run.domani/domani
REMOTE · DOMANI.RUN · SCANNED OCT 2
Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security97
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the run.domani/domani MCP server?
run.domani/domani is a hosted endpoint at https://domani.run/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · domani.run
claude mcp add --transport http run-domani-domani 'https://domani.run/mcp'
{
"mcpServers": {
"run-domani-domani": {
"url": "https://domani.run/mcp"
}
}
} {
"servers": {
"run-domani-domani": {
"type": "http",
"url": "https://domani.run/mcp"
}
}
} [mcp_servers.run-domani-domani] url = "https://domani.run/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"run-domani-domani": {
"type": "remote",
"url": "https://domani.run/mcp",
"enabled": true
}
}
} openclaw mcp add run-domani-domani --url 'https://domani.run/mcp' --transport streamable-http
mcp_servers:
run-domani-domani:
url: "https://domani.run/mcp" {
"McpServers": {
"run-domani-domani": {
"Transport": "http",
"Url": "https://domani.run/mcp"
}
}
} assistant mcp add run-domani-domani -t streamable-http -u 'https://domani.run/mcp'
{
"mcpServers": {
"run-domani-domani": {
"type": "http",
"url": "https://domani.run/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 1 Sept 26 0
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: fail → pass ▲ security
- First check of Authorization: partial security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- Tool “create_mailbox” rewrote its description, which is the text the model reads security
- Tool “create_webhook” rewrote its description, which is the text the model reads security
- Tool “get_activation” rewrote its description, which is the text the model reads security
- Tool “provision_agent” rewrote its description, which is the text the model reads security
- Tool “set_email_webhook” rewrote its description, which is the text the model reads security
- Tool “test_email_webhook” rewrote its description, which is the text the model reads security
- Tool “update_webhook” rewrote its description, which is the text the model reads security
- “create_webhook” added an optional parameter “headers” cosmetic
- “provision_agent” added an optional parameter “webhook_headers” cosmetic
- “set_email_webhook” added an optional parameter “headers” cosmetic
- “update_webhook” added an optional parameter “headers” cosmetic
- 22 Aug 26 0
- Tool “cancel_plan” rewrote its description, which is the text the model reads security
- Tool “upgrade_plan” rewrote its description, which is the text the model reads security
- Tool “cancel_plan” changed its title: Cancel Pro Plan → Cancel Paid Plan cosmetic
- Tool “upgrade_plan” changed its title: Upgrade to Pro → Upgrade Plan cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Probed https://domani.run/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=domani.run | CN=YE1,O=Let's Encrypt,C=US | 3 Sept 2026 | 2 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5eede2c575a4a399afb967c7ab765a4e095 |
| SANs: *.domani.run, domani.run | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of domani.run. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| run. | present | 37315 | 8 | Verified |
| domani.run. | present | 2371 | 13 | Verified |
| domani.run. | Verified address RRset verified with the apex keys |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource"
Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://vercel.live https://va.vercel-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'; connect-src 'self' https://api.stripe.com https://cloudflare-dns.com https://vercel.live https://va.vercel-scripts.com; frame-src https://js.stripe.com https://vercel.live |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
| www-authenticate | Bearer realm="domani", resource_metadata="https://domani.run/.well-known/oauth-protected-resource" |
Protected resource metadata
| Document | https://domani.run/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://domani.run/mcp |
| Authorisation server | https://domani.run |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://domani.run/mcp | Auth required | 401 | |
| http (plaintext) | http://domani.run/mcp | HTTPS enforced | 308 | https://domani.run/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
set_listing_price Set Listing Price ~106
Set a 'For Sale' price on a parked domain, or remove the listing. When a price is set and parking is enabled, visitors see a 'For Sale' page with the price and a contact form to reach the domain owner. Set price to null to remove the listing.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to configure, e.g. example.com |
| price | – | yes | Sale price in USD (e.g. 499.99), or null to remove the listing |
No output schema declared.
No examples provided.
set_nameservers Set Nameservers ~109
Replace the nameservers for a domain you own. Requires 2–13 valid hostnames. Common values: OpenSRS DNS (ns1.systemdns.com, ns2.systemdns.com, ns3.systemdns.com), Cloudflare (assigned per account), custom NS.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to set nameservers for |
| nameservers | array | yes | Array of nameserver hostnames, e.g. ['ns1.systemdns.com', 'ns2.systemdns.com'] |
No output schema declared.
No examples provided.
set_parking Set Parking ~162
Enable or disable the parking page for a domain you own. When enabled, visitors to the domain see a default parking page (or a 'For Sale' page if a listing price is set). Parking is enabled by default for newly purchased domains. IMPORTANT: If the domain has existing DNS records, the response will include requires_confirmation=true and show the records that will be overwritten. You MUST inform the user and get their approval before calling again with confirm=true.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Set to true to confirm overwriting existing DNS records. Only needed when the first call returns requires_confirmation=true. |
| domain | string | yes | Domain to configure, e.g. example.com |
| enabled | boolean | yes | true to enable the parking page, false to disable it |
No output schema declared.
