# OSIR Domain Registrar (remote · be.osir.com)

Register, renew, transfer, and manage domains, DNS, VPS, and email with 105 tools. By OSIR.

- Trust score: 79/100 (medium)
- Change this week: +4
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-24

> **Recent critical change**: Authorization (2026-09-03). See the changelog below before you install this server.

## Components

- remote · `be.osir.com`: 79/100 (this document), [markdown](https://verifymcp.io/servers/com-osir-domain-registrar/be.md), [page](https://verifymcp.io/servers/com-osir-domain-registrar/be)

## Channel facts

- Endpoint: `https://be.osir.com/mcp/http`
- Transports: `streamable-http`
- Auth: `none`
- Version: `2.4.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-24.

- **Endpoint Security**: 66/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (buildVpsInstance).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 79/100
  - 85% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 14561 tokens (~136/item across 107 items; 105 tools + 2 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 73/100
  - Stability observed for 22 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (10% of tools); any adoption earns full credit.
- **Tool Safety**: 97/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 14 of 16 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "getTransferQuote" implies "transfer" and declares readOnlyHint instead, contradicting what its own name says it does.
  - An AI judge read all 107 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the OSIR Domain Registrar MCP server?

OSIR Domain Registrar is a hosted endpoint at https://be.osir.com/mcp/http, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-osir-domain-registrar 'https://be.osir.com/mcp/http'
```

### Cursor

```json
{
  "mcpServers": {
    "com-osir-domain-registrar": {
      "url": "https://be.osir.com/mcp/http"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-osir-domain-registrar": {
      "type": "http",
      "url": "https://be.osir.com/mcp/http"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-osir-domain-registrar]
url = "https://be.osir.com/mcp/http"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-osir-domain-registrar": {
      "type": "remote",
      "url": "https://be.osir.com/mcp/http",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-osir-domain-registrar --url 'https://be.osir.com/mcp/http' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-osir-domain-registrar:
    url: "https://be.osir.com/mcp/http"
```

### Netclaw

```json
{
  "McpServers": {
    "com-osir-domain-registrar": {
      "Transport": "http",
      "Url": "https://be.osir.com/mcp/http"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-osir-domain-registrar -t streamable-http -u 'https://be.osir.com/mcp/http'
```

### Other

```json
{
  "mcpServers": {
    "com-osir-domain-registrar": {
      "type": "http",
      "url": "https://be.osir.com/mcp/http"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-24 (score 79, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-22 (score 78, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-20 (score 77, +1)

- [security] Tool “osirAppDeploy” rewrote its description, which is the text the model reads
- [security] Tool “osirAppMoveToOwned” rewrote its description, which is the text the model reads
- [security] Tool “osirAppStatus” rewrote its description, which is the text the model reads
- [security] Tool “osirSitePublish” rewrote its description, which is the text the model reads

### 2026-09-18 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 74, 0)

- [security] Tool “changeVpsPaymentTerm” rewrote its description, which is the text the model reads
- [security] Tool “deleteSshKey” rewrote its description, which is the text the model reads

### 2026-09-13 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-11 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (105)

### `addPrefixToDomain` (~118 tokens)

addPrefixToDomain: Generate domain suggestions by adding prefixes to a base name.

Input parameters:

- `lang` (string): Language code; default "eng".
- `maxResults` (integer): Maximum suggestions to return; default 20.
- `name` (string, required): Base name to prefix, e.g. "mycompany".
- `tlds` (string): Comma-separated TLDs without leading dots, e.g. "com,net".
- `vocabulary` (string): Prefix vocabulary: "@prefixes" or a custom comma-separated list.

### `addSshKey` (~172 tokens)

addSshKey: Store an SSH public key on your account so it can be injected into VPS installs. Idempotent: storing a key you already have returns the existing one instead of creating a duplicate, so it is safe to call before every order. Returns the key id to pass to orderVps or buildVpsInstance. Requires authentication.

Input parameters:

- `name` (string, required): A label for the key, e.g. 'laptop'.
- `publicKey` (string, required): The full single-line OpenSSH public key, e.g. 'ssh-ed25519 AAAA... user@host'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `addSuffixToDomain` (~120 tokens)

addSuffixToDomain: Generate domain suggestions by adding suffixes to a base name.

Input parameters:

- `lang` (string): Language code; default "eng".
- `maxResults` (integer): Maximum suggestions to return; default 20.
- `name` (string, required): Base name to suffix, e.g. "mycompany".
- `tlds` (string): Comma-separated TLDs without leading dots, e.g. "com,net".
- `vocabulary` (string): Suffix vocabulary: "@suffixes" or a custom comma-separated list.

### `buildVpsInstance` (~287 tokens)

buildVpsInstance: Stage an operating system install (or reinstall) on a VPS instance. DESTRUCTIVE: ERASES ALL DATA on the server, including any deployed application, and cannot be undone. The install is asynchronous; afterwards poll getVpsInstanceDetails until buildState is COMPLETE. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `hostname` (string): Hostname for the rebuilt server; defaults to the instance's current hostname.
- `instanceId` (string, required): VPS instance id from listMyVpsInstances.
- `operatingSystemId` (integer, required): Integer OS template id from listVpsOsTemplates, resolved with this same instanceId.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `sshKeyIds` (array): Integer SSH key ids from listMySshKeys, injected during install; without one you may not be able to log in.
- `swap` (number): Swap size: 256, 512, or 768 (MB), or 1, 1.5, 2, 3, 4, 5, 6, or 8 (GB).

### `bulkDomainSuggestions` (~173 tokens)

bulkDomainSuggestions: Generate domain suggestions for 1-10 keywords across 1-6 TLDs (hard cap), grouped by originating keyword. Typical flow: call listCategorizedTlds first to pick 3-6 TLDs, then this tool. Per-suggestion availability may be "available", "taken", or "unknown"; confirm "unknown" or premium-TLD names with checkDomainAvailability before recommending.

Input parameters:

- `keywords` (array, required): 1-10 keywords describing the project.
- `lang` (string): Language code; default "eng".
- `maxResults` (integer): Maximum suggestions per keyword; default 20.
- `tlds` (array, required): 1-6 TLDs without leading dots (use "tech", not ".tech"), chosen from listCategorizedTlds.

