Domeneshop MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_HTTP_TOKEN | No | Required for HTTP; separate random secret, at least 32 characters | |
| DOMENESHOP_TOKEN | Yes | Required upstream API token | |
| DOMENESHOP_SECRET | Yes | Required upstream API secret | |
| MCP_ALLOWED_HOSTS | No | HTTP Host allowlist; local hosts by default; explicit for non-loopback binds | |
| MCP_ALLOWED_ORIGINS | No | Optional exact HTTP Origin allowlist; local origins by default | |
| DOMENESHOP_STATE_DIR | No | Backups/receipts directory | ~/.domeneshop-mcp |
| DOMENESHOP_ALLOW_WRITES | No | Set exactly 'true' to enable apply_plan | false |
| DOMENESHOP_ALLOWED_DOMAINS | No | Optional comma-separated exact domain names; omitted = all |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_domainsA | List account domains; optional substring search. Returns deterministic count. |
| get_domainB | Get domain registration, expiry, nameservers and enabled services. |
| list_dns_recordsB | List DNS, optionally filtering relative host (e.g. @, www) and record type. |
| get_dns_recordC | Read the exact DNS record ID within a domain. |
| create_dns_recordA | Preview adding one record. Identical records are a no-op; use apply_plan to write. |
| update_dns_recordB | Preview replacing the full payload of a specific DNS record, preserving its ID. |
| delete_dns_recordB | Preview deletion of an exact DNS record; shows its current contents. |
| plan_dns_batchA | Preview up to 100 ordered creates/updates/deletes. Batch execution is non-atomic. |
| list_forwardsC | List HTTP/WWW forwards for a domain. |
| get_forwardC | Get the forward for a relative host, e.g. www or @. |
| create_forwardB | Preview a new HTTP forward with DNS collision checks. |
| update_forwardB | Preview updating the existing forward at forward.host. Host cannot be renamed. |
| delete_forwardC | Preview deletion of a specific HTTP forward. |
| update_dynamic_dnsA | Preview DDNS for fully qualified hostnames. Omitted IP requires use_request_ip=true; that mode uses the server's egress IP and cannot verify the intended client IP. |
| list_invoicesA | List invoices from the past three years, optionally by payment status. Invoice URLs may grant access to invoice content; treat them as private. |
| get_invoiceB | Get a single account invoice by invoice number. |
| account_overviewB | Summarize domain counts, statuses and domains expiring within the chosen period. |
| export_zoneB | Export a complete JSON snapshot of DNS and forwards; no filesystem write. |
| ensure_dns_recordsC | Preview idempotent DNS setup/import. By default only adds missing exact records. replace_rrsets=true replaces ALL records of each supplied host/type; other sets stay. |
| setup_websiteB | Preview apex A/AAAA and optional www CNAME. Replaces supplied host/type sets. An omitted address family is preserved. Conflicting www records require explicit resolution. |
| add_verification_txtB | Preview adding a TXT verification token without replacing existing TXT/SPF records. |
| replace_ipB | Preview replacing an exact A/AAAA address across explicitly selected domains. Includes matching mail hosts. Preserves TTL and all unrelated records. |
| copy_dns_recordsA | Preview copying DNS to another domain, optionally selected hosts. Adds only; skips exact duplicates; keeps absolute target names unchanged. |
| audit_dnsA | Inspect configuration for duplicate records, CNAME collisions, multiple SPF and DMARC. This is a bounded configuration check, not a complete email or DNS security audit. |
| restore_dns_backupA | Preview restoring DNS content from this server's pre-change backup ID (= plan ID). Recreated records get new IDs. Forwards require separate explicit changes. |
| get_planB | Read a plan preview or the stored execution result in this process. |
| apply_planA | Execute an authorized preview before it expires. Backs up state, rejects drift, verifies writes by readback and stops on failure. Never automatically replays writes. A multi-operation plan is not atomic. Check returned status, not just tool success. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| prepare_website | Inspect and prepare a website DNS change. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| capabilities |
TDQS
Scored across 27 tools
Most tools have clearly distinct targets (domains vs DNS records vs forwards vs invoices vs plans), and the preview/apply convention is applied consistently. However, several high-level DNS writers (ensure_dns_records, setup_website, replace_ip, copy_dns_records, add_verification_txt) overlap with the primitive create/update/delete_dns_record tools, so an agent must read carefully to choose the right one.
Nearly all names follow a predictable snake_case verb_noun pattern (list_domains, create_dns_record, update_forward, apply_plan). The only real deviation is the noun-first account_overview, which is a minor cosmetic inconsistency.
27 tools is heavy for a single server and sits above the comfortable 3-15 range. The scope is genuinely broad (domains, DNS, forwards, DDNS, invoices, backups, plan lifecycle), so most tools earn their place, but the count is borderline for what could be split.
Coverage is strong: full DNS record CRUD, forwards CRUD, DDNS, invoice retrieval, batch planning, zone export, audit, and backup/restore. The main gap is domain registration lifecycle (no create/delete/transfer/nameserver-set operations on the domain itself), but core DNS and account workflows are covered.