Server data from the Official MCP Registry
MCP server for the Transkribus REST API — collections, documents, HTR/OCR, and models.
About
MCP server for the Transkribus REST API — collections, documents, HTR/OCR, and models.
Security Report
This MCP server for the Transkribus REST API demonstrates strong security practices with comprehensive credential handling, session token redaction, and proper authentication. Code quality is excellent with extensive regression tests covering sensitive data leakage. Permissions appropriately match the server's purpose of interacting with the Transkribus API. Minor code quality observations exist but do not warrant concern given the overall security posture. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.
3 files analyzed · 9 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-lazyants-transkribus": {
"args": [
"-y",
"@lazyants/transkribus-mcp-server"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
transkribus-mcp-server
MCP server for the Transkribus REST API. Manage collections, documents, HTR/OCR recognition, models, and more through the Model Context Protocol.
300 tools across 22 resource domains, with 8 entry points so you can pick the right server for your MCP client's tool limit.
API scope: This server covers the legacy Transkribus TrpServer REST API. The newer Processing API v2 (OIDC auth,
/processing/v2,account.readcoop.eu) is intentionally out of scope.
Installation
npm install -g @lazyants/transkribus-mcp-server
Or run directly:
npx @lazyants/transkribus-mcp-server
Configuration
Transkribus uses session-based authentication. You can authenticate in two ways:
Option 1: Username + Password (auto-login)
export TRANSKRIBUS_USER=your-email@example.com
export TRANSKRIBUS_PASSWORD=your-password
The server will automatically log in and manage the session.
Option 2: Direct session ID
export TRANSKRIBUS_SESSION_ID=your-session-id
Use this if you already have a valid session from the Transkribus platform.
Entry Points
| Command | Domains | Tools |
|---|---|---|
transkribus-mcp-server | All 22 domains | 300 |
transkribus-mcp-collections | Auth, Collections (core/docs/pages/users/crowd/editdecl/credits/stats/labels/activity/tags) | 132 |
transkribus-mcp-admin | Auth, Admin, Credits, Uploads, Labels, Files, System, Root | 62 |
transkribus-mcp-transcription | Auth, Recognition, Layout Analysis, PyLaia, P2PaLA, DU | 47 |
transkribus-mcp-users | Auth, Users, Crowdsourcing, eLearning | 29 |
transkribus-mcp-models | Auth, Models | 26 |
transkribus-mcp-jobs | Auth, Jobs, Actions | 18 |
transkribus-mcp-search | Auth, Search, KWS | 16 |
Use split servers to reduce context size — pick only the splits you need.
Claude Code
Add to ~/.claude/settings.json:
{
"mcpServers": {
"transkribus": {
"command": "npx",
"args": ["-y", "@lazyants/transkribus-mcp-server"],
"env": {
"TRANSKRIBUS_USER": "your-email@example.com",
"TRANSKRIBUS_PASSWORD": "your-password"
}
}
}
}
Or use split servers (pick the splits you need):
{
"mcpServers": {
"transkribus-collections": {
"command": "npx",
"args": ["-y", "-p", "@lazyants/transkribus-mcp-server", "transkribus-mcp-collections"],
"env": {
"TRANSKRIBUS_USER": "your-email@example.com",
"TRANSKRIBUS_PASSWORD": "your-password"
}
},
"transkribus-transcription": {
"command": "npx",
"args": ["-y", "-p", "@lazyants/transkribus-mcp-server", "transkribus-mcp-transcription"],
"env": {
"TRANSKRIBUS_USER": "your-email@example.com",
"TRANSKRIBUS_PASSWORD": "your-password"
}
}
}
}
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"transkribus": {
"command": "npx",
"args": ["-y", "@lazyants/transkribus-mcp-server"],
"env": {
"TRANSKRIBUS_USER": "your-email@example.com",
"TRANSKRIBUS_PASSWORD": "your-password"
}
}
}
}
Security
- Never commit your credentials to version control
- Use environment variables or a
.envfile (excluded via.gitignore) - Session IDs expire — prefer username/password for long-running setups
Disclaimer
This is an unofficial MCP server for Transkribus. The authors are not affiliated with READ-COOP SCE. Use at your own risk.