### `cancelTransfer` (~119 tokens)

cancelTransfer: Stage cancellation of a pending domain transfer. DESTRUCTIVE and irreversible once executed. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `domain` (string, required): Fully qualified domain name whose pending transfer to cancel, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `changeVpsPaymentTerm` (~165 tokens)

changeVpsPaymentTerm: Stage a change of the payment term (billing cycle) for a VPS instance. Affects what you are billed. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `instanceId` (string, required): VPS instance id from listMyVpsInstances.
- `paymentTerm` (string, required): New billing cycle: 'MONTHLY', 'SEMI_ANNUAL', 'ANNUAL', 'BIENNIAL', or 'TRIENNIAL'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `checkDeviceLoginStatus` (~91 tokens)

checkDeviceLoginStatus: Poll for device login completion. Call this after loginWithDevice() once you have opened the verification URL and signed in. Required: deviceCode (the device_code returned by loginWithDevice). On success returns a sessionKey; pass it as the sessionKey argument on every subsequent authenticated tool call.

Input parameters:

- `deviceCode` (string, required): The device_code value returned by loginWithDevice.

Output parameters:

- `expiresIn` (integer)
- `message` (string)
- `sessionKey` (string)
- `status` (string)
- `success` (boolean)
- `tokenType` (string)

### `checkDomainAvailability` (~116 tokens)

checkDomainAvailability: Check if a domain name is available for registration, with price. No authentication required; anonymous callers get list pricing, authenticated callers get their account pricing. Required: domain (e.g., 'example.com')

Input parameters:

- `domain` (string, required): Fully qualified domain name to check, like "example.com", without scheme.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

Output parameters:

- `available` (boolean)
- `currency` (string)
- `domain` (string)
- `isPremium` (boolean)
- `message` (string)
- `price` (number)

### `checkHostAvailability` (~104 tokens)

checkHostAvailability: Check if a host/glue record name is available for creation. Requires authentication. Returns whether the hostname is free; call before createHost.

Input parameters:

- `hostname` (string, required): Fully qualified host name to check, e.g. 'ns1.example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `checkKeywordAvailability` (~120 tokens)

checkKeywordAvailability: Check keyword availability across all supported TLDs and registries with detailed per-domain results. Use checkKeywordAvailabilitySummary instead when you only need counts; it is faster.

Input parameters:

- `keyword` (string, required): Keyword to check, without a TLD, e.g. "example".
- `registries` (string): Comma-separated registry filter, e.g. "verisign,pir,id,centralnic".
- `tlds` (string): Comma-separated TLDs without leading dots, e.g. "com,net".

### `checkKeywordAvailabilitySummary` (~110 tokens)

checkKeywordAvailabilitySummary: Check keyword availability across TLDs and registries. Summary statistics only (no per-domain results), faster than checkKeywordAvailability.

Input parameters:

- `keyword` (string, required): Keyword to check, without a TLD, e.g. "example".
- `registries` (string): Comma-separated registry filter, e.g. "verisign,pir".
- `tlds` (string): Comma-separated TLDs without leading dots, e.g. "com,net".

### `countMyVpsInstances` (~74 tokens)

countMyVpsInstances: Get the total count of VPS instances owned by the authenticated user. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `createAccount` (~326 tokens)

createAccount: Create a new OSIR customer account; step 1 of onboarding, no authentication required. The contact must be the PRINCIPAL's real ICANN registrant contact (the human or business the account is for), never the AI agent itself. Sends a verification email; complete via verifyAccount with the emailed code. While PENDING_VERIFICATION the account can search, quote and fund; billable actions need ACTIVE. Calling again for a PENDING account re-sends the verification email.

Input parameters:

- `acceptedTerms` (boolean, required): Must be true; requires the principal's actual consent to the OSIR terms of service.
- `accountType` (string, required): Account type: INDIVIDUAL or ORGANIZATION.
- `agentName` (string): Name of the AI agent acting for the principal, recorded for the audit trail.
- `agentVendor` (string): Vendor of the AI agent acting for the principal, recorded for the audit trail.
- `contact` (object, required): The principal's real ICANN registrant contact (firstName, lastName, email, phone, street1, city, country), never the AI agent itself.
- `email` (string, required): Account login email; valid mailbox that receives the verification code.
- `password` (string): Optional account password; if omitted the account is agent-managed until a password is set.
- `principalReference` (string): Principal's own reference identifying who the agent acted for, recorded for the audit trail.
- `termsVersion` (string, required): Version of the OSIR terms the principal accepted, e.g. '2026-09'.

Output parameters:

- `accountId` (string)
- `contactId` (string)
- `nextSteps` (array)
- `status` (string)
- `verification` (object)

### `createContact` (~245 tokens)

createContact: Create a new contact for use with domain registrations. Requires authentication. Returns the created contact including its id for assignment to domains.

Input parameters:

- `city` (string, required): City name.
- `country` (string, required): Country as a 2-letter ISO 3166-1 alpha-2 code, e.g. 'US'.
- `email` (string, required): Contact's email address.
- `firstName` (string, required): Contact's first name.
- `lastName` (string, required): Contact's last name.
- `organization` (string): Organization or company name, if any.
- `phone` (string, required): Phone number in '+CC.number' format, e.g. '+1.5551234567'.
- `postalCode` (string, required): Postal or ZIP code.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `state` (string): State, province, or region, if applicable.
- `street1` (string, required): First street address line.
- `street2` (string): Second street address line, if needed.

### `createDnsRecord` (~254 tokens)

createDnsRecord: Create a new DNS record for a domain. Requires authentication. For newly registered domains the zone is initialized automatically if missing. Returns the created record including its id for later updates or deletion.

Input parameters:

- `content` (string, required): Record value, e.g. an IPv4 dotted-quad or IPv6 address for A/AAAA, a hostname for CNAME/MX/NS, or text for TXT.
- `domain` (string, required): Fully qualified domain name the record belongs to, e.g. 'example.com'.
- `name` (string, required): Record name relative to the zone, e.g. 'www', 'mail', or '@' for the apex.
- `priority` (integer): Priority for MX/SRV records only; defaults to 0 when omitted.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `ttl` (integer): Time to live in seconds; defaults to 3600 when omitted.
- `type` (string, required): Record type: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA.

