Skip to main content
Glama
649,985 tools. Updated 2026-10-11 05:51

"Let's Encrypt" matching MCP tools:

  • Start issuing a FREE 90-day Let's Encrypt certificate for a domain (no account required). Step 1 of 3. Pick a validation method with `challenge`: "dns-01" (default; publish a TXT record; covers apex + www) or "http-01" (serve a file over HTTP on port 80; issues the exact domain only). dns-01 with a DNS-provider API token is the most automatable; http-01 suits a server you control on port 80. Returns an order_id plus either dns_records (dns-01) or http_files (http-01) to put in place. Next: poll `check_certificate_propagation` until all_found, then call `finalize_certificate`. Strongly prefer the CSR path at finalize (the private key never leaves the user's machine). Issuing automatically offers the user ongoing monitoring by email once it completes - don't add a monitor manually afterward.
    ConnectorNo auth
  • Finalize and issue a certificate order in one call: validates the DNS challenges, waits for Let's Encrypt, and returns the issued cert. Step 3 of issuance - call after check_certificate_propagation reports all_found. STRONGLY PREFER passing csr_pem (generate the key + CSR locally with openssl so the private key never leaves the machine). Returns leaf_pem/chain_pem/fullchain_pem. If you must, pass a passphrase instead to get a PKCS#12 bundle - but a CSR is safer. If it replies "still validating", DNS hasn't fully propagated: re-check check_certificate_propagation and call again. Needs a locally-generated CSR (csr_pem) - requires a local shell with openssl. On a surface without one (e.g. a Claude.ai custom connector) this can't complete; it returns guidance to finish in Claude Code/Cowork or the web form. Scanning and monitoring work everywhere. On success the structuredContent carries a `handoff` object - relay `handoff.message` to the user and do NOT separately call add_monitor; the cert→monitoring handoff is automatic and server-side.
    ConnectorNo auth
  • Relays a message you sealed locally with /svc/msg2-sdk.mjs (seal(mailbox, inner) → {ephemeralPubKey, viewTag, ct}). This tool cannot encrypt for you: sending plaintext here would expose it to the relay, so it only accepts the sealed triple. Replay-idempotent (a resend returns duplicate:true). The message appears in the public feed at releaseAt. If you cannot run the SDK, use v1 (POST /api/messages/send) and know that v1 is plaintext.
    ConnectorNo auth
  • [other] [symmetric_cipher] AES-XTS 可调窄分组模式加解密(IEEE 1619 / NIST SP 800-38E)。algorithm 可选 AES128XTS(key 32B = 数据密钥 16B + 调组密钥 16B)或 AES256XTS(key 64B = 32B + 32B)。tweak_in_hex 为 16 字节调整值,编码数据单元编号/扇区地址,密文与数据单元位置绑定。process_type 可选 Encrypt / Decrypt(两个变换不同,须显式声明)。输入 16B ~ 16MB,无填充,密文与明文等长;非 16 倍数的尾部自动走密文窃取(ciphertext stealing)。模式特点:各数据单元独立加密,支持并行与随机访问,同一数据单元加解密自同步;同一密钥下 tweak 严禁重复使用(否则两个数据单元明文相同会直接暴露相等关系);XTS 只提供保密性、可塑性攻击下无认证,需要防篡改时在外层叠加 AEAD 或签名。典型使用场景:BitLocker / LUKS2 / FileVault 全盘加密,AMD SEV-SNP 以 AES-256-XTS + VEK 加密 guest 内存(tweak 按物理地址派生,每页唯一),Intel TDX 内存加密同族。返回字段:output_data_in_hex、output_length、output_sha256、algorithm。
    ConnectorNo auth
  • Create an Eveoy checkout and return a payment link. Pricing mirrors the order page: $24.99 per verified customer base, plus two options — a guaranteed purchase (guarantee_type "visit_purchase": every shopper buys your chosen SKU at your register; you add the SKU price in cents, tax included, $5–$100, at cost — no item fee) and a shopper bonus ($20–$200 per shopper, 33% platform fee on the bonus only — the only platform fee; every $20 = +1 photo and +1 social set per shopper, max +3 each). Omit guarantee_type for a visit-only order. The server recomputes the total — what get_pricing quotes is exactly what Stripe charges. Works for agents directly — no sign-in required. Use this when the user has decided to buy and confirmed the size: - They picked a customers-per-location count (and optionally locations, guarantee, SKU price, bonus) and want to pay - Trigger phrases: "buy a pilot", "start checkout", "place an order", "let's order 100 customers with a guaranteed purchase" Provide your_name, work_email, brand_website, and campaign_start_date (at least 14 days out) — or call capture_profile first and I will reuse your saved details, then I only need campaign_start_date. For a guaranteed purchase also provide top_sku_price_cents. Returns: { checkout_url, session_id, total, customers, guarantee_type, fee_breakdown } — pay on Stripe's hosted page; no charge until then. Do NOT use this for: price-only questions (use get_pricing), saving your company (use capture_profile), or order status (use check_order_status). Confirm the customer count, guarantee choice, and total with the user first. Cost: free to call. Latency: 2-5s. Creates a real checkout session and a CRM deal (no charge until the user pays). Confirm first.
    ConnectorNo auth
  • Disable a managed KMS key: new encrypt/sign operations are blocked, while data already encrypted under it stays decryptable locally by existing grantees. Reversible only by an operator re-enabling the key — there is no enable tool here. Use kms_revoke_grant instead to cut off ONE principal while the key stays in service. Find the id with kms_list_keys. Returns the updated key, with `disabledAt` now set.
    Connector
    Destructive
    No auth

