Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

OSIR Domain Registrar

REMOTE · BE.OSIR.COM · SCANNED SEP 24

Register, renew, transfer, and manage domains, DNS, VPS, and email with 105 tools. By OSIR.

Available components

+4 this week 79 Trust /100

Recent critical change

Authorization (3 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security66
Transport & Reachability100
Schema Quality & AI Usability79
  • 85% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 14561 tokens (~136/item across 107 items; 105 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management73
  • Stability observed for 22 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (10% of tools); any adoption earns full credit.Pass
Tool Safety97
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 14 of 16 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "getTransferQuote" implies "transfer" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
  • An AI judge read all 107 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the OSIR Domain Registrar MCP server?

OSIR Domain Registrar is a hosted endpoint at https://be.osir.com/mcp/http, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · be.osir.com

# add to Claude Code
claude mcp add --transport http com-osir-domain-registrar 'https://be.osir.com/mcp/http'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-osir-domain-registrar": {
      "url": "https://be.osir.com/mcp/http"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-osir-domain-registrar": {
      "type": "http",
      "url": "https://be.osir.com/mcp/http"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-osir-domain-registrar]
url = "https://be.osir.com/mcp/http"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-osir-domain-registrar": {
      "type": "remote",
      "url": "https://be.osir.com/mcp/http",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-osir-domain-registrar --url 'https://be.osir.com/mcp/http' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-osir-domain-registrar:
    url: "https://be.osir.com/mcp/http"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-osir-domain-registrar": {
      "Transport": "http",
      "Url": "https://be.osir.com/mcp/http"
    }
  }
}
# add to Vellum
assistant mcp add com-osir-domain-registrar -t streamable-http -u 'https://be.osir.com/mcp/http'
// mcp.json
{
  "mcpServers": {
    "com-osir-domain-registrar": {
      "type": "http",
      "url": "https://be.osir.com/mcp/http"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 24 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

  • 22 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 +1
    • Tool “osirAppDeploy” rewrote its description, which is the text the model reads security
    • Tool “osirAppMoveToOwned” rewrote its description, which is the text the model reads security
    • Tool “osirAppStatus” rewrote its description, which is the text the model reads security
    • Tool “osirSitePublish” rewrote its description, which is the text the model reads security
  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 0
    • Tool “changeVpsPaymentTerm” rewrote its description, which is the text the model reads security
    • Tool “deleteSshKey” rewrote its description, which is the text the model reads security
  • 13 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 24 Sept 2026 · Probed https://be.osir.com/mcp/http

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=be.osir.com CN=YE2,O=Let's Encrypt,C=US 15 Aug 2026 13 Nov 2026 ECDSA 256 ECDSA-SHA384 6e7a28cc9e2e81b0b48372f6ba4660b2201
SANs: be.osir.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of be.osir.com. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
osir.com. present 46538 13 Verified
be.osir.com. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://be.osir.com/mcp/http Verified 200
http (plaintext) http://be.osir.com/mcp/http HTTPS enforced 301 https://be.osir.com/mcp/http
MCP tools · 105 exposed · ~14,266 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
getRecentActivity ~71

getRecentActivity: Get the most recent activity across all domains and services for the user. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

getTransferQuote ~111

getTransferQuote: Get a transfer price quote for a domain. Requires authentication. Returns transfer price, currency, extension years, and new expiration date. Call before initiateTransfer to show the user the cost.

NameTypeReqDescription
domainstringyesFully qualified domain name to quote, e.g. 'example.com'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
NameTypeReqDescription
currencystring
domainstring
extensionYearsstring
messagestring
newExpirationDatestring
successboolean
transferPricestring

No examples provided.

getTransferStatus ~101

getTransferStatus: Check the current status of a domain transfer. Requires authentication. Returns status, request date, current registrar, and expected completion.

NameTypeReqDescription
domainstringyesFully qualified domain name whose transfer to check, e.g. 'example.com'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

getVpsInstanceDetails ~90

getVpsInstanceDetails: Get detailed information about a specific VPS instance including resource usage. Requires authentication.

NameTypeReqDescription
instanceIdstringyesVPS instance id from listMyVpsInstances.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

getVpsPackageDetails ~106

getVpsPackageDetails: Get detailed information about a specific VPS package including all pricing tiers. Requires authentication. For anonymous browsing use listVpsPackages, which already includes per-term pricing.