### `createHost` (~158 tokens)

createHost: Create a new host/glue record, e.g. for custom nameservers like 'ns1.example.com'. Requires authentication. Check the name first with checkHostAvailability. Returns the created host record.

Input parameters:

- `hostname` (string, required): Fully qualified host name to create, e.g. 'ns1.example.com'.
- `ipAddresses` (array, required): IP addresses for the host, IPv4 dotted-quad or IPv6, e.g. ['192.0.2.1', '198.51.100.1'].
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `createMailbox` (~270 tokens)

createMailbox: Stage creation of a paid mailbox on a mail-enabled domain. BILLABLE: deducts from account balance; get a quote with getMailboxQuote and confirm the price with the user first. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve. The result of the confirmed action contains the generated password EXACTLY ONCE; it can never be retrieved again, so show it to the user immediately (they can change it later with setMailboxPassword). Also share the client settings from the result (IMAP/SMTP/webmail).

Input parameters:

- `domain` (string, required): An ACTIVE mail-enabled domain from listMailDomains.
- `localPart` (string, required): The part of the address before the @; the full mailbox address becomes 'localPart@domain', e.g. 'user@example.com'.
- `packageId` (string, required): Mailbox plan id from listMailPlans; there is no default.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `term` (string): Payment term: 'MONTHLY' or 'ANNUAL' (default ANNUAL).

### `createPaymentSession` (~173 tokens)

createPaymentSession: Stage a Stripe checkout session to add funds to the account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve. The executed result includes checkoutUrl (hand it to the human to pay) and expiresAt; then poll getPaymentTransactions until the balance credit appears.

Input parameters:

- `amount` (number, required): Amount to add to the balance, in the account currency as a decimal (e.g. 25.00).
- `currency` (string): 3-letter ISO 4217 currency code, default USD.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `deleteContact` (~120 tokens)

deleteContact: Stage deletion of a contact. DESTRUCTIVE; fails if the contact is assigned to active domains. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `contactId` (string, required): Identifier of the contact to delete, as returned by listContacts.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `deleteDnsRecord` (~140 tokens)

deleteDnsRecord: Stage deletion of a DNS record. DESTRUCTIVE and irreversible once executed. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `domain` (string, required): Fully qualified domain name the record belongs to, e.g. 'example.com'.
- `recordId` (string, required): Identifier of the record to delete, as returned by listDnsRecords.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `deleteHost` (~119 tokens)

deleteHost: Stage deletion of a host/glue record. DESTRUCTIVE and irreversible once executed. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `hostname` (string, required): Fully qualified host name to delete, e.g. 'ns1.example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `deleteMailbox` (~119 tokens)

deleteMailbox: Stage deletion of a mailbox. The mailbox stops working immediately and its data is destroyed after a 14-day grace period. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `mailboxId` (string, required): Mailbox id from listMailboxes.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `deleteSshKey` (~130 tokens)

deleteSshKey: Stage removal of an SSH key from your account. This does not affect servers already built with it, and the key can simply be added again. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `keyId` (integer, required): Integer key id from listMySshKeys.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `deleteVpsInstance` (~116 tokens)

deleteVpsInstance: Stage deletion/cancellation of a VPS instance. DESTRUCTIVE and irreversible. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `instanceId` (string, required): VPS instance id from listMyVpsInstances.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `enableMailDomain` (~254 tokens)

enableMailDomain: Enable email hosting on a domain you own. Free; mailboxes are what cost money. If the call fails with a DNS conflict (an existing SPF or MX record), ask the user for explicit consent, then re-call with spfMergeConfirmed=true and/or takeoverConfirmed=true. Requires authentication.

Input parameters:

- `dnsMode` (string): 'PDNS_AUTO' (default) publishes all mail DNS records automatically; the domain must use our nameservers. 'EXTERNAL_MANUAL' returns the DNS records for you to publish at your DNS provider, and the dom…
- `domain` (string, required): The domain to enable email hosting on, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `spfMergeConfirmed` (boolean): Set true, only with the user's explicit consent, to replace a foreign SPF record.
- `takeoverConfirmed` (boolean): Set true, only with the user's explicit consent, to repoint a foreign MX record; this moves their live email.

### `executeConfirmedAction` (~97 tokens)

executeConfirmedAction: Execute a previously staged destructive or financial action after user approval. The action expires after 5 minutes and can only be executed once.

Input parameters:

- `actionId` (string, required): The action UUID from the staging tool's response.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `generateDomainSuggestions` (~138 tokens)

generateDomainSuggestions: Generate domain name suggestions based on keywords. This is the preferred suggestion tool for a single keyword; use it over suggestAlternatives. Returns suggested names with availability.

Input parameters:

- `lang` (string): Language code; default "eng".
- `maxResults` (integer): Maximum suggestions to return; default 20.
- `name` (string, required): Keyword or base name to build suggestions from, e.g. "mycompany".
- `tlds` (string): Comma-separated TLDs without leading dots, e.g. "com,net".
- `useNumbers` (boolean): Allow digits in generated suggestions (true/false).

### `getAccountBalance` (~67 tokens)

getAccountBalance: Get the current account balance for the authenticated user. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

Output parameters:

- `balance` (string)
- `currency` (string)
- `message` (string)
- `success` (boolean)

### `getAccountSummary` (~80 tokens)

getAccountSummary: Get a comprehensive summary of the user's account: profile, balance, domain count, VPS count, and pending transfers. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getAuthStatus` (~80 tokens)

getAuthStatus: Check whether the current session is authenticated. Returns authenticated status and token expiry. Optional: sessionKey (from checkDeviceLoginStatus).

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

Output parameters:

- `authenticated` (boolean)
- `tokenExpiresIn` (integer)
- `username` (string)

### `getContact` (~103 tokens)

getContact: Get detailed information about a specific contact. Requires authentication. Get the contactId from listContacts. Returns name, email, phone, organization, and address.

Input parameters:

- `contactId` (string, required): Identifier of the contact to fetch, as returned by listContacts.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getContactsForDomain` (~107 tokens)

getContactsForDomain: Get all contacts (registrant, admin, tech, billing) assigned to a domain. Requires authentication. Returns the contact assigned to each role.

