Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

run.domani/domani

REMOTE · DOMANI.RUN · SCANNED OCT 2

Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC.

Available components

0 this week 39 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security97
  • The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
  • The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
  • HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
  • The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
  • DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
  • The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the run.domani/domani MCP server?

run.domani/domani is a hosted endpoint at https://domani.run/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · domani.run

# add to Claude Code
claude mcp add --transport http run-domani-domani 'https://domani.run/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "run-domani-domani": {
      "url": "https://domani.run/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "run-domani-domani": {
      "type": "http",
      "url": "https://domani.run/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.run-domani-domani]
url = "https://domani.run/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "run-domani-domani": {
      "type": "remote",
      "url": "https://domani.run/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add run-domani-domani --url 'https://domani.run/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  run-domani-domani:
    url: "https://domani.run/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "run-domani-domani": {
      "Transport": "http",
      "Url": "https://domani.run/mcp"
    }
  }
}
# add to Vellum
assistant mcp add run-domani-domani -t streamable-http -u 'https://domani.run/mcp'
// mcp.json
{
  "mcpServers": {
    "run-domani-domani": {
      "type": "http",
      "url": "https://domani.run/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 1 Sept 26 0
    • Endpoint reachability: reachable → behind authorisation ▼ security
    • Stability: pass → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Transport: pass → unverified ▼ security
    • Authorization: fail → pass ▲ security
    • First check of Authorization: partial security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • First check of Schema quality: unverified functional
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 0
    • Stability: 0.97 → pass security
    • Tool “create_mailbox” rewrote its description, which is the text the model reads security
    • Tool “create_webhook” rewrote its description, which is the text the model reads security
    • Tool “get_activation” rewrote its description, which is the text the model reads security
    • Tool “provision_agent” rewrote its description, which is the text the model reads security
    • Tool “set_email_webhook” rewrote its description, which is the text the model reads security
    • Tool “test_email_webhook” rewrote its description, which is the text the model reads security
    • Tool “update_webhook” rewrote its description, which is the text the model reads security
    • “create_webhook” added an optional parameter “headers” cosmetic
    • “provision_agent” added an optional parameter “webhook_headers” cosmetic
    • “set_email_webhook” added an optional parameter “headers” cosmetic
    • “update_webhook” added an optional parameter “headers” cosmetic
  • 22 Aug 26 0
    • Tool “cancel_plan” rewrote its description, which is the text the model reads security
    • Tool “upgrade_plan” rewrote its description, which is the text the model reads security
    • Tool “cancel_plan” changed its title: Cancel Pro Plan → Cancel Paid Plan cosmetic
    • Tool “upgrade_plan” changed its title: Upgrade to Pro → Upgrade Plan cosmetic
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Probed https://domani.run/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=domani.run CN=YE1,O=Let's Encrypt,C=US 3 Sept 2026 2 Dec 2026 ECDSA 256 ECDSA-SHA384 5eede2c575a4a399afb967c7ab765a4e095
SANs: *.domani.run, domani.run
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of domani.run. — Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
run. present 37315 8 Verified
domani.run. present 2371 13 Verified
domani.run. Verified address RRset verified with the apex keys
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"

Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"
Header Value
strict-transport-security max-age=63072000
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://vercel.live https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'; connect-src 'self' https://api.stripe.com https://cloudflare-dns.com https://vercel.live https://va.vercel-scripts.com; frame-src https://js.stripe.com https://vercel.live
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()
www-authenticate Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://domani.run/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://domani.run/mcp
Authorisation server https://domani.run

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://domani.run/mcp Auth required 401
http (plaintext) http://domani.run/mcp HTTPS enforced 308 https://domani.run/mcp
MCP tools · 122 exposed · ~13,182 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
acquire_domain ~110

Ask domani to acquire a specific taken, unlisted domain on your behalf. Agents source the owner via RDAP, reach out anonymously, and negotiate - commission-only, no upfront fee. Owner interest opens an anonymous negotiation you can accept/counter. Note: many owners are unreachable (GDPR-redacted WHOIS). Requires deals:write scope.

NameTypeReqDescription
domainstringyesThe taken domain you want, e.g. dream.com
max_budgetnumber–Your ceiling in USD (optional)

No output schema declared.

