run.domani/domani
REMOTE · DOMANI.RUN · SCANNED OCT 2
Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security97
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the run.domani/domani MCP server?
run.domani/domani is a hosted endpoint at https://domani.run/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · domani.run
claude mcp add --transport http run-domani-domani 'https://domani.run/mcp'
{
"mcpServers": {
"run-domani-domani": {
"url": "https://domani.run/mcp"
}
}
} {
"servers": {
"run-domani-domani": {
"type": "http",
"url": "https://domani.run/mcp"
}
}
} [mcp_servers.run-domani-domani] url = "https://domani.run/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"run-domani-domani": {
"type": "remote",
"url": "https://domani.run/mcp",
"enabled": true
}
}
} openclaw mcp add run-domani-domani --url 'https://domani.run/mcp' --transport streamable-http
mcp_servers:
run-domani-domani:
url: "https://domani.run/mcp" {
"McpServers": {
"run-domani-domani": {
"Transport": "http",
"Url": "https://domani.run/mcp"
}
}
} assistant mcp add run-domani-domani -t streamable-http -u 'https://domani.run/mcp'
{
"mcpServers": {
"run-domani-domani": {
"type": "http",
"url": "https://domani.run/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 1 Sept 26 0
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: fail → pass ▲ security
- First check of Authorization: partial security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- Tool “create_mailbox” rewrote its description, which is the text the model reads security
- Tool “create_webhook” rewrote its description, which is the text the model reads security
- Tool “get_activation” rewrote its description, which is the text the model reads security
- Tool “provision_agent” rewrote its description, which is the text the model reads security
- Tool “set_email_webhook” rewrote its description, which is the text the model reads security
- Tool “test_email_webhook” rewrote its description, which is the text the model reads security
- Tool “update_webhook” rewrote its description, which is the text the model reads security
- “create_webhook” added an optional parameter “headers” cosmetic
- “provision_agent” added an optional parameter “webhook_headers” cosmetic
- “set_email_webhook” added an optional parameter “headers” cosmetic
- “update_webhook” added an optional parameter “headers” cosmetic
- 22 Aug 26 0
- Tool “cancel_plan” rewrote its description, which is the text the model reads security
- Tool “upgrade_plan” rewrote its description, which is the text the model reads security
- Tool “cancel_plan” changed its title: Cancel Pro Plan → Cancel Paid Plan cosmetic
- Tool “upgrade_plan” changed its title: Upgrade to Pro → Upgrade Plan cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Probed https://domani.run/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=domani.run | CN=YE1,O=Let's Encrypt,C=US | 3 Sept 2026 | 2 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5eede2c575a4a399afb967c7ab765a4e095 |
| SANs: *.domani.run, domani.run | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of domani.run. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| run. | present | 37315 | 8 | Verified |
| domani.run. | present | 2371 | 13 | Verified |
| domani.run. | Verified address RRset verified with the apex keys |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"
Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://vercel.live https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'; connect-src 'self' https://api.stripe.com https://cloudflare-dns.com https://vercel.live https://va.vercel-scripts.com; frame-src https://js.stripe.com https://vercel.live |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
| www-authenticate | Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource" |
Protected resource metadata
| Document | https://domani.run/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://domani.run/mcp |
| Authorisation server | https://domani.run |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://domani.run/mcp | Auth required | 401 | |
| http (plaintext) | http://domani.run/mcp | HTTPS enforced | 308 | https://domani.run/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
acquire_domain Acquire Domain (Broker) ~110
Ask domani to acquire a specific taken, unlisted domain on your behalf. Agents source the owner via RDAP, reach out anonymously, and negotiate - commission-only, no upfront fee. Owner interest opens an anonymous negotiation you can accept/counter. Note: many owners are unreachable (GDPR-redacted WHOIS). Requires deals:write scope.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The taken domain you want, e.g. dream.com |
| max_budget | number | – | Your ceiling in USD (optional) |
No output schema declared.