Input parameters:

- `domain` (string, required): Fully qualified domain name whose contacts to fetch, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getDedicatedServerCatalog` (~30 tokens)

getDedicatedServerCatalog: Get all available dedicated server configurations with pricing and specifications. No authentication required.

### `getDnsRecord` (~134 tokens)

getDnsRecord: Get details of a specific DNS record by id. Requires authentication. Get the recordId from listDnsRecords. Returns the record's name, type, content, TTL, and priority.

Input parameters:

- `domain` (string, required): Fully qualified domain name the record belongs to, e.g. 'example.com'.
- `recordId` (string, required): Identifier of the record to fetch, as returned by listDnsRecords.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getDomainAuditTrail` (~98 tokens)

getDomainAuditTrail: Get the audit trail (history of all changes) for a specific domain. Requires authentication.

Input parameters:

- `domain` (string, required): Fully qualified domain name to fetch the audit trail for (e.g. 'example.com').
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getDomainExtensions` (~31 tokens)

getDomainExtensions: Get all available domain extensions (TLDs) with pricing information. No authentication required.

### `getDomainInfo` (~135 tokens)

getDomainInfo: Get registry (EPP) state plus account settings for one domain: status, nameservers, lock state, auto-renew, privacy, creation/expiry dates, premium/expired/redemption info. Dates are null while a registration is still pending at the registry; autoRenew is omitted for transferredOut domains.

Input parameters:

- `domain` (string, required): Fully qualified domain name, like "example.com", without scheme.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getDomainPricing` (~96 tokens)

getDomainPricing: Get pricing for domain extensions from the product catalog. Requires authentication.

Input parameters:

- `extension` (string): Domain extension to filter by, without the leading dot (e.g. 'com', 'net', 'org').
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

Output parameters:

- `message` (string)
- `pricing` (array)
- `success` (boolean)

### `getHostingBundle` (~112 tokens)

getHostingBundle: Get the hosting options and exact prices for a specific domain: recommended VPS packages (cheapest first), email plans, web forwarding, and app/site deployment. No authentication required. Call this ONCE after a successful availability check or registration to make a concise hosting offer; do not repeat the offer in the same conversation. Prices are display prices; the authoritative amount is computed at purchase.

Input parameters:

- `domain` (string, required): Fully qualified domain name to get hosting options for (e.g. 'example.com').

Output parameters:

- `domain` (string)
- `nextSteps` (array)
- `options` (object)

### `getHostsForDomain` (~102 tokens)

getHostsForDomain: List all host/glue records associated with a domain. Requires authentication. Returns each host name and its IP addresses.

Input parameters:

- `domain` (string, required): Fully qualified domain name whose host records to list, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getInvoiceDetails` (~89 tokens)

getInvoiceDetails: Get detailed information about a specific invoice including line items. Requires authentication.

Input parameters:

- `invoiceId` (string, required): The identifier of the invoice to fetch, as returned by listInvoices.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getInvoiceStatistics` (~71 tokens)

getInvoiceStatistics: Get summary statistics of invoices: total paid, pending, overdue amounts. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getMailDnsRecords` (~105 tokens)

getMailDnsRecords: Get the DNS records a mail domain needs (MX, SPF, DKIM, ...), for customers managing DNS externally. Requires authentication.

Input parameters:

- `domain` (string, required): A mail-enabled domain from listMailDomains, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getMailboxQuote` (~121 tokens)

getMailboxQuote: Get a display-only price quote for a mailbox plan. The backend re-derives the authoritative price at purchase. Requires authentication.

Input parameters:

- `packageId` (string, required): Mailbox plan id from listMailPlans.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `term` (string): Payment term: 'MONTHLY' or 'ANNUAL' (default ANNUAL).

Output parameters:

- `currency` (string)
- `message` (string)
- `packageId` (string)
- `packageName` (string)
- `priceCents` (integer)
- `quotaBytes` (integer)
- `success` (boolean)
- `term` (string)

### `getMailboxUsage` (~75 tokens)

getMailboxUsage: Get disk usage per mailbox in bytes, for quota display alongside the plan's quotaBytes. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getMyAuditLogs` (~97 tokens)

getMyAuditLogs: Get recent audit logs for the authenticated user across all services. Requires authentication.

Input parameters:

- `page` (integer): Zero-based page number for pagination.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `size` (integer): Number of log entries per page.

### `getMyProfile` (~80 tokens)

getMyProfile: Get the authenticated user's profile and account information including name, email, organization, balance, and domain/VPS counts. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getPaymentTransactions` (~91 tokens)

getPaymentTransactions: Get payment transaction history for the authenticated user. Requires authentication.

Input parameters:

- `page` (integer): Zero-based page number for pagination.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `size` (integer): Number of transactions per page.

### `getProductCatalog` (~33 tokens)

getProductCatalog: Get the complete product catalog including domain extensions, VPS packages, and dedicated servers. No authentication required.

### `getRecentActivity` (~71 tokens)

getRecentActivity: Get the most recent activity across all domains and services for the user. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getTransferQuote` (~111 tokens)

getTransferQuote: Get a transfer price quote for a domain. Requires authentication. Returns transfer price, currency, extension years, and new expiration date. Call before initiateTransfer to show the user the cost.

Input parameters:

- `domain` (string, required): Fully qualified domain name to quote, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

Output parameters:

- `currency` (string)
- `domain` (string)
- `extensionYears` (string)
- `message` (string)
- `newExpirationDate` (string)
- `success` (boolean)
- `transferPrice` (string)

### `getTransferStatus` (~101 tokens)

getTransferStatus: Check the current status of a domain transfer. Requires authentication. Returns status, request date, current registrar, and expected completion.

Input parameters:

- `domain` (string, required): Fully qualified domain name whose transfer to check, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getVpsInstanceDetails` (~90 tokens)

getVpsInstanceDetails: Get detailed information about a specific VPS instance including resource usage. Requires authentication.

