@porkbunllc/mcp-server

MCPcommunitylive
v0.38.1com.porkbunUnknownUpdated 2d agonpmGitHub

Official Porkbun MCP server: domains, DNS, SSL, hosting and Cloudflare via the Porkbun API.

Endpoint healthlive
checked 16h ago · 227ms · auth required
100% of the last 1 check reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (stdio, streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
32GitHub stars
2Forks
2d agoLast update
Reads these credentials
  • PORKBUN_API_KEYAPI keyoptional

    Porkbun API key (pk1_...). Optional: the documentation tools work without it.

  • PORKBUN_SECRET_API_KEYAPI keyoptional

    Porkbun secret API key (sk1_...).

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorcom.porkbun
LicenseUnknown
Version0.38.1
Sourcenpm+mcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/20
→ Publisher: run `forge publish` from the package repo to claim ownership
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
—npm maintainer match+0/5
→ Earned once your identity is verified above and that login is an npm maintainer of this package
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface40 tools · 1 privileged
Security scan✓ Cleanv0.38.1 · todayHow well does this scan work?
EvalsNone
IndexedSep 27, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 1 privileged
Statically extracted from the published packagev0.38.1 · 16h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

pingVerify the Porkbun API connection and credentials. Returns the caller's public IP and whether the API key is valid. Use this as a first sanity check before making other calls.

Verify the Porkbun API connection and credentials. Returns the caller's public IP and whether the API key is valid. Use this as a first sanity check before making other calls.

No input schema was published for this tool.

check_domainNo description published

This tool published no description. Forge does not invent one.

check_domainsNo description published

This tool published no description. Forge does not invent one.

get_registration_requirementsNo description published

This tool published no description. Forge does not invent one.

list_domainsNo description published

This tool published no description. Forge does not invent one.

get_domainGet the metadata for a single domain in the authenticated account: status, TLD, create date, expire date, security lock, WHOIS privacy, auto-renew, API access opt-in, and (optionally) labels. Returns an error with code `DOMAIN_NOT_FOUND` if the domain isn't in the account.

Get the metadata for a single domain in the authenticated account: status, TLD, create date, expire date, security lock, WHOIS privacy, auto-renew, API access opt-in, and (optionally) labels. Returns an error with code `DOMAIN_NOT_FOUND` if the domain isn't in the account.

No input schema was published for this tool.

get_balanceNo description published

This tool published no description. Forge does not invent one.

get_auto_topupRead the account's auto top-up configuration: whether it is on, the balance threshold that triggers it, the amount added, whether a payment method is actually on file, and `effectiveAmount` — what `top_up_account_credit` would charge right now. If `paymentMethodOnFile` is false the settings are ine…

Read the account's auto top-up configuration: whether it is on, the balance threshold that triggers it, the amount added, whether a payment method is actually on file, and `effectiveAmount` — what `top_up_account_credit` would charge right now. If `paymentMethodOnFile` is false the settings are ine…

No input schema was published for this tool.

configure_auto_topupNo description published

This tool published no description. Forge does not invent one.

top_up_account_creditNo description published

This tool published no description. Forge does not invent one.

create_sandbox_keyInstantly create a free SANDBOX API key — NO credentials or approval needed (works before you have any keys). Returns a `pk1_sb_` / `sk1_sb_` pair for a throwaway test account seeded with $1000 fake credit. Set the returned keys as PORKBUN_API_KEY / PORKBUN_SECRET_API_KEY (or pass them to any tool)…

Instantly create a free SANDBOX API key — NO credentials or approval needed (works before you have any keys). Returns a `pk1_sb_` / `sk1_sb_` pair for a throwaway test account seeded with $1000 fake credit. Set the returned keys as PORKBUN_API_KEY / PORKBUN_SECRET_API_KEY (or pass them to any tool)…

No input schema was published for this tool.

sandbox_topupSANDBOX ONLY. Grant fake account credit to the sandbox account so paid operations (register/renew/transfer) can keep being exercised after funds run out. Requires a sandbox API key (`pk1_sb_…`). Optional `amount_cents` (integer US cents) (default 100000 = $1000; capped 1,000,000). Returns the new b…

SANDBOX ONLY. Grant fake account credit to the sandbox account so paid operations (register/renew/transfer) can keep being exercised after funds run out. Requires a sandbox API key (`pk1_sb_…`). Optional `amount_cents` (integer US cents) (default 100000 = $1000; capped 1,000,000). Returns the new b…

No input schema was published for this tool.

sandbox_resetSANDBOX ONLY. Wipe the sandbox account's simulated state (domains, DNS, orders, credit) and re-grant $1000 fake credit — a clean slate between test runs. Requires a sandbox API key (`pk1_sb_…`). With a live key this endpoint is not available.

