Official Porkbun MCP server — exposes the Porkbun v3 API as 30 native tools for Claude Desktop, Cursor, and other AI agents. Idempotency-safe writes, full domain lifecycle.
概要
A Model Context Protocol server that exposes the Porkbun v3 API as native tools for AI agents — Claude Desktop, Cursor, Cline, and any other MCP-compatible client. v0.22.0 — full Porkbun v3 coverage (domains, DNS, SSL, hosting, webhooks). Provisions and mints WordPress REST API credentials so an agent can manage the site it just created. Moves domains to a customer's and then manages those records, the proxy and zone settings. An isolated : a pk1_sb_ key runs every tool against a simulated environment with fake credit — no real registry actions, DNS changes or charges — and still delivers signed webhooks. A credential-free returns schema-accurate example responses for any endpoint. The list_doc_topics / read_doc / search_docs tools let an agent ground itself in Porkbun's own documentation (the /llms Markdown surface) mid-conversation — no web browsing required, and . You can add the server purely to research the API, then supply keys when you're ready for live operations.
README
Porkbun MCP Server
A Model Context Protocol server that exposes the Porkbun v3 API as native tools for AI agents — Claude Desktop, Cursor, Cline, and any other MCP-compatible client.
Setup guide, client configs and the full tool list: porkbun.com/mcp
Status: v0.22.0 — full Porkbun v3 coverage (domains, DNS, SSL, hosting, webhooks). Provisions Cloud for WordPress and mints WordPress REST API credentials so an agent can manage the site it just created. Moves domains to a customer’s own Cloudflare account and then manages those records, the proxy and zone settings. An isolated sandbox: a
pk1_sb_key runs every tool against a simulated environment with fake credit — no real registry actions, DNS changes or charges — and still delivers signed webhooks. A credential-free mock server returns schema-accurate example responses for any endpoint.
What’s included (95 tools)
Read tools (free, no spend, no state changes)
| Tool | Description |
|---|---|
ping |
Verify API connectivity and credentials |
check_domain |
Check availability and pricing for a single domain |
get_registration_requirements |
TLD registration requirements as JSON Schema — is it API-registerable, the create payload, and registry eligibility fields (.us nexus, .ca legal type, …) |
get_pricing |
Get registration/renewal/transfer pricing for all TLDs (no auth needed) |
list_marketplace |
Browse the Porkbun aftermarket — filter by TLD, max price, name substring |
search_closeouts |
Search expired-domain closeouts; filter by age, price, TLD, name length; sort by registration date |
get_closeout |
One closeout plus its binding total (closeout price + the renewal/transfer year) |
buy_closeout |
Buy a closeout outright. Spends account credit |
list_domains |
Paginate through domains; filter by tld, expiry, auto-renew, API access |
get_domain |
Get metadata for a single domain in the account |
get_balance |
Get account credit balance |
get_api_settings |
Get monthly spend limit, low-balance alert, auto top-up config, MTD spend |
get_nameservers |
Get current nameservers for a domain |
list_dns_records |
List DNS records for a domain |
scan_dns_records |
Discover what a domain publishes now, from its live nameservers (use before a transfer — a transfer carries no zone data) |
import_dns_records |
Bulk-create records from a supplied list or a live scan; idempotent, already-present records are skipped |
list_dnssec_records |
List DNSSEC DS records published at the registry |
list_url_forwards |
List URL forwarding rules for a domain (incl. exact redirectType: 301/302/307/masked) |
list_glue_records |
List glue records (host-to-IP mappings) for a domain |
list_transfers |
List in-progress and recent inbound transfers |
get_transfer_status |
Get status of a specific inbound transfer |
get_ssl_bundle |
Retrieve the free Porkbun-issued SSL bundle for a domain |
get_contacts |
Get a domain’s four contacts (registrant/admin/tech/billing) with current values |
get_webhook_event_types |
List the event types a webhook endpoint can subscribe to |
list_webhooks |
List webhook endpoints (URL, events, status, delivery health, secret) |
get_webhook |
Get a single webhook endpoint by id |
list_webhook_deliveries |
List recent delivery attempts (status, attempts, HTTP, error); ~30-day history |
get_webhook_delivery |
Get a single delivery incl. the full signed payload |
list_doc_topics |
List Porkbun API doc topics (the docs index) |
read_doc |
Read a doc page as Markdown (dns, webhooks, … or overview/full) |
search_docs |
Keyword-search the full reference; returns the most relevant sections |
The list_doc_topics / read_doc / search_docs tools let an agent ground itself in Porkbun’s own documentation (the /llms Markdown surface) mid-conversation — no web browsing required, and no API credentials needed. You can add the server purely to research the API, then supply keys when you’re ready for live operations.
