{"auth":{"authorization_servers":["https://api.customdomain.ai","https://mcp.customdomain.ai"],"grant_types_supported":["authorization_code","refresh_token","client_credentials"],"resource_metadata":"https://mcp.customdomain.ai/.well-known/oauth-protected-resource","scopes_supported":["domains:read","domains:connect","domains:disconnect","domains:purchase"],"token_endpoint":"https://mcp.customdomain.ai/token","type":"oauth2"},"description":"Put a user on their own branded domain with automatic HTTPS, and set that domain up for email, for one domain or thousands. For SaaS platforms, email platforms, website builders, and AI agents: availability search, suggestions, purchase (authorization-gated), guided DNS connection with the exact records returned, forwarding, email authentication (MX, SPF, DKIM, DMARC), and portfolio listing. The end user never touches a DNS panel.","documentation":"https://docs.customdomain.ai/docs/mcp/overview","endpoint":"https://mcp.customdomain.ai/mcp","keywords":["custom domains","custom domains as a service","bring your own domain","custom domain per tenant","white label domain","vanity domain","automatic TLS","SSL for SaaS","apex and CNAME setup","on-demand TLS","connect a domain","buy a domain","email domain setup","MX SPF DKIM DMARC","domain forwarding","manage domains","domains for AI agents"],"name":"customdomain-mcp","protocol":"mcp","protocolVersion":"2025-06-18","provider":{"name":"CustomDomain","url":"https://customdomain.ai"},"schema_version":"1.0","tools":[{"name":"search-domain-availability","description":"Check whether a domain is available to register, with real-time price and renewal price. Use before create-domain-order when a user needs a new domain."},{"name":"generate-domain-suggestions","description":"Generate available-to-register domain suggestions for a set of keywords, each with real-time price and renewal price. Only available domains are returned; the top pick is marked."},{"name":"create-domain-order","description":"Start a domain registration/purchase through the resolved registrar. Enterprise/direct registrars return an orderId; sharing registrars return a checkout link and jobId to poll. This spends money and is authorization-gated. After the domain is registered, use connect-domain to point it at the user's app."},{"name":"connect-domain","description":"Attach a domain the user already owns to their app and set it up to serve with automatic HTTPS. Returns the authoritative DNS records to add (a CNAME/A to the edge) in the records field, a link for the user, and a jobId to poll with check-connection-status. The link is a one-click provider authorization ONLY when the domain's DNS provider supports Domain Connect; otherwise it opens the same records in the console. Read the message field, which says which one you got and whether the provider instead offers a sign-in rail. Relay the records to the user; never writes DNS directly."},{"name":"check-connection-status","description":"Read the live status of a domain connection by its connectionId (the jobId connect-domain returned is the same id), and get the authoritative DNS records to add in the records field. Key completion off the boolean connected:true (the reliable terminal signal); the status string is one of pending, propagating, live, failed. Poll this until connected is true (usually under a few minutes once records are in place). When a connection failed, errorCode says why. managed:true means the platform holds a durable grant for this domain and reapply-connection can heal it server-side; false means any repair needs the user at their DNS provider."},{"name":"check-order-status","description":"Read the live status of a domain order by orderId (enterprise) or jobId (sharing). Provide exactly one."},{"name":"reapply-connection","description":"Re-apply a managed connection: the control plane recomputes its desired DNS records from stored config and re-pushes them through the connection's stored grant. Use this to self-heal a domain that has drifted or fallen out of live. Never supply records; they are recomputed server-side. Fails if the connection is not managed or has no stored grant: check managed:true on list-connections or check-connection-status before calling, rather than using this to probe."},{"name":"disconnect-domain","description":"Disconnect a domain: the control plane reverts its DNS through the stored grant, then deletes the grant and connection. This takes the domain offline and cannot be undone here, so ask the user first and send the domain they confirmed in confirm; a confirmation that does not name the connection's domain disconnects nothing. Needs the domains:disconnect scope, which is separate from connecting. Never supply records; the revert is computed server-side."},{"name":"discover-provider","description":"Detect where a domain's DNS is hosted and which automated setup rails are available (Domain Connect, OAuth, automatic). Read-only; writes no DNS. Use it before connect-domain / forward-domain / add-email to see whether the domain can be configured in one click or needs the user to add records manually. It also returns the pre-flight advisories: recordConflicts lists live records that clash with the ones the connect would write (tell the user to clear them first), willFallbackToManual warns that the provider stops writing automatically past conflictTolerance conflicts so the one-click rail would quietly become a manual record list, a recordConflicts entry of kind caa-blocks-letsencrypt means the domain's CAA record would block HTTPS issuance until Let's Encrypt is authorized, and a non-empty apexMessage means the provider cannot host the record a root domain needs, so connect a subdomain instead. Report these before asking the user to authorize anything."},{"name":"forward-domain","description":"Forward (permanent 301 redirect) a domain to a destination URL or host. When the domain's DNS provider supports one-click (Domain Connect) setup, returns a link for the user to authorize at their provider; otherwise returns the DNS records to add in the records field plus a console link with the same guided setup. Either way returns a connectionId to poll with check-connection-status. Never writes DNS directly."},{"name":"add-email","description":"Set up a domain to send and receive email with correct authentication (MX, SPF, DKIM, DMARC) so mail is delivered and not spoofed. Ideal for an email platform onboarding a customer's sending domain. Pass provider (google, microsoft365, or zoho) to auto-fill the standard MX and SPF and supply only the DKIM values your platform generated, or set each field manually. Uses server-side record templates; supply settings, never raw DNS records. Returns the records to add in the records field, a one-click authorize link when the domain's DNS provider supports it (a console link with the same records otherwise), and a connectionId to poll."},{"name":"list-connections","description":"List the domains connected across the account so an agent can inventory, monitor, and reconcile a whole portfolio, not just the one job it started. Returns each connection's domain, connectionId, live status, connected flag, setup type, and managed flag. Optionally filter by status (pending, propagating, live, failed). Read-only. Pair with reapply-connection to heal any that are not live, but only rows with managed:true can be re-applied, so check that first instead of calling reapply-connection to find out."},{"name":"check-certificate-status","description":"Read the HTTPS certificate of a connected domain: issuer, expiry, days left, whether renewal is failing and the last error. Certificates renew on their own. attention is empty when nothing needs a person, else failed, renewal_failing, expired or expiring. Read-only."},{"name":"recheck-connection","description":"Re-run a connection's DNS check now instead of waiting for the next scheduled one: a failed connection re-enters verification, a live one is checked for drift. Returns which records resolve and the new status; poll check-connection-status for the outcome. Writes no DNS. Use diagnose-connection first to see what is missing, and recheck once the user has fixed it."},{"name":"diagnose-connection","description":"Explain, record by record, what public DNS shows for a connection and what the user still has to do: each record is found, missing or mismatch with what DNS answers today, plus the issues that explain it (a hostname typed in the Name field, a proxy in front, a leftover record). Read-only; never changes the connection."},{"name":"check-billing-status","description":"Check whether the workspace may connect new domains right now. When it may not, restricted is true, code is billing_required and details say where an owner or admin fixes billing. Also returns the plan and this month's usage. Read-only. Use it after a billing_required failure or before a batch of connects."},{"name":"list-domain-orders","description":"List the domain purchases made through the account, newest first: each order's status, domain, registrar and the checkout link when there is one. Read-only. Use check-order-status for one order."}],"transport":["streamable-http"],"version":"0.5.0"}