No examples provided.
set_security_lock Set Security Lock ~66
Lock or unlock a domain's transfer lock (clientTransferProhibited). When locked, transfer requests are rejected. Unlock before transferring to another registrar.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to configure |
| locked | boolean | yes | true to lock (prevent transfers), false to unlock |
No output schema declared.
No examples provided.
set_whois_privacy Set WHOIS Privacy ~68
Enable or disable WHOIS privacy for a domain you own. When enabled, your personal contact information is hidden from public WHOIS lookups.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to configure |
| enabled | boolean | yes | true to enable WHOIS privacy, false to disable |
No output schema declared.
No examples provided.
setup_billing Setup Billing ~115
Get a checkout URL for the user to add a payment card. Returns a URL - tell the user to open it in their browser. After they complete the form, call get_account to verify has_payment_method is true. Only needed for card payments - agents with crypto wallets can skip this and pay with USDC on Base via x402 protocol.
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | – | 'checkout' (default) returns a URL for the user to open in browser. 'setup_intent' returns a client_secret for Stripe.js integration. |
No output schema declared.
No examples provided.
setup_domain_email Setup Domain Email ~101
Pre-configure email DNS on a domain (optional). This is called automatically by create_mailbox when needed. Use this only to pre-configure DNS before creating mailboxes. Pass force=true to override existing email provider (Google Workspace, Fastmail, Proton).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to enable email on, e.g. mysite.com |
| force | boolean | – | Override existing MX records (e.g. Google Workspace). Default: false |
No output schema declared.
No examples provided.
snapshot_dns Snapshot DNS ~72
Capture all DNS records for a domain via public DNS lookups. Discovers subdomains from CT logs, SPF, and common names. Stores a server-side backup. Use before migrations or transfers.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to snapshot |
| extra_subdomains | array | – | Additional subdomains to include |
No output schema declared.
No examples provided.
suggest_domains Suggest Domains ~211
AI-powered domain suggestions. Given a project description, generates full domain names with creative TLDs (e.g. codebuddy.dev, wavify.fm), checks availability, and returns only available domains with pricing.
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | – | Number of suggestions to return (default 10) |
| exclude | array | – | Domains to exclude from suggestions (e.g. from previous calls) |
| lang | string | – | Language/cultural inspiration: names will draw from this language's words, aesthetics, and culture |
| prompt | string | yes | Project description or keywords, e.g. 'AI coding assistant' |
| style | string | – | Name style: 'single' (one word), 'creative' (evocative/metaphorical single word), 'short' (3-6 chars), 'brandable' (invented names), 'keyword' (descriptive) |
| tlds | array | – | Preferred TLDs without dots (e.g. ['com', 'dev']). Results will prioritize these. |
No output schema declared.
No examples provided.
test_email_webhook Test Email Webhook ~82
Send one signed test payload to the mailbox webhook URL. Returns HTTP status and success/failure. Tests are not retried; live inbound events are durable and retried up to three times. API: POST /api/emails/{address}/webhook/test.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Mailbox domain |
| slug | string | yes | Mailbox slug |
No output schema declared.
No examples provided.
transfer_domain Transfer Domain ~235
Initiate a domain transfer from another provider. PAID. The transfer includes 1 year of renewal, preserves current nameservers, and does not migrate DNS. Call plan_domain_adoption first, show the exact price and continuity plan, then get explicit confirmation before calling this. Requires the authorization/EPP code from the current provider.
| Name | Type | Req | Description |
|---|---|---|---|
| auth_code | string | yes | Authorization/EPP code from the current provider |
| domain | string | yes | Domain to transfer, e.g. mysite.com |
| extra_subdomains | array | – | Additional subdomains to include in the pre-transfer DNS snapshot. We auto-discover subdomains via CT logs, SPF, MX/DKIM inference, and a common wordlist - use this for any custom subdomains we might… |
| payment_chain | string | – | Chain the USDC payment was sent on. |
| payment_method | string | – | Payment method: 'card' to charge card on file, 'usdc' to pay with USDC. Overrides the user's default preference for this request. |
| payment_tx | string | – | Transaction hash of a USDC payment already sent on-chain. |
No output schema declared.
No examples provided.
unsell_domain Unsell Domain ~61
Remove an active for-sale listing for a domain you own. The domain stays in your account but is no longer purchasable on the marketplace. Requires domains:write scope.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to unlist, e.g. premium.com |
No output schema declared.