Input parameters:

- `instanceId` (string, required): VPS instance id from listMyVpsInstances.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `getVpsPackageDetails` (~106 tokens)

getVpsPackageDetails: Get detailed information about a specific VPS package including all pricing tiers. Requires authentication. For anonymous browsing use listVpsPackages, which already includes per-term pricing.

Input parameters:

- `packageId` (string, required): VPS package id from listVpsPackages.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `initializeDnsZone` (~142 tokens)

initializeDnsZone: Initialize (create) the DNS zone for a domain. NOT needed after registerDomain, which initializes the zone automatically. Use only for pre-existing domains without a zone (e.g. after a transfer, or if registration opted out with initializeDnsZone:false). Safe on existing zones, it will not overwrite records. Requires authentication.

Input parameters:

- `domain` (string, required): Fully qualified domain name to create the zone for, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `initiateTransfer` (~174 tokens)

initiateTransfer: Starts a transfer for a domain already prepared at the losing registrar (unlocked, auth code in hand). transferDomain (domain tools) stages transfer + registrant assignment in one step; use that when the user gives you contact details. Deducts from account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `authCode` (string, required): EPP/transfer authorization code obtained from the losing registrar.
- `domain` (string, required): Fully qualified domain name to transfer in, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listCategorizedTlds` (~242 tokens)

listCategorizedTlds: List TLDs from the OSIR catalog that have category and audience metadata, with registration and renewal prices as decimal strings (e.g. '10.39'). Use it to pick 3-6 relevant TLDs before calling bulkDomainSuggestions. Filters: price cap, exclude ccTLDs/restricted/premium, registry. Returns unranked candidates with categories, audience, prices, and flags. No auth required.

Input parameters:

- `excludeCcTLDs` (boolean): Set true to exclude country-code and IDN TLDs.
- `excludePremium` (boolean): Set true only when the user explicitly asks for no premium or surprise pricing; premium-flagged TLDs still register most names at the standard price, so do not use this as a budget filter.
- `excludeRestricted` (boolean): Set true to exclude TLDs with registry-level registration restrictions.
- `maxRegisterPrice` (number): Maximum registration price as a decimal; TLDs priced above it are excluded.
- `registry` (string): Filter to TLDs operated by this registry name (case-insensitive exact match).

### `listContacts` (~111 tokens)

listContacts: List all contacts for the authenticated user, optionally filtered by a search term. Requires authentication. Returns each contact with its id for use in getContact, updateContact, deleteContact, or domain registration.

Input parameters:

- `search` (string): Optional search term matched against contact name, email, or organization.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listDnsRecords` (~123 tokens)

listDnsRecords: List all DNS records for a domain. Requires authentication. Returns each record with its id, name, type, content, TTL, and priority; use the record id with getDnsRecord, updateDnsRecord, or deleteDnsRecord.

Input parameters:

- `domain` (string, required): Fully qualified domain name whose records to list, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listInvoices` (~129 tokens)

listInvoices: List invoices for the authenticated user with optional status filtering and pagination. Requires authentication.

Input parameters:

- `page` (integer): Zero-based page number for pagination, default 0.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `size` (integer): Number of invoices per page, default 20.
- `status` (string): Filter by invoice status: DRAFT, PENDING, PAID, CANCELLED, or OVERDUE.

### `listMailDomains` (~81 tokens)

listMailDomains: List your domains that are enabled for email hosting, with status (PENDING_DNS or ACTIVE) and DNS mode. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listMailPlans` (~84 tokens)

listMailPlans: List available email mailbox plans with quotas and prices (monthly and annual, in cents). Requires authentication. Always quote prices from here, never from memory.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listMailboxes` (~74 tokens)

listMailboxes: List your mailboxes with plan, payment term, status, and next renewal date. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listMySshKeys` (~105 tokens)

listMySshKeys: List the SSH keys stored on your account, with their ids and SHA256 fingerprints. Use this to check whether a key is already stored and to get the ids to pass to orderVps or buildVpsInstance. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listMyVpsInstances` (~71 tokens)

listMyVpsInstances: List all VPS instances owned by the authenticated user. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listPendingTransfers` (~85 tokens)

listPendingTransfers: List all pending incoming (gaining) domain transfers. Requires authentication. Returns each transfer with its status, request date, current registrar, and expected completion.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listUserDomains` (~72 tokens)

listUserDomains: List all domains owned by the authenticated user. No parameters required. Must be authenticated first.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listVpsLocations` (~33 tokens)

listVpsLocations: List available VPS hosting locations (cities/countries) with available packages. No authentication required.

### `listVpsOsTemplates` (~234 tokens)

listVpsOsTemplates: List operating system templates available to install. Requires authentication. Pass EXACTLY ONE of packageId (to pick an operatingSystemId for orderVps, so the server arrives with an OS on it) or instanceId (to pick a template for reinstalling via buildVpsInstance). The two are not interchangeable: the available set depends on the package. Template ids change over time, so always resolve an id here rather than reusing a remembered or hardcoded one.

Input parameters:

- `includeEol` (boolean): Include end-of-life templates (default false).
- `instanceId` (string): VPS instance id from listMyVpsInstances; use to see what an existing server can be reinstalled with via buildVpsInstance.
- `packageId` (string): VPS package id from listVpsPackages; use BEFORE ordering to pick an operatingSystemId for orderVps.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `listVpsPackages` (~32 tokens)

listVpsPackages: List available VPS hosting packages with pricing, specs, and locations. No authentication required.

### `lockDomain` (~84 tokens)

lockDomain: Enable registrar lock on a domain to prevent unauthorized transfers.

Input parameters:

- `domain` (string, required): Fully qualified domain name to lock, like "example.com", without scheme.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `loginToVpsPanel` (~98 tokens)

loginToVpsPanel: Generate a one-time login URL to the VPS control panel (VirtFusion) for managing the server. Requires authentication.

Input parameters:

- `instanceId` (string, required): VPS instance id from listMyVpsInstances.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `loginWithDevice` (~71 tokens)

loginWithDevice: Start a device authorization login (RFC 8628). Returns a verificationUri and userCode. Open the URI in your browser, enter the code, and sign in with your OSIR credentials. Then call checkDeviceLoginStatus with the returned deviceCode to complete login. No parameters required.