NameTypeReqDescription
packageIdstringyesVPS package id from listVpsPackages.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

initializeDnsZone ~142

initializeDnsZone: Initialize (create) the DNS zone for a domain. NOT needed after registerDomain, which initializes the zone automatically. Use only for pre-existing domains without a zone (e.g. after a transfer, or if registration opted out with initializeDnsZone:false). Safe on existing zones, it will not overwrite records. Requires authentication.

NameTypeReqDescription
domainstringyesFully qualified domain name to create the zone for, e.g. 'example.com'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

initiateTransfer ~174

initiateTransfer: Starts a transfer for a domain already prepared at the losing registrar (unlocked, auth code in hand). transferDomain (domain tools) stages transfer + registrant assignment in one step; use that when the user gives you contact details. Deducts from account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
authCodestringyesEPP/transfer authorization code obtained from the losing registrar.
domainstringyesFully qualified domain name to transfer in, e.g. 'example.com'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listCategorizedTlds ~242

listCategorizedTlds: List TLDs from the OSIR catalog that have category and audience metadata, with registration and renewal prices as decimal strings (e.g. '10.39'). Use it to pick 3-6 relevant TLDs before calling bulkDomainSuggestions. Filters: price cap, exclude ccTLDs/restricted/premium, registry. Returns unranked candidates with categories, audience, prices, and flags. No auth required.

NameTypeReqDescription
excludeCcTLDsbooleanSet true to exclude country-code and IDN TLDs.
excludePremiumbooleanSet true only when the user explicitly asks for no premium or surprise pricing; premium-flagged TLDs still register most names at the standard price, so do not use this as a budget filter.
excludeRestrictedbooleanSet true to exclude TLDs with registry-level registration restrictions.
maxRegisterPricenumberMaximum registration price as a decimal; TLDs priced above it are excluded.
registrystringFilter to TLDs operated by this registry name (case-insensitive exact match).

No output schema declared.

No examples provided.

listContacts ~111

listContacts: List all contacts for the authenticated user, optionally filtered by a search term. Requires authentication. Returns each contact with its id for use in getContact, updateContact, deleteContact, or domain registration.

NameTypeReqDescription
searchstringOptional search term matched against contact name, email, or organization.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listDnsRecords ~123

listDnsRecords: List all DNS records for a domain. Requires authentication. Returns each record with its id, name, type, content, TTL, and priority; use the record id with getDnsRecord, updateDnsRecord, or deleteDnsRecord.

NameTypeReqDescription
domainstringyesFully qualified domain name whose records to list, e.g. 'example.com'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listInvoices ~129

listInvoices: List invoices for the authenticated user with optional status filtering and pagination. Requires authentication.

NameTypeReqDescription
pageintegerZero-based page number for pagination, default 0.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
sizeintegerNumber of invoices per page, default 20.
statusstringFilter by invoice status: DRAFT, PENDING, PAID, CANCELLED, or OVERDUE.

No output schema declared.

No examples provided.

listMailboxes ~74

listMailboxes: List your mailboxes with plan, payment term, status, and next renewal date. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listMailDomains ~81

listMailDomains: List your domains that are enabled for email hosting, with status (PENDING_DNS or ACTIVE) and DNS mode. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listMailPlans ~84

listMailPlans: List available email mailbox plans with quotas and prices (monthly and annual, in cents). Requires authentication. Always quote prices from here, never from memory.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listMySshKeys ~105

listMySshKeys: List the SSH keys stored on your account, with their ids and SHA256 fingerprints. Use this to check whether a key is already stored and to get the ids to pass to orderVps or buildVpsInstance. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listMyVpsInstances ~71

listMyVpsInstances: List all VPS instances owned by the authenticated user. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listPendingTransfers ~85

listPendingTransfers: List all pending incoming (gaining) domain transfers. Requires authentication. Returns each transfer with its status, request date, current registrar, and expected completion.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listUserDomains ~72

listUserDomains: List all domains owned by the authenticated user. No parameters required. Must be authenticated first.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listVpsLocations ~33

listVpsLocations: List available VPS hosting locations (cities/countries) with available packages. No authentication required.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

listVpsOsTemplates ~234

listVpsOsTemplates: List operating system templates available to install. Requires authentication. Pass EXACTLY ONE of packageId (to pick an operatingSystemId for orderVps, so the server arrives with an OS on it) or instanceId (to pick a template for reinstalling via buildVpsInstance). The two are not interchangeable: the available set depends on the package. Template ids change over time, so always resolve an id here rather than reusing a remembered or hardcoded one.