No examples provided.

add_dnssec ~164

Publish a DNSSEC delegation-signer (DS) record at the registry to enable DNSSEC. Get the DS values from your zone provider after signing the zone.

NameTypeReqDescription
algorithmstringyesDNSSEC algorithm number, e.g. 13 (ECDSAP256SHA256)
digeststringyesHex digest of the DNSKEY
digestTypestringyesDigest type number, e.g. 2 (SHA-256)
domainstringyesDomain name to enable DNSSEC for
flagsstring–Optional DNSKEY flags, e.g. 257 (KSK)
keyTagstringyesKey tag, e.g. 12345
maxSigLifestring–Optional max signature life in seconds

No output schema declared.

No examples provided.

add_mail_rule ~200

Add an inbound filtering rule to a mailbox. If a message matches (by from/to/subject/body), the action runs: drop, mark_read, forward (to action_arg), webhook_only (skip forward-to), or label (with action_arg). Rules run in priority order (lower first); first match wins. API: POST /api/emails/{address}/rules.

NameTypeReqDescription
actionstringyesWhat to do on match
action_argstring–For 'forward': the destination email. For 'label': the label value.
domainstringyesMailbox domain
enabledboolean–Default true
match_fieldstringyesWhich field to match on
match_opstringyesHow to match
match_valuestringyesThe value/pattern to match
priorityinteger–Lower runs first (default 0)
slugstringyesMailbox slug

No output schema declared.

No examples provided.

add_mailbox_alias ~137

Add an alias address that delivers into an existing mailbox, without using a mailbox slot. Useful for multiple public addresses (sales@, hello@, contact@) landing in one inbox. The alias must be on the same domain as the mailbox. API: POST /api/emails/{address}/aliases.

NameTypeReqDescription
aliasstringyesAlias address - a bare slug ('sales') or a full address on the same domain ('sales@mysite.com')
domainstringyesMailbox domain, e.g. mysite.com
slugstringyesMailbox slug the alias delivers to, e.g. inbox

No output schema declared.

No examples provided.

add_suppression ~76

Manually add an address to your suppression list so future sends skip it. Hard bounces and complaints are added automatically - use this for addresses you want to stop emailing. API: POST /api/suppressions.

NameTypeReqDescription
addressstringyesEmail address to suppress
reasonstring–Reason (default: manual)

No output schema declared.

No examples provided.

browse_marketplace ~77

Browse domains for sale on the Domani marketplace. Returns all active listings with prices. Use buy_domain to purchase a listed domain.

NameTypeReqDescription
max_pricenumber–Maximum price in USD
orderstring–Sort order (default: asc)
sortstring–Sort by price or TLD (default: price)

No output schema declared.

No examples provided.

buy_aftermarket ~240

Buy a taken domain that's listed for sale on an aftermarket (Afternic/Sedo) at its buy-now price, natively - no external site. Use when search shows a domain with for_sale.buyable = true. Always confirm the price with the user first. Pass max_price to cap it. If the listing is make-offer only (not buyable), use acquire_domain (broker) to negotiate instead. Crypto/USDC works like buy_domain (402 -> pay -> retry with payment_tx).

NameTypeReqDescription
domainstringyesThe taken, for-sale domain to buy, e.g. kami.world
max_pricenumber–Hard ceiling in USD. Defaults to the listing's buy-now price. The purchase is rejected if the live price is above this.
payment_chainstring–Chain the USDC payment was sent on. Required with payment_tx.
payment_methodstring–'card' to charge the card on file, 'usdc' to pay with crypto.
payment_txstring–Tx hash of a USDC payment already sent on-chain (step 2 of the USDC flow).

No output schema declared.

No examples provided.

buy_domain ~326

Purchase one or more domains. Always confirm with the user before calling. Accepts a single domain or an array of up to 10 (card only for bulk). If the user wants to pay with crypto/USDC: call with payment_method: 'usdc' - you'll get a 402 with a wallet address and amount. Tell the user to send that amount in USDC, then once they give you the tx hash, retry with payment_tx and payment_chain. Don't explain protocol details to the user - just tell them the address, amount, and chain.

