Official Porkbun MCP server: domains, DNS, SSL, hosting and Cloudflare via the Porkbun API.
Déduit des transports déclarés par cette annonce (stdio, streamable-http). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.
PORKBUN_API_KEYClé d’APIfacultatifPorkbun API key (pk1_...). Optional: the documentation tools work without it.
PORKBUN_SECRET_API_KEYClé d’APIfacultatifPorkbun secret API key (sk1_...).
Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.
pingVerify the Porkbun API connection and credentials. Returns the caller's public IP and whether the API key is valid. Use this as a first sanity check before making other calls.Verify the Porkbun API connection and credentials. Returns the caller's public IP and whether the API key is valid. Use this as a first sanity check before making other calls.
Aucun schéma d’entrée n’a été publié pour cet outil.
check_domainAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
check_domainsAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
get_registration_requirementsAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
list_domainsAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
get_domainGet the metadata for a single domain in the authenticated account: status, TLD, create date, expire date, security lock, WHOIS privacy, auto-renew, API access opt-in, and (optionally) labels. Returns an error with code `DOMAIN_NOT_FOUND` if the domain isn't in the account.Get the metadata for a single domain in the authenticated account: status, TLD, create date, expire date, security lock, WHOIS privacy, auto-renew, API access opt-in, and (optionally) labels. Returns an error with code `DOMAIN_NOT_FOUND` if the domain isn't in the account.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_balanceAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
get_auto_topupRead the account's auto top-up configuration: whether it is on, the balance threshold that triggers it, the amount added, whether a payment method is actually on file, and `effectiveAmount` — what `top_up_account_credit` would charge right now. If `paymentMethodOnFile` is false the settings are ine…Read the account's auto top-up configuration: whether it is on, the balance threshold that triggers it, the amount added, whether a payment method is actually on file, and `effectiveAmount` — what `top_up_account_credit` would charge right now. If `paymentMethodOnFile` is false the settings are ine…
Aucun schéma d’entrée n’a été publié pour cet outil.
configure_auto_topupAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
top_up_account_creditAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
create_sandbox_keyInstantly create a free SANDBOX API key — NO credentials or approval needed (works before you have any keys). Returns a `pk1_sb_` / `sk1_sb_` pair for a throwaway test account seeded with $1000 fake credit. Set the returned keys as PORKBUN_API_KEY / PORKBUN_SECRET_API_KEY (or pass them to any tool)…Instantly create a free SANDBOX API key — NO credentials or approval needed (works before you have any keys). Returns a `pk1_sb_` / `sk1_sb_` pair for a throwaway test account seeded with $1000 fake credit. Set the returned keys as PORKBUN_API_KEY / PORKBUN_SECRET_API_KEY (or pass them to any tool)…
Aucun schéma d’entrée n’a été publié pour cet outil.
sandbox_topupSANDBOX ONLY. Grant fake account credit to the sandbox account so paid operations (register/renew/transfer) can keep being exercised after funds run out. Requires a sandbox API key (`pk1_sb_…`). Optional `amount_cents` (integer US cents) (default 100000 = $1000; capped 1,000,000). Returns the new b…SANDBOX ONLY. Grant fake account credit to the sandbox account so paid operations (register/renew/transfer) can keep being exercised after funds run out. Requires a sandbox API key (`pk1_sb_…`). Optional `amount_cents` (integer US cents) (default 100000 = $1000; capped 1,000,000). Returns the new b…
Aucun schéma d’entrée n’a été publié pour cet outil.
sandbox_resetSANDBOX ONLY. Wipe the sandbox account's simulated state (domains, DNS, orders, credit) and re-grant $1000 fake credit — a clean slate between test runs. Requires a sandbox API key (`pk1_sb_…`). With a live key this endpoint is not available.SANDBOX ONLY. Wipe the sandbox account's simulated state (domains, DNS, orders, credit) and re-grant $1000 fake credit — a clean slate between test runs. Requires a sandbox API key (`pk1_sb_…`). With a live key this endpoint is not available.