Domain lifecycle writes (spend account credit)
| Tool | Description |
|---|---|
register_domain |
Register a new domain — call check_domain first to confirm price |
renew_domain |
Renew an existing domain |
transfer_domain |
Initiate an inbound transfer (returns transferId; takes 5-7 days) |
get_transfer_setup |
Where a held inbound transfer is and what it is waiting on |
prepare_transfer |
Create the DNS zone for a held transfer, before the domain moves |
start_transfer |
Release a held transfer to the registry (refuses on an empty zone) |
cancel_transfer |
Cancel a pending inbound transfer and refund it |
update_transfer_auth_code |
Replace the auth code on a stalled transfer and re-queue it |
Domain settings writes (free)
| Tool | Description |
|---|---|
update_auto_renew |
Turn auto-renewal on or off |
update_nameservers |
Replace the nameserver list for a domain (full replace, not append) |
update_contacts |
Edit domain contacts — any subset of registrant/admin/tech/billing; a registrant change fires the new-owner notice email. On address-validated TLDs (.de/.nrw/.uk/.us/.ca/.au/.eu/.in/.nz families) it validates the registrant address — resolve with address_validation_choice. A .au registrant name/org change is a website-only ownership trade. |
DNS / DNSSEC / URL-forwarding / glue writes (free)
| Tool | Description |
|---|---|
create_dns_record |
Create a new DNS record (A, AAAA, CNAME, MX, TXT, etc.) |
update_dns_record |
Update an existing DNS record by its ID |
delete_dns_record |
Delete a DNS record by its ID |
create_dnssec_record |
Submit a DNSSEC DS record to the registry |
delete_dnssec_record |
Remove a DNSSEC DS record by key tag |
create_url_forward |
Create a URL forwarding rule (permanent/temporary/masked; optional redirect_type 301/302/307/masked) |
delete_url_forward |
Delete a URL forwarding rule by ID |
create_glue_record |
Create a glue record (host-to-IP mapping at the registry) |
update_glue_record |
Replace the IP list for a glue record |
delete_glue_record |
Delete a glue record by host |
Secure Static Hosting
| Tool | Description |
|---|---|
list_hosting_plans |
List API-provisionable hosting products + plans, with price (cents), interval, trial length, features |
create_hosting |
Provision hosting for a domain by sku (from list_hosting_plans) — first provision per domain is a 15-day free trial that auto-renews at the plan price; re-provision after deprovision is charged to account credit (one free trial per domain). Switches the domain to Porkbun NS (gated by agree_to_nameserver_change); requires acknowledged_cost. dry_run supported |
get_hosting |
Get hosting status for a domain (plan, trial, expiry, auto-renew) |
deploy_site |
Upload static files (base64, ≤10MB/call) to a domain’s hosting |
list_hosting_files |
List files under a path in a domain’s hosting |
delete_hosting_file |
Delete a file (or empty dir) from a domain’s hosting |
make_hosting_dir |
Create a directory (and missing parents) in a domain’s hosting (deploy auto-creates dirs in a file path) |
delete_hosting |
Deprovision (cancel) hosting for a domain |
Cloud for WordPress
create_hosting with a CLOUDWORDPRESS… sku provisions a managed WordPress site instead of static hosting (the file tools don’t apply — manage it through WordPress).
| Tool | Description |
|---|---|
create_wp_credentials |
Mint a WordPress Application Password (returned once) so an agent can drive the site via /wp-json/ with HTTP Basic. Defaults to a dedicated least-privilege editor user; administrator requires an explicit acknowledgement (it can install plugins = run code) |
list_wp_credentials |
List application passwords on the site (metadata only — passwords can’t be re-read) |
delete_wp_credentials |
Revoke an application password by uuid, or all of them |
Cloudflare connect (move domains to the customer’s own Cloudflare account)
Connecting the Cloudflare account itself is a human step — Cloudflare’s consent screen has to be completed in a browser — so get_cloudflare_connection hands you a URL to show your user, then acts as the poll target. Everything after that is automated.
