Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

run.domani/domani

REMOTE · DOMANI.RUN · SCANNED OCT 2

Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC.

Available components

0 this week 39 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security97
  • The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
  • The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
  • HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
  • The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
  • DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
  • The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the run.domani/domani MCP server?

run.domani/domani is a hosted endpoint at https://domani.run/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · domani.run

# add to Claude Code
claude mcp add --transport http run-domani-domani 'https://domani.run/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "run-domani-domani": {
      "url": "https://domani.run/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "run-domani-domani": {
      "type": "http",
      "url": "https://domani.run/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.run-domani-domani]
url = "https://domani.run/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "run-domani-domani": {
      "type": "remote",
      "url": "https://domani.run/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add run-domani-domani --url 'https://domani.run/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  run-domani-domani:
    url: "https://domani.run/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "run-domani-domani": {
      "Transport": "http",
      "Url": "https://domani.run/mcp"
    }
  }
}
# add to Vellum
assistant mcp add run-domani-domani -t streamable-http -u 'https://domani.run/mcp'
// mcp.json
{
  "mcpServers": {
    "run-domani-domani": {
      "type": "http",
      "url": "https://domani.run/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 1 Sept 26 0
    • Endpoint reachability: reachable → behind authorisation ▼ security
    • Stability: pass → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Transport: pass → unverified ▼ security
    • Authorization: fail → pass ▲ security
    • First check of Authorization: partial security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • First check of Schema quality: unverified functional
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 0
    • Stability: 0.97 → pass security
    • Tool “create_mailbox” rewrote its description, which is the text the model reads security
    • Tool “create_webhook” rewrote its description, which is the text the model reads security
    • Tool “get_activation” rewrote its description, which is the text the model reads security
    • Tool “provision_agent” rewrote its description, which is the text the model reads security
    • Tool “set_email_webhook” rewrote its description, which is the text the model reads security
    • Tool “test_email_webhook” rewrote its description, which is the text the model reads security
    • Tool “update_webhook” rewrote its description, which is the text the model reads security
    • “create_webhook” added an optional parameter “headers” cosmetic
    • “provision_agent” added an optional parameter “webhook_headers” cosmetic
    • “set_email_webhook” added an optional parameter “headers” cosmetic
    • “update_webhook” added an optional parameter “headers” cosmetic
  • 22 Aug 26 0
    • Tool “cancel_plan” rewrote its description, which is the text the model reads security
    • Tool “upgrade_plan” rewrote its description, which is the text the model reads security
    • Tool “cancel_plan” changed its title: Cancel Pro Plan → Cancel Paid Plan cosmetic
    • Tool “upgrade_plan” changed its title: Upgrade to Pro → Upgrade Plan cosmetic
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Probed https://domani.run/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=domani.run CN=YE1,O=Let's Encrypt,C=US 3 Sept 2026 2 Dec 2026 ECDSA 256 ECDSA-SHA384 5eede2c575a4a399afb967c7ab765a4e095
SANs: *.domani.run, domani.run
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of domani.run. — Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
run. present 37315 8 Verified
domani.run. present 2371 13 Verified
domani.run. Verified address RRset verified with the apex keys
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"

Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"
Header Value
strict-transport-security max-age=63072000
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://vercel.live https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'; connect-src 'self' https://api.stripe.com https://cloudflare-dns.com https://vercel.live https://va.vercel-scripts.com; frame-src https://js.stripe.com https://vercel.live
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()
www-authenticate Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://domani.run/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://domani.run/mcp
Authorisation server https://domani.run

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://domani.run/mcp Auth required 401
http (plaintext) http://domani.run/mcp HTTPS enforced 308 https://domani.run/mcp
MCP tools · 122 exposed · ~13,182 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
set_listing_price ~106

Set a 'For Sale' price on a parked domain, or remove the listing. When a price is set and parking is enabled, visitors see a 'For Sale' page with the price and a contact form to reach the domain owner. Set price to null to remove the listing.

NameTypeReqDescription
domainstringyesDomain to configure, e.g. example.com
price–yesSale price in USD (e.g. 499.99), or null to remove the listing

No output schema declared.

No examples provided.

set_nameservers ~109

Replace the nameservers for a domain you own. Requires 2–13 valid hostnames. Common values: OpenSRS DNS (ns1.systemdns.com, ns2.systemdns.com, ns3.systemdns.com), Cloudflare (assigned per account), custom NS.

NameTypeReqDescription
domainstringyesDomain name to set nameservers for
nameserversarrayyesArray of nameserver hostnames, e.g. ['ns1.systemdns.com', 'ns2.systemdns.com']

No output schema declared.