No examples provided.
add_dnssec Add DNSSEC DS Record ~164
Publish a DNSSEC delegation-signer (DS) record at the registry to enable DNSSEC. Get the DS values from your zone provider after signing the zone.
| Name | Type | Req | Description |
|---|---|---|---|
| algorithm | string | yes | DNSSEC algorithm number, e.g. 13 (ECDSAP256SHA256) |
| digest | string | yes | Hex digest of the DNSKEY |
| digestType | string | yes | Digest type number, e.g. 2 (SHA-256) |
| domain | string | yes | Domain name to enable DNSSEC for |
| flags | string | – | Optional DNSKEY flags, e.g. 257 (KSK) |
| keyTag | string | yes | Key tag, e.g. 12345 |
| maxSigLife | string | – | Optional max signature life in seconds |
No output schema declared.
No examples provided.
add_mail_rule Add Mail Rule ~200
Add an inbound filtering rule to a mailbox. If a message matches (by from/to/subject/body), the action runs: drop, mark_read, forward (to action_arg), webhook_only (skip forward-to), or label (with action_arg). Rules run in priority order (lower first); first match wins. API: POST /api/emails/{address}/rules.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | What to do on match |
| action_arg | string | – | For 'forward': the destination email. For 'label': the label value. |
| domain | string | yes | Mailbox domain |
| enabled | boolean | – | Default true |
| match_field | string | yes | Which field to match on |
| match_op | string | yes | How to match |
| match_value | string | yes | The value/pattern to match |
| priority | integer | – | Lower runs first (default 0) |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
add_mailbox_alias Add Mailbox Alias ~137
Add an alias address that delivers into an existing mailbox, without using a mailbox slot. Useful for multiple public addresses (sales@, hello@, contact@) landing in one inbox. The alias must be on the same domain as the mailbox. API: POST /api/emails/{address}/aliases.
| Name | Type | Req | Description |
|---|---|---|---|
| alias | string | yes | Alias address - a bare slug ('sales') or a full address on the same domain ('sales@mysite.com') |
| domain | string | yes | Mailbox domain, e.g. mysite.com |
| slug | string | yes | Mailbox slug the alias delivers to, e.g. inbox |
No output schema declared.
No examples provided.
add_suppression Add Suppression ~76
Manually add an address to your suppression list so future sends skip it. Hard bounces and complaints are added automatically - use this for addresses you want to stop emailing. API: POST /api/suppressions.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Email address to suppress |
| reason | string | – | Reason (default: manual) |
No output schema declared.
No examples provided.
browse_marketplace Browse Marketplace ~77
Browse domains for sale on the Domani marketplace. Returns all active listings with prices. Use buy_domain to purchase a listed domain.
| Name | Type | Req | Description |
|---|---|---|---|
| max_price | number | – | Maximum price in USD |
| order | string | – | Sort order (default: asc) |
| sort | string | – | Sort by price or TLD (default: price) |
No output schema declared.
No examples provided.
buy_aftermarket Buy Aftermarket Domain ~240
Buy a taken domain that's listed for sale on an aftermarket (Afternic/Sedo) at its buy-now price, natively - no external site. Use when search shows a domain with for_sale.buyable = true. Always confirm the price with the user first. Pass max_price to cap it. If the listing is make-offer only (not buyable), use acquire_domain (broker) to negotiate instead. Crypto/USDC works like buy_domain (402 -> pay -> retry with payment_tx).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The taken, for-sale domain to buy, e.g. kami.world |
| max_price | number | – | Hard ceiling in USD. Defaults to the listing's buy-now price. The purchase is rejected if the live price is above this. |
| payment_chain | string | – | Chain the USDC payment was sent on. Required with payment_tx. |
| payment_method | string | – | 'card' to charge the card on file, 'usdc' to pay with crypto. |
| payment_tx | string | – | Tx hash of a USDC payment already sent on-chain (step 2 of the USDC flow). |
No output schema declared.
