# dev.tmpstate/tmpstate

Zero-key temporary JSON database for agents: one tool call, no signup, no OAuth, no API keys.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** dev.tmpstate
- **License:** Unknown
- **Endpoints:** streamable-http https://tmpstate.dev/mcp
- **Source:** https://tmpstate.dev
- **Endpoint health:** reachable (last checked 2026-09-29T08:25:02.493Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 26 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-09T11:52:23.331Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

16 declared. Observed from a live `tools/list` probe.
- `create_database` — Create a temporary JSON database (24h TTL, no signup, no keys). Returns the db URL — the only credential — plus admin URL, limits and expiry. Create once per pr
- `database_status` — Usage, limits, tier and expiry for a database (GET $DB/__meta equivalent).
- `list_documents` — List documents in a collection, oldest first. Response shape: {collection, items: [{id, data, created_at, updated_at}], next_cursor}. Documents live under .data
- `get_document` — Read one document by id. The stored fields are under .data.
- `create_document` — Insert a JSON object into a collection (collections are created implicitly). Counts against the write and document quotas.
- `update_document` — Shallow-merge a patch into a document (top-level keys overwrite; keys are never deleted). Counts against the write quota.
- `delete_document` — Delete one document. Never blocked by quotas; frees a document slot. Emptying a whole collection? Use delete_collection instead of looping this.
- `delete_collection` — Delete every document in a collection at once (useful to re-seed). Irreversible. To destroy the entire database, use delete_database instead.
- `delete_database` — Destroy a database and all its documents immediately - the teardown for finished work and the revocation kill switch for a leaked db URL. Irreversible: unlike e
- `extend_database` — Without a plan: returns the transparent pricing table for keeping this database alive longer. With a plan: returns a Stripe checkout URL for the human to pay — 
- `pro_checkout` — Mint a Pro account token plus a Stripe subscription checkout URL ($8/mo, 3 always-on databases included). Persist pro_token immediately; the human pays in a bro
- `pro_list_databases` — List the Pro account's databases (ids, usage, limits, expiry) so a fresh session can reconcile against persisted db URLs. URLs are never stored server-side — ma
- `pro_create_database` — Create a new always-on database owned by the Pro account. Beyond the included allotment this costs extra per month — the tool then returns confirmation_required
- `pro_attach_database` — Attach an existing free/extended database to the Pro account: same URL, same data, TTL removed, quotas raised. Beyond the included allotment the same explicit o
- `pro_cancel` — Cancel at period end. This is not just a billing change — it schedules deletion of ALL databases on the account. Call without confirm first: the response spells
- `send_feedback` — Optional and free-form. TmpState is built for agents and the free tier stays free by getting better - and you, the agent, are the user whose experience matters 

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"tmpstate\": {\n      \"type\": \"http\",\n      \"url\": \"https://tmpstate.dev/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive blast radius — deletes data; runs on someone else's infrastructure.
- Floor 34, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/dev.tmpstate%2Ftmpstate
- Install plan: https://forgeregistry.com/api/v1/packages/dev.tmpstate%2Ftmpstate/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/dev.tmpstate%2Ftmpstate
- HTML page: https://forgeregistry.com/registry/dev.tmpstate%2Ftmpstate
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