No examples provided.

set_parking ~162

Enable or disable the parking page for a domain you own. When enabled, visitors to the domain see a default parking page (or a 'For Sale' page if a listing price is set). Parking is enabled by default for newly purchased domains. IMPORTANT: If the domain has existing DNS records, the response will include requires_confirmation=true and show the records that will be overwritten. You MUST inform the user and get their approval before calling again with confirm=true.

NameTypeReqDescription
confirmboolean–Set to true to confirm overwriting existing DNS records. Only needed when the first call returns requires_confirmation=true.
domainstringyesDomain to configure, e.g. example.com
enabledbooleanyestrue to enable the parking page, false to disable it

No output schema declared.

No examples provided.

set_security_lock ~66

Lock or unlock a domain's transfer lock (clientTransferProhibited). When locked, transfer requests are rejected. Unlock before transferring to another registrar.

NameTypeReqDescription
domainstringyesDomain name to configure
lockedbooleanyestrue to lock (prevent transfers), false to unlock

No output schema declared.

No examples provided.

set_whois_privacy ~68

Enable or disable WHOIS privacy for a domain you own. When enabled, your personal contact information is hidden from public WHOIS lookups.

NameTypeReqDescription
domainstringyesDomain name to configure
enabledbooleanyestrue to enable WHOIS privacy, false to disable

No output schema declared.

No examples provided.

setup_billing ~115

Get a checkout URL for the user to add a payment card. Returns a URL - tell the user to open it in their browser. After they complete the form, call get_account to verify has_payment_method is true. Only needed for card payments - agents with crypto wallets can skip this and pay with USDC on Base via x402 protocol.

NameTypeReqDescription
modestring–'checkout' (default) returns a URL for the user to open in browser. 'setup_intent' returns a client_secret for Stripe.js integration.

No output schema declared.

No examples provided.

setup_domain_email ~101

Pre-configure email DNS on a domain (optional). This is called automatically by create_mailbox when needed. Use this only to pre-configure DNS before creating mailboxes. Pass force=true to override existing email provider (Google Workspace, Fastmail, Proton).

NameTypeReqDescription
domainstringyesDomain to enable email on, e.g. mysite.com
forceboolean–Override existing MX records (e.g. Google Workspace). Default: false

No output schema declared.

No examples provided.

snapshot_dns ~72

Capture all DNS records for a domain via public DNS lookups. Discovers subdomains from CT logs, SPF, and common names. Stores a server-side backup. Use before migrations or transfers.

NameTypeReqDescription
domainstringyesDomain name to snapshot
extra_subdomainsarray–Additional subdomains to include

No output schema declared.

No examples provided.

suggest_domains ~211

AI-powered domain suggestions. Given a project description, generates full domain names with creative TLDs (e.g. codebuddy.dev, wavify.fm), checks availability, and returns only available domains with pricing.

NameTypeReqDescription
countnumber–Number of suggestions to return (default 10)
excludearray–Domains to exclude from suggestions (e.g. from previous calls)
langstring–Language/cultural inspiration: names will draw from this language's words, aesthetics, and culture
promptstringyesProject description or keywords, e.g. 'AI coding assistant'
stylestring–Name style: 'single' (one word), 'creative' (evocative/metaphorical single word), 'short' (3-6 chars), 'brandable' (invented names), 'keyword' (descriptive)
tldsarray–Preferred TLDs without dots (e.g. ['com', 'dev']). Results will prioritize these.

No output schema declared.

No examples provided.

test_email_webhook ~82

Send one signed test payload to the mailbox webhook URL. Returns HTTP status and success/failure. Tests are not retried; live inbound events are durable and retried up to three times. API: POST /api/emails/{address}/webhook/test.

NameTypeReqDescription
domainstringyesMailbox domain
slugstringyesMailbox slug

No output schema declared.

No examples provided.

transfer_domain ~235

Initiate a domain transfer from another provider. PAID. The transfer includes 1 year of renewal, preserves current nameservers, and does not migrate DNS. Call plan_domain_adoption first, show the exact price and continuity plan, then get explicit confirmation before calling this. Requires the authorization/EPP code from the current provider.

NameTypeReqDescription
auth_codestringyesAuthorization/EPP code from the current provider
domainstringyesDomain to transfer, e.g. mysite.com
extra_subdomainsarray–Additional subdomains to include in the pre-transfer DNS snapshot. We auto-discover subdomains via CT logs, SPF, MX/DKIM inference, and a common wordlist - use this for any custom subdomains we might…
payment_chainstring–Chain the USDC payment was sent on.
payment_methodstring–Payment method: 'card' to charge card on file, 'usdc' to pay with USDC. Overrides the user's default preference for this request.
payment_txstring–Transaction hash of a USDC payment already sent on-chain.

No output schema declared.