Aucun schéma d’entrée n’a été publié pour cet outil.
sandbox_trigger_webhookSANDBOX ONLY. Fire a sample signed webhook event to your registered endpoints so you can test your handler and HMAC signature verification for ANY event type on demand — including cron-driven events like `domain.expiring` that don't result from a single API call. Register an endpoint first with the…SANDBOX ONLY. Fire a sample signed webhook event to your registered endpoints so you can test your handler and HMAC signature verification for ANY event type on demand — including cron-driven events like `domain.expiring` that don't result from a single API call. Register an endpoint first with the…
Aucun schéma d’entrée n’a été publié pour cet outil.
mock_callGet a schema-accurate EXAMPLE response for any API endpoint with NO credentials — nothing to set up. Mirrors the real path under /mock (e.g. path `domain/listAll` or `dns/create/example.com`). Touches no datastore and returns the exact shape the live API would. Set `error: true` to see the error-re…Get a schema-accurate EXAMPLE response for any API endpoint with NO credentials — nothing to set up. Mirrors the real path under /mock (e.g. path `domain/listAll` or `dns/create/example.com`). Touches no datastore and returns the exact shape the live API would. Set `error: true` to see the error-re…
Aucun schéma d’entrée n’a été publié pour cet outil.
get_pricingGet current Porkbun pricing: registration, renewal and transfer prices per TLD in USD. No authentication required. **Pass `tlds` whenever you know which TLDs matter** (e.g. `["com", "io"]`): without it the response lists every TLD Porkbun sells, around 900 of them. Case, a leading dot and IDN form…Get current Porkbun pricing: registration, renewal and transfer prices per TLD in USD. No authentication required. **Pass `tlds` whenever you know which TLDs matter** (e.g. `["com", "io"]`): without it the response lists every TLD Porkbun sells, around 900 of them. Case, a leading dot and IDN form…
Aucun schéma d’entrée n’a été publié pour cet outil.
list_dns_recordsList all DNS records for a domain in the authenticated account. Returns each record's id, type (A, AAAA, CNAME, MX, TXT, etc.), name (subdomain or empty for apex), content, ttl, and priority (where applicable). The `id` field is required when editing or deleting a specific record.List all DNS records for a domain in the authenticated account. Returns each record's id, type (A, AAAA, CNAME, MX, TXT, etc.), name (subdomain or empty for apex), content, ttl, and priority (where applicable). The `id` field is required when editing or deleting a specific record.
Aucun schéma d’entrée n’a été publié pour cet outil.
scan_dns_recordsDiscover the DNS records a domain currently publishes by querying its live authoritative nameservers. Writes nothing.Discover the DNS records a domain currently publishes by querying its live authoritative nameservers. Writes nothing.
Aucun schéma d’entrée n’a été publié pour cet outil.
import_dns_recordsCreate many DNS records on a Porkbun domain in one call — the companion to scan_dns_records for keeping a transferred domain working.Create many DNS records on a Porkbun domain in one call — the companion to scan_dns_records for keeping a transferred domain working.
Aucun schéma d’entrée n’a été publié pour cet outil.
search_closeoutsSearch expired-domain closeouts: names that did not sell at auction and are now offered at a fixed price that descends on a schedule. No bidding — the first buyer at the current price takes the name.Search expired-domain closeouts: names that did not sell at auction and are now offered at a fixed price that descends on a schedule. No bidding — the first buyer at the current price takes the name.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_closeoutGet one closeout plus `totalPrice` — the binding amount, which is the closeout price plus the registration year that comes with it.Get one closeout plus `totalPrice` — the binding amount, which is the closeout price plus the registration year that comes with it.
Aucun schéma d’entrée n’a été publié pour cet outil.
buy_closeout**Spends account credit.** Buys a closeout at its current price and claims the name. Confirm the total with the user first.**Spends account credit.** Buys a closeout at its current price and claims the name. Confirm the total with the user first.
Aucun schéma d’entrée n’a été publié pour cet outil.
get_transfer_setupReport where a held inbound transfer is and what it is waiting on: whether it is held at PENDINGDNS, whether its DNS zone exists, how many records it holds, what the domain currently delegates to, and the next step. Use this to resume a no-downtime transfer instead of tracking that state yourself.Report where a held inbound transfer is and what it is waiting on: whether it is held at PENDINGDNS, whether its DNS zone exists, how many records it holds, what the domain currently delegates to, and the next step. Use this to resume a no-downtime transfer instead of tracking that state yourself.
