MCP server for wafle — the LLM-first multi-tenant commerce platform. Wraps the wafle REST API and exposes ~50 tools to Claude Desktop, Claude Code, and any MCP-compatible client.
Four domain management tools with strong naming (verb_noun pattern), comprehensive descriptions (150-250 chars each), and well-structured input schemas using enums and type constraints. All parameters have descriptions. Output schemas are documented in descriptions but not formally declared in JSON Schema. Error handling guidance is present but could be more actionable. Tool composition is clean, each tool has a single responsibility. No security issues detected (no secrets in params). Descriptions are LLM-optimized and include WHEN to use each tool.
Attach a new custom domain (e.g. 'mi-tienda.com') to a wafle store. Wafle generates a verification_token and returns the 3 alternative DNS instructions the tenant must apply. After creating, the tenant updates DNS at their provider, then call `wafle_domains_verify` (or wait for the 5min cron) to drive verification + SSL + nginx provisioning. Validation rules: lowercase FQDN only, no IPs, no wildcards, no .wafle.click subdomains, max 10 active domains per tenant.
List the custom domains attached to a wafle store. Returns each domain's status (pending_verification / verifying / ssl_pending / active / ssl_failed / disabled), SSL expiry, verification token, and DNS-setup instructions for all 3 verification methods (TXT/CNAME/file). Use first when the user asks 'what domains does store X have?' or before giving DNS instructions to a new tenant.
Fetch the full status of a single attached domain — current status (pending/verifying/active/etc), SSL expiry, last renewal, log of recent events. Includes the original DNS-setup instructions so you can re-show them to the tenant. Use to answer 'is mi-tienda.com working yet?' or to debug a stuck verification.
Trigger immediate verification + SSL + nginx provisioning for a previously-added domain. Idempotent — safe to call repeatedly. The pipeline: 1. Probe TXT / CNAME / file methods (any one passes). 2. If passed → request a Let's Encrypt cert via acme.sh. 3. Render the per-domain nginx config and signal a reload. 4. Mark the domain `active` and append events to the log. Rate-limited to 1 attempt per minute per domain (DNS + acme upstream).
Output schemas not formally declared in JSON Schema format. Descriptions document return structure but tools lack outputSchema field in registration, forcing LLMs to infer structure from text.
Error responses lack actionable recovery guidance. Descriptions mention rate limits and validation rules but tools do not document specific error codes or recovery steps (e.g., 'If rate-limited, retry after 60 seconds').
wafle_domains_list lacks pagination limit enforcement. Description states 'limit 1-200' but no explicit validation or default is documented. Large result sets could exhaust context windows.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2025-06-18+ | v2 |
wafle_domains_add has conditional parameter dependency (custom_target_url required only if storefront_target='custom') documented in description but not enforced via schema constraints or validation.
Tool descriptions include validation rules (e.g., 'lowercase FQDN only, no IPs, no wildcards') but do not specify what error message the LLM will receive if constraints are violated, limiting self-correction.