyesTemplate UUID or slug. This route accepts either.

No output schema declared.

No examples provided.

upload_file ~360

Store an image, font or PDF in the account's asset bucket and get back a `kamy://asset/<id>` reference you can drop anywhere inside a render_pdf / render_html data payload — Kamy swaps it for a fresh signed URL at render time. That reference is the point of this tool: it is how a logo, signature image or custom font gets into a template without hosting it yourself. Pass contentBase64 and this server performs the upload for you, returning { id, assetRef, bytes, uploaded: true }. Omit contentBase64 for files too big to pass through a tool call and you get the raw slot instead — { uploadUrl, uploadMethod, uploadHeaders, expiresAt, uploaded: false } — then PUT the bytes yourself within 15 minutes. Inline uploads are capped at 5 MB here; the API itself allows 100 MB via that URL. Only the listed MIME types are accepted. Requires a Kamy API key with the `uploads:write` scope; without a key, returns dashboard setup instructions.

NameTypeReqDescription
contentBase64string–Base64 bytes to upload. When supplied, this server PUTs them to the pre-signed URL and the asset is immediately usable. Omit for files too large to pass through a tool call — you then get uploadUrl b…
contentTypestringyesMIME type. The API rejects anything outside this list.
filenamestringyesName to store the asset under. Characters outside [A-Za-z0-9._-] are replaced with '_'.
sizeBytesinteger–Declared size in bytes. Computed automatically when contentBase64 is supplied. Max 100 MB.

No output schema declared.

No examples provided.

validate_payload ~98

Dry-run a render payload against a template's schema WITHOUT producing a PDF or using quota. Returns per-field self-healing errors (expected type, value received, allowed values, an example) so you can fix the data before render_pdf. Requires a Kamy API key.

NameTypeReqDescription
dataobjectyesThe data payload to validate against the template schema.
templatestringyesTemplate slug (e.g. 'invoice') or template UUID.

No output schema declared.

No examples provided.

verify_attestation ~207

Ask Kamy whether a SHA-256 digest has an attestation on record — the tool that actually returns a verdict. Takes a digest, not a file: if what you hold is a PDF, run verify_pdf_signature over the bytes first and pass the sha256 it gives you. A match returns { verified: true, artifact_type, recorded_at, signature, public_key }. A false result means no attestation exists for those exact bytes, which happens both when content was altered after attestation and when it was simply never attested; it does not by itself identify tampering or a culprit. Public surface — like the extract_document verify URL, no API key is required, so a recipient can confirm an artifact independently of whoever sent it.

NameTypeReqDescription
hashstringyesSHA-256 of the artifact you want to check, as hex. Hash the bytes you actually hold — if they were modified after attestation, the digest won't match any record and `verified` comes back false.

No output schema declared.

No examples provided.

verify_mcp_server ~252

Detect when an MCP server changes its tool manifest after you adopted it — the 'rug pull' case, where a server you already trusted silently rewrites a tool's description or input schema. Pass server_url and Kamy fetches that third-party server's manifest itself, or pass manifest when you already hold it (local or private servers). Returns status 'new' (first fingerprint for this account — nothing to compare against yet), 'unchanged', or 'mutated', plus a per-tool changes list with previous and current hashes. 'unchanged' means only that it matches what Kamy recorded previously; it is not a judgement that the server is trustworthy, and a first-ever 'new' result establishes a baseline rather than clearing anything. Requires a Kamy API key.

NameTypeReqDescription
manifest––A tool manifest you already hold — the `tools/list` result, or an object with a `tools` array. Use this when the server isn't reachable from Kamy (local stdio server, private network). Supply either…
server_urlstring–URL of the MCP server to fingerprint. Kamy fetches its tool manifest server-side. Supply either server_url or manifest.

No output schema declared.

No examples provided.

verify_pdf_signature ~191

Turn PDF bytes you are holding into their SHA-256 digest and the matching kamy.dev/verify/{sha256} page URL. Purely local: the MCP Worker hashes the base64 in memory, makes no Kamy API call, stores nothing and forwards nothing, so it works with no key and never leaves a trace. Note it returns no verdict — it does not tell you whether the document is genuine, signed, or on record anywhere. It is the first half of a check: take the sha256 it returns and pass it to verify_attestation for the actual yes/no, or hand a person the verify_url to open. Use this whenever you have the file itself; use verify_attestation directly when someone has already given you a digest.

NameTypeReqDescription
pdfBase64stringyesBase64-encoded PDF bytes. The MCP Worker hashes the file in-memory and does not store or forward it.

No output schema declared.

No examples provided.

Common questions

What is the Kamy MCP server?

Kamy is an MCP server listed in the public MCP registry as dev.kamy/kamy. Document API for AI-native software: render PDFs, e-sign, PAdES-seal, and verify. This page covers its hosted endpoint (https://mcp.kamy.dev/mcp).

Is the Kamy MCP server safe to use?

Kamy scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Kamy MCP server expose?

Kamy exposes 59 tools: list_templates, get_template_schema, create_template, update_template, publish_template, and 54 more. Their descriptions and schemas cost roughly 14,125 tokens of context every time the server is loaded.

Does the Kamy MCP server require authentication?

No. We connected to Kamy without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Kamy MCP server still maintained?

Kamy is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.