# monacloud-mcp

MCP server for MONA Cloud — deploy apps (Vercel alternative), Supabase-compatible Postgres/Auth/Storage bases (Supabase alternative), VND wallet, MONA Pay & Mail — for AI agents (Claude, Cursor, Codex) in Vietnam.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.11.1
- **Author:** MONA Software
- **License:** MIT
- **npm:** monacloud-mcp
- **Source:** https://github.com/mona-software/monacloud-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 16 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-19T17:58:50.661Z
- **Version scanned:** 0.10.11
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `cloud_domain_search` — Kiểm tra tên miền còn trống và xem giá mua (VND, đã VAT). KHÔNG cần đăng nhập MONA Pass — gọi được ngay cả khi người dùng chưa có tài khoản; dùng trước khi mua/
- `cloud_domain_registrant_get` — Lấy thông tin chủ thể (registrant) đã lưu. Cần dữ liệu này để mua tên miền.
- `cloud_domain_registrant_set` — Lưu thông tin chủ thể để đăng ký tên miền. HỎI NGƯỜI DÙNG cung cấp NGAY TRONG PHIÊN: họ tên, email, điện thoại, địa chỉ. Tên miền .vn cá nhân cần thêm CCCD 12 s
- `cloud_domain_buy`
- `cloud_domain_reserve`
- `cloud_domain_reserve_status` — Xem reservation đã nhận tiền chưa / đã claim chưa / còn hạn không. Guest truyền claim_token (hoặc guest_token) nhận từ cloud_domain_reserve; chủ reservation đã 
- `cloud_domain_claim`
- `cloud_domain_reserve_release` — Huỷ reservation chưa nhận tiền (người dùng đổi ý / chọn tên khác). Đã có tiền vào thì không huỷ được — dùng cloud_domain_claim.
- `cloud_domain_list` — Liệt kê tên miền đã đưa vào MONA Cloud (import + mua). sandbox=true → xem domain sandbox.
- `cloud_domain_verify_start` — Sinh bản khai đã điền sẵn và link upload hồ sơ .vn. Dùng sau khi mua tên miền .vn (status=pending_verification).
- `cloud_domain_verify_status` — Kiểm tra trạng thái duyệt hồ sơ đăng ký .vn (profile_status từ MONA Host).
- `cloud_domain_health` — Kiểm tra hạn đăng ký, trạng thái hồ sơ, NS, SSL và cảnh báo tên miền đã mua.
- `cloud_domain_renew`
- `cloud_domain_wait` — Long-poll cho đến khi tên miền chuyển sang active/failed (mặc định timeout=60s). Dùng sau cloud_domain_buy để chờ MONA Host xử lý.
- `cloud_domain_webhook_set` — Đăng ký URL nhận sự kiện domain.status_changed (ký HMAC). Mỗi user 1 webhook; gọi lại để cập nhật.
- `cloud_domain_attach`
- `cloud_domain_dns_list` — Liệt kê bản ghi DNS (A/CNAME/MX/TXT...) của tên miền đăng ký tại MONA Cloud. domain_id lấy từ cloud_domain_list.
- `cloud_domain_dns_add` — Thêm 1 bản ghi DNS. Vd trỏ web: type=A, name=@, data=<IP>. Trỏ www: type=CNAME, name=www, data=<domain>. AI làm trọn.
- `cloud_domain_dns_update` — Sửa 1 bản ghi DNS theo record_id (lấy từ cloud_domain_dns_list).
- `cloud_domain_dns_delete` — Xoá 1 bản ghi DNS theo record_id.
- `cloud_domain_ns_set` — Đổi NS cho tên miền (≥2). Vd giữ DNS ở MONA: ns1.mona.host, ns2.mona.host. Hoặc chuyển sang Cloudflare/nhà khác. AI làm hoàn toàn.
- `mail_account`
- `mail_plans` — Khi chọn gói gửi mail, đọc giá và quota hiện hành. / Use to compare current email plans.
- `mail_plan_set` — Khi cần đổi quota, chọn gói; gói trả phí trừ ví VND, thiếu tiền gọi cloud_topup. / Use to change the email plan.
- `mail_send` — Khi gửi OTP hoặc thông báo, dùng domain đã verify; onboarding@monamail.vn chỉ gửi tới email chủ. sandbox=true thử 0đ, không gửi ra Internet. / Use to send trans
- `mail_status` — Khi cần xác nhận thư đã giao, đọc trạng thái, events và sandbox_preview. / Use to inspect an email after sending.
- `mail_list` — Khi tra lịch sử gửi, lọc theo trạng thái, người nhận hoặc thời gian. / Use to search sent email history.
- `mail_domain_add` — Khi gửi bằng domain của app, thêm domain. Trả record DNS; nếu người dùng dùng Cloudflare có thể gọi mail_domain_cloudflare với token của họ (không lưu). / Use t
- `mail_domain_verify` — Khi đã thêm DNS, kiểm DKIM và trạng thái domain. / Use after adding DNS records to verify the sender domain.
- `mail_domain_cloudflare` — Khi người dùng cung cấp token Cloudflare, thêm DNS rồi verify domain. Token dùng một lần, không lưu, không log. / Use a user-provided Cloudflare token to config
- `mail_domains_list` — Khi chọn địa chỉ gửi, xem domain và trạng thái xác minh. / Use to find verified sender domains.
- `mail_api_key_create` — Khi tích hợp SDK vào app, tạo key live hoặc test. Key chỉ trả một lần; ghi vào .env của app dưới tên MONAMAIL_API_KEY, không cần in ra chat. / Use to create an 
- `mail_api_keys_list` — Khi kiểm tra key của app, đọc prefix và trạng thái; không trả secret. / Use to inspect existing API key metadata.
- `mail_api_key_revoke` — Khi key không còn dùng hoặc bị lộ, thu hồi bằng key_id. / Use to revoke an unused or compromised API key.
- `mail_webhook_create` — Khi app cần nhận sự kiện gửi hoặc bounce, đăng ký HTTPS webhook; lưu secret một lần vào .env, không log. / Use to subscribe an app to email events.
- `mail_webhooks_list` — Khi kiểm tra cấu hình sự kiện của app, liệt kê webhook. / Use to inspect registered email webhooks.
- `mail_webhook_test` — Khi đã có endpoint, gửi mẫu email.delivered để kiểm tra HTTP response. / Use to test webhook delivery to an app.
- `mail_suppressions_list` — Khi thư bị suppressed, xem địa chỉ và lý do ngừng gửi. / Use to diagnose suppressed recipients.
- `mail_suppression_remove` — Khi đã xử lý nguyên nhân chặn, gỡ suppression của tài khoản; lớp toàn hệ không gỡ được. / Use to remove an account-level suppression.
- `mail_template_create` — Khi app dùng lại nội dung mail, tạo template với biến {{ten_bien}}. / Use to create a reusable email template.

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"monacloud\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"monacloud-mcp\"\n      ],\n      \"env\": {\n        \"MONACLOUD_TOKEN\": \"<YOUR_MONACLOUD_TOKEN>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `MONACLOUD_TOKEN` — Monacloud Token (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Extensive blast radius — deletes data; holds an api key.
- Floor 53, ceiling 53 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/monacloud-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/monacloud-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/monacloud-mcp
- HTML page: https://forgeregistry.com/registry/monacloud-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
