# com.multilocale/multilocale

Manage translation projects, phrases and locales with secure organization-scoped tools and views.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.1.1
- **Author:** com.multilocale
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.multilocale.com/mcp
- **Source:** https://www.multilocale.com/integrations/mcp-server/
- **Endpoint health:** reachable (last checked 2026-09-20T11:49:41.538Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-20T11:49:41.538Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

17 declared. Observed from a live `tools/list` probe.
- `list_projects` — List all MultiLocale projects the authenticated user has access to. Returns a bounded Markdown and structured preview of project ids, names, locales, and timest
- `get_project` — Fetch a single MultiLocale project by id or name. Returns bounded Markdown and structured project metadata, including name, configured locales, and timestamps.
- `add_project` — Create a MultiLocale project with a default locale and optional additional locales. Refuses to create a duplicate project name in the authenticated organization
- `update_project` — Update a MultiLocale project’s default locale, complete locale list, or translation context. Project names are intentionally not changed because phrases referen
- `list_phrases` — List translation phrases for a MultiLocale project. Optionally filter by language or key. Returns a bounded Markdown and structured preview of id, key, language
- `get_phrase` — Fetch translations for one exact phrase key in a MultiLocale project. Returns a bounded Markdown and structured preview across locales, or a single locale when 
- `search_phrases` — Search translation phrases for a MultiLocale project by matching a query string against phrase keys and values. Returns a bounded Markdown and structured previe
- `find_duplicate_phrase_values` — Find keys in a bounded scan of one MultiLocale project whose default-locale translations have the same value. The result explicitly reports when the scan or out
- `find_missing_translations` — Report missing keys in a bounded scan of one locale or up to 10 configured locales, compared with the project default locale. The result explicitly reports part
- `export_locale_dictionary` — Export one locale of a MultiLocale project as bounded, sorted key/value entries. Results are API-paginated with a maximum of 50 entries per call and each value 
- `list_team_members` — List a bounded roster for the authenticated MultiLocale organization. Returns only each member's display name and role. Email addresses, member IDs, role IDs, p
- `add_phrase` — Create a new key in a project’s default locale and generate translations for every other configured locale. Omit value to use the key as its source value. Refus
- `update_phrase` — Update the translation value for a specific phrase key and language in a MultiLocale project. Phrases may be shared across projects — updating affects all proje
- `add_locale` — Add a new locale to a project and generate translations for every key currently missing in that locale. Uses the default-locale value as the source for each tra
- `share_phrase` — Attach every locale translation for one key in a source project to one or more target projects. The underlying phrase rows become shared, so future edits affect
- `delete_phrase` — Permanently delete every locale translation for one key in a project. If a phrase is shared with other projects, this deletes the shared row for those projects 
- `show_project_overview` — Render a bounded overview for a known MultiLocale project. Use this after listing projects or when the user provides a project id or name. It shows safe project

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"multilocale\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.multilocale.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 32, ceiling 56 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.multilocale%2Fmultilocale
- Install plan: https://forgeregistry.com/api/v1/packages/com.multilocale%2Fmultilocale/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.multilocale%2Fmultilocale
- HTML page: https://forgeregistry.com/registry/com.multilocale%2Fmultilocale
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