Releasing
Releases ship via the GitHub Release event. Maintainer flow:
-
Bump the version in
package.json,package-lock.json, andserver.json(npm version <x.y.z> --no-git-tag-versionupdates the first two together).npm run check-versionshard-fails unlesspackage.json#/versionandserver.json#/packages[0].versionagree.server.json#/versionis checked loosely: it must be present, and it only fails when it regresses belowpackages[0].version— a value left behind at the previous release passes with aWARN:line and exit 0. The script does not look atpackage-lock.jsonorCHANGELOG.mdat all, so read its output rather than trusting its exit code. -
Update
CHANGELOG.md. -
Commit, and merge the version bump to
mainbefore creating the release. Then create the tag yourself, on a SHA you have checked, and only then create the release from it:V=X.Y.Z && PR=<release-pr-number> && SHA="$(gh pr view "$PR" --json mergeCommit -q .mergeCommit.oid)" && test -n "$SHA" && git fetch origin main && git merge-base --is-ancestor "$SHA" origin/main && PKG="$(git show "$SHA:package.json")" && test "$(printf '%s' "$PKG" | node -pe 'JSON.parse(require("fs").readFileSync(0,"utf8")).version')" = "$V" && CL="$(git show "$SHA:CHANGELOG.md")" && printf '%s\n' "$CL" | awk -v v="$V" 'index($0,"## ["v"]")==1{f=1;next} /^## \[/{f=0} /^\[[0-9]+\.[0-9]+\.[0-9]+\]:/{f=0} f' > "/tmp/notes-v$V.md" && grep -q '[^[:space:]]' "/tmp/notes-v$V.md" && git tag -a "v$V" "$SHA" -m "v$V" && git push origin "v$V" && gh release create "v$V" --verify-tag --notes-file "/tmp/notes-v$V.md"The failure this prevents: with no existing tag,
gh release create vX.Y.Zplaces one on the tip of the default branch. Run it while the bump is still on a release branch and it tags the previous release's commit; the workflow then publishes whatever version it finds in that commit'spackage.json, producing avX.Y.ZGitHub Release that silently republishes the old version. The publish workflow now refuses to continue whenGITHUB_REF_NAMEis notv<package.json version>, so that exact scenario fails beforenpm publishrather than silently republishing. The sequence above is still required, and guards a case the workflow cannot: the workflow guard only runs once a release already exists, and it passes for any commit carrying the right version — so it catches a mis-tagged release, not the wrong commit being tagged.Each element is load-bearing:
gh pr view … .mergeCommit.oidnames the release PR's own squash commit. Do not substitutegit rev-parse origin/main: that is merely whatever sits onmainat the moment you look, so an unrelated merge landing in the gap gets tagged and shipped instead.ghexits 0 and prints nothing for an unmerged PR, hence the explicittest -n.- The
&&chain stops at the first failure instead of falling through to the irreversible step. Bothgit showcalls are assigned to a variable rather than piped directly, so their exit status is actually checked — a pipeline reports only its last command's status unlesspipefailis set, which is not assumed here. git merge-base --is-ancestorproves the commit is reachable frommain. Mere existence is not enough: a commit can be present locally because another branch was fetched, and if its version files happen to match it would otherwise pass every remaining check.- The version test reads
package.jsonout of the target commit, not the working tree — which would still show the right version while$SHApointed elsewhere. - The
awklifts that version's section out of the commit'sCHANGELOG.mdfor--notes-file. Without it the release body is whatever--notes-from-tagfinds in the annotation — here the literal stringvX.Y.Z, a poor release note for any version and a misleading one for a release carrying a breaking change. It stops at the next## [heading or at the first link-reference definition, because the oldest entry has no heading after it and would otherwise swallow the whole link-reference block.grep -qrather thantest -sguards the result: a section empty apart from its blank line still produces a one-byte file, whichtest -saccepts. --verify-tagmakesghabort rather than invent a tag if the push did not land — the guard against the tip-of-default-branch fallback described above.
If
gh release createfails after the tag is already pushed, do not rerun the whole block; it will stop atgit tag, which is correct. Rerun only the final command. -
The
Publish to npm + MCP Registryworkflow runs automatically: itnpm publishes with provenance, polls the registry until the tarball is available, then pushes the matchingserver.jsonto the MCP Registry viamcp-publisher.
The workflow skips npm publish cleanly if the version is already on npm (cutover guard for releases that were partially published manually).
npm authentication
Publishing uses npm Trusted Publishing: the workflow's GitHub OIDC token (id-token: write) is exchanged for a one-shot publish token at runtime. No NPM_TOKEN secret needs to live in the repo.
The binding is configured in the npm web UI (package → Trusted Publishers): provider GitHub Actions, organization lazyants, repository transkribus-mcp-server, workflow publish-registry.yml.
License
FSL-1.1-MIT — see LICENSE for the full terms. Versions 1.x remain MIT-licensed.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