No examples provided.
buy_domain Buy Domain ~326
Purchase one or more domains. Always confirm with the user before calling. Accepts a single domain or an array of up to 10 (card only for bulk). If the user wants to pay with crypto/USDC: call with payment_method: 'usdc' - you'll get a 402 with a wallet address and amount. Tell the user to send that amount in USDC, then once they give you the tx hash, retry with payment_tx and payment_chain. Don't explain protocol details to the user - just tell them the address, amount, and chain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Single domain to purchase, e.g. mysite.com |
| domains | array | – | Array of domains to purchase, e.g. ["a.com", "b.dev"]. Max 10. |
| max_price | number | – | Ceiling in USD for the total charge. If the real price is above it, the purchase fails with PRICE_ABOVE_MAX and nothing is charged. Set it from the price the user approved. |
| payment_chain | string | – | Chain the USDC payment was sent on. Required with payment_tx. |
| payment_method | string | – | Payment method: 'card' to charge card on file, 'usdc' to pay with USDC. Overrides the user's default preference for this request. |
| payment_tx | string | – | Transaction hash of a USDC payment already sent on-chain. Required for step 2 of USDC flow. |
| years | integer | – | Number of years to register (1-10, default 1). Price is multiplied by years. |
No output schema declared.
No examples provided.
cancel_backorder Cancel Backorder ~46
Stop watching a domain by cancelling a backorder. Only backorders in the 'watching' state can be cancelled.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The backorder ID to cancel |
No output schema declared.
No examples provided.
cancel_broker_request Cancel Broker Request ~35
Cancel an active domain acquisition request. Requires deals:write scope.
| Name | Type | Req | Description |
|---|---|---|---|
| request_id | string | yes | The broker request ID |
No output schema declared.
No examples provided.
cancel_plan Cancel Paid Plan ~41
Cancel the user's current paid subscription. The subscription remains active until the end of the current billing period, then reverts to the free plan. Returns the cancellation date.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
check_email Check Email ~51
Check email DNS health for a domain: MX records, SPF, DMARC, DKIM. Auto-detects the email provider from MX records.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check email health for |
No output schema declared.
No examples provided.
check_email_deliverability Check Email Deliverability ~194
Run the same deliverability and abuse-safety checks used by send_email, without sending or consuming quota. Use this before authentication, payment, onboarding, or high-volume messages. API: POST /api/emails/{address}/deliverability-check.
| Name | Type | Req | Description |
|---|---|---|---|
| allow_risky_content | boolean | – | Deprecated compatibility field. Public HTTPS third-party auth links are allowed with a warning; objective safety blocks cannot be overridden |
| attachments | array | – | Attachment metadata only; content is not required for preflight |
| domain | string | yes | Sender mailbox domain, e.g. mysite.com or domani.run |
| html | string | – | HTML body |
| idempotency_key | string | – | Stable idempotency key for this logical message |
| slug | string | yes | Sender mailbox slug, e.g. hello |
| subject | string | – | Email subject line |
| text | string | – | Plain-text body |
No output schema declared.
No examples provided.
check_transfer_eligibility Check Transfer Eligibility ~78
Pre-check whether a domain can be transferred. Returns transfer price, eligibility status, and any blockers (unsupported TLD, ICANN waiting period, domain locked, etc.). Always call this before transfer_domain to verify eligibility and show the user the price.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check, e.g. mysite.com |
No output schema declared.
No examples provided.
check_transfer_status Check Transfer Status ~52
Check the status of an inbound domain transfer. Returns detailed status (pending_owner, pending_admin, pending_registry, completed, cancelled) with actionable hints.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check transfer status for |
No output schema declared.
No examples provided.
claim_identity Claim a free identity ~150
Give your agent a free identity at <handle>.domani.run - a live profile page, no domain purchase, instantly. The frictionless way to start; upgrade to your own real domain later. Optional name/bio/emoji/email/links.
| Name | Type | Req | Description |
|---|---|---|---|
| bio | string | – | Short description (<= 280 chars) |
| string | – | Public contact email (e.g. your free @domani.run inbox) | |
| emoji | string | – | Avatar emoji |
| links | array | – | Up to 6 links |
| name | string | – | Display name |
| slug | string | yes | The handle - becomes <slug>.domani.run (lowercase letters, numbers, hyphens) |
No output schema declared.
No examples provided.
clear_catch_all Clear Catch-All ~56
Remove the catch-all on a domain. Email to unmatched addresses will be dropped again. API: DELETE /api/domains/{domain}/email/catch-all.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to clear the catch-all on |
No output schema declared.
