Back to Browse

Thatmgmt MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for ThatMgmt: domain availability, quotes, registration prep. Crypto checkout.

About

MCP server for ThatMgmt: domain availability, quotes, registration prep. Crypto checkout.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

8 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

ThatMgmt API key, sent as a Bearer token. Only needed for tenant tools (portfolio, suggestions, dry-run, prepare-registration); the public reads work without it.Required

Environment variable: TMGMT_API_KEY

API base URL override.Optional

Environment variable: TMGMT_BASE_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-thingscorp-thatmgmt-mcp": {
      "env": {
        "TMGMT_API_KEY": "your-tmgmt-api-key-here",
        "TMGMT_BASE_URL": "your-tmgmt-base-url-here"
      },
      "args": [
        "-y",
        "@thatmgmt/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

thatmgmt-mcp

An MCP (Model Context Protocol) server that wraps the ThatMgmt domain API. An AI agent in Cursor, Claude Code, or Replit can check availability, get name suggestions, lock a price quote, and prepare a registration, all without touching a dashboard.

Base API: https://api.thatmgmt.com Spec: https://thatmgmt.com/openapi.json (47 routes) Machine docs: https://thatmgmt.com/llms-full.txt

Try it with zero signup (no API key)

The public reads need no key and no account. Run the published package with zero install: npx -y @thatmgmt/mcp. Or clone and run:

git clone https://github.com/thingscorp/thatmgmt-mcp.git thatmgmt-mcp
cd thatmgmt-mcp
npm install
node src/index.js

Then in your MCP client, call tmgmt_capabilities to see the public surface, domains_check_availability to check a name, and domains_get_quote for the locked price: wholesale plus the itemized 0.15% platform cut, printed plainly. Example quote for a 1-year .com: $12.99 wholesale + $0.02 cut = $13.01 total.

Setup with an API key (tenant tools)

Prereqs: Node 18+.

git clone https://github.com/thingscorp/thatmgmt-mcp.git thatmgmt-mcp
cd thatmgmt-mcp
npm install
export TMGMT_API_KEY="your-thatmgmt-api-key"

The key is only needed for tenant tools: name suggestions, portfolio views, the dry-run planner, and prepare-registration. Everything else works without it.

Add to your MCP client config (Claude Code / Cursor):

{
  "mcpServers": {
    "thatmgmt": {
      "command": "node",
      "args": ["/path/to/thatmgmt-mcp/src/index.js"],
      "env": { "TMGMT_API_KEY": "your-thatmgmt-api-key" }
    }
  }
}

Verify:

npm test

Optional: TMGMT_BASE_URL overrides the API base (default https://api.thatmgmt.com). TMGMT_TIMEOUT_MS overrides the per-request timeout in milliseconds (default 30000). Transient failures (network errors, timeouts, 429s, retryable 5xx) are retried once on side-effect-free calls; the server never retries anything that could move money.

The two-step purchase flow

Spend-effect actions never execute blindly. The intended flow, written into every tool description so agents show the human the price first:

  1. Quote. Call domains_get_quote. It returns the locked price: wholesaleCents, the itemized 1% cut (platformCutCents, platformCutBasisPoints), and totalCents. No key needed. Show this to the human.
  2. Plan. Call domains_prepare_registration (needs TMGMT_API_KEY). It returns the safety-checked plan. It never executes anything.

Pricing: no subscription. A flat 1% cut applies to spend-effect actions only. Checkout options (crypto via Privy, or card/bank fallback) are arranged outside this server.

Important: what this server cannot do

The ThatMgmt API exposes no execute endpoints. Purchase, renewal, transfer, and DNS changes are never executed by the API; the API returns validated plans and preflights instead. This server therefore cannot register, renew, or transfer a domain, and it will never claim it did.

src/approval.js holds the approval gate that future execute tools will use: quote id passed back plus an explicit approved: true flag, or the call is refused. The gate is implemented and tested now so the safety design is ready the day execute routes exist.

Current release: 0.2.1 (read-only public tools plus validated plans). Execute tools are planned for the 0.3.0 release.

Tools

ToolWhat it doesAPI routeKey needed
tmgmt_healthLiveness checkGET /health/liveNo
tmgmt_capabilitiesDiscover the public no-auth surfaceGET /v1/public/capabilitiesNo
domains_check_availabilityCheck if a domain is availableGET /v1/public/availabilityNo
domains_get_quoteLocked price quote: wholesale + itemized 1% cut + total (step 1)GET /v1/public/quoteNo
domains_suggestSuggest alternative namesGET /v1/domains/suggestionsYes
domains_prepare_registrationSafety-checked plan, never executes (step 2)GET /v1/domains/prepare-registrationYes
domains_listList portfolio domainsGET /v1/domainsYes
domains_dnsInspect DNS records for a domainGET /v1/domains/{resourceId}/dnsYes
portfolio_healthPortfolio health summaryGET /v1/portfolio/healthYes
portfolio_renewal_riskRenewal-risk viewGET /v1/portfolio/renewal-riskYes
portfolio_exceptionsPrioritized exception queueGET /v1/portfolio/exceptionsYes
orders_dry_runFull order plan with itemized pricing, never moves moneyPOST /v1/orders/dry-runYes
offeringsOffering coverage matrixGET /v1/offeringsYes

Public tools never send an Authorization header and never ask for a key. Tenant tools return 401 without a key; the server tells you to set TMGMT_API_KEY. The key is sent as a Bearer token and is never logged.

Agent skill

skills/thatmgmt/SKILL.md is the agent skill for this server: when to use it, the tool list, and the two-step purchase flow. Point your agent at it for the fastest start.

Development

npm test   # 47 tests, mocked HTTP, no live calls

Registry

server.json is the manifest for the official MCP registry (io.github.Thingscorp/thatmgmt-mcp). Releases are automated: pushing a version tag (e.g. v0.2.1) triggers the Publish to npm workflow (npm publish via the NPM_TOKEN secret) and the Publish to MCP Registry** workflow (validates server.json, publishes via GitHub OIDC).