No examples provided.

unsell_domain ~61

Remove an active for-sale listing for a domain you own. The domain stays in your account but is no longer purchasable on the marketplace. Requires domains:write scope.

NameTypeReqDescription
domainstringyesDomain to unlist, e.g. premium.com

No output schema declared.

No examples provided.

update_email_messages ~161

Apply a retry-safe lifecycle action to up to 100 messages. Returns a durable per-item operation receipt. Reuse the exact idempotency key after timeouts; never invent a new key for the same logical action. Permanent deletion requires email:delete. API: POST /api/emails/{address}/messages/actions.

NameTypeReqDescription
actionstringyes–
destinationstring–Required for move
domainstringyesMailbox domain
idempotency_keystringyesCaller-stable key for this exact logical batch
message_idsarrayyesExplicit message IDs
readboolean–Required for mark_read
slugstringyesMailbox slug
starredboolean–Required for star

No output schema declared.

No examples provided.

update_identity ~68

Update a free identity's name/bio/emoji/email/links.

NameTypeReqDescription
biostring––
emailstring––
emojistring––
linksarray––
namestring––
slugstringyesThe handle to update

No output schema declared.

No examples provided.

update_listing ~65

Update the price and/or description of an active marketplace listing. Requires domains:write scope.

NameTypeReqDescription
description––New description (null to clear)
domainstringyesDomain with active listing, e.g. premium.com
pricenumber–New price in USD

No output schema declared.

No examples provided.

update_webhook ~124

Update an existing webhook's URL, subscribed events, active status, or encrypted auth headers. Use list_webhooks to get the webhook ID first.

NameTypeReqDescription
activeboolean–Set to false to pause the webhook, true to resume
eventsarray–New list of event types to subscribe to
headersobject–Replace auth headers. Only Authorization and X-API-Key are accepted. Send {} to clear them.
urlstring–New HTTPS URL for the webhook
webhook_idstringyesID of the webhook to update

No output schema declared.

No examples provided.

upgrade_plan ~71

Get a Stripe checkout URL for the Agent plan ($19/month). Returns a URL. Tell the user to open it in their browser to complete the upgrade. Use this when the user hits the free plan monthly send limit (MONTHLY_LIMIT_EXCEEDED error). Fleet and Scale can be selected on the pricing page.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

verify_connection ~87

Verify that a provider connection is working by checking DNS propagation. Use after connect_domain to confirm records are live.

NameTypeReqDescription
domainstringyesDomain to verify
methodstring–Method name if applicable
providerstring–Provider name, e.g. vercel
targetstring–Target for auto-detection, e.g. my-app.vercel.app

No output schema declared.

No examples provided.

verify_import ~44

Verify DNS TXT record and complete domain import. Call after adding the TXT record from import_domain.

NameTypeReqDescription
domainstringyesDomain to verify, e.g. mysite.com

No output schema declared.

No examples provided.

verify_service ~113

Add DNS records to verify domain ownership for a third-party service (Stripe, Google Search Console, AWS SES, Postmark, Resend, Facebook, HubSpot, Microsoft 365). Unknown services fall back to a generic TXT record.

NameTypeReqDescription
domainstringyesDomain name
servicestringyesService name (e.g. stripe, google-search-console, aws-ses, postmark, resend, facebook, hubspot, microsoft-365)
tokenstringyesVerification token provided by the service

No output schema declared.

No examples provided.

watch_transfer ~91

Watch a domain and get notified (email + webhook) when it becomes eligible for transfer. Uses RDAP to check ICANN lock periods and EPP status codes. If the domain is already eligible, returns immediately without creating a watch. If not eligible but has a known date, creates a watch and notifies you when it's ready.

NameTypeReqDescription
domainstringyesDomain to watch, e.g. example.com

No output schema declared.

No examples provided.

whois_lookup ~80

Look up domain registration data via RDAP (modern WHOIS). Returns registrar, dates, status, nameservers, DNSSEC, and contact information (registrant, admin, tech, billing - often redacted for privacy). Works for any domain - no ownership required.

NameTypeReqDescription
domainstringyesDomain to look up, e.g. example.com

No output schema declared.

No examples provided.

Common questions

What is the run.domani/domani MCP server?

run.domani/domani is an MCP server listed in the public MCP registry as run.domani/domani. Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC. This page covers its hosted endpoint (https://domani.run/mcp).

Is the run.domani/domani MCP server safe to use?

run.domani/domani scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the run.domani/domani MCP server expose?

run.domani/domani exposes 122 tools: get_account, get_activation, search, suggest_domains, list_tlds, and 117 more. Their descriptions and schemas cost roughly 13,182 tokens of context every time the server is loaded.

Does the run.domani/domani MCP server require authentication?

Yes. run.domani/domani asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the run.domani/domani MCP server still maintained?

run.domani/domani is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.