NameTypeReqDescription
includeEolbooleanInclude end-of-life templates (default false).
instanceIdstringVPS instance id from listMyVpsInstances; use to see what an existing server can be reinstalled with via buildVpsInstance.
packageIdstringVPS package id from listVpsPackages; use BEFORE ordering to pick an operatingSystemId for orderVps.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

listVpsPackages ~32

listVpsPackages: List available VPS hosting packages with pricing, specs, and locations. No authentication required.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

lockDomain ~84

lockDomain: Enable registrar lock on a domain to prevent unauthorized transfers.

NameTypeReqDescription
domainstringyesFully qualified domain name to lock, like "example.com", without scheme.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

loginToVpsPanel ~98

loginToVpsPanel: Generate a one-time login URL to the VPS control panel (VirtFusion) for managing the server. Requires authentication.

NameTypeReqDescription
instanceIdstringyesVPS instance id from listMyVpsInstances.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

loginWithDevice ~71

loginWithDevice: Start a device authorization login (RFC 8628). Returns a verificationUri and userCode. Open the URI in your browser, enter the code, and sign in with your OSIR credentials. Then call checkDeviceLoginStatus with the returned deviceCode to complete login. No parameters required.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

logout ~84

logout: Log out: revokes the session's tokens at the identity provider immediately. Optional: sessionKey (from checkDeviceLoginStatus); pass it to end that conversation session.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

orderVps ~244

orderVps: Stage an order for a new VPS instance; deducts from account balance. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
hostnamestringyesHostname for the new server, e.g. 'myserver.example.com'.
operatingSystemIdintegerInteger OS template id resolved with listVpsOsTemplates using this same packageId; omit to get a server with NO operating system installed.
packageIdstringyesVPS package id from listVpsPackages.
paymentTermstringyesBilling cycle: 'MONTHLY', 'SEMI_ANNUAL', 'ANNUAL', 'BIENNIAL', or 'TRIENNIAL'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
sshKeyIdsarrayInteger SSH key ids from listMySshKeys or addSshKey, injected during install; without one you cannot log in.

No output schema declared.

No examples provided.

osirAppCreateUpload ~106

osirAppCreateUpload: Create an upload ticket for deploying app source code to Osir. Returns an uploadTicket, a putUrl, and instructions to zip the project and upload it. After uploading, call osirAppDeploy with the uploadTicket. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirAppDelete ~125

osirAppDelete: Stage deletion of an Osir app. DESTRUCTIVE and irreversible: removes its microVM, image, route, and data. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve. Requires authentication.

NameTypeReqDescription
appIdstringyesApp id from osirAppList.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirAppDeploy ~294

osirAppDeploy: Deploy an app to Osir (free tier) and get a live HTTPS URL; the app runs isolated in a microVM. Deploying an existing app name redeploys it (new version) and applies any secrets set via osirAppSetSecret. A plain static website (HTML/CSS/JS with no framework or build step) is also supported: it is auto-detected and served directly; pass language 'node' for it. If the app was moved to the user's own VPS, redeploying under the same name updates it there and keeps its domain. Requires authentication.

NameTypeReqDescription
languagestringyesRuntime language: 'node', 'python', 'php-laravel', or 'go'; use 'node' for a plain static site.
namestringyesApp name: lowercase letters, digits, and hyphens, e.g. 'habit-tracker'.
regionstringRegion: 'us' or 'al' ('al' is Albania/Tirana); defaults to the platform's home region.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
uploadTicketstringyesUpload ticket from osirAppCreateUpload, after uploading the zipped source to its putUrl.

No output schema declared.

No examples provided.

osirAppGetSource ~167

osirAppGetSource: Get a short-lived signed download URL for an Osir app's current source zip. Use this to make edits to a deployed app without the user re-attaching the project: download, patch the files, then osirAppCreateUpload (PUT the new zip) and osirAppDeploy under the SAME name; the platform rebuilds and, for owned-tier apps, auto-ships the new version to the user's box. Requires authentication.