### `logout` (~84 tokens)

logout: Log out: revokes the session's tokens at the identity provider immediately. Optional: sessionKey (from checkDeviceLoginStatus); pass it to end that conversation session.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `orderVps` (~244 tokens)

orderVps: Stage an order for a new VPS instance; deducts from account balance. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `hostname` (string, required): Hostname for the new server, e.g. 'myserver.example.com'.
- `operatingSystemId` (integer): Integer OS template id resolved with listVpsOsTemplates using this same packageId; omit to get a server with NO operating system installed.
- `packageId` (string, required): VPS package id from listVpsPackages.
- `paymentTerm` (string, required): Billing cycle: 'MONTHLY', 'SEMI_ANNUAL', 'ANNUAL', 'BIENNIAL', or 'TRIENNIAL'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `sshKeyIds` (array): Integer SSH key ids from listMySshKeys or addSshKey, injected during install; without one you cannot log in.

### `osirAppCreateUpload` (~106 tokens)

osirAppCreateUpload: Create an upload ticket for deploying app source code to Osir. Returns an uploadTicket, a putUrl, and instructions to zip the project and upload it. After uploading, call osirAppDeploy with the uploadTicket. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirAppDelete` (~125 tokens)

osirAppDelete: Stage deletion of an Osir app. DESTRUCTIVE and irreversible: removes its microVM, image, route, and data. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve. Requires authentication.

Input parameters:

- `appId` (string, required): App id from osirAppList.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirAppDeploy` (~294 tokens)

osirAppDeploy: Deploy an app to Osir (free tier) and get a live HTTPS URL; the app runs isolated in a microVM. Deploying an existing app name redeploys it (new version) and applies any secrets set via osirAppSetSecret. A plain static website (HTML/CSS/JS with no framework or build step) is also supported: it is auto-detected and served directly; pass language 'node' for it. If the app was moved to the user's own VPS, redeploying under the same name updates it there and keeps its domain. Requires authentication.

Input parameters:

- `language` (string, required): Runtime language: 'node', 'python', 'php-laravel', or 'go'; use 'node' for a plain static site.
- `name` (string, required): App name: lowercase letters, digits, and hyphens, e.g. 'habit-tracker'.
- `region` (string): Region: 'us' or 'al' ('al' is Albania/Tirana); defaults to the platform's home region.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `uploadTicket` (string, required): Upload ticket from osirAppCreateUpload, after uploading the zipped source to its putUrl.

### `osirAppGetSource` (~167 tokens)

osirAppGetSource: Get a short-lived signed download URL for an Osir app's current source zip. Use this to make edits to a deployed app without the user re-attaching the project: download, patch the files, then osirAppCreateUpload (PUT the new zip) and osirAppDeploy under the SAME name; the platform rebuilds and, for owned-tier apps, auto-ships the new version to the user's box. Requires authentication.

Input parameters:

- `appName` (string, required): The deployed app's name, as shown by osirAppList.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirAppList` (~74 tokens)

osirAppList: List the authenticated user's deployed Osir apps with their live URLs and status. Requires authentication.

Input parameters:

- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirAppLogs` (~111 tokens)

osirAppLogs: Get recent logs from an Osir app's microVM ('why is my app broken?'). Requires authentication.

Input parameters:

- `appId` (string, required): App id from osirAppList.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `tail` (integer): Number of recent log lines to return (default 100).

### `osirAppMoveToOwned` (~479 tokens)

osirAppMoveToOwned: Move a deployed Osir app from the shared free tier onto a VPS owned by the user. TWO WAYS IN. (1) The user already owns a VPS: pass instanceId (from listMyVpsInstances) and NO packageId - this ATTACHES the app to that server, SPENDS NOTHING and needs no confirmation. (2) No server yet: pass packageId (from listVpsPackages) and the call stages a VPS order (COSTS MONEY): returns an actionId; present the price/summary to the user and call executeConfirmedAction only if they approve. Before staging any order this tool checks whether the user ALREADY has a box for this app (its C2 binding, then their own VPS list) and attaches that instead - a retry after a failed move never buys a second server. After the move starts the platform ships the app onto the box server-side, which takes about two minutes; watch it with osirAppStatus ('ownedMove'). Calling this tool again while a move is still running just reports its progress, and calling it after one FAILED retries the ship - unless osirAppStatus says the VPS refused the Osir deploy key or its web ports are taken: then retry only after the user has made the changes that message lists. If the result status is BUILDING or BUILD_FAILED, follow its nextStep. Requires authentication.

Input parameters:

- `appName` (string, required): The deployed app's name, as shown by osirAppList.
- `domain` (string): Custom domain to serve the app on; DNS is bound automatically if the domain is hosted on osir.app nameservers, otherwise the result returns the IP and manual DNS instructions.
- `instanceId` (string): Id of a VPS the user ALREADY owns, from listMyVpsInstances. Given this, the app is attached to that server and nothing is ordered or charged. Never invent one.
- `packageId` (string): VPS package id from listVpsPackages. Required ONLY when a server has to be ordered; omit it when passing instanceId.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirAppProvisionDatabase` (~137 tokens)

osirAppProvisionDatabase: Provision a managed Postgres database for an Osir app. The connection string is stored as the app's DATABASE_URL secret (encrypted, injected on the next osirAppDeploy) and is NEVER returned. Requires authentication.

Input parameters:

- `appId` (string, required): App id from osirAppList.
- `engine` (string): Database engine; only 'postgres' (the default) is supported.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirAppSetSecret` (~156 tokens)

osirAppSetSecret: Set an environment secret for an Osir app (e.g. DATABASE_URL, API_KEY). The value is stored encrypted and injected as an env var on the next osirAppDeploy of the app; it is NEVER returned or logged. Requires authentication.

Input parameters:

- `appId` (string, required): App id from osirAppList.
- `key` (string, required): Environment variable name, e.g. 'API_KEY'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `value` (string, required): The secret value; never returned or logged.

