OSIR Domain Registrar
REMOTE · BE.OSIR.COM · SCANNED SEP 24
Register, renew, transfer, and manage domains, DNS, VPS, and email with 105 tools. By OSIR.
Available components
Recent critical change
Authorization (3 Sept 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (buildVpsInstance). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability79
- 85% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 14561 tokens (~136/item across 107 items; 105 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management73
- Stability observed for 22 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (10% of tools); any adoption earns full credit.Pass
Tool Safety97
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 14 of 16 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "getTransferQuote" implies "transfer" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 107 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the OSIR Domain Registrar MCP server?
OSIR Domain Registrar is a hosted endpoint at https://be.osir.com/mcp/http, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · be.osir.com
claude mcp add --transport http com-osir-domain-registrar 'https://be.osir.com/mcp/http'
{
"mcpServers": {
"com-osir-domain-registrar": {
"url": "https://be.osir.com/mcp/http"
}
}
} {
"servers": {
"com-osir-domain-registrar": {
"type": "http",
"url": "https://be.osir.com/mcp/http"
}
}
} [mcp_servers.com-osir-domain-registrar] url = "https://be.osir.com/mcp/http"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-osir-domain-registrar": {
"type": "remote",
"url": "https://be.osir.com/mcp/http",
"enabled": true
}
}
} openclaw mcp add com-osir-domain-registrar --url 'https://be.osir.com/mcp/http' --transport streamable-http
mcp_servers:
com-osir-domain-registrar:
url: "https://be.osir.com/mcp/http" {
"McpServers": {
"com-osir-domain-registrar": {
"Transport": "http",
"Url": "https://be.osir.com/mcp/http"
}
}
} assistant mcp add com-osir-domain-registrar -t streamable-http -u 'https://be.osir.com/mcp/http'
{
"mcpServers": {
"com-osir-domain-registrar": {
"type": "http",
"url": "https://be.osir.com/mcp/http"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 22 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 +1
- Tool “osirAppDeploy” rewrote its description, which is the text the model reads security
- Tool “osirAppMoveToOwned” rewrote its description, which is the text the model reads security
- Tool “osirAppStatus” rewrote its description, which is the text the model reads security
- Tool “osirSitePublish” rewrote its description, which is the text the model reads security
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 0
- Tool “changeVpsPaymentTerm” rewrote its description, which is the text the model reads security
- Tool “deleteSshKey” rewrote its description, which is the text the model reads security
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://be.osir.com/mcp/http
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=be.osir.com | CN=YE2,O=Let's Encrypt,C=US | 15 Aug 2026 | 13 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 6e7a28cc9e2e81b0b48372f6ba4660b2201 |
| SANs: be.osir.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of be.osir.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| osir.com. | present | 46538 | 13 | Verified |
| be.osir.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://be.osir.com/mcp/http | Verified | 200 | |
| http (plaintext) | http://be.osir.com/mcp/http | HTTPS enforced | 301 | https://be.osir.com/mcp/http |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
getRecentActivity ~71
getRecentActivity: Get the most recent activity across all domains and services for the user. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
getTransferQuote ~111
getTransferQuote: Get a transfer price quote for a domain. Requires authentication. Returns transfer price, currency, extension years, and new expiration date. Call before initiateTransfer to show the user the cost.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to quote, e.g. 'example.com'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | – | – |
| domain | string | – | – |
| extensionYears | string | – | – |
| message | string | – | – |
| newExpirationDate | string | – | – |
| success | boolean | – | – |
| transferPrice | string | – | – |
No examples provided.
getTransferStatus ~101
getTransferStatus: Check the current status of a domain transfer. Requires authentication. Returns status, request date, current registrar, and expected completion.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name whose transfer to check, e.g. 'example.com'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
getVpsInstanceDetails ~90
getVpsInstanceDetails: Get detailed information about a specific VPS instance including resource usage. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| instanceId | string | yes | VPS instance id from listMyVpsInstances. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
getVpsPackageDetails ~106
getVpsPackageDetails: Get detailed information about a specific VPS package including all pricing tiers. Requires authentication. For anonymous browsing use listVpsPackages, which already includes per-term pricing.