No examples provided.
clone_dns Clone DNS ~120
Copy the DNS setup of one domain you own onto another (e.g. brand.com → brand.dev with the same A/CNAME/MX). Merges by default (source wins on collisions, keeps the target's other records); set replace=true for an exact mirror.
| Name | Type | Req | Description |
|---|---|---|---|
| from_domain | string | yes | Source domain to copy DNS from (must be yours) |
| replace | boolean | – | Exact mirror - drop target records the source doesn't have. Default: merge |
| to_domain | string | yes | Target domain to write the DNS onto (must be yours) |
No output schema declared.
No examples provided.
connect_domain Connect Domain ~287
Connect a domain to a hosting or email provider. Auto-detects provider from target, or accepts explicit provider name. For domains bought through the platform, DNS records are set automatically (status: dns_set). For imported domains (external registrar), returns the records as instructions to add manually (status: manual_setup_required). If the connect would REPLACE existing MX records pointing at another provider, it fails with MX_REPLACEMENT_REQUIRES_CONFIRMATION - preview with dry_run, confirm with the user, then retry with confirm_replace_mx. The response includes a next_steps array with provider-specific actions. Supported hosting: vercel, netlify, cloudflare-pages, github-pages, railway, fly. Email: google-workspace, fastmail, proton.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_replace_mx | boolean | – | Confirm replacing existing MX records that point at another provider (moves the domain's email) |
| domain | string | yes | Domain to connect, e.g. mysite.com |
| dry_run | boolean | – | Preview only - returns the diff (create/replace/keep) without writing |
| method | string | – | Connection method if provider has multiple, e.g. cname-only |
| provider | string | – | Explicit provider name, e.g. vercel, google-workspace |
| target | string | – | Target URL for auto-detection, e.g. my-app.vercel.app |
No output schema declared.
No examples provided.
create_backorder Create Backorder ~171
Place a backorder on a domain that is currently registered to someone else. We watch it and automatically register it for the user when it becomes available (drops) - availability is polled every few minutes. The user is charged only if the catch succeeds - no upfront fee. Requires a card on file or payment_method 'balance'. Confirm the domain with the user first. Best-effort: a contested drop may be taken by a specialized drop-catcher first.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | The currently-taken domain to watch and catch on drop, e.g. taken.com |
| max_price | number | – | Max USD to pay when caught. Defaults to the current registration price. |
| payment_method | string | – | How to pay when caught: 'card' or 'balance' (marketplace credit). |
No output schema declared.
No examples provided.
create_hosted_mailbox Create Hosted Mailbox ~176
Create a real IMAP/SMTP mailbox on a domain you own (connect Apple Mail, Thunderbird, or any mail client), instead of an API mailbox. Pass workspace_id to create it in a workspace you own and atomically adopt the domain boundary. Provisions the mailbox on our mail server, publishes DNS when we manage it, and returns the DNS records, mail client settings, and a one-time app password. API: POST /api/emails with kind=hosted.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | A domain you own, e.g. mysite.com |
| name | string | – | Display name for the mailbox |
| slug | string | yes | Local part, e.g. 'me' for me@mysite.com |
| workspace_id | string | – | Workspace ID from list_workspaces; owner-only |
No output schema declared.
No examples provided.
create_mailbox Create Mailbox ~244
Create an email address. Specify slug (required) and optionally domain. Pass workspace_id to create it inside a workspace you own; custom-domain creation atomically adopts the domain and all unscoped sibling mailboxes so a domain is never split. Custom-domain capacity follows the active account or workspace plan. For imported domains (external registrar): returns DNS records to add manually at your registrar. For domani.run: omit domain; each account has one free mailbox. Pass force=true to override an existing email provider (Google Workspace, etc.). API: POST /api/emails with {address}.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Domain for the mailbox. Omit for domani.run |
| force | boolean | – | Override existing MX records (e.g. Google Workspace). Default: false |
| name | string | – | Display name for outbound emails, e.g. 'John Doe'. Shows as 'John Doe <slug@domain>' in recipients' inboxes |
| slug | string | yes | Local part of the email address, e.g. 'hello' for hello@mysite.com |
| workspace_id | string | – | Workspace ID from list_workspaces; owner-only |
No output schema declared.