SANDBOX ONLY. Wipe the sandbox account's simulated state (domains, DNS, orders, credit) and re-grant $1000 fake credit — a clean slate between test runs. Requires a sandbox API key (`pk1_sb_…`). With a live key this endpoint is not available.

No input schema was published for this tool.

sandbox_trigger_webhookSANDBOX ONLY. Fire a sample signed webhook event to your registered endpoints so you can test your handler and HMAC signature verification for ANY event type on demand — including cron-driven events like `domain.expiring` that don't result from a single API call. Register an endpoint first with the…

SANDBOX ONLY. Fire a sample signed webhook event to your registered endpoints so you can test your handler and HMAC signature verification for ANY event type on demand — including cron-driven events like `domain.expiring` that don't result from a single API call. Register an endpoint first with the…

No input schema was published for this tool.

mock_callGet a schema-accurate EXAMPLE response for any API endpoint with NO credentials — nothing to set up. Mirrors the real path under /mock (e.g. path `domain/listAll` or `dns/create/example.com`). Touches no datastore and returns the exact shape the live API would. Set `error: true` to see the error-re…

Get a schema-accurate EXAMPLE response for any API endpoint with NO credentials — nothing to set up. Mirrors the real path under /mock (e.g. path `domain/listAll` or `dns/create/example.com`). Touches no datastore and returns the exact shape the live API would. Set `error: true` to see the error-re…

No input schema was published for this tool.

get_pricingGet current Porkbun pricing: registration, renewal and transfer prices per TLD in USD. No authentication required. **Pass `tlds` whenever you know which TLDs matter** (e.g. `["com", "io"]`): without it the response lists every TLD Porkbun sells, around 900 of them. Case, a leading dot and IDN form…

Get current Porkbun pricing: registration, renewal and transfer prices per TLD in USD. No authentication required. **Pass `tlds` whenever you know which TLDs matter** (e.g. `["com", "io"]`): without it the response lists every TLD Porkbun sells, around 900 of them. Case, a leading dot and IDN form…

No input schema was published for this tool.

list_dns_recordsList all DNS records for a domain in the authenticated account. Returns each record's id, type (A, AAAA, CNAME, MX, TXT, etc.), name (subdomain or empty for apex), content, ttl, and priority (where applicable). The `id` field is required when editing or deleting a specific record.

List all DNS records for a domain in the authenticated account. Returns each record's id, type (A, AAAA, CNAME, MX, TXT, etc.), name (subdomain or empty for apex), content, ttl, and priority (where applicable). The `id` field is required when editing or deleting a specific record.

No input schema was published for this tool.

scan_dns_recordsDiscover the DNS records a domain currently publishes by querying its live authoritative nameservers. Writes nothing.

Discover the DNS records a domain currently publishes by querying its live authoritative nameservers. Writes nothing.

No input schema was published for this tool.

import_dns_recordsCreate many DNS records on a Porkbun domain in one call — the companion to scan_dns_records for keeping a transferred domain working.

Create many DNS records on a Porkbun domain in one call — the companion to scan_dns_records for keeping a transferred domain working.

No input schema was published for this tool.

search_closeoutsSearch expired-domain closeouts: names that did not sell at auction and are now offered at a fixed price that descends on a schedule. No bidding — the first buyer at the current price takes the name.

Search expired-domain closeouts: names that did not sell at auction and are now offered at a fixed price that descends on a schedule. No bidding — the first buyer at the current price takes the name.

No input schema was published for this tool.

get_closeoutGet one closeout plus `totalPrice` — the binding amount, which is the closeout price plus the registration year that comes with it.

Get one closeout plus `totalPrice` — the binding amount, which is the closeout price plus the registration year that comes with it.

No input schema was published for this tool.

buy_closeout**Spends account credit.** Buys a closeout at its current price and claims the name. Confirm the total with the user first.

**Spends account credit.** Buys a closeout at its current price and claims the name. Confirm the total with the user first.

No input schema was published for this tool.

get_transfer_setupReport where a held inbound transfer is and what it is waiting on: whether it is held at PENDINGDNS, whether its DNS zone exists, how many records it holds, what the domain currently delegates to, and the next step. Use this to resume a no-downtime transfer instead of tracking that state yourself.

Report where a held inbound transfer is and what it is waiting on: whether it is held at PENDINGDNS, whether its DNS zone exists, how many records it holds, what the domain currently delegates to, and the next step. Use this to resume a no-downtime transfer instead of tracking that state yourself.