| Name | Type | Req | Description |
|---|---|---|---|
| packageId | string | yes | VPS package id from listVpsPackages. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
initializeDnsZone ~142
initializeDnsZone: Initialize (create) the DNS zone for a domain. NOT needed after registerDomain, which initializes the zone automatically. Use only for pre-existing domains without a zone (e.g. after a transfer, or if registration opted out with initializeDnsZone:false). Safe on existing zones, it will not overwrite records. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to create the zone for, e.g. 'example.com'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
initiateTransfer ~174
initiateTransfer: Starts a transfer for a domain already prepared at the losing registrar (unlocked, auth code in hand). transferDomain (domain tools) stages transfer + registrant assignment in one step; use that when the user gives you contact details. Deducts from account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| authCode | string | yes | EPP/transfer authorization code obtained from the losing registrar. |
| domain | string | yes | Fully qualified domain name to transfer in, e.g. 'example.com'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listCategorizedTlds ~242
listCategorizedTlds: List TLDs from the OSIR catalog that have category and audience metadata, with registration and renewal prices as decimal strings (e.g. '10.39'). Use it to pick 3-6 relevant TLDs before calling bulkDomainSuggestions. Filters: price cap, exclude ccTLDs/restricted/premium, registry. Returns unranked candidates with categories, audience, prices, and flags. No auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| excludeCcTLDs | boolean | – | Set true to exclude country-code and IDN TLDs. |
| excludePremium | boolean | – | Set true only when the user explicitly asks for no premium or surprise pricing; premium-flagged TLDs still register most names at the standard price, so do not use this as a budget filter. |
| excludeRestricted | boolean | – | Set true to exclude TLDs with registry-level registration restrictions. |
| maxRegisterPrice | number | – | Maximum registration price as a decimal; TLDs priced above it are excluded. |
| registry | string | – | Filter to TLDs operated by this registry name (case-insensitive exact match). |
No output schema declared.
No examples provided.
listContacts ~111
listContacts: List all contacts for the authenticated user, optionally filtered by a search term. Requires authentication. Returns each contact with its id for use in getContact, updateContact, deleteContact, or domain registration.
| Name | Type | Req | Description |
|---|---|---|---|
| search | string | – | Optional search term matched against contact name, email, or organization. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listDnsRecords ~123
listDnsRecords: List all DNS records for a domain. Requires authentication. Returns each record with its id, name, type, content, TTL, and priority; use the record id with getDnsRecord, updateDnsRecord, or deleteDnsRecord.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name whose records to list, e.g. 'example.com'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listInvoices ~129
listInvoices: List invoices for the authenticated user with optional status filtering and pagination. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | Zero-based page number for pagination, default 0. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| size | integer | – | Number of invoices per page, default 20. |
| status | string | – | Filter by invoice status: DRAFT, PENDING, PAID, CANCELLED, or OVERDUE. |
No output schema declared.
No examples provided.
listMailboxes ~74
listMailboxes: List your mailboxes with plan, payment term, status, and next renewal date. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listMailDomains ~81
listMailDomains: List your domains that are enabled for email hosting, with status (PENDING_DNS or ACTIVE) and DNS mode. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listMailPlans ~84
listMailPlans: List available email mailbox plans with quotas and prices (monthly and annual, in cents). Requires authentication. Always quote prices from here, never from memory.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listMySshKeys ~105
listMySshKeys: List the SSH keys stored on your account, with their ids and SHA256 fingerprints. Use this to check whether a key is already stored and to get the ids to pass to orderVps or buildVpsInstance. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listMyVpsInstances ~71
listMyVpsInstances: List all VPS instances owned by the authenticated user. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listPendingTransfers ~85
listPendingTransfers: List all pending incoming (gaining) domain transfers. Requires authentication. Returns each transfer with its status, request date, current registrar, and expected completion.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listUserDomains ~72
listUserDomains: List all domains owned by the authenticated user. No parameters required. Must be authenticated first.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listVpsLocations ~33
listVpsLocations: List available VPS hosting locations (cities/countries) with available packages. No authentication required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
listVpsOsTemplates ~234
listVpsOsTemplates: List operating system templates available to install. Requires authentication. Pass EXACTLY ONE of packageId (to pick an operatingSystemId for orderVps, so the server arrives with an OS on it) or instanceId (to pick a template for reinstalling via buildVpsInstance). The two are not interchangeable: the available set depends on the package. Template ids change over time, so always resolve an id here rather than reusing a remembered or hardcoded one.