NameTypeReqDescription
appNamestringyesThe deployed app's name, as shown by osirAppList.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirAppList ~74

osirAppList: List the authenticated user's deployed Osir apps with their live URLs and status. Requires authentication.

NameTypeReqDescription
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirAppLogs ~111

osirAppLogs: Get recent logs from an Osir app's microVM ('why is my app broken?'). Requires authentication.

NameTypeReqDescription
appIdstringyesApp id from osirAppList.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
tailintegerNumber of recent log lines to return (default 100).

No output schema declared.

No examples provided.

osirAppMoveToOwned ~479

osirAppMoveToOwned: Move a deployed Osir app from the shared free tier onto a VPS owned by the user. TWO WAYS IN. (1) The user already owns a VPS: pass instanceId (from listMyVpsInstances) and NO packageId - this ATTACHES the app to that server, SPENDS NOTHING and needs no confirmation. (2) No server yet: pass packageId (from listVpsPackages) and the call stages a VPS order (COSTS MONEY): returns an actionId; present the price/summary to the user and call executeConfirmedAction only if they approve. Before staging any order this tool checks whether the user ALREADY has a box for this app (its C2 binding, then their own VPS list) and attaches that instead - a retry after a failed move never buys a second server. After the move starts the platform ships the app onto the box server-side, which takes about two minutes; watch it with osirAppStatus ('ownedMove'). Calling this tool again while a move is still running just reports its progress, and calling it after one FAILED retries the ship - unless osirAppStatus says the VPS refused the Osir deploy key or its web ports are taken: then retry only after the user has made the changes that message lists. If the result status is BUILDING or BUILD_FAILED, follow its nextStep. Requires authentication.

NameTypeReqDescription
appNamestringyesThe deployed app's name, as shown by osirAppList.
domainstringCustom domain to serve the app on; DNS is bound automatically if the domain is hosted on osir.app nameservers, otherwise the result returns the IP and manual DNS instructions.
instanceIdstringId of a VPS the user ALREADY owns, from listMyVpsInstances. Given this, the app is attached to that server and nothing is ordered or charged. Never invent one.
packageIdstringVPS package id from listVpsPackages. Required ONLY when a server has to be ordered; omit it when passing instanceId.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirAppProvisionDatabase ~137

osirAppProvisionDatabase: Provision a managed Postgres database for an Osir app. The connection string is stored as the app's DATABASE_URL secret (encrypted, injected on the next osirAppDeploy) and is NEVER returned. Requires authentication.

NameTypeReqDescription
appIdstringyesApp id from osirAppList.
enginestringDatabase engine; only 'postgres' (the default) is supported.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirAppSetSecret ~156

osirAppSetSecret: Set an environment secret for an Osir app (e.g. DATABASE_URL, API_KEY). The value is stored encrypted and injected as an env var on the next osirAppDeploy of the app; it is NEVER returned or logged. Requires authentication.

NameTypeReqDescription
appIdstringyesApp id from osirAppList.
keystringyesEnvironment variable name, e.g. 'API_KEY'.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
valuestringyesThe secret value; never returned or logged.

No output schema declared.

No examples provided.

osirAppStatus ~283

osirAppStatus: Get an Osir app's current status, live URL, and health ('is my app working?'). If the status is BUILD_FAILED, 'recentErrors' explains why so you can fix the source and redeploy. 'qa' is an independent black-box check of the LIVE app after deploy: qa.status PASSED means it loaded and worked; FAILED means it deployed but didn't actually work, and qa.findings lists the problems so you can fix and redeploy. 'ownedMove' tracks a move onto the user's own VPS, which leaves tier and status unchanged while it runs: state MOVING (in progress, stage says where, ~2 minutes in total), MOVED (done - tier reads 'owned'), FAILED or REFUSED (follow this result's message: usually call osirAppMoveToOwned again to retry, which never orders a second server; but when the VPS refused the Osir deploy key or its web ports are taken, the user must fix the VPS first, and the message says how). Requires authentication.