NameTypeReqDescription
domainstring–Single domain to purchase, e.g. mysite.com
domainsarray–Array of domains to purchase, e.g. ["a.com", "b.dev"]. Max 10.
max_pricenumber–Ceiling in USD for the total charge. If the real price is above it, the purchase fails with PRICE_ABOVE_MAX and nothing is charged. Set it from the price the user approved.
payment_chainstring–Chain the USDC payment was sent on. Required with payment_tx.
payment_methodstring–Payment method: 'card' to charge card on file, 'usdc' to pay with USDC. Overrides the user's default preference for this request.
payment_txstring–Transaction hash of a USDC payment already sent on-chain. Required for step 2 of USDC flow.
yearsinteger–Number of years to register (1-10, default 1). Price is multiplied by years.

No output schema declared.

No examples provided.

cancel_backorder ~46

Stop watching a domain by cancelling a backorder. Only backorders in the 'watching' state can be cancelled.

NameTypeReqDescription
idstringyesThe backorder ID to cancel

No output schema declared.

No examples provided.

cancel_broker_request ~35

Cancel an active domain acquisition request. Requires deals:write scope.

NameTypeReqDescription
request_idstringyesThe broker request ID

No output schema declared.

No examples provided.

cancel_plan ~41

Cancel the user's current paid subscription. The subscription remains active until the end of the current billing period, then reverts to the free plan. Returns the cancellation date.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

check_email ~51

Check email DNS health for a domain: MX records, SPF, DMARC, DKIM. Auto-detects the email provider from MX records.

NameTypeReqDescription
domainstringyesDomain to check email health for

No output schema declared.

No examples provided.

check_email_deliverability ~194

Run the same deliverability and abuse-safety checks used by send_email, without sending or consuming quota. Use this before authentication, payment, onboarding, or high-volume messages. API: POST /api/emails/{address}/deliverability-check.

NameTypeReqDescription
allow_risky_contentboolean–Deprecated compatibility field. Public HTTPS third-party auth links are allowed with a warning; objective safety blocks cannot be overridden
attachmentsarray–Attachment metadata only; content is not required for preflight
domainstringyesSender mailbox domain, e.g. mysite.com or domani.run
htmlstring–HTML body
idempotency_keystring–Stable idempotency key for this logical message
slugstringyesSender mailbox slug, e.g. hello
subjectstring–Email subject line
textstring–Plain-text body

No output schema declared.

No examples provided.

check_transfer_eligibility ~78

Pre-check whether a domain can be transferred. Returns transfer price, eligibility status, and any blockers (unsupported TLD, ICANN waiting period, domain locked, etc.). Always call this before transfer_domain to verify eligibility and show the user the price.

NameTypeReqDescription
domainstringyesDomain to check, e.g. mysite.com

No output schema declared.

No examples provided.

check_transfer_status ~52

Check the status of an inbound domain transfer. Returns detailed status (pending_owner, pending_admin, pending_registry, completed, cancelled) with actionable hints.

NameTypeReqDescription
domainstringyesDomain to check transfer status for

No output schema declared.

No examples provided.

claim_identity ~150

Give your agent a free identity at <handle>.domani.run - a live profile page, no domain purchase, instantly. The frictionless way to start; upgrade to your own real domain later. Optional name/bio/emoji/email/links.

NameTypeReqDescription
biostring–Short description (<= 280 chars)
emailstring–Public contact email (e.g. your free @domani.run inbox)
emojistring–Avatar emoji
linksarray–Up to 6 links
namestring–Display name
slugstringyesThe handle - becomes <slug>.domani.run (lowercase letters, numbers, hyphens)

No output schema declared.

No examples provided.

clear_catch_all ~56

Remove the catch-all on a domain. Email to unmatched addresses will be dropped again. API: DELETE /api/domains/{domain}/email/catch-all.

NameTypeReqDescription
domainstringyesDomain to clear the catch-all on

No output schema declared.

No examples provided.

clone_dns ~120

Copy the DNS setup of one domain you own onto another (e.g. brand.com → brand.dev with the same A/CNAME/MX). Merges by default (source wins on collisions, keeps the target's other records); set replace=true for an exact mirror.