No input schema was published for this tool.

prepare_transferCreate the Porkbun DNS zone for a domain whose inbound transfer is held, so records can be added before the domain moves. Step 2 of the no-downtime sequence (transfer_domain with hold_for_dns_setup, prepare_transfer, import_dns_records, start_transfer). Returns the Porkbun nameservers. The zone is…

Create the Porkbun DNS zone for a domain whose inbound transfer is held, so records can be added before the domain moves. Step 2 of the no-downtime sequence (transfer_domain with hold_for_dns_setup, prepare_transfer, import_dns_records, start_transfer). Returns the Porkbun nameservers. The zone is…

No input schema was published for this tool.

start_transferRelease a held inbound transfer to the registry. Final step of the no-downtime sequence, and the only thing that releases a hold — nothing does it on a timer, so a held transfer waits indefinitely until you call this. Refuses with TRANSFER_ZONE_EMPTY if the zone has no records, which is the outage…

Release a held inbound transfer to the registry. Final step of the no-downtime sequence, and the only thing that releases a hold — nothing does it on a timer, so a held transfer waits indefinitely until you call this. Refuses with TRANSFER_ZONE_EMPTY if the zone has no records, which is the outage…

No input schema was published for this tool.

cancel_transfer**Cancels a paid inbound transfer and refunds the order.** Confirm with the user first. The order is deliberate: mark cancelled locally, withdraw at the registry, verify the registry accepted the withdrawal, then refund. If the registry state cannot be confirmed it restores the transfer and returns…

**Cancels a paid inbound transfer and refunds the order.** Confirm with the user first. The order is deliberate: mark cancelled locally, withdraw at the registry, verify the registry accepted the withdrawal, then refund. If the registry state cannot be confirmed it restores the transfer and returns…

No input schema was published for this tool.

update_transfer_auth_codeReplace the authorization code on an inbound transfer that stalled because the code was wrong, and re-queue it — instead of cancelling, refunding and resubmitting. The new code is validated against the registry before being stored, so a bad one is rejected here rather than failing again days later.…

Replace the authorization code on an inbound transfer that stalled because the code was wrong, and re-queue it — instead of cancelling, refunding and resubmitting. The new code is validated against the registry before being stored, so a bad one is rejected here rather than failing again days later.…

No input schema was published for this tool.

get_ssl_bundleRetrieve the free Porkbun-issued SSL certificate bundle for a domain. Returns the certificate chain, private key, and public key (PEM-encoded strings). Porkbun automatically provisions Let's Encrypt certificates for all registered domains using Porkbun nameservers. Use this to install TLS on a serv…

Retrieve the free Porkbun-issued SSL certificate bundle for a domain. Returns the certificate chain, private key, and public key (PEM-encoded strings). Porkbun automatically provisions Let's Encrypt certificates for all registered domains using Porkbun nameservers. Use this to install TLS on a serv…

No input schema was published for this tool.

get_nameserversGet the current nameservers configured for a domain in the authenticated account. Returns an array of nameserver hostnames, read live from the registry. Read-only complement to `update_nameservers`. **Treat the result as an unordered set** — registries return nameservers in whatever order they like…

Get the current nameservers configured for a domain in the authenticated account. Returns an array of nameserver hostnames, read live from the registry. Read-only complement to `update_nameservers`. **Treat the result as an unordered set** — registries return nameservers in whatever order they like…

No input schema was published for this tool.

list_url_forwardsList all URL forwarding rules configured for a domain. Each entry includes its `id` (used by `delete_url_forward`), the source subdomain, the destination URL, the redirect `type` (permanent/temporary/masked), the exact `redirectType` code (301/302/307/masked — distinguishes 302 from 307), and wheth…

List all URL forwarding rules configured for a domain. Each entry includes its `id` (used by `delete_url_forward`), the source subdomain, the destination URL, the redirect `type` (permanent/temporary/masked), the exact `redirectType` code (301/302/307/masked — distinguishes 302 from 307), and wheth…

No input schema was published for this tool.

list_dnssec_recordsNo description published

This tool published no description. Forge does not invent one.

list_transfersNo description published

This tool published no description. Forge does not invent one.

get_transfer_statusNo description published

This tool published no description. Forge does not invent one.

list_marketplaceNo description published

This tool published no description. Forge does not invent one.

get_api_settingsNo description published

This tool published no description. Forge does not invent one.

list_glue_recordsNo description published

This tool published no description. Forge does not invent one.

create_glue_recordNo description published

This tool published no description. Forge does not invent one.

update_glue_recordNo description published

This tool published no description. Forge does not invent one.

delete_glue_recordprivilegedNo description published

This tool published no description. Forge does not invent one.

register_domainNo description published

This tool published no description. Forge does not invent one.

23 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Official Porkbun MCP server: domains, DNS, SSL, hosting and Cloudflare via the Porkbun API.

Keywords
mcp
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-27 — observed resolution, not a publisher declaration.

60 packages resolved · 2 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the depth-4 limit. Anything below that level was never resolved.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

53 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+41 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.