No examples provided.
create_mailbox_credential Create App Password ~90
Create an app password for a hosted mailbox, used as the password in a mail client. The secret is returned once - store it. API: POST /api/emails/{address}/credentials.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Hosted mailbox domain |
| label | string | – | Label to identify this app password, e.g. 'Laptop Mail' |
| slug | string | yes | Hosted mailbox slug |
No output schema declared.
No examples provided.
create_token Create API Token ~933
Create a new API token with optional scoped permissions and spend caps. The full key is returned only once - save it immediately. A token can only grant scopes it already has (scope attenuation) and spend caps at or below its own. Scopes: domains:read (GET /api/domains, GET /api/domains/{domain}, GET /api/domains/{domain}/dns, /dnssec, /status, /email/check, /auth-code, /transfer-away, /transfer-status, /analytics), domains:write (PUT /api/domains/{domain}/dns, POST/DELETE /api/domains/{domain}/dnssec, POST /connect, POST /verify, PUT /settings, PUT /parking, PUT/DELETE /api/domains/{domain}/for-sale, POST /api/domains/import, POST /import/verify), domains:transfer (POST /api/domains/buy, POST /transfer, POST /renew (involves payment, includes marketplace purchases)), tokens:read (GET /api/tokens), tokens:write (POST /api/tokens, DELETE /api/tokens/{id}), webhooks:read (GET /api/webhooks, GET /api/webhooks/{id}/deliveries), webhooks:write (POST /api/webhooks, PATCH /api/webhooks/{id}, DELETE /api/webhooks/{id}), email:read (GET /api/emails, /api/emails/{address}, /api/emails/{address}/messages, /api/emails/{address}/aliases, /api/email/changes, /api/domains/{domain}/email/status, /api/domains/{domain}/email/deliverability, /api/suppressions), email:write (POST /api/emails, POST /api/emails/{address}/send, POST /api/domains/{domain}/email/setup, aliases + catch-all, POST/DELETE /api/suppressions), email:delete (Permanently delete messages already in Trash. Moving messages to Trash only requires email:write. Grant this scope only to agents allowed to irreversibly erase email content), email:auth_secrets (Read messages classified as authentication mail (OTP / verification codes, password resets, magic links). Without it, email:read still lists them but subject and body come back redacted - so a stolen agent token can't harvest 2FA codes. Grant it only to agents that genuinely need to complete logins), account:read (GET /api/me, GET /api/agents/identity), account:write…
| Name | Type | Req | Description |
|---|---|---|---|
| agent_identity_id | string | – | Optional owned AgentIdentity id. Mail actions made with this token are attributed to that agent |
| expires_at | string | – | Absolute expiration date (ISO 8601). Alternative to expires_in |
| expires_in | integer | – | Token lifetime in seconds (min 3600 = 1h, max 31536000 = 1y). Omit for no expiration |
| max_per_month | number | – | Rolling calendar-month spend cap in USD for all paid operations with this token |
| max_per_tx | number | – | Per-transaction spend cap in USD - any single charge above it is rejected server-side (SPEND_CAP_EXCEEDED) |
| name | string | – | Human-readable label, e.g. 'CI/CD', 'Sub-Agent'. Defaults to 'CLI' |
| scopes | array | – | Permission scopes for this token. Defaults to parent token's scopes. Use ['*'] for full access |
No output schema declared.
No examples provided.
create_webhook Create Webhook ~140
Register a new webhook endpoint to receive event notifications. The URL must use HTTPS. Optional Authorization or X-API-Key headers are encrypted and sent with every delivery. The webhook secret is returned only once - save it to verify incoming payloads with HMAC-SHA256.
| Name | Type | Req | Description |
|---|---|---|---|
| events | array | yes | Event types to subscribe to, e.g. ["domain.purchased", "dns.updated"]. Use list_webhook_events to see all available types. |
| headers | object | – | Optional auth headers. Only Authorization and X-API-Key are accepted; values are encrypted and never returned. |
| url | string | yes | HTTPS URL that will receive webhook POST requests |
No output schema declared.
No examples provided.
delete_dnssec Delete DNSSEC DS Record ~61
Remove a DNSSEC delegation-signer (DS) record at the registry by its key tag. Removing all DS records disables DNSSEC.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name |
| keyTag | string | yes | Key tag of the DS record to remove |
No output schema declared.