Matching MCP Servers

Matching MCP Connectors

  • SSL/TLS scanning, free Let's Encrypt issuance, and certificate-expiry monitoring.

  • 14 PDF tools: merge, split, compress, watermark, encrypt, organize, metadata, page extraction.

  • Create a new project on sota.io. Each project automatically provisions: (1) a managed PostgreSQL 17 database accessible via the DATABASE_URL environment variable (auto-injected, no configuration needed), (2) PgBouncer connection pooling (pool size 20, max 100 clients), (3) automatic daily database backups with 7-day retention, (4) a live URL at https://{slug}.sota.io with automatic HTTPS via Let's Encrypt. The project slug is auto-generated from the name (lowercase, hyphens, max 63 chars) and is immutable after creation. Supported frameworks: Next.js, Node.js (Express/Fastify/Koa), Python (Flask/FastAPI/Django), or any language via custom Dockerfile. You can also add up to 5 custom domains per project with automatic HTTPS (via API: POST /v1/projects/:id/domains with {domain: "yourdomain.com"}). DNS: A record to 23.88.45.28 for apex domains, CNAME to {slug}.sota.io for subdomains. Optionally associate the project with a public git repository at create-time by passing `git_url` (and optional `git_branch`). The association is informational — it shows up in the dashboard and the `sota deploy --git` CLI flag can default to it — but does NOT enable auto-deploy-on-push yet.
    ConnectorNo auth
  • Add a custom domain to a sota.io project. Each project supports up to 5 custom domains with automatic HTTPS via Let's Encrypt. Returns DNS setup instructions: for apex domains (example.com), add an A record pointing to 23.88.45.28; for subdomains (app.example.com), add a CNAME record pointing to {slug}.sota.io. Domain statuses: pending (waiting for DNS) → verified (SSL provisioning) → active (live with HTTPS). After DNS is configured, verification and SSL provisioning happen automatically.
    ConnectorNo auth
  • ALWAYS call this — don't just say 'open the Fixidu app' or 'go to fixidu.com' in prose without calling it — whenever you tell a user to book, check out, pay, or manage their account. Never send someone to 'the app' without also handing them this real, clickable link; a name alone isn't enough for someone who doesn't have it installed. Triggers include: the user says 'book now'/'book it'/'let's book' or anything meaning that, you're about to tell them booking/payment/checkout must happen in the app, or you don't know whether they even have the app installed yet (default to assuming they might not — call this rather than skip it). Returns the real Play Store / App Store link for their platform. If their platform isn't known, ask or just return both.
    ConnectorNo auth
  • Stellt ein neues Let's-Encrypt-SSL-Zertifikat für eine Domain aus (über sslit) und ersetzt damit das aktuelle Zertifikat. Sichert standardmäßig die Domain selbst, www und webmail; mail.<domain> nur auf Wunsch (include_mail), da das einen bereits existierenden mail.