| Name | Type | Req | Description |
|---|---|---|---|
| includeEol | boolean | – | Include end-of-life templates (default false). |
| instanceId | string | – | VPS instance id from listMyVpsInstances; use to see what an existing server can be reinstalled with via buildVpsInstance. |
| packageId | string | – | VPS package id from listVpsPackages; use BEFORE ordering to pick an operatingSystemId for orderVps. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
listVpsPackages ~32
listVpsPackages: List available VPS hosting packages with pricing, specs, and locations. No authentication required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lockDomain ~84
lockDomain: Enable registrar lock on a domain to prevent unauthorized transfers.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to lock, like "example.com", without scheme. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
loginToVpsPanel ~98
loginToVpsPanel: Generate a one-time login URL to the VPS control panel (VirtFusion) for managing the server. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| instanceId | string | yes | VPS instance id from listMyVpsInstances. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
loginWithDevice ~71
loginWithDevice: Start a device authorization login (RFC 8628). Returns a verificationUri and userCode. Open the URI in your browser, enter the code, and sign in with your OSIR credentials. Then call checkDeviceLoginStatus with the returned deviceCode to complete login. No parameters required.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
logout ~84
logout: Log out: revokes the session's tokens at the identity provider immediately. Optional: sessionKey (from checkDeviceLoginStatus); pass it to end that conversation session.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
orderVps ~244
orderVps: Stage an order for a new VPS instance; deducts from account balance. Requires authentication. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| hostname | string | yes | Hostname for the new server, e.g. 'myserver.example.com'. |
| operatingSystemId | integer | – | Integer OS template id resolved with listVpsOsTemplates using this same packageId; omit to get a server with NO operating system installed. |
| packageId | string | yes | VPS package id from listVpsPackages. |
| paymentTerm | string | yes | Billing cycle: 'MONTHLY', 'SEMI_ANNUAL', 'ANNUAL', 'BIENNIAL', or 'TRIENNIAL'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| sshKeyIds | array | – | Integer SSH key ids from listMySshKeys or addSshKey, injected during install; without one you cannot log in. |
No output schema declared.
No examples provided.
osirAppCreateUpload ~106
osirAppCreateUpload: Create an upload ticket for deploying app source code to Osir. Returns an uploadTicket, a putUrl, and instructions to zip the project and upload it. After uploading, call osirAppDeploy with the uploadTicket. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirAppDelete ~125
osirAppDelete: Stage deletion of an Osir app. DESTRUCTIVE and irreversible: removes its microVM, image, route, and data. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id from osirAppList. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirAppDeploy ~294
osirAppDeploy: Deploy an app to Osir (free tier) and get a live HTTPS URL; the app runs isolated in a microVM. Deploying an existing app name redeploys it (new version) and applies any secrets set via osirAppSetSecret. A plain static website (HTML/CSS/JS with no framework or build step) is also supported: it is auto-detected and served directly; pass language 'node' for it. If the app was moved to the user's own VPS, redeploying under the same name updates it there and keeps its domain. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| language | string | yes | Runtime language: 'node', 'python', 'php-laravel', or 'go'; use 'node' for a plain static site. |
| name | string | yes | App name: lowercase letters, digits, and hyphens, e.g. 'habit-tracker'. |
| region | string | – | Region: 'us' or 'al' ('al' is Albania/Tirana); defaults to the platform's home region. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| uploadTicket | string | yes | Upload ticket from osirAppCreateUpload, after uploading the zipped source to its putUrl. |
No output schema declared.
No examples provided.
osirAppGetSource ~167
osirAppGetSource: Get a short-lived signed download URL for an Osir app's current source zip. Use this to make edits to a deployed app without the user re-attaching the project: download, patch the files, then osirAppCreateUpload (PUT the new zip) and osirAppDeploy under the SAME name; the platform rebuilds and, for owned-tier apps, auto-ships the new version to the user's box. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appName | string | yes | The deployed app's name, as shown by osirAppList. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirAppList ~74
osirAppList: List the authenticated user's deployed Osir apps with their live URLs and status. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirAppLogs ~111
osirAppLogs: Get recent logs from an Osir app's microVM ('why is my app broken?'). Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id from osirAppList. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| tail | integer | – | Number of recent log lines to return (default 100). |
No output schema declared.