### `osirAppStatus` (~283 tokens)

osirAppStatus: Get an Osir app's current status, live URL, and health ('is my app working?'). If the status is BUILD_FAILED, 'recentErrors' explains why so you can fix the source and redeploy. 'qa' is an independent black-box check of the LIVE app after deploy: qa.status PASSED means it loaded and worked; FAILED means it deployed but didn't actually work, and qa.findings lists the problems so you can fix and redeploy. 'ownedMove' tracks a move onto the user's own VPS, which leaves tier and status unchanged while it runs: state MOVING (in progress, stage says where, ~2 minutes in total), MOVED (done - tier reads 'owned'), FAILED or REFUSED (follow this result's message: usually call osirAppMoveToOwned again to retry, which never orders a second server; but when the VPS refused the Osir deploy key or its web ports are taken, the user must fix the VPS first, and the message says how). Requires authentication.

Input parameters:

- `appId` (string, required): App id from osirAppList or a deploy result.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `osirSiteDesignBrief` (~364 tokens)

osirSiteDesignBrief: Step 1 of designing a NEW website with OSIR. Validates the brief and returns 'systemPrompt', the structured design brief and constraints YOU must then follow to write one complete self-contained HTML page, plus 'editRules' for later revisions. Call it before osirSitePublish for a new site, then publish the finished page with osirSitePublish. No authentication needed.

Input parameters:

- `audience` (string, required): Who visits the site and why.
- `briefJson` (string): Optional JSON object with extras the user provided: site_type, sections[], language (ISO code, default en), tone (warm|premium|playful|technical|minimal|bold), mood_words[] (max 5), brand{logo_url, p…
- `businessName` (string, required): The business or project name.
- `pageJob` (string, required): The page's single job: get_contact, sell_product, book_appointment, collect_signups, inform_portfolio, or other.
- `primaryAction` (string, required): The one primary call to action, e.g. 'Book a table'.
- `whatItIs` (string, required): What the business concretely does or sells.

### `osirSitePublish` (~317 tokens)

osirSitePublish: Publish a single-page website to a live HTTPS URL on Osir (free tier). ANY complete HTML document works: the user's own site, a page designed in this chat, or one from the osirSiteDesignBrief flow. Calling again with the same name redeploys the new version. For MULTI-FILE sites (separate CSS/JS/images) use osirAppCreateUpload + osirAppDeploy with a zip instead. Then poll osirAppStatus until READY. If the app was moved to the user's own VPS, redeploying under the same name updates it there and keeps its domain. Requires authentication.

Input parameters:

- `designContract` (boolean): Set true ONLY for pages generated via the osirSiteDesignBrief flow; additionally enforces its output contract (exactly one <h1>, self-contained, no external scripts/CSS except Google Fonts, no iframe…
- `html` (string, required): The complete <html> document to publish (max 1 MiB).
- `name` (string, required): Site name: lowercase letters, digits, and hyphens, e.g. 'bar-mediterran'.
- `region` (string): Region: 'us' or 'al' ('al' is Albania/Tirana).
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `payInvoice` (~112 tokens)

payInvoice: Stage payment of an outstanding invoice from account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `invoiceId` (string, required): The identifier of the outstanding invoice to pay, as returned by listInvoices.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `previewPaymentFees` (~116 tokens)

previewPaymentFees: Preview the fees that would be charged for a given payment amount. Requires authentication.

Input parameters:

- `amount` (number, required): Payment amount to preview, in the account currency as a decimal (e.g. 25.00).
- `currency` (string): 3-letter ISO 4217 currency code, default USD.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

Output parameters:

- `amount` (string)
- `currency` (string)
- `fee` (string)
- `message` (string)
- `success` (boolean)
- `total` (string)

### `registerDomain` (~299 tokens)

registerDomain: Stage registration of a new domain name. Deducts from account balance. The DNS zone is initialised automatically after registration (asynchronously; if createDnsRecord right after registration reports a missing zone, retry after a few seconds). Pass initializeDnsZone:false to opt out. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `autoRenew` (boolean): Enable automatic renewal; defaults to true.
- `domain` (string, required): Fully qualified domain name to register, like "example.com", without scheme.
- `initializeDnsZone` (boolean): Initialise the DNS zone after registration; defaults to true.
- `nameservers` (array, required): List of nameserver hostnames, e.g. ["ns1.example.com", "ns2.example.com"].
- `privacyProtection` (boolean): Enable WHOIS privacy protection; defaults to true.
- `registrantInfo` (object, required): ICANN registrant contact of the domain owner: firstName, lastName, email, phone (+CC.number), and address (street, city, postalCode, country as 2-letter ISO code).
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `years` (integer, required): Registration period in years, 1-10.

### `renewDomain` (~133 tokens)

renewDomain: Stage renewal of a domain for a specified number of years. Deducts from account balance. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `domain` (string, required): Fully qualified domain name to renew, like "example.com", without scheme.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `years` (integer, required): Renewal period in years, 1-10.

### `setMailboxPassword` (~104 tokens)

setMailboxPassword: Set a new password on a mailbox. Never log or store the password. Requires authentication.

Input parameters:

- `mailboxId` (string, required): Mailbox id from listMailboxes.
- `password` (string, required): The new mailbox password; never log or store it.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `spinDomainWords` (~137 tokens)

spinDomainWords: Generate domain suggestions by spinning/replacing words with similar alternatives.

Input parameters:

- `lang` (string): Language code; default "eng".
- `maxResults` (integer): Maximum suggestions to return; default 20.
- `name` (string, required): Comma-separated words to spin, e.g. "pizza,restaurant".
- `position` (integer): 0-based index of the word to replace.
- `similarity` (number): Similarity threshold for replacements, 0.0-1.0.
- `tlds` (string): Comma-separated TLDs without leading dots, e.g. "com,net".

### `suggestAlternatives` (~112 tokens)

suggestAlternatives: Suggest alternative domain names if the requested one is unavailable. Legacy; prefer generateDomainSuggestions.