<domain>-DNS-Record voraussetzt und sonst mit einer konkreten Fehlermeldung fehlschlägt. Let's Encrypt erlaubt nur 5 identische Zertifikate pro Woche. Dagegen schützen zwei Prüfungen, die beide ihre Grenzen nennen: (1) gezählt werden die Ausstellungen, die in den letzten 7 Tagen ÜBER TURBOPRESS für diese Domain liefen (eigenes Prüfprotokoll) — ab 5 wird abgelehnt; Ausstellungen über das Plesk-Panel oder einen anderen Anbieter zählt diese Zahl nicht mit, sie ist also eine Untergrenze, keine Bilanz des Kontingents. (2) eine Frischeprüfung am live ausgelieferten Zertifikat: Stammt es von Let's Encrypt und ist es weniger als 7 Tage alt, wird ebenfalls abgelehnt — das ist ein Indiz, keine Zählung, und es sagt nur, WAS ausgeliefert wird, nicht wer es ausgestellt hat (ein vorgeschaltetes CDN/Proxy kann ein fremdes sein). force=true übergeht beides. Konnte eine der beiden Prüfungen nicht greifen (TLS-Handshake fehlgeschlagen oder Protokoll unlesbar), fällt der Schutz NICHT stillschweigend aus: Die Antwort sagt dann ausdrücklich, dass er nur unvollständig gegriffen hat. Antwortet mit dem live bestätigten Ergebnis (Aussteller, abgedeckte Namen, Gültigkeit) — oder ausdrücklich als unbestätigt, wenn die Live-Verifikation nicht möglich war.
    Connector
    Destructive
    OAuth
  • Encrypt a PDF with a password (AES). The result requires the password to open. Returns base64.
    ConnectorNo auth
  • Return the current state of a certificate order (dns_pending, validating, ready, completed, failed) and per-authorization Let's Encrypt statuses. Use it to resume an interrupted issuance.
    ConnectorNo auth
  • Revoke a service token by id. Future key fetches by that token stop immediately, so any workload still using it loses access on its next read. If the holder may have cached the key already, also rotate the environment on the local crypto plane — revocation alone does not re-encrypt anything. Find the id with list_tokens. Returns { ok, tokenId }.
    Connector
    Destructive
    No auth
  • Save where the work got to, in a STRUCTURED shape so the next invocation can actually act on it. FREE. `objective` and `next_action` are REQUIRED and a checkpoint without them is refused — a vague checkpoint produces a vague briefing, so the schema is the guardrail. Work state is small: aim for a few kilobytes, not a transcript. The ENVELOPE (objective, next_action, status, files, risks and the rest) is cleartext and is what resume_packet synthesizes from. The BODY (`body`, `state`, `provider_extras`) is opaque — never parsed, indexed or logged in any mode. Set privacy_mode:'client_key' and encrypt the body yourself if it is sensitive; we then cannot read it and never hold your key. FREE — this tool never charges. Authenticate with Authorization: Bearer <agent_secret>, or pass agent_key as an argument if your host cannot set headers. Equivalent HTTP route: POST /v1/checkpoint/put.
    ConnectorNo auth
  • Get the REST endpoint for long-running Noir proof generation. This hosted tool redirects; it does not generate a proof inside the MCP call. POST https://ai.zkproofport.app/api/v1/prove POST with {circuit} → 402 challenge with live accepts → sign the selected payment offer → retry with circuit-specific inputs and PAYMENT-SIGNATURE; include X-Payment-Nonce when supplied. Encrypt inputs only when the challenge supplies teePublicKey. Legacy X-Payment-TX requires X-Payment-Nonce. Action binding is optional for arc_eligibility and giwa_attestation: send both domain_separator and action_hash for a signed EIP-712 action, or omit both for an identity-only proof. Other circuits do not support actions. This deployment provides no hardware TEE attestation. HTTPS protects transport, but the prover receives proof inputs. Read the canonical guide before preparing inputs: - coinbase_attestation: https://ai.zkproofport.app/api/v1/guide/coinbase_attestation - coinbase_country_attestation: https://ai.zkproofport.app/api/v1/guide/coinbase_country_attestation - oidc_domain_attestation: https://ai.zkproofport.app/api/v1/guide/oidc_domain_attestation - arc_eligibility: https://ai.zkproofport.app/api/v1/guide/arc_eligibility - giwa_attestation: https://ai.zkproofport.app/api/v1/guide/giwa_attestation