get_cloudflare_connection— connected or not, and where to send the human if not (poll this)list_cloudflare_inventory— every domain with its eligibility and a plain-English reasonpreview_cloudflare_move— exactly which records a move would copy or drop, queueing nothingconnect_domains_to_cloudflare— queue one or many (async: returns queued, never connected)get_cloudflare_queue/get_cloudflare_domain_status— progress, and the audit trailretry_cloudflare_domain/rollback_cloudflare_domain— re-queue a failure, or restore Porkbun nameserversget_cloudflare_records/create_cloudflare_record/edit_cloudflare_record/delete_cloudflare_record— manage DNS in the zone that actually answers once a domain has movedset_cloudflare_proxy— turn the orange cloud on or off, per record (a move always imports DNS-only, on purpose)get_cloudflare_zone— Cloudflare’s own zone state, plus nameserver-drift detectionget_cloudflare_zone_settings/set_cloudflare_zone_settings— SSL mode and friendsdisconnect_cloudflare— forget the grant (domains already moved keep working)
Sandbox / test mode
Use a sandbox API key (public key prefixed pk1_sb_, secret sk1_sb_) and every tool above runs against an isolated test environment — same server, you just swap the key. Registrations, renewals, transfers, DNS, contacts, glue, and DNSSEC are all simulated against a separate sandbox datastore: no real registry actions, no DNS changes, no certificates, and no charges. Your sandbox account starts with fake account credit, availability/pricing reflect the real catalog, and every response includes "sandbox": true. Create a sandbox key on porkbun.com/account/api. Or mint one instantly with create_sandbox_key — no signup, no credentials. (Hosting and email endpoints aren’t simulated and return SANDBOX_UNSUPPORTED with a sandbox key.)
| Tool | Description |
|---|---|
create_sandbox_key |
No credentials needed — instantly mint a throwaway sandbox key pair (pk1_sb_/sk1_sb_, $1000 fake credit) so an agent can start testing before it has any keys |
sandbox_topup |
Sandbox only — grant fake account credit (default $1000) so paid ops can keep being exercised after funds run out |
sandbox_reset |
Sandbox only — wipe the sandbox account’s domains/DNS/orders/credit and re-grant $1000, for a clean slate between test runs |
sandbox_trigger_webhook |
Sandbox only — fire a sample signed webhook event of any type (incl. cron-driven domain.expiring) to your registered endpoints, to test your handler + signature verification on demand |
Mock server (no credentials)
mock_call returns a schema-accurate example response for any endpoint with no key required — nothing to set up. Pass a path like domain/listAll or dns/create/example.com (omit it to list every mockable endpoint), or set error: true for the error shape. Responses touch no datastore and match the live API’s shape exactly, so you can build and test client code before you have any credentials.
| Tool | Description |
|---|---|
mock_call |
No credentials needed — schema-accurate example response for any endpoint (path mirrors the real route; error: true for the error shape; omit path to list all mockable endpoints) |
Webhook writes (free)
| Tool | Description |
|---|---|
create_webhook |
Register an HTTPS endpoint to receive signed event payloads; returns the signing secret |
update_webhook |
Change an endpoint’s URL, events, or status (ACTIVE/DISABLED) |
rotate_webhook_secret |
Generate a new signing secret for an endpoint |
test_webhook |
Send a webhook.test event to confirm reachability and signature verification |
resend_webhook |
Re-queue a past delivery (reuses the original event id) |
delete_webhook |
Delete a webhook endpoint |
Porkbun POSTs a signed JSON payload to your endpoint when subscribed events occur (domain.registered, domain.renewed, domain.transfer.completed, domain.expiring, dns.record.created|updated|deleted). Verify the X-Porkbun-Signature header — it’s sha256= + HMAC-SHA256 of {timestamp}.{rawBody} keyed by the endpoint secret, where {timestamp} is the X-Porkbun-Webhook-Timestamp header.
Install
You’ll need Node.js 18 or newer.
npx -y @porkbunllc/mcp-server
This downloads and runs the latest version on demand. No global install needed.
Configure your MCP client
Claude Desktop
Add this to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"porkbun": {
"command": "npx",
"args": ["-y", "@porkbunllc/mcp-server"],
"env": {
"PORKBUN_API_KEY": "pk1_your_public_key_here",
"PORKBUN_SECRET_API_KEY": "sk1_your_secret_key_here"
}
}
}
}
Restart Claude Desktop. Porkbun tools should appear in the tool picker.