NameTypeReqDescription
appIdstringyesApp id from osirAppList or a deploy result.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

osirSiteDesignBrief ~364

osirSiteDesignBrief: Step 1 of designing a NEW website with OSIR. Validates the brief and returns 'systemPrompt', the structured design brief and constraints YOU must then follow to write one complete self-contained HTML page, plus 'editRules' for later revisions. Call it before osirSitePublish for a new site, then publish the finished page with osirSitePublish. No authentication needed.

NameTypeReqDescription
audiencestringyesWho visits the site and why.
briefJsonstringOptional JSON object with extras the user provided: site_type, sections[], language (ISO code, default en), tone (warm|premium|playful|technical|minimal|bold), mood_words[] (max 5), brand{logo_url, p…
businessNamestringyesThe business or project name.
pageJobstringyesThe page's single job: get_contact, sell_product, book_appointment, collect_signups, inform_portfolio, or other.
primaryActionstringyesThe one primary call to action, e.g. 'Book a table'.
whatItIsstringyesWhat the business concretely does or sells.

No output schema declared.

No examples provided.

osirSitePublish ~317

osirSitePublish: Publish a single-page website to a live HTTPS URL on Osir (free tier). ANY complete HTML document works: the user's own site, a page designed in this chat, or one from the osirSiteDesignBrief flow. Calling again with the same name redeploys the new version. For MULTI-FILE sites (separate CSS/JS/images) use osirAppCreateUpload + osirAppDeploy with a zip instead. Then poll osirAppStatus until READY. If the app was moved to the user's own VPS, redeploying under the same name updates it there and keeps its domain. Requires authentication.

NameTypeReqDescription
designContractbooleanSet true ONLY for pages generated via the osirSiteDesignBrief flow; additionally enforces its output contract (exactly one <h1>, self-contained, no external scripts/CSS except Google Fonts, no iframe…
htmlstringyesThe complete <html> document to publish (max 1 MiB).
namestringyesSite name: lowercase letters, digits, and hyphens, e.g. 'bar-mediterran'.
regionstringRegion: 'us' or 'al' ('al' is Albania/Tirana).
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

payInvoice ~112

payInvoice: Stage payment of an outstanding invoice from account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
invoiceIdstringyesThe identifier of the outstanding invoice to pay, as returned by listInvoices.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

previewPaymentFees ~116

previewPaymentFees: Preview the fees that would be charged for a given payment amount. Requires authentication.

NameTypeReqDescription
amountnumberyesPayment amount to preview, in the account currency as a decimal (e.g. 25.00).
currencystring3-letter ISO 4217 currency code, default USD.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
NameTypeReqDescription
amountstring
currencystring
feestring
messagestring
successboolean
totalstring

No examples provided.

registerDomain ~299

registerDomain: Stage registration of a new domain name. Deducts from account balance. The DNS zone is initialised automatically after registration (asynchronously; if createDnsRecord right after registration reports a missing zone, retry after a few seconds). Pass initializeDnsZone:false to opt out. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
autoRenewbooleanEnable automatic renewal; defaults to true.
domainstringyesFully qualified domain name to register, like "example.com", without scheme.
initializeDnsZonebooleanInitialise the DNS zone after registration; defaults to true.
nameserversarrayyesList of nameserver hostnames, e.g. ["ns1.example.com", "ns2.example.com"].
privacyProtectionbooleanEnable WHOIS privacy protection; defaults to true.
registrantInfoobjectyesICANN registrant contact of the domain owner: firstName, lastName, email, phone (+CC.number), and address (street, city, postalCode, country as 2-letter ISO code).
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
yearsintegeryesRegistration period in years, 1-10.

No output schema declared.

No examples provided.

renewDomain ~133

renewDomain: Stage renewal of a domain for a specified number of years. Deducts from account balance. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
domainstringyesFully qualified domain name to renew, like "example.com", without scheme.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
yearsintegeryesRenewal period in years, 1-10.

No output schema declared.

No examples provided.

setMailboxPassword ~104

setMailboxPassword: Set a new password on a mailbox. Never log or store the password. Requires authentication.

NameTypeReqDescription
mailboxIdstringyesMailbox id from listMailboxes.
passwordstringyesThe new mailbox password; never log or store it.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

spinDomainWords ~137

spinDomainWords: Generate domain suggestions by spinning/replacing words with similar alternatives.