No examples provided.
update_email_messages Update Email Messages ~161
Apply a retry-safe lifecycle action to up to 100 messages. Returns a durable per-item operation receipt. Reuse the exact idempotency key after timeouts; never invent a new key for the same logical action. Permanent deletion requires email:delete. API: POST /api/emails/{address}/messages/actions.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| destination | string | – | Required for move |
| domain | string | yes | Mailbox domain |
| idempotency_key | string | yes | Caller-stable key for this exact logical batch |
| message_ids | array | yes | Explicit message IDs |
| read | boolean | – | Required for mark_read |
| slug | string | yes | Mailbox slug |
| starred | boolean | – | Required for star |
No output schema declared.
No examples provided.
update_identity Update identity ~68
Update a free identity's name/bio/emoji/email/links.
| Name | Type | Req | Description |
|---|---|---|---|
| bio | string | – | – |
| string | – | – | |
| emoji | string | – | – |
| links | array | – | – |
| name | string | – | – |
| slug | string | yes | The handle to update |
No output schema declared.
No examples provided.
update_listing Update Listing ~65
Update the price and/or description of an active marketplace listing. Requires domains:write scope.
| Name | Type | Req | Description |
|---|---|---|---|
| description | – | – | New description (null to clear) |
| domain | string | yes | Domain with active listing, e.g. premium.com |
| price | number | – | New price in USD |
No output schema declared.
No examples provided.
update_webhook Update Webhook ~124
Update an existing webhook's URL, subscribed events, active status, or encrypted auth headers. Use list_webhooks to get the webhook ID first.
| Name | Type | Req | Description |
|---|---|---|---|
| active | boolean | – | Set to false to pause the webhook, true to resume |
| events | array | – | New list of event types to subscribe to |
| headers | object | – | Replace auth headers. Only Authorization and X-API-Key are accepted. Send {} to clear them. |
| url | string | – | New HTTPS URL for the webhook |
| webhook_id | string | yes | ID of the webhook to update |
No output schema declared.
No examples provided.
upgrade_plan Upgrade Plan ~71
Get a Stripe checkout URL for the Agent plan ($19/month). Returns a URL. Tell the user to open it in their browser to complete the upgrade. Use this when the user hits the free plan monthly send limit (MONTHLY_LIMIT_EXCEEDED error). Fleet and Scale can be selected on the pricing page.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
verify_connection Verify Connection ~87
Verify that a provider connection is working by checking DNS propagation. Use after connect_domain to confirm records are live.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to verify |
| method | string | – | Method name if applicable |
| provider | string | – | Provider name, e.g. vercel |
| target | string | – | Target for auto-detection, e.g. my-app.vercel.app |
No output schema declared.
No examples provided.
verify_import Verify Import ~44
Verify DNS TXT record and complete domain import. Call after adding the TXT record from import_domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to verify, e.g. mysite.com |
No output schema declared.
No examples provided.
verify_service Verify Service ~113
Add DNS records to verify domain ownership for a third-party service (Stripe, Google Search Console, AWS SES, Postmark, Resend, Facebook, HubSpot, Microsoft 365). Unknown services fall back to a generic TXT record.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name |
| service | string | yes | Service name (e.g. stripe, google-search-console, aws-ses, postmark, resend, facebook, hubspot, microsoft-365) |
| token | string | yes | Verification token provided by the service |
No output schema declared.
No examples provided.
watch_transfer Watch Transfer ~91
Watch a domain and get notified (email + webhook) when it becomes eligible for transfer. Uses RDAP to check ICANN lock periods and EPP status codes. If the domain is already eligible, returns immediately without creating a watch. If not eligible but has a known date, creates a watch and notifies you when it's ready.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to watch, e.g. example.com |
No output schema declared.
No examples provided.
whois_lookup WHOIS Lookup ~80
Look up domain registration data via RDAP (modern WHOIS). Returns registrar, dates, status, nameservers, DNSSEC, and contact information (registrant, admin, tech, billing - often redacted for privacy). Works for any domain - no ownership required.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to look up, e.g. example.com |
No output schema declared.
No examples provided.
What is the run.domani/domani MCP server?
run.domani/domani is an MCP server listed in the public MCP registry as run.domani/domani. Internet identity for AI agents: register or broker domains, email, DNS - pay by card or USDC. This page covers its hosted endpoint (https://domani.run/mcp).
Is the run.domani/domani MCP server safe to use?
run.domani/domani scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the run.domani/domani MCP server expose?
run.domani/domani exposes 122 tools: get_account, get_activation, search, suggest_domains, list_tlds, and 117 more. Their descriptions and schemas cost roughly 13,182 tokens of context every time the server is loaded.
Does the run.domani/domani MCP server require authentication?
Yes. run.domani/domani asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the run.domani/domani MCP server still maintained?
run.domani/domani is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.