Production MCP server for WHMCS DomainsReseller API on Cloudflare Workers
This server has solid fundamentals: 27 tools with clear verb_noun naming (auth_login, domains_lookup, order_domains_register), consistent schema registration via Zod, and structured error handling. However, parameter descriptions are sparse, output schemas are not documented, and several tools conflate concerns or lack idempotency guarantees. The tool portfolio is well-organized by domain (auth, domains, order, billing, system, tlds), but composition issues and missing pagination on list operations drag the overall quality to 'fair' rather than 'good'. Most individual tools score 60-70; a few score higher due to strong naming and error handling, but none reach 80+ due to incomplete documentation of outputs and parameter constraints.
Authenticate with the DomainsReseller API. Validates credentials against upstream and returns an opaque session token for all subsequent tool calls. Never share your API key again after login.
Revoke an active session. Deletes the session from the server, invalidating the session token immediately.
Get current billing credits/balance for the reseller account. Note: .gr domain transfers are free of charge and do not require credits.
Get contact details (WHOIS) for a domain.
Update contact details for a domain. Requires Registrant, Admin, Technical, and Billing contacts.
Get DNS records for a domain.
Output schemas not documented. Tools return domain info, contact details, DNS records, etc., but LLMs have no visibility into the response structure. This forces agents to treat responses as opaque text, reducing reasoning quality and increasing token waste.
Parameter descriptions sparse or missing. Many tools have inputs like 'contactdetails' (object), 'nameservers' (object), 'records' (array) with only one-sentence descriptions. LLMs cannot infer the inner structure of these objects. Add detailed docs for required vs optional fields, field types, and constraints.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 51 | - | v1 |
Save/update DNS records for a domain. Provide an array of DNS records.
Get email forwarding rules configured for a domain.
Create or update email forwarding rules for a domain.
Get detailed information about a domain.
Get the domain lock status.
Update the domain lock status (enable/disable).
Check domain availability. Provide a search term and array of TLDs to check.
Get domain name suggestions based on a search term.
Delete a child/glue nameserver from a domain.
Get the nameservers configured for a domain.
Modify a child/glue nameserver IP address for a domain.
Register a child/glue nameserver for a domain.
Update nameservers for a domain. ns1 and ns2 are required; ns3-ns5 are optional.
Release/delete a domain from your account.
Register a new domain name. Provide registrant contact details via 'owner' (single contact) or 'contacts' (only the registrant field is sent to the upstream API). The domain must have a paid invoice in the system before registration can proceed.
Renew an existing domain registration. The domain must have a paid invoice in the system before renewal can proceed.
Transfer a domain to your account. Provide registrant contact via 'owner' or 'contacts'. The domain must have a paid invoice in the system before transfer can proceed. Special rules for .gr domains: (1) transfers are free of charge; (2) transfers are instant and cannot be recalled; (3) the Greek registry does not allow any nameserver or contact changes during transfer — nameservers are not required and are ignored; (4) upon successful transfer the domain is automatically synced and set to Active.
Get pricing for a specific domain for registration, transfer, or renewal.
Get the upstream DomainsReseller API version. Useful for health checks.
List all available TLDs (top-level domains) supported by the reseller.
Get pricing for all available TLDs.
Session token required on every call but no guidance on lifetime or caching. The auth_login description says 'opaque session token for all subsequent tool calls' but never clarifies expiration, refresh mechanisms, or retry behavior if token becomes invalid. This forces agents to guess on error handling.
No pagination documented. tlds_list, tlds_pricing_get, and potentially domains_lookup_suggestions may return large result sets. Without limit/offset/cursor parameters and result count in responses, LLMs cannot efficiently handle domain/TLD discovery at scale.
Destructive operations (domains_release, domains_nameservers_delete) lack confirmation step. These tools can permanently delete nameservers or release domains. No indication that agents should confirm with the user first, increasing risk of irreversible mistakes.
Order tools (register, transfer, renew) require external invoice creation. Descriptions mention 'The domain must have a paid invoice in the system before registration can proceed' but do not explain how the agent creates that invoice or what the error looks like if one is missing. This blocks the agent mid-workflow with no recovery guidance.
order_domains_transfer has special .gr rules documented only in description text, not encoded as schema constraints or enum values. LLMs will miss nuances like 'nameservers not required for .gr' and may pass invalid params, causing failures.
Tool composition gap: domains_lookup returns availability but no pricing; order_pricing_domains_get returns pricing but requires a fully qualified domain name. An agent needs to lookup 'example' across 10 TLDs, then call pricing 10 times separately. No batch variant or combined tool exists. This wastes tokens and latency.