# @porkbunllc/mcp-server

Official Porkbun MCP server: domains, DNS, SSL, hosting and Cloudflare via the Porkbun API.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.38.1
- **Author:** com.porkbun
- **License:** Unknown
- **npm:** @porkbunllc/mcp-server
- **Endpoints:** streamable-http https://mcp.porkbun.com/mcp
- **Source:** https://github.com/oborseth/Porkbun-MCP
- **Endpoint health:** reachable (last checked 2026-09-27T13:55:28.232Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-27T13:54:44.178Z
- **Version scanned:** 0.38.1
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `ping` — Verify the Porkbun API connection and credentials. Returns the caller's public IP and whether the API key is valid. Use this as a first sanity check before maki
- `check_domain`
- `check_domains`
- `get_registration_requirements`
- `list_domains`
- `get_domain` — Get the metadata for a single domain in the authenticated account: status, TLD, create date, expire date, security lock, WHOIS privacy, auto-renew, API access o
- `get_balance`
- `get_auto_topup` — Read the account's auto top-up configuration: whether it is on, the balance threshold that triggers it, the amount added, whether a payment method is actually o
- `configure_auto_topup`
- `top_up_account_credit`
- `create_sandbox_key` — Instantly create a free SANDBOX API key — NO credentials or approval needed (works before you have any keys). Returns a `pk1_sb_` / `sk1_sb_` pair for a throwaw
- `sandbox_topup` — SANDBOX ONLY. Grant fake account credit to the sandbox account so paid operations (register/renew/transfer) can keep being exercised after funds run out. Requir
- `sandbox_reset` — SANDBOX ONLY. Wipe the sandbox account's simulated state (domains, DNS, orders, credit) and re-grant $1000 fake credit — a clean slate between test runs. Requir
- `sandbox_trigger_webhook` — SANDBOX ONLY. Fire a sample signed webhook event to your registered endpoints so you can test your handler and HMAC signature verification for ANY event type on
- `mock_call` — Get a schema-accurate EXAMPLE response for any API endpoint with NO credentials — nothing to set up. Mirrors the real path under /mock (e.g. path `domain/listAl
- `get_pricing` — Get current Porkbun pricing: registration, renewal and transfer prices per TLD in USD. No authentication required. **Pass `tlds` whenever you know which TLDs ma
- `list_dns_records` — List all DNS records for a domain in the authenticated account. Returns each record's id, type (A, AAAA, CNAME, MX, TXT, etc.), name (subdomain or empty for ape
- `scan_dns_records` — Discover the DNS records a domain currently publishes by querying its live authoritative nameservers. Writes nothing.
- `import_dns_records` — Create many DNS records on a Porkbun domain in one call — the companion to scan_dns_records for keeping a transferred domain working.
- `search_closeouts` — Search expired-domain closeouts: names that did not sell at auction and are now offered at a fixed price that descends on a schedule. No bidding — the first buy
- `get_closeout` — Get one closeout plus `totalPrice` — the binding amount, which is the closeout price plus the registration year that comes with it.
- `buy_closeout` — **Spends account credit.** Buys a closeout at its current price and claims the name. Confirm the total with the user first.
- `get_transfer_setup` — Report where a held inbound transfer is and what it is waiting on: whether it is held at PENDINGDNS, whether its DNS zone exists, how many records it holds, wha
- `prepare_transfer` — Create the Porkbun DNS zone for a domain whose inbound transfer is held, so records can be added before the domain moves. Step 2 of the no-downtime sequence (tr
- `start_transfer` — Release a held inbound transfer to the registry. Final step of the no-downtime sequence, and the only thing that releases a hold — nothing does it on a timer, s
- `cancel_transfer` — **Cancels a paid inbound transfer and refunds the order.** Confirm with the user first. The order is deliberate: mark cancelled locally, withdraw at the registr
- `update_transfer_auth_code` — Replace the authorization code on an inbound transfer that stalled because the code was wrong, and re-queue it — instead of cancelling, refunding and resubmitti
- `get_ssl_bundle` — Retrieve the free Porkbun-issued SSL certificate bundle for a domain. Returns the certificate chain, private key, and public key (PEM-encoded strings). Porkbun 
- `get_nameservers` — Get the current nameservers configured for a domain in the authenticated account. Returns an array of nameserver hostnames, read live from the registry. Read-on
- `list_url_forwards` — List all URL forwarding rules configured for a domain. Each entry includes its `id` (used by `delete_url_forward`), the source subdomain, the destination URL, t
- `list_dnssec_records`
- `list_transfers`
- `get_transfer_status`
- `list_marketplace`
- `get_api_settings`
- `list_glue_records`
- `create_glue_record`
- `update_glue_record`
- `delete_glue_record`
- `register_domain`

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp-server\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@porkbunllc/mcp-server\"\n      ],\n      \"env\": {\n        \"PORKBUN_API_KEY\": \"<YOUR_PORKBUN_API_KEY>\",\n        \"PORKBUN_SECRET_API_KEY\": \"<YOUR_PORKBUN_SECRET_API_KEY>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `PORKBUN_API_KEY` — Porkbun API Key (optional)
- `PORKBUN_SECRET_API_KEY` — Porkbun Secret API Key (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 2 credentials (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Extensive blast radius — deletes data; runs locally and hosted.
- Floor 58, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40porkbunllc%2Fmcp-server
- Install plan: https://forgeregistry.com/api/v1/packages/%40porkbunllc%2Fmcp-server/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40porkbunllc%2Fmcp-server
- HTML page: https://forgeregistry.com/registry/%40porkbunllc%2Fmcp-server
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