Input parameters:

- `domain` (string, required): Fully qualified domain name to find alternatives for, like "example.com", without scheme.
- `limit` (integer): Maximum number of suggestions to return; default 10.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `transferDomain` (~183 tokens)

transferDomain: Stage transfer of a domain from another registrar to OSIR. Deducts from account balance. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `authCode` (string, required): EPP authorization code obtained from the current registrar.
- `domain` (string, required): Fully qualified domain name to transfer, like "example.com", without scheme.
- `registrantInfo` (object, required): ICANN registrant contact of the domain owner: firstName, lastName, email, phone (+CC.number), and address (street, city, postalCode, country as 2-letter ISO code).
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `unlockDomain` (~118 tokens)

unlockDomain: Stage removal of registrar lock from a domain to allow transfers. DESTRUCTIVE: reduces domain security. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

Input parameters:

- `domain` (string, required): Fully qualified domain name to unlock, like "example.com", without scheme.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `updateContact` (~274 tokens)

updateContact: Update an existing contact's information. Requires authentication. Only the fields you provide are changed; omitted fields keep their current values. Get the contactId from listContacts. Returns the updated contact.

Input parameters:

- `city` (string): New city name.
- `contactId` (string, required): Identifier of the contact to update, as returned by listContacts.
- `country` (string): New country as a 2-letter ISO 3166-1 alpha-2 code, e.g. 'US'.
- `email` (string): New email address.
- `firstName` (string): New first name.
- `lastName` (string): New last name.
- `organization` (string): New organization or company name.
- `phone` (string): New phone number in '+CC.number' format, e.g. '+1.5551234567'.
- `postalCode` (string): New postal or ZIP code.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `state` (string): New state, province, or region.
- `street1` (string): New first street address line.
- `street2` (string): New second street address line.

### `updateDnsRecord` (~249 tokens)

updateDnsRecord: Update an existing DNS record. Requires authentication. Only the fields you provide are changed; omitted fields keep their current values. Get the recordId from listDnsRecords. Returns the updated record.

Input parameters:

- `content` (string): New record value, e.g. an IPv4 dotted-quad or IPv6 address, hostname, or text.
- `domain` (string, required): Fully qualified domain name the record belongs to, e.g. 'example.com'.
- `name` (string): New record name relative to the zone, e.g. 'www' or '@' for the apex.
- `priority` (integer): New priority for MX/SRV records only.
- `recordId` (string, required): Identifier of the record to update, as returned by listDnsRecords.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
- `ttl` (integer): New time to live in seconds.
- `type` (string): New record type: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA.

### `updateDomainAutoRenew` (~103 tokens)

updateDomainAutoRenew: Enable or disable auto-renewal for a domain.

Input parameters:

- `domain` (string, required): Fully qualified domain name, like "example.com", without scheme.
- `enabled` (boolean, required): true to enable automatic renewal, false to disable it.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `updateDomainPrivacy` (~103 tokens)

updateDomainPrivacy: Enable or disable WHOIS privacy protection for a domain.

Input parameters:

- `domain` (string, required): Fully qualified domain name, like "example.com", without scheme.
- `enabled` (boolean, required): true to enable WHOIS privacy protection, false to disable it.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `updateNameservers` (~122 tokens)

updateNameservers: Update nameservers for a domain. Replaces the current nameserver set with the given list.

Input parameters:

- `domain` (string, required): Fully qualified domain name, like "example.com", without scheme.
- `nameservers` (array, required): List of nameserver hostnames, e.g. ["ns1.example.com", "ns2.example.com"].
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

### `validateDomainName` (~47 tokens)

validateDomainName: Validate if a domain name format is correct. No authentication required.

Input parameters:

- `domain` (string, required): Fully qualified domain name to validate, like "example.com", without scheme.

### `verifyAccount` (~119 tokens)

verifyAccount: Verify a newly created OSIR account with the code from the verification email; step 2 of onboarding, no authentication required. The code is the same token as the email link, so the principal can relay it to their agent. On success the account becomes ACTIVE and billable actions are unlocked. If the code expired, call createAccount again with the same email to get a fresh one.

Input parameters:

- `accountId` (string, required): Account identifier returned by createAccount.
- `code` (string, required): Verification code from the email sent by createAccount.

Output parameters:

- `nextSteps` (array)
- `status` (string)

### `verifyMailDns` (~105 tokens)

verifyMailDns: Check that a mail domain's DNS records resolve; activates the domain for email when all records are found. Returns any still-missing records. Requires authentication.

Input parameters:

- `domain` (string, required): The mail-enabled domain to verify, e.g. 'example.com'.
- `sessionKey` (string): Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-osir-domain-registrar/be#diagnostics

## Score history

- 2026-09-24: 79
- 2026-09-23: 78
- 2026-09-22: 78
- 2026-09-21: 77
- 2026-09-20: 77
- 2026-09-19: 76
- 2026-09-18: 76
- 2026-09-17: 75
- 2026-09-16: 75
- 2026-09-15: 74
- 2026-09-14: 74
- 2026-09-13: 74
- 2026-09-12: 73
- 2026-09-11: 73
- 2026-09-10: 72
- 2026-09-09: 72
- 2026-09-08: 71
- 2026-09-07: 71
- 2026-09-06: 70
- 2026-09-05: 70
- 2026-09-04: 69
- 2026-09-03: 69
- 2026-09-02: 60

## Common questions

### What is the OSIR Domain Registrar MCP server?

OSIR Domain Registrar is an MCP server listed in the public MCP registry as com.osir/domain-registrar. Register, renew, transfer, and manage domains, DNS, VPS, and email with 105 tools. By OSIR. This page covers its hosted endpoint (https://be.osir.com/mcp/http).

### Is the OSIR Domain Registrar MCP server safe to use?

OSIR Domain Registrar scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the OSIR Domain Registrar MCP server expose?

OSIR Domain Registrar exposes 105 tools: addPrefixToDomain, addSshKey, addSuffixToDomain, buildVpsInstance, bulkDomainSuggestions, and 100 more. Their descriptions and schemas cost roughly 14,266 tokens of context every time the server is loaded.

### Does the OSIR Domain Registrar MCP server require authentication?

No. We connected to OSIR Domain Registrar without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the OSIR Domain Registrar MCP server still maintained?

OSIR Domain Registrar is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://be.osir.com/mcp/http
- Repository: https://github.com/Osir-Inc/mcp-a2a
- Website: https://osir.com/en/mcp/
- Changelog RSS feed: https://verifymcp.io/servers/com-osir-domain-registrar/be.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-osir-domain-registrar/be.json
- HTML version of this page: https://verifymcp.io/servers/com-osir-domain-registrar/be
