Technitium MCP
# Technitium MCP


A small tool that lets Claude read and change a
[Technitium DNS Server](https://technitium.com/dns/) through its API.
It runs on your own computer. Your token stays on your computer.
## What Claude can do with it
- Look at stats, settings, zones, logs, and users.
- Turn ad blocking on, off, or pause it.
- Flush the cache and refresh block lists.
- Change settings and zones.
- List, add and delete DNS records (technitium_records).
- Test a lookup (technitium_resolve).
- Anything else in the Technitium API. 137 endpoints are in the catalog.
## Safety
Every call has a safety level.
- **read**: runs right away.
- **change**: does not run until Claude asks you and sets `confirm`.
- **destructive**: deleting, restoring, importing, password changes,
disabling users, and changing ports or listeners.
It also needs the exact endpoint path typed back.
Other protections:
- Login and create-token calls are blocked. They would put a password in the chat.
- The token is never printed. It is removed from error messages.
- File downloads (backups, logs) are saved to a folder. They are not sent to chat.
Default folder: `technitium-downloads` in your home folder.
## Set up
### 1. Make an API token
1. Open the Technitium web page.
2. Go to the Administration part, then Sessions, then create an API token.
Menu names can differ a little by version.
3. Best: make a separate user just for this, and make the token from that user.
Then you can delete it on its own later.
4. Give the token a name, like `Claude`.
**Do not paste the token in a chat.** Put it only in the config file below.
If it ever lands in a chat, delete that token and make a new one.
### 2. Add the tool to Claude
Open the Claude desktop app settings and find the MCP servers config file.
Add the block from `claude_desktop_config.example.json`.
Change the address and token.
- `TECHNITIUM_URL`: your server, like `http://172.16.90.10:5380`
- `TECHNITIUM_TOKEN`: your token
That file now holds a secret. Do not share it. Do not put it on GitHub.
The example uses `uvx`. If you do not have it, use Python instead:
```
pip install D:\GitHub-Projects\technitium-mcp
```
Then use `"command": "technitium-mcp"` and no args.
Restart the Claude desktop app.
### 3. Try it
Ask Claude: "Show my Technitium stats for the last day."
## Other settings
- `TECHNITIUM_VERIFY_TLS=false`: for an https address with a self-signed certificate.
- `TECHNITIUM_TOKEN_IN_QUERY=true`: for an old Technitium version that ignores the
Bearer header. This puts the token in the URL, so avoid it if you can.
- `TECHNITIUM_DOWNLOAD_DIR`: where downloads are saved.
## Test it
```
pip install mcp
python tests/test_server.py
```
The test starts a fake Technitium and checks every tool and every safety rule.
## Limits
- File uploads are not supported yet: zone import, settings restore, and
app install from a file. Installing an app from a URL works.
- Cluster options are in the catalog but not tested.
- Tested against a fake server only. Not yet tested on a real one.
## Credits
Endpoint list built from the official
[Technitium API docs](https://github.com/TechnitiumSoftware/DnsServer/blob/master/APIDOCS.md).
Technitium is made by Technitium. This project is not made by Technitium.
## License
MIT. See [LICENSE](LICENSE).
TDQS
Scored across 11 tools
The generic technitium_call can invoke any endpoint, which overlaps heavily with the specialized wrappers (settings_get/set, blocking, flush_cache, zones, records, stats, resolve), so an agent may struggle to choose between the guided tool and the raw call. technitium_endpoints vs technitium_endpoint_help are also adjacent (discovery vs parameter lookup), though their descriptions distinguish them reasonably well.
All tools share a clear technitium_ prefix in snake_case, which keeps them readable and grouped. However the suffix conventions are mixed: some use noun_verb ordering (endpoint_help, settings_get, settings_set) while others use verb_noun (flush_cache) or bare nouns (stats, zones, records).
11 tools is well within the ideal 3-15 range and each tool maps to a distinct area of DNS server management (settings, blocking, cache, zones, records, resolve, stats, discovery). The set is cohesive without obvious filler.
Core lifecycle coverage is strong: read/write settings, blocking toggle, cache flush, zone listing, record list/add/delete, resolution, and stats, plus a generic call and endpoint discovery as an escape hatch for uncovered APIs. The main gap is in-place record update (only delete+add is documented) and no explicit user/permission or DHCP management, though the raw call partly compensates.