No examples provided.
delete_mailbox Delete Mailbox ~83
Delete a mailbox and all its messages (including attachments). Requires confirm=true. Call without confirm first to see what will be deleted. API: DELETE /api/emails/{address}.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Must be true to actually delete. Omit to preview. |
| domain | string | yes | Mailbox domain |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
delete_message Delete Message ~74
Move an email message to Trash. This is reversible with update_email_messages action=restore. API: DELETE /api/emails/{address}/messages/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Mailbox domain |
| message_id | string | yes | ID of the message to delete |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
delete_messages Delete Messages (Bulk) ~111
Retry-safely move messages to Trash and return a durable per-item receipt. Reuse the exact idempotency key after timeouts. Reversible with update_email_messages action=restore. API: POST /api/emails/{address}/messages/delete.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Mailbox domain |
| idempotency_key | string | yes | Caller-stable key for this exact logical batch |
| message_ids | array | yes | IDs of messages to delete |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
delete_webhook Delete Webhook ~41
Delete a webhook endpoint. All pending deliveries will be cancelled. This action cannot be undone.
| Name | Type | Req | Description |
|---|---|---|---|
| webhook_id | string | yes | ID of the webhook to delete |
No output schema declared.
No examples provided.
dns_check DNS Check ~203
Fast DNS-based domain existence check. Tests if a name is taken across many TLDs at once (faster than search, no pricing). Returns 'taken' (definitely registered) and 'candidates' (potentially available). Use this to narrow down before calling search for pricing. Use preset: 'extended' to check 30+ creative/exotic TLDs when basic ones are all taken.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Domain name without TLD, e.g. 'myapp' |
| preset | string | – | Use a curated TLD preset: 'basic' (10 common TLDs) or 'extended' (30+ including creative/exotic TLDs). Merged with explicit tlds if both provided. Defaults to 'basic' when tlds is omitted. |
| tlds | array | – | TLDs to check, e.g. ['com', 'dev', 'ai', 'io']. Optional if preset is provided. |
No output schema declared.
No examples provided.
domain_status Domain Status ~40
Check domain health: DNS propagation, SSL status, email (MX) configuration, and expiry date
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check status for |
No output schema declared.
No examples provided.
finalize_negotiation Finalize Negotiation ~135
As the buyer, pay the agreed price to create the escrow deal and start the transfer. Same payment methods as a purchase (card, USDC, x402). Requires domains:transfer scope. For a broker-sourced acquisition, if the agreed price is above the max_budget you set, this returns BUDGET_EXCEEDED - retry with confirm_over_budget: true to proceed anyway.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_over_budget | boolean | – | Set true to finalize a broker deal above the max_budget you set on the acquisition request |
| negotiation_id | string | yes | The agreed negotiation to finalize |
| payment_method | string | – | – |
No output schema declared.
No examples provided.
forward_message Forward Email ~121
Forward an email message to another address. Includes the original message context (sender, date, subject, body). Optionally prepend a note. Subject is auto-prefixed with 'Fwd:'. API: POST /api/emails/{address}/messages/{id}/forward.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Mailbox domain |
| message_id | string | yes | ID of the message to forward |
| slug | string | yes | Mailbox slug |
| text | string | – | Optional note to prepend to the forwarded message |
| to | – | yes | Recipient email address(es) |
No output schema declared.
No examples provided.
get_account Get Account ~36
Get your account details, payment status, contact info status (has_contact), and referral code. Contact info must be set before purchasing domains.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_activation Get Activation ~56
Call this immediately after authentication. Follow its first recommended action until the account has a real product milestone. For agent email, create a free inbox, configure its authenticated webhook, then test delivery. Tool discovery and authentication alone never count as activation.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_auth_code Get Auth Code ~58
Get the EPP/auth code needed to transfer a domain to another registrar. Automatically unlocks the domain if it's locked. Give this code to the new registrar to initiate the transfer.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to get auth code for |
No output schema declared.