NameTypeReqDescription
from_domainstringyesSource domain to copy DNS from (must be yours)
replaceboolean–Exact mirror - drop target records the source doesn't have. Default: merge
to_domainstringyesTarget domain to write the DNS onto (must be yours)

No output schema declared.

No examples provided.

connect_domain ~287

Connect a domain to a hosting or email provider. Auto-detects provider from target, or accepts explicit provider name. For domains bought through the platform, DNS records are set automatically (status: dns_set). For imported domains (external registrar), returns the records as instructions to add manually (status: manual_setup_required). If the connect would REPLACE existing MX records pointing at another provider, it fails with MX_REPLACEMENT_REQUIRES_CONFIRMATION - preview with dry_run, confirm with the user, then retry with confirm_replace_mx. The response includes a next_steps array with provider-specific actions. Supported hosting: vercel, netlify, cloudflare-pages, github-pages, railway, fly. Email: google-workspace, fastmail, proton.

NameTypeReqDescription
confirm_replace_mxboolean–Confirm replacing existing MX records that point at another provider (moves the domain's email)
domainstringyesDomain to connect, e.g. mysite.com
dry_runboolean–Preview only - returns the diff (create/replace/keep) without writing
methodstring–Connection method if provider has multiple, e.g. cname-only
providerstring–Explicit provider name, e.g. vercel, google-workspace
targetstring–Target URL for auto-detection, e.g. my-app.vercel.app

No output schema declared.

No examples provided.

create_backorder ~171

Place a backorder on a domain that is currently registered to someone else. We watch it and automatically register it for the user when it becomes available (drops) - availability is polled every few minutes. The user is charged only if the catch succeeds - no upfront fee. Requires a card on file or payment_method 'balance'. Confirm the domain with the user first. Best-effort: a contested drop may be taken by a specialized drop-catcher first.

NameTypeReqDescription
domainstringyesThe currently-taken domain to watch and catch on drop, e.g. taken.com
max_pricenumber–Max USD to pay when caught. Defaults to the current registration price.
payment_methodstring–How to pay when caught: 'card' or 'balance' (marketplace credit).

No output schema declared.

No examples provided.

create_hosted_mailbox ~176

Create a real IMAP/SMTP mailbox on a domain you own (connect Apple Mail, Thunderbird, or any mail client), instead of an API mailbox. Pass workspace_id to create it in a workspace you own and atomically adopt the domain boundary. Provisions the mailbox on our mail server, publishes DNS when we manage it, and returns the DNS records, mail client settings, and a one-time app password. API: POST /api/emails with kind=hosted.

NameTypeReqDescription
domainstringyesA domain you own, e.g. mysite.com
namestring–Display name for the mailbox
slugstringyesLocal part, e.g. 'me' for me@mysite.com
workspace_idstring–Workspace ID from list_workspaces; owner-only

No output schema declared.

No examples provided.

create_mailbox ~244

Create an email address. Specify slug (required) and optionally domain. Pass workspace_id to create it inside a workspace you own; custom-domain creation atomically adopts the domain and all unscoped sibling mailboxes so a domain is never split. Custom-domain capacity follows the active account or workspace plan. For imported domains (external registrar): returns DNS records to add manually at your registrar. For domani.run: omit domain; each account has one free mailbox. Pass force=true to override an existing email provider (Google Workspace, etc.). API: POST /api/emails with {address}.

NameTypeReqDescription
domainstring–Domain for the mailbox. Omit for domani.run
forceboolean–Override existing MX records (e.g. Google Workspace). Default: false
namestring–Display name for outbound emails, e.g. 'John Doe'. Shows as 'John Doe <slug@domain>' in recipients' inboxes
slugstringyesLocal part of the email address, e.g. 'hello' for hello@mysite.com
workspace_idstring–Workspace ID from list_workspaces; owner-only

No output schema declared.

No examples provided.

create_mailbox_credential ~90

Create an app password for a hosted mailbox, used as the password in a mail client. The secret is returned once - store it. API: POST /api/emails/{address}/credentials.

NameTypeReqDescription
domainstringyesHosted mailbox domain
labelstring–Label to identify this app password, e.g. 'Laptop Mail'
slugstringyesHosted mailbox slug

No output schema declared.

