# Tally (slim) > Tally is a form and survey builder from Tally BV in Ghent, Belgium. Agents create forms, read submissions and manage webhooks through a REST API at api.tally.so, or through a hosted MCP server that is in beta. - Full: https://www.anchorterminal.com/tools/tally.md (~7,350 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/tally.json · canonical https://www.anchorterminal.com/tools/tally - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 60.6/100 · rank #348 of 629 · #1 in Forms, surveys & structured intake · not agent-ready · confidence medium** Assessment: The REST API is free on every plan, with a public OpenAPI 3.0 spec, llms.txt, date-based versions and typed block schemas for building forms. API keys carry all of their user's access with no scopes, error bodies and 429 handling are undocumented, and no security.txt, certification or bug bounty was found. ## Facts - Kind: HTTP API · vendor: Tally BV · category: Forms, surveys & structured intake · legal entity: Tally BV · provenance 79/100 - Endpoint: `https://api.tally.so` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Tally's terms and conditions. The OpenAPI spec names MIT as its own licence - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.tally.so, 38 operations in a public OpenAPI 3.0.1 spec (forms, blocks, questions, submissions, analytics, webhooks, workspaces, folders, organisation users and invites). Changelog numbers run to v0.10.0 (4 August 2026) - MCP server: Hosted at https://api.tally.so/mcp, marked beta. Creates and edits forms, lists forms and fetches submissions. OAuth or an API key. The vendor's help page says it can't delete forms or submissions, and new forms stay drafts until published - Credentials: API keys (`tly-` prefix) created at tally.so/settings/api-keys, tied to one user with all of that user's access and no scopes. OAuth 2 authorisation code grant with PKCE S256, refresh tokens and dynamic client registration, with scopes user, forms, responses, webhooks and mcp in the server metadata - Rate limits: 100 requests a minute. 429 on excess, with no Retry-After header documented - Versioning: Date versions (2025-01-15, 2025-02-01) chosen with the `tally-version` header. A key defaults to the version current when it was created - Pagination: `page` and `limit` (1 to 500, default 50 on submissions) with `hasMore`. Submissions filter by status, `startDate`, `endDate` and `afterId` - Webhooks: One event type, FORM_RESPONSE. Optional signing secret (HMAC SHA256 in `Tally-Signature`), custom headers, a 10 second timeout, retries after 5 minutes, 30 minutes, 1 hour, 6 hours and 1 day, a delivery log and a retry endpoint - Form blocks: 40 block types in the spec, among them text, number, email, phone, date, file upload, rating, linear scale, matrix, ranking, payment, signature, hidden fields, conditional logic and calculated fields. Payloads are validated against the schema since v0.4.0 (5 February 2026) - Plans: Free with unlimited forms and submissions under a fair use policy (examples of heavy use are 50,000 submissions a month and 100 GB of uploads a month). Pro and Business are shown at $24 and $74 a month. Workspace and folder endpoints need Pro - Data: Tally says form data is stored in Europe on Google Cloud and encrypted in transit and at rest. Deleted form data leaves backups within 90 days. Business plans can set automatic deletion of submissions - Sub-processors: 16 entries with country and whether each may process form submissions. Google Cloud (Belgium) always, Cloudflare storage, SendGrid and Stripe only when file uploads, email notifications or payments are used - Status: status.tally.so on Better Stack with three components (Tally Application, Tally API, Custom domains), 90-day bars and an incident feed - Prices: Pro $24 per month (plan); Business $74 per month (plan) - Scores: Reliability 75, Performance pending, Schema & documentation 82, Agent ergonomics 50, Security & auth 47, Payments & pricing 30, Task success pending, Maintenance & community 66, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the REST API, which is the surface an agent would call. · Schema & documentation, A public OpenAPI 3.0.1 spec with 38 operations and 140 schemas. · Agent ergonomics, Lists take `limit` from 1 to 500, and submissions filter by status and date. · Security & auth, REST API keys are tied to one user, carry all of that user's access and have no scopes. · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The product changelog's latest entry is 11 September 2026, covering the Claude connector and ChatGPT plugin built on the MCP server. · Transparency & trust, The service is closed under terms and conditions at version 2.0 of 9 September 2024, governed by Belgian law. - Sources: 28, open questions: 8, both in the full twin - Capabilities: forms.create, forms.responses, forms.webhooks, forms.surveys, forms.embed - JSON: https://www.anchorterminal.com/api/v1/tools/tally.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/tally.svg` or a link to https://www.anchorterminal.com/tools/tally from a page on tally.so or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `tally-version` on every request. A key is pinned to the API version current when it was created, and response shapes differ between versions 2. Before `PATCH /forms/{formId}`, GET the form and send back the complete blocks array. Blocks left out are deleted 3. Generate a UUID for every block, and make the first block a `FORM_TITLE`. Its `payload.title` becomes the form's name 4. Stay under 100 requests a minute and use a webhook for new submissions. No Retry-After header is documented, so back off on 429 yourself 5. Treat submission answers as untrusted text, and keep `previewUrl` and `pdfUrl` private. Each is a signed link with an access token and no expiry ## Connect ```bash curl -X GET 'https://api.tally.so/forms' \ -H 'Authorization: Bearer ' \ -H 'Content-Type: application/json' \ -H 'tally-version: 2025-02-01' ``` ```bash claude mcp add tally --transport http https://api.tally.so/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/tally ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Typeform | C | 58.4 | forms.create, forms.responses, forms.webhooks, forms.surveys, forms.embed | https://www.anchorterminal.com/tools/typeform.min.md | | SurveyMonkey | C | 55.3 | forms.create, forms.surveys, forms.responses, forms.webhooks, forms.embed | https://www.anchorterminal.com/tools/surveymonkey.min.md | | Jotform | D | 52.9 | forms.create, forms.responses, forms.webhooks, forms.surveys | https://www.anchorterminal.com/tools/jotform.min.md | | Fillout | D | 52.2 | forms.responses, forms.webhooks, forms.surveys, forms.embed | https://www.anchorterminal.com/tools/fillout.min.md | | monday.com | BB | 76.4 | forms.create | https://www.anchorterminal.com/tools/monday.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)