Docs-only, no keys: the documentation tools (
search_docs,read_doc,list_doc_topics) work without credentials, so you can omit theenvblock entirely to use the server just for API research. The authenticated tools return a clear “set PORKBUN_API_KEY” message until you add keys.
Cursor / Cline / Continue
Most MCP-aware editors use a similar mcpServers config block. See your client’s documentation for the exact location.
Get API keys
Create API keys at porkbun.com/account/api. You’ll need both the public key (pk1_…) and the secret key (sk1_…).
By default, API access is opt-in per domain. To use the API to manage all your domains, enable the “Opt In All Domains” toggle in the same settings page. Otherwise you’ll need to enable API access for each domain individually under Domain Management.
Recommended: scope the key to your agent
Each API key supports two optional restrictions, set via the gear icon next to the key in porkbun.com/account/api:
- Allowed IPs — one entry per line; supports bare IPv4/IPv6 plus CIDR ranges (
198.51.100.0/24,2001:db8::/32). Requests from other IPs fail with HTTP 403IP_NOT_ALLOWEDbefore any other check runs. - Allowed domains — one entry per line, exact match. Operations against domains not in the list fail with HTTP 403
DOMAIN_NOT_ALLOWED.
Empty fields = no restriction (matches current behavior). When you give an MCP server a key, the recommended pattern is:
- Create a fresh key dedicated to the agent (not your master key).
- List the specific domains the agent should manage.
- If you know the agent’s egress IP, list it too.
The blast radius of an accidentally-leaked key drops to “operations on these domains from this IP” instead of “anything on the account.”
Environment variables
| Variable | Required | Purpose |
|---|---|---|
PORKBUN_API_KEY |
for live ops | Your Porkbun public API key. Omit to use only the credential-free documentation tools. |
PORKBUN_SECRET_API_KEY |
for live ops | Your Porkbun secret API key. Omit to use only the credential-free documentation tools. |
PORKBUN_BASE_URL |
no | Override the API base URL (e.g. for testing against api-betamax.porkbun.com/api/json/v3) |
PORKBUN_DOCS_BASE |
no | Override the docs host used by the *_doc(s) tools (default https://porkbun.com) |
Local development
git clone https://github.com/oborseth/Porkbun-MCP.git
cd Porkbun-MCP
npm install
npm run build
npm start # or: node dist/index.js
The server speaks JSON-RPC 2.0 over stdio. Smoke test from a shell:
(printf '%s\n' \
'{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}}}' \
'{"jsonrpc":"2.0","method":"notifications/initialized"}' \
'{"jsonrpc":"2.0","id":2,"method":"tools/list"}') \
| PORKBUN_API_KEY=pk1_… PORKBUN_SECRET_API_KEY=sk1_… node dist/index.js
Reliability
Write operations automatically attach a per-call Idempotency-Key header. Retried calls within 24 hours return the cached response, so your agent can safely retry on network errors without double-charging or double-registering.
Privacy
This MCP server is a thin client that runs locally (on your machine, or wherever you host it) and relays your requests directly to the Porkbun API over HTTPS. It does not add any data collection of its own:
- What it sends, and to whom. Your API key/secret and the arguments of each tool call are sent only to
https://api.porkbun.com(and, for the credential-free documentation and mock tools, tohttps://porkbun.com). Nothing is sent anywhere else. - Storage. The server keeps your credentials in memory for the lifetime of the process (read from environment variables); it does not write them to disk, log them, or cache your data.
- No telemetry. There is no analytics, tracking, or third-party sharing performed by this connector.
- Data you access through it (domains, DNS, contacts, billing, etc.) is your Porkbun account data, handled by Porkbun under its policy.
Full data-handling, retention, third-party, and contact details are in Porkbun’s privacy policy: https://porkbun.com/legal/agreement/privacy_policy
License
MIT
Links
インストール
npx -y @porkbunllc/mcp-server設定
{
"mcpServers": {
"porkbun": {
"command": "npx",
"args": ["-y", "@porkbunllc/mcp-server"],
"env": {
"PORKBUN_API_KEY": "pk1_your_public_key_here",
"PORKBUN_SECRET_API_KEY": "sk1_your_secret_key_here"
}
}
}
}