No examples provided.
osirAppMoveToOwned ~479
osirAppMoveToOwned: Move a deployed Osir app from the shared free tier onto a VPS owned by the user. TWO WAYS IN. (1) The user already owns a VPS: pass instanceId (from listMyVpsInstances) and NO packageId - this ATTACHES the app to that server, SPENDS NOTHING and needs no confirmation. (2) No server yet: pass packageId (from listVpsPackages) and the call stages a VPS order (COSTS MONEY): returns an actionId; present the price/summary to the user and call executeConfirmedAction only if they approve. Before staging any order this tool checks whether the user ALREADY has a box for this app (its C2 binding, then their own VPS list) and attaches that instead - a retry after a failed move never buys a second server. After the move starts the platform ships the app onto the box server-side, which takes about two minutes; watch it with osirAppStatus ('ownedMove'). Calling this tool again while a move is still running just reports its progress, and calling it after one FAILED retries the ship - unless osirAppStatus says the VPS refused the Osir deploy key or its web ports are taken: then retry only after the user has made the changes that message lists. If the result status is BUILDING or BUILD_FAILED, follow its nextStep. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appName | string | yes | The deployed app's name, as shown by osirAppList. |
| domain | string | – | Custom domain to serve the app on; DNS is bound automatically if the domain is hosted on osir.app nameservers, otherwise the result returns the IP and manual DNS instructions. |
| instanceId | string | – | Id of a VPS the user ALREADY owns, from listMyVpsInstances. Given this, the app is attached to that server and nothing is ordered or charged. Never invent one. |
| packageId | string | – | VPS package id from listVpsPackages. Required ONLY when a server has to be ordered; omit it when passing instanceId. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirAppProvisionDatabase ~137
osirAppProvisionDatabase: Provision a managed Postgres database for an Osir app. The connection string is stored as the app's DATABASE_URL secret (encrypted, injected on the next osirAppDeploy) and is NEVER returned. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id from osirAppList. |
| engine | string | – | Database engine; only 'postgres' (the default) is supported. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirAppSetSecret ~156
osirAppSetSecret: Set an environment secret for an Osir app (e.g. DATABASE_URL, API_KEY). The value is stored encrypted and injected as an env var on the next osirAppDeploy of the app; it is NEVER returned or logged. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id from osirAppList. |
| key | string | yes | Environment variable name, e.g. 'API_KEY'. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| value | string | yes | The secret value; never returned or logged. |
No output schema declared.
No examples provided.
osirAppStatus ~283
osirAppStatus: Get an Osir app's current status, live URL, and health ('is my app working?'). If the status is BUILD_FAILED, 'recentErrors' explains why so you can fix the source and redeploy. 'qa' is an independent black-box check of the LIVE app after deploy: qa.status PASSED means it loaded and worked; FAILED means it deployed but didn't actually work, and qa.findings lists the problems so you can fix and redeploy. 'ownedMove' tracks a move onto the user's own VPS, which leaves tier and status unchanged while it runs: state MOVING (in progress, stage says where, ~2 minutes in total), MOVED (done - tier reads 'owned'), FAILED or REFUSED (follow this result's message: usually call osirAppMoveToOwned again to retry, which never orders a second server; but when the VPS refused the Osir deploy key or its web ports are taken, the user must fix the VPS first, and the message says how). Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id from osirAppList or a deploy result. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
osirSiteDesignBrief ~364
osirSiteDesignBrief: Step 1 of designing a NEW website with OSIR. Validates the brief and returns 'systemPrompt', the structured design brief and constraints YOU must then follow to write one complete self-contained HTML page, plus 'editRules' for later revisions. Call it before osirSitePublish for a new site, then publish the finished page with osirSitePublish. No authentication needed.
| Name | Type | Req | Description |
|---|---|---|---|
| audience | string | yes | Who visits the site and why. |
| briefJson | string | – | Optional JSON object with extras the user provided: site_type, sections[], language (ISO code, default en), tone (warm|premium|playful|technical|minimal|bold), mood_words[] (max 5), brand{logo_url, p… |
| businessName | string | yes | The business or project name. |
| pageJob | string | yes | The page's single job: get_contact, sell_product, book_appointment, collect_signups, inform_portfolio, or other. |
| primaryAction | string | yes | The one primary call to action, e.g. 'Book a table'. |
| whatItIs | string | yes | What the business concretely does or sells. |
No output schema declared.