NameTypeReqDescription
langstringLanguage code; default "eng".
maxResultsintegerMaximum suggestions to return; default 20.
namestringyesComma-separated words to spin, e.g. "pizza,restaurant".
positioninteger0-based index of the word to replace.
similaritynumberSimilarity threshold for replacements, 0.0-1.0.
tldsstringComma-separated TLDs without leading dots, e.g. "com,net".

No output schema declared.

No examples provided.

suggestAlternatives ~112

suggestAlternatives: Suggest alternative domain names if the requested one is unavailable. Legacy; prefer generateDomainSuggestions.

NameTypeReqDescription
domainstringyesFully qualified domain name to find alternatives for, like "example.com", without scheme.
limitintegerMaximum number of suggestions to return; default 10.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

transferDomain ~183

transferDomain: Stage transfer of a domain from another registrar to OSIR. Deducts from account balance. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
authCodestringyesEPP authorization code obtained from the current registrar.
domainstringyesFully qualified domain name to transfer, like "example.com", without scheme.
registrantInfoobjectyesICANN registrant contact of the domain owner: firstName, lastName, email, phone (+CC.number), and address (street, city, postalCode, country as 2-letter ISO code).
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

unlockDomain ~118

unlockDomain: Stage removal of registrar lock from a domain to allow transfers. DESTRUCTIVE: reduces domain security. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.

NameTypeReqDescription
domainstringyesFully qualified domain name to unlock, like "example.com", without scheme.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

updateContact ~274

updateContact: Update an existing contact's information. Requires authentication. Only the fields you provide are changed; omitted fields keep their current values. Get the contactId from listContacts. Returns the updated contact.

NameTypeReqDescription
citystringNew city name.
contactIdstringyesIdentifier of the contact to update, as returned by listContacts.
countrystringNew country as a 2-letter ISO 3166-1 alpha-2 code, e.g. 'US'.
emailstringNew email address.
firstNamestringNew first name.
lastNamestringNew last name.
organizationstringNew organization or company name.
phonestringNew phone number in '+CC.number' format, e.g. '+1.5551234567'.
postalCodestringNew postal or ZIP code.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
statestringNew state, province, or region.
street1stringNew first street address line.
street2stringNew second street address line.

No output schema declared.

No examples provided.

updateDnsRecord ~249

updateDnsRecord: Update an existing DNS record. Requires authentication. Only the fields you provide are changed; omitted fields keep their current values. Get the recordId from listDnsRecords. Returns the updated record.

NameTypeReqDescription
contentstringNew record value, e.g. an IPv4 dotted-quad or IPv6 address, hostname, or text.
domainstringyesFully qualified domain name the record belongs to, e.g. 'example.com'.
namestringNew record name relative to the zone, e.g. 'www' or '@' for the apex.
priorityintegerNew priority for MX/SRV records only.
recordIdstringyesIdentifier of the record to update, as returned by listDnsRecords.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.
ttlintegerNew time to live in seconds.
typestringNew record type: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA.

No output schema declared.

No examples provided.

updateDomainAutoRenew ~103

updateDomainAutoRenew: Enable or disable auto-renewal for a domain.

NameTypeReqDescription
domainstringyesFully qualified domain name, like "example.com", without scheme.
enabledbooleanyestrue to enable automatic renewal, false to disable it.
sessionKeystringSession key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth.

No output schema declared.

No examples provided.

Common questions

What is the OSIR Domain Registrar MCP server?

OSIR Domain Registrar is an MCP server listed in the public MCP registry as com.osir/domain-registrar. Register, renew, transfer, and manage domains, DNS, VPS, and email with 105 tools. By OSIR. This page covers its hosted endpoint (https://be.osir.com/mcp/http).

Is the OSIR Domain Registrar MCP server safe to use?

OSIR Domain Registrar scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the OSIR Domain Registrar MCP server expose?

OSIR Domain Registrar exposes 105 tools: addPrefixToDomain, addSshKey, addSuffixToDomain, buildVpsInstance, bulkDomainSuggestions, and 100 more. Their descriptions and schemas cost roughly 14,266 tokens of context every time the server is loaded.

Does the OSIR Domain Registrar MCP server require authentication?

No. We connected to OSIR Domain Registrar without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the OSIR Domain Registrar MCP server still maintained?

OSIR Domain Registrar is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.