# com.tamgara/tamgara

Fill in 1,000+ legal PDF templates in many languages, get a signed PDF back. Free, no API key.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** com.tamgara
- **License:** Unknown
- **Endpoints:** streamable-http https://api.tamgara.com/api/mcp
- **Source:** https://tamgara.com/api/
- **Endpoint health:** reachable (last checked 2026-09-17T12:06:25.789Z, 4 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 6 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-17T12:06:25.789Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

33 declared. Observed from a live `tools/list` probe.
- `info` — Überblick über Tamgara: Anzahl Vorlagen, Sprachen, Rechtsräume.
- `list_languages` — Alle unterstützten Basissprachen mit Vorlagen-Anzahl, RTL-Flag und Rechtsräumen.
- `list_locales` — Alle Locales (Sprache×Land) mit lokalisierter Rechtsphrase.
- `list_categories` — Vorlagen-Kategorien mit Anzahl (cancellation, sale, rental, …).
- `search_templates` — Vorlagen suchen/filtern. Freitext über Titel/Slug/Beschreibung, optional nach Sprache, Land (ISO-2, z. B. "DE", "EG") und Kategorie. Liefert Slugs zum Weiterver
- `get_template` — Details + Feld-Schema einer Vorlage: welche Felder (Name, Typ, Label, Optionen) auszufüllen sind, plus Rechtsraum. Adressierbar per slug ODER per id+lang. Feldn
- `fill_template` — Vorlage ausfüllen (und optional signieren) → fertiges PDF als base64. answers ist ein Objekt Feldname→Wert (Text/Datum "TT.MM.JJJJ" als String, Checkbox true/fa
- `list_providers` — Anbieter für Kündigungen (Kündigungsadresse/Fax/Frist). Länder: de, at, ch. Optional Freitextsuche.
- `get_provider` — Ein Anbieter per id (Kündigungsadresse, Fax, typische Frist).
- `fax_countries` — Unterstützte Fax-Zielländer + Hinweise zur E.164-Nummer.
- `fax_ping` — Prüft, ob Faxversand verfügbar ist und ob er bezahlt (Stripe) läuft.
- `fax_quote` — Preis für einen Faxversand. Seitenzahl aus pdfBase64 abgeleitet, wenn nicht angegeben.
- `fax_create_checkout` — Startet den bezahlten Faxversand: liefert eine Stripe-Checkout-URL. Der MENSCH bezahlt über diese URL; danach fax_confirm mit der job_id. (Kein kostenloser Dire
- `fax_confirm` — Nach erfolgter Zahlung: Fax in die Warteschlange geben. Braucht die job_id aus fax_create_checkout.
- `fax_status` — Zustellstatus eines Fax (queued/sending/success/failed) per id.
- `brief_ping` — Prüft, ob Briefversand (Post via LetterXpress) verfügbar/bezahlt ist.
- `brief_quote` — Preis für einen Postbrief (Standard oder Einschreiben). Länder: DE/AT/CH.
- `brief_create_checkout` — Startet den bezahlten Briefversand: liefert eine Stripe-Checkout-URL. Der MENSCH bezahlt; danach brief_confirm mit der job_id. (Kein kostenloser Direktversand ü
- `brief_confirm` — Nach Zahlung: Brief einreichen. Braucht die job_id aus brief_create_checkout.
- `brief_status` — Status/Tracking eines Briefs per id.
- `brief_cancel` — Storniert einen Brief im 15-Minuten-Fenster von LetterXpress.
- `envelope_create` — Sendet ein PDF zur mehrparteiigen elektronischen Signatur (DocuSign-Stil). Liefert die Vorgangs-id, einen ownerKey (geheim halten!) und pro Empfänger einen Sign
- `envelope_status` — Status eines Signier-Vorgangs (wer hat gesehen/unterschrieben) per id + ownerKey.
- `envelope_send_invite` — Verschickt (erneut) die Signier-Einladung per E-Mail an einen Empfänger. Nur mit ownerKey.
- `envelope_void` — Storniert/annulliert einen Signier-Vorgang. Nur mit ownerKey.
- `envelope_upload_final` — Lädt das fertige (z. B. lokal signierte) PDF für einen Vorgang hoch. Nur mit ownerKey.
- `inspect_pdf` — Ein BELIEBIGES PDF (base64) analysieren: Seitenzahl/-größen, ausfüllbare Formularfelder (Name, Typ, Label, Optionen), Signaturfelder und Unterschrifts-Positione
- `fill_pdf` — Ein BELIEBIGES (nicht-Katalog-)PDF ausfüllen und optional signieren → fertiges PDF (base64). answers = Feldname→Wert (aus inspect_pdf). Unterschrift wird in erk
- `pdf_from_images` — Aus einem oder mehreren Bildern (base64 PNG/JPEG) ein PDF bauen — ein Bild pro Seite (Foto/Scan → PDF).
- `add_cover_page` — Stellt einem PDF ein DIN-5008-Adressblatt voran (für den Postversand). recipient = {name,street,zip,city,country}.
- `apply_scan_answers` — Befüllt erkannte Felder eines gescannten (nicht-AcroForm-)PDFs: Text auf Schreiblinien, X in Checkboxen — per Ratio-Positionen (z. B. aus einer Feld-Erkennung).
- `account_balance` — Guthaben-Konto abfragen (Kostendeckel für kostenpflichtige KI-Calls). Das Konto mit 1 € Startgutschein wird beim ersten kostenpflichtigen Call ausgestellt und d
- `account_topup` — Guthaben aufladen. Hinweis: Die Zahlung wird gerade eingerichtet — der Aufladewunsch wird vermerkt, aber noch nicht real belastet (die kostenlosen Funktionen bl

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"tamgara\": {\n      \"type\": \"http\",\n      \"url\": \"https://api.tamgara.com/api/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on someone else's infrastructure.
- Floor 26, ceiling 50 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.tamgara%2Ftamgara
- Install plan: https://forgeregistry.com/api/v1/packages/com.tamgara%2Ftamgara/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.tamgara%2Ftamgara
- HTML page: https://forgeregistry.com/registry/com.tamgara%2Ftamgara
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