No examples provided.
osirSitePublish ~317
osirSitePublish: Publish a single-page website to a live HTTPS URL on Osir (free tier). ANY complete HTML document works: the user's own site, a page designed in this chat, or one from the osirSiteDesignBrief flow. Calling again with the same name redeploys the new version. For MULTI-FILE sites (separate CSS/JS/images) use osirAppCreateUpload + osirAppDeploy with a zip instead. Then poll osirAppStatus until READY. If the app was moved to the user's own VPS, redeploying under the same name updates it there and keeps its domain. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| designContract | boolean | – | Set true ONLY for pages generated via the osirSiteDesignBrief flow; additionally enforces its output contract (exactly one <h1>, self-contained, no external scripts/CSS except Google Fonts, no iframe… |
| html | string | yes | The complete <html> document to publish (max 1 MiB). |
| name | string | yes | Site name: lowercase letters, digits, and hyphens, e.g. 'bar-mediterran'. |
| region | string | – | Region: 'us' or 'al' ('al' is Albania/Tirana). |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
payInvoice ~112
payInvoice: Stage payment of an outstanding invoice from account balance. Requires authentication. Returns an actionId; present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| invoiceId | string | yes | The identifier of the outstanding invoice to pay, as returned by listInvoices. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
previewPaymentFees ~116
previewPaymentFees: Preview the fees that would be charged for a given payment amount. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Payment amount to preview, in the account currency as a decimal (e.g. 25.00). |
| currency | string | – | 3-letter ISO 4217 currency code, default USD. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| Name | Type | Req | Description |
|---|---|---|---|
| amount | string | – | – |
| currency | string | – | – |
| fee | string | – | – |
| message | string | – | – |
| success | boolean | – | – |
| total | string | – | – |
No examples provided.
registerDomain ~299
registerDomain: Stage registration of a new domain name. Deducts from account balance. The DNS zone is initialised automatically after registration (asynchronously; if createDnsRecord right after registration reports a missing zone, retry after a few seconds). Pass initializeDnsZone:false to opt out. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| autoRenew | boolean | – | Enable automatic renewal; defaults to true. |
| domain | string | yes | Fully qualified domain name to register, like "example.com", without scheme. |
| initializeDnsZone | boolean | – | Initialise the DNS zone after registration; defaults to true. |
| nameservers | array | yes | List of nameserver hostnames, e.g. ["ns1.example.com", "ns2.example.com"]. |
| privacyProtection | boolean | – | Enable WHOIS privacy protection; defaults to true. |
| registrantInfo | object | yes | ICANN registrant contact of the domain owner: firstName, lastName, email, phone (+CC.number), and address (street, city, postalCode, country as 2-letter ISO code). |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| years | integer | yes | Registration period in years, 1-10. |
No output schema declared.
No examples provided.
renewDomain ~133
renewDomain: Stage renewal of a domain for a specified number of years. Deducts from account balance. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to renew, like "example.com", without scheme. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| years | integer | yes | Renewal period in years, 1-10. |
No output schema declared.
No examples provided.
setMailboxPassword ~104
setMailboxPassword: Set a new password on a mailbox. Never log or store the password. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| mailboxId | string | yes | Mailbox id from listMailboxes. |
| password | string | yes | The new mailbox password; never log or store it. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
spinDomainWords ~137
spinDomainWords: Generate domain suggestions by spinning/replacing words with similar alternatives.
| Name | Type | Req | Description |
|---|---|---|---|
| lang | string | – | Language code; default "eng". |
| maxResults | integer | – | Maximum suggestions to return; default 20. |
| name | string | yes | Comma-separated words to spin, e.g. "pizza,restaurant". |
| position | integer | – | 0-based index of the word to replace. |
| similarity | number | – | Similarity threshold for replacements, 0.0-1.0. |
| tlds | string | – | Comma-separated TLDs without leading dots, e.g. "com,net". |
No output schema declared.