No examples provided.

create_token ~933

Create a new API token with optional scoped permissions and spend caps. The full key is returned only once - save it immediately. A token can only grant scopes it already has (scope attenuation) and spend caps at or below its own. Scopes: domains:read (GET /api/domains, GET /api/domains/{domain}, GET /api/domains/{domain}/dns, /dnssec, /status, /email/check, /auth-code, /transfer-away, /transfer-status, /analytics), domains:write (PUT /api/domains/{domain}/dns, POST/DELETE /api/domains/{domain}/dnssec, POST /connect, POST /verify, PUT /settings, PUT /parking, PUT/DELETE /api/domains/{domain}/for-sale, POST /api/domains/import, POST /import/verify), domains:transfer (POST /api/domains/buy, POST /transfer, POST /renew (involves payment, includes marketplace purchases)), tokens:read (GET /api/tokens), tokens:write (POST /api/tokens, DELETE /api/tokens/{id}), webhooks:read (GET /api/webhooks, GET /api/webhooks/{id}/deliveries), webhooks:write (POST /api/webhooks, PATCH /api/webhooks/{id}, DELETE /api/webhooks/{id}), email:read (GET /api/emails, /api/emails/{address}, /api/emails/{address}/messages, /api/emails/{address}/aliases, /api/email/changes, /api/domains/{domain}/email/status, /api/domains/{domain}/email/deliverability, /api/suppressions), email:write (POST /api/emails, POST /api/emails/{address}/send, POST /api/domains/{domain}/email/setup, aliases + catch-all, POST/DELETE /api/suppressions), email:delete (Permanently delete messages already in Trash. Moving messages to Trash only requires email:write. Grant this scope only to agents allowed to irreversibly erase email content), email:auth_secrets (Read messages classified as authentication mail (OTP / verification codes, password resets, magic links). Without it, email:read still lists them but subject and body come back redacted - so a stolen agent token can't harvest 2FA codes. Grant it only to agents that genuinely need to complete logins), account:read (GET /api/me, GET /api/agents/identity), account:write…

NameTypeReqDescription
agent_identity_idstring–Optional owned AgentIdentity id. Mail actions made with this token are attributed to that agent
expires_atstring–Absolute expiration date (ISO 8601). Alternative to expires_in
expires_ininteger–Token lifetime in seconds (min 3600 = 1h, max 31536000 = 1y). Omit for no expiration
max_per_monthnumber–Rolling calendar-month spend cap in USD for all paid operations with this token
max_per_txnumber–Per-transaction spend cap in USD - any single charge above it is rejected server-side (SPEND_CAP_EXCEEDED)
namestring–Human-readable label, e.g. 'CI/CD', 'Sub-Agent'. Defaults to 'CLI'
scopesarray–Permission scopes for this token. Defaults to parent token's scopes. Use ['*'] for full access

No output schema declared.

No examples provided.

create_webhook ~140

Register a new webhook endpoint to receive event notifications. The URL must use HTTPS. Optional Authorization or X-API-Key headers are encrypted and sent with every delivery. The webhook secret is returned only once - save it to verify incoming payloads with HMAC-SHA256.

NameTypeReqDescription
eventsarrayyesEvent types to subscribe to, e.g. ["domain.purchased", "dns.updated"]. Use list_webhook_events to see all available types.
headersobject–Optional auth headers. Only Authorization and X-API-Key are accepted; values are encrypted and never returned.
urlstringyesHTTPS URL that will receive webhook POST requests

No output schema declared.

No examples provided.

delete_dnssec ~61

Remove a DNSSEC delegation-signer (DS) record at the registry by its key tag. Removing all DS records disables DNSSEC.

NameTypeReqDescription
domainstringyesDomain name
keyTagstringyesKey tag of the DS record to remove

No output schema declared.

No examples provided.

delete_mailbox ~83

Delete a mailbox and all its messages (including attachments). Requires confirm=true. Call without confirm first to see what will be deleted. API: DELETE /api/emails/{address}.

NameTypeReqDescription
confirmboolean–Must be true to actually delete. Omit to preview.
domainstringyesMailbox domain
slugstringyesMailbox slug

No output schema declared.