Aucun schéma d’entrée n’a été publié pour cet outil.
prepare_transferCreate the Porkbun DNS zone for a domain whose inbound transfer is held, so records can be added before the domain moves. Step 2 of the no-downtime sequence (transfer_domain with hold_for_dns_setup, prepare_transfer, import_dns_records, start_transfer). Returns the Porkbun nameservers. The zone is…Create the Porkbun DNS zone for a domain whose inbound transfer is held, so records can be added before the domain moves. Step 2 of the no-downtime sequence (transfer_domain with hold_for_dns_setup, prepare_transfer, import_dns_records, start_transfer). Returns the Porkbun nameservers. The zone is…
Aucun schéma d’entrée n’a été publié pour cet outil.
start_transferRelease a held inbound transfer to the registry. Final step of the no-downtime sequence, and the only thing that releases a hold — nothing does it on a timer, so a held transfer waits indefinitely until you call this. Refuses with TRANSFER_ZONE_EMPTY if the zone has no records, which is the outage…Release a held inbound transfer to the registry. Final step of the no-downtime sequence, and the only thing that releases a hold — nothing does it on a timer, so a held transfer waits indefinitely until you call this. Refuses with TRANSFER_ZONE_EMPTY if the zone has no records, which is the outage…
Aucun schéma d’entrée n’a été publié pour cet outil.
cancel_transfer**Cancels a paid inbound transfer and refunds the order.** Confirm with the user first. The order is deliberate: mark cancelled locally, withdraw at the registry, verify the registry accepted the withdrawal, then refund. If the registry state cannot be confirmed it restores the transfer and returns…**Cancels a paid inbound transfer and refunds the order.** Confirm with the user first. The order is deliberate: mark cancelled locally, withdraw at the registry, verify the registry accepted the withdrawal, then refund. If the registry state cannot be confirmed it restores the transfer and returns…
Aucun schéma d’entrée n’a été publié pour cet outil.
update_transfer_auth_codeReplace the authorization code on an inbound transfer that stalled because the code was wrong, and re-queue it — instead of cancelling, refunding and resubmitting. The new code is validated against the registry before being stored, so a bad one is rejected here rather than failing again days later.…Replace the authorization code on an inbound transfer that stalled because the code was wrong, and re-queue it — instead of cancelling, refunding and resubmitting. The new code is validated against the registry before being stored, so a bad one is rejected here rather than failing again days later.…
Aucun schéma d’entrée n’a été publié pour cet outil.
get_ssl_bundleRetrieve the free Porkbun-issued SSL certificate bundle for a domain. Returns the certificate chain, private key, and public key (PEM-encoded strings). Porkbun automatically provisions Let's Encrypt certificates for all registered domains using Porkbun nameservers. Use this to install TLS on a serv…Retrieve the free Porkbun-issued SSL certificate bundle for a domain. Returns the certificate chain, private key, and public key (PEM-encoded strings). Porkbun automatically provisions Let's Encrypt certificates for all registered domains using Porkbun nameservers. Use this to install TLS on a serv…
Aucun schéma d’entrée n’a été publié pour cet outil.
get_nameserversGet the current nameservers configured for a domain in the authenticated account. Returns an array of nameserver hostnames, read live from the registry. Read-only complement to `update_nameservers`. **Treat the result as an unordered set** — registries return nameservers in whatever order they like…Get the current nameservers configured for a domain in the authenticated account. Returns an array of nameserver hostnames, read live from the registry. Read-only complement to `update_nameservers`. **Treat the result as an unordered set** — registries return nameservers in whatever order they like…
Aucun schéma d’entrée n’a été publié pour cet outil.
list_url_forwardsList all URL forwarding rules configured for a domain. Each entry includes its `id` (used by `delete_url_forward`), the source subdomain, the destination URL, the redirect `type` (permanent/temporary/masked), the exact `redirectType` code (301/302/307/masked — distinguishes 302 from 307), and wheth…List all URL forwarding rules configured for a domain. Each entry includes its `id` (used by `delete_url_forward`), the source subdomain, the destination URL, the redirect `type` (permanent/temporary/masked), the exact `redirectType` code (301/302/307/masked — distinguishes 302 from 307), and wheth…
Aucun schéma d’entrée n’a été publié pour cet outil.
list_dnssec_recordsAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
list_transfersAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
get_transfer_statusAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
list_marketplaceAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
get_api_settingsAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
list_glue_recordsAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
create_glue_recordAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
update_glue_recordAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
delete_glue_recordprivilégiéAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
register_domainAucune description publiéeCet outil n’a publié aucune description. Forge n’en invente pas.
23 outils sur 40 ont publié une description.
Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.
Official Porkbun MCP server: domains, DNS, SSL, hosting and Cloudflare via the Porkbun API.
Les noms cliquables ouvrent l’index Forge de toutes les entrées observées exposant cet outil. Parcourir tous les outils indexés.
L'exploration s'est arrêtée à la limite de profondeur 4. Tout ce qui se trouve en dessous n'a jamais été résolu.
L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.
36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)
53 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.
+41 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.
Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.