No examples provided.
get_broker_inquiry_state Read Broker Inquiry State (Owner) ~80
Owner-agent read path: poll the current, anonymized state of a broker inquiry with your token before acting. Returns the domain, the buyer's offer on the table, whose move it is, and the actions available now. Never exposes the buyer's identity or budget.
| Name | Type | Req | Description |
|---|---|---|---|
| token | string | yes | The outreach token from your inquiry email |
No output schema declared.
No examples provided.
get_deal_invoice Get Deal Invoice ~66
Get a role-aware receipt/statement for a marketplace deal. Buyers see what they paid; sellers see the sale, the platform commission line, and the net payout. Works for every payment method. Requires deals:read scope.
| Name | Type | Req | Description |
|---|---|---|---|
| deal_id | string | yes | The deal ID |
No output schema declared.
No examples provided.
get_dns Get DNS Records ~56
Get DNS records for a domain you own. Returns each record with a stable id, plus a zone_version token - pass it to set_dns to detect concurrent zone changes.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to get DNS records for |
No output schema declared.
No examples provided.
get_dnssec Get DNSSEC ~58
List the DNSSEC delegation-signer (DS) records for a domain you own, and whether DNSSEC is enabled. Pair with TLSA records (via set_dns) for DANE.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to inspect |
No output schema declared.
No examples provided.
get_domain_email_status Get Domain Email Status ~45
Check if email is enabled on a domain and whether DNS records are verified. Returns record status and mailbox count.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check email status for |
No output schema declared.
No examples provided.
get_domain_info Get Domain Info ~48
Get detailed information about a domain you own, including auto-renew status, security lock, WHOIS privacy, and provider data.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to get info for |
No output schema declared.
No examples provided.
get_domain_preview Get Domain Preview ~62
Get website preview metadata (title, description, image, favicon) for any domain. Useful for understanding what a taken domain is currently used for. Data is cached for 7 days.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to preview, e.g. google.com |
No output schema declared.
No examples provided.
get_email_deliverability Get Email Deliverability ~81
Get an owner-scoped email health report for a domain. Separates deterministic DNS readiness, 30-day bounce and complaint outcomes, account safety state, and measured inbox placement. A readiness score is not an Inbox probability. API: GET /api/domains/{domain}/email/deliverability.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to inspect |
No output schema declared.
No examples provided.
get_mailbox_client_settings Get Mail Client Settings ~77
Get IMAP/SMTP settings for a hosted mailbox to configure a mail client (Apple Mail, Thunderbird). Username is the full address; password is an app password. API: GET /api/emails/{address}/client-settings.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Hosted mailbox domain |
| slug | string | yes | Hosted mailbox slug |
No output schema declared.
No examples provided.
get_message Get Message ~72
Get a single message by ID with full content, headers, delivery events, and attachment download URLs. API: GET /api/emails/{address}/messages/{id}.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Mailbox domain |
| message_id | string | yes | Message ID |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
get_nameservers Get Nameservers ~50
Get the authoritative nameservers configured for a domain you own. If empty, DNS operations (parking, email, connect) will fail.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to get nameservers for |
No output schema declared.
No examples provided.
get_parking_analytics Get Parking Analytics ~78
Get visitor analytics for a parked domain - page views, inquiries, conversion rate, 30-day daily breakdown, and the 5 most recent inquiries. Use this to check how much traffic a parked domain gets and whether it's converting into buyer inquiries.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to get analytics for, e.g. example.com |
No output schema declared.
No examples provided.
get_transfer_away Get Transfer Away Status ~47
Check the status of an outbound domain transfer. Use after getting an auth code and initiating the transfer at the new registrar.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to check transfer status for |
No output schema declared.
No examples provided.
What is the run.domani/domani MCP server?
run.domani/domani is an MCP server listed in the public MCP registry as run.domani/domani. Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC. This page covers its hosted endpoint (https://domani.run/mcp).
Is the run.domani/domani MCP server safe to use?
run.domani/domani scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the run.domani/domani MCP server expose?
run.domani/domani exposes 122 tools: get_account, get_activation, search, suggest_domains, list_tlds, and 117 more. Their descriptions and schemas cost roughly 13,182 tokens of context every time the server is loaded.
Does the run.domani/domani MCP server require authentication?
Yes. run.domani/domani asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the run.domani/domani MCP server still maintained?
run.domani/domani is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.