Skip to main content
Glama
README.md
# Hostkey MCP Server

MCP server for [Hostkey](https://hostkey.com/) (**.com** portal, InvAPI `invapi.hostkey.com`).
Runs locally over stdio — Cursor, VS Code, and other MCP clients.

| | |
|---|---|
| **Endpoint** | `https://invapi.hostkey.com` (hardcoded) |
| **Auth** | `HOSTKEY_API_KEY` |
| **Tools** | 132 typed tools + `call_api_raw` |

Gives the model access to your Hostkey account: servers, catalog and ordering, power, OS reinstall,
network, DNS, snapshots, IPMI/console, ISO, S3, Remote Hands, billing, and API keys.

For the **.ru** portal use the separate package `hostkey-mcp-server-ru`.

## 1. Get an API key

[InvAPI](https://invapi.hostkey.com) → API keys → create a key.

Prefer a dedicated key for MCP. Per-server keys limit access to one server.
DNS writes need the `pdns/edit` permission.

## 2. Install

### Cursor

`.cursor/mcp.json`:

```json
{
  "mcpServers": {
    "hostkey-mcp-server": {
      "command": "npx",
      "args": ["-y", "hostkey-mcp-server"],
      "env": {
        "HOSTKEY_API_KEY": "your-api-key"
      }
    }
  }
}
```

### VS Code

`.vscode/mcp.json`:

```json
{
  "mcp.servers": {
    "hostkey-mcp-server": {
      "command": "npx",
      "args": ["-y", "hostkey-mcp-server"],
      "env": {
        "HOSTKEY_API_KEY": "your-api-key"
      }
    }
  }
}
```

Optional: `HOSTKEY_TOKEN_TTL`, `HOSTKEY_HTTP_TIMEOUT`, `HOSTKEY_ALLOW_DESTRUCTIVE`
(see `.env.example`).

From source (Node.js ≥ 20): `npm install && npm run build`.

## 3. Confirming dangerous operations

Every write call needs `confirm=true`. Without it, nothing changes.

Also:

- `order_server` defaults to `dry_run` — a real order only after explicit consent;
- OS reinstall, PXE, and service cancellation require `HOSTKEY_ALLOW_DESTRUCTIVE=1`;
- passwords and tokens are masked in responses.

Long jobs (deploy, reinstall) return a callback key — poll with `check_task`.

## 4. Tools

Groups (full list via `tools/list`):

| Group | Examples |
|---|---|
| Servers | `get_servers`, `get_server`, `get_power_status` |
| Catalog | `list_presets`, `list_os`, `list_traffic_plans` |
| Power & order | `power_on`, `power_off`, `order_server`, `reinstall_server` |
| PXE | `create_reinstall_task` → … → `clear_pxe_config` |
| Network / DNS | ports, PTR, zones and records |
| Snapshots, ISO, S3 | VM snapshots, images, buckets |
| Remote Hands | duty-shift tickets (`request_rh_*`, `rhr_*`) |
| Billing | invoices, payments, contacts |
| Misc | `check_task`, `call_api_raw` |

## Prompts

| Prompt | Purpose |
|---|---|
| `order_server_prompt` | guided server order |
| `reinstall_server_prompt` | OS reinstall |
| `troubleshoot_server_prompt` | diagnostics |

Or just ask: “list my servers” / “order a VPS in NL”.

TDQS

B3.2/5.0

Scored across 132 tools

Disambiguation3/5

Many tools are distinct, but there are overlapping concepts like DNS zones vs. domains, and multiple tools for listing buckets (s3_get_buckets vs s3_get_buckets_via_queue). The sheer volume (132) increases the chance of misselection despite clear descriptions.

Naming Consistency4/5

Most tools follow a verb_noun pattern (e.g., get_invoice, create_api_key, delete_dns_record). However, there are inconsistencies like 'logout', 'port_on/off' vs 'power_on/off', and some tools use different verb forms (list vs get, create vs add) for similar operations.

Tool Count1/5

132 tools is extreme and overwhelming for an MCP server. Even a comprehensive hosting API would be better split into multiple focused servers. The count far exceeds practical usability and increases cognitive load for agents.

Completeness4/5

The tool surface covers a wide range of domains: server management, billing, DNS, S3, remote hands, and API key management. There is a raw API call tool for gaps, making the coverage quite comprehensive. Minor gaps exist (e.g., no direct server hostname update tool), but they are addressable.

Maintenance

ActivityMaintained
ResponsivenessNo issues