No examples provided.
suggestAlternatives ~112
suggestAlternatives: Suggest alternative domain names if the requested one is unavailable. Legacy; prefer generateDomainSuggestions.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to find alternatives for, like "example.com", without scheme. |
| limit | integer | – | Maximum number of suggestions to return; default 10. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
transferDomain ~183
transferDomain: Stage transfer of a domain from another registrar to OSIR. Deducts from account balance. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| authCode | string | yes | EPP authorization code obtained from the current registrar. |
| domain | string | yes | Fully qualified domain name to transfer, like "example.com", without scheme. |
| registrantInfo | object | yes | ICANN registrant contact of the domain owner: firstName, lastName, email, phone (+CC.number), and address (street, city, postalCode, country as 2-letter ISO code). |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
unlockDomain ~118
unlockDomain: Stage removal of registrar lock from a domain to allow transfers. DESTRUCTIVE: reduces domain security. Returns an actionId: present the summary to the user, then call executeConfirmedAction with the actionId if they approve.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name to unlock, like "example.com", without scheme. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
updateContact ~274
updateContact: Update an existing contact's information. Requires authentication. Only the fields you provide are changed; omitted fields keep their current values. Get the contactId from listContacts. Returns the updated contact.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | New city name. |
| contactId | string | yes | Identifier of the contact to update, as returned by listContacts. |
| country | string | – | New country as a 2-letter ISO 3166-1 alpha-2 code, e.g. 'US'. |
| string | – | New email address. | |
| firstName | string | – | New first name. |
| lastName | string | – | New last name. |
| organization | string | – | New organization or company name. |
| phone | string | – | New phone number in '+CC.number' format, e.g. '+1.5551234567'. |
| postalCode | string | – | New postal or ZIP code. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| state | string | – | New state, province, or region. |
| street1 | string | – | New first street address line. |
| street2 | string | – | New second street address line. |
No output schema declared.
No examples provided.
updateDnsRecord ~249
updateDnsRecord: Update an existing DNS record. Requires authentication. Only the fields you provide are changed; omitted fields keep their current values. Get the recordId from listDnsRecords. Returns the updated record.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | New record value, e.g. an IPv4 dotted-quad or IPv6 address, hostname, or text. |
| domain | string | yes | Fully qualified domain name the record belongs to, e.g. 'example.com'. |
| name | string | – | New record name relative to the zone, e.g. 'www' or '@' for the apex. |
| priority | integer | – | New priority for MX/SRV records only. |
| recordId | string | yes | Identifier of the record to update, as returned by listDnsRecords. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
| ttl | integer | – | New time to live in seconds. |
| type | string | – | New record type: A, AAAA, CNAME, MX, TXT, NS, SRV, CAA. |
No output schema declared.
No examples provided.
updateDomainAutoRenew ~103
updateDomainAutoRenew: Enable or disable auto-renewal for a domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Fully qualified domain name, like "example.com", without scheme. |
| enabled | boolean | yes | true to enable automatic renewal, false to disable it. |
| sessionKey | string | – | Session key (osk_...) returned by checkDeviceLoginStatus. Pass it on every call when logged in via the in-chat device flow; omit when connected via OAuth. |
No output schema declared.
No examples provided.
What is the OSIR Domain Registrar MCP server?
OSIR Domain Registrar is an MCP server listed in the public MCP registry as com.osir/domain-registrar. Register, renew, transfer, and manage domains, DNS, VPS, and email with 105 tools. By OSIR. This page covers its hosted endpoint (https://be.osir.com/mcp/http).
Is the OSIR Domain Registrar MCP server safe to use?
OSIR Domain Registrar scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the OSIR Domain Registrar MCP server expose?
OSIR Domain Registrar exposes 105 tools: addPrefixToDomain, addSshKey, addSuffixToDomain, buildVpsInstance, bulkDomainSuggestions, and 100 more. Their descriptions and schemas cost roughly 14,266 tokens of context every time the server is loaded.
Does the OSIR Domain Registrar MCP server require authentication?
No. We connected to OSIR Domain Registrar without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the OSIR Domain Registrar MCP server still maintained?
OSIR Domain Registrar is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.