    ConnectorNo auth
  • Publish a Let's Encrypt DNS-01 challenge: creates a TXT record at _acme-challenge.<label>.<domain> with the token your ACME client printed. Use this to get a certificate without exposing port 80 (for example for a wildcard cert, or a host behind NAT). DNS propagates within seconds, then tell your ACME client to continue. For a normal public web server, HTTP-01 validation needs no DNS record at all.
    ConnectorNo auth
  • Upload an encrypted diagnostic bundle when the operator's node has problems. The bundle is encrypted client-side with a retrieval code the operator must share with support before logs can be read. Use this when the operator reports errors, crashes, or misbehavior. The pcc-node CLI runs `pcc-node logs --send` locally to collect+encrypt; prefer that path when available. This tool is for agent-driven uploads when the bundle is already prepared.
    ConnectorNo auth
  • Convert a UTF-8 string into standard Base64 when you need a portable text encoding for credentials, binary-safe transport, or embedding data in JSON/HTTP fields. Use when: - Encode this UTF-8 string as Base64 - Convert plain text into standard Base64 for transport - Produce a Base64 representation of a credential or payload string Do not use when: - Decode Base64 back to text (use base64_decode) - Percent-encode URL components (use url_encode) - Hash or encrypt data for security—Base64 is encoding only
    ConnectorNo auth
  • Convert a UTF-8 string into standard Base64 when you need a portable text encoding for credentials, binary-safe transport, or embedding data in JSON/HTTP fields. Use when: - Encode this UTF-8 string as Base64 - Convert plain text into standard Base64 for transport - Produce a Base64 representation of a credential or payload string Do not use when: - Decode Base64 back to text (use base64_decode) - Percent-encode URL components (use url_encode) - Hash or encrypt data for security—Base64 is encoding only
    ConnectorNo auth
  • Record a mandate: what you were told (instruction), what you did (action) and optionally what came of it (outcome), each as text or as its sha-256. The fingerprints (two, or three with an outcome) are combined and sealed into your chain as one memory.seal, so every later stamp, witness signature and anchor covers them. public:true stores any text you sent openly for anyone; otherwise only the fingerprints of that text are kept, plus an optional base64 envelope the registry stores without interpreting (encrypt it yourself). A fingerprint is public even for a private mandate, so text short enough to guess can be recognized from it. Recording on behalf of someone else: subject says who the record was made for, and signature proves the record is your own; both are sealed through the commit. Returns the mandate id, its page, the commit payload and how to verify. WRITES: this call changes stored state and is not safe to repeat blindly.
    ConnectorNo auth