No examples provided.

delete_message ~74

Move an email message to Trash. This is reversible with update_email_messages action=restore. API: DELETE /api/emails/{address}/messages/{id}.

NameTypeReqDescription
domainstringyesMailbox domain
message_idstringyesID of the message to delete
slugstringyesMailbox slug

No output schema declared.

No examples provided.

delete_messages ~111

Retry-safely move messages to Trash and return a durable per-item receipt. Reuse the exact idempotency key after timeouts. Reversible with update_email_messages action=restore. API: POST /api/emails/{address}/messages/delete.

NameTypeReqDescription
domainstringyesMailbox domain
idempotency_keystringyesCaller-stable key for this exact logical batch
message_idsarrayyesIDs of messages to delete
slugstringyesMailbox slug

No output schema declared.

No examples provided.

delete_webhook ~41

Delete a webhook endpoint. All pending deliveries will be cancelled. This action cannot be undone.

NameTypeReqDescription
webhook_idstringyesID of the webhook to delete

No output schema declared.

No examples provided.

dns_check ~203

Fast DNS-based domain existence check. Tests if a name is taken across many TLDs at once (faster than search, no pricing). Returns 'taken' (definitely registered) and 'candidates' (potentially available). Use this to narrow down before calling search for pricing. Use preset: 'extended' to check 30+ creative/exotic TLDs when basic ones are all taken.

NameTypeReqDescription
namestringyesDomain name without TLD, e.g. 'myapp'
presetstring–Use a curated TLD preset: 'basic' (10 common TLDs) or 'extended' (30+ including creative/exotic TLDs). Merged with explicit tlds if both provided. Defaults to 'basic' when tlds is omitted.
tldsarray–TLDs to check, e.g. ['com', 'dev', 'ai', 'io']. Optional if preset is provided.

No output schema declared.

No examples provided.

domain_status ~40

Check domain health: DNS propagation, SSL status, email (MX) configuration, and expiry date

NameTypeReqDescription
domainstringyesDomain to check status for

No output schema declared.

No examples provided.

finalize_negotiation ~135

As the buyer, pay the agreed price to create the escrow deal and start the transfer. Same payment methods as a purchase (card, USDC, x402). Requires domains:transfer scope. For a broker-sourced acquisition, if the agreed price is above the max_budget you set, this returns BUDGET_EXCEEDED - retry with confirm_over_budget: true to proceed anyway.

NameTypeReqDescription
confirm_over_budgetboolean–Set true to finalize a broker deal above the max_budget you set on the acquisition request
negotiation_idstringyesThe agreed negotiation to finalize
payment_methodstring––

No output schema declared.

No examples provided.

forward_message ~121

Forward an email message to another address. Includes the original message context (sender, date, subject, body). Optionally prepend a note. Subject is auto-prefixed with 'Fwd:'. API: POST /api/emails/{address}/messages/{id}/forward.

NameTypeReqDescription
domainstringyesMailbox domain
message_idstringyesID of the message to forward
slugstringyesMailbox slug
textstring–Optional note to prepend to the forwarded message
to–yesRecipient email address(es)

No output schema declared.

No examples provided.

get_account ~36

Get your account details, payment status, contact info status (has_contact), and referral code. Contact info must be set before purchasing domains.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_activation ~56

Call this immediately after authentication. Follow its first recommended action until the account has a real product milestone. For agent email, create a free inbox, configure its authenticated webhook, then test delivery. Tool discovery and authentication alone never count as activation.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_auth_code ~58

Get the EPP/auth code needed to transfer a domain to another registrar. Automatically unlocks the domain if it's locked. Give this code to the new registrar to initiate the transfer.

NameTypeReqDescription
domainstringyesDomain to get auth code for

No output schema declared.

No examples provided.

get_broker_inquiry_state ~80

Owner-agent read path: poll the current, anonymized state of a broker inquiry with your token before acting. Returns the domain, the buyer's offer on the table, whose move it is, and the actions available now. Never exposes the buyer's identity or budget.

NameTypeReqDescription
tokenstringyesThe outreach token from your inquiry email

No output schema declared.

No examples provided.

get_deal_invoice ~66

Get a role-aware receipt/statement for a marketplace deal. Buyers see what they paid; sellers see the sale, the platform commission line, and the net payout. Works for every payment method. Requires deals:read scope.

NameTypeReqDescription
deal_idstringyesThe deal ID

No output schema declared.

No examples provided.

get_dns ~56

Get DNS records for a domain you own. Returns each record with a stable id, plus a zone_version token - pass it to set_dns to detect concurrent zone changes.

NameTypeReqDescription
domainstringyesDomain name to get DNS records for

No output schema declared.

No examples provided.

get_dnssec ~58

List the DNSSEC delegation-signer (DS) records for a domain you own, and whether DNSSEC is enabled. Pair with TLSA records (via set_dns) for DANE.

NameTypeReqDescription
domainstringyesDomain name to inspect

No output schema declared.

No examples provided.

get_domain_email_status ~45

Check if email is enabled on a domain and whether DNS records are verified. Returns record status and mailbox count.

NameTypeReqDescription
domainstringyesDomain to check email status for

No output schema declared.

No examples provided.

get_domain_info ~48

Get detailed information about a domain you own, including auto-renew status, security lock, WHOIS privacy, and provider data.

NameTypeReqDescription
domainstringyesDomain name to get info for

No output schema declared.

No examples provided.

get_domain_preview ~62

Get website preview metadata (title, description, image, favicon) for any domain. Useful for understanding what a taken domain is currently used for. Data is cached for 7 days.

NameTypeReqDescription
domainstringyesDomain to preview, e.g. google.com

No output schema declared.

No examples provided.

get_email_deliverability ~81

Get an owner-scoped email health report for a domain. Separates deterministic DNS readiness, 30-day bounce and complaint outcomes, account safety state, and measured inbox placement. A readiness score is not an Inbox probability. API: GET /api/domains/{domain}/email/deliverability.

NameTypeReqDescription
domainstringyesDomain to inspect

No output schema declared.

No examples provided.

get_mailbox_client_settings ~77

Get IMAP/SMTP settings for a hosted mailbox to configure a mail client (Apple Mail, Thunderbird). Username is the full address; password is an app password. API: GET /api/emails/{address}/client-settings.

NameTypeReqDescription
domainstringyesHosted mailbox domain
slugstringyesHosted mailbox slug

No output schema declared.

No examples provided.

get_message ~72

Get a single message by ID with full content, headers, delivery events, and attachment download URLs. API: GET /api/emails/{address}/messages/{id}.

NameTypeReqDescription
domainstringyesMailbox domain
message_idstringyesMessage ID
slugstringyesMailbox slug

No output schema declared.

No examples provided.

get_nameservers ~50

Get the authoritative nameservers configured for a domain you own. If empty, DNS operations (parking, email, connect) will fail.

NameTypeReqDescription
domainstringyesDomain name to get nameservers for

No output schema declared.

No examples provided.

get_parking_analytics ~78

Get visitor analytics for a parked domain - page views, inquiries, conversion rate, 30-day daily breakdown, and the 5 most recent inquiries. Use this to check how much traffic a parked domain gets and whether it's converting into buyer inquiries.

NameTypeReqDescription
domainstringyesDomain to get analytics for, e.g. example.com

No output schema declared.

No examples provided.

get_transfer_away ~47

Check the status of an outbound domain transfer. Use after getting an auth code and initiating the transfer at the new registrar.

NameTypeReqDescription
domainstringyesDomain to check transfer status for

No output schema declared.

No examples provided.

Common questions

What is the run.domani/domani MCP server?

run.domani/domani is an MCP server listed in the public MCP registry as run.domani/domani. Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC. This page covers its hosted endpoint (https://domani.run/mcp).

Is the run.domani/domani MCP server safe to use?

run.domani/domani scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the run.domani/domani MCP server expose?

run.domani/domani exposes 122 tools: get_account, get_activation, search, suggest_domains, list_tlds, and 117 more. Their descriptions and schemas cost roughly 13,182 tokens of context every time the server is loaded.

Does the run.domani/domani MCP server require authentication?

Yes. run.domani/domani asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the run.domani/domani MCP server still maintained?

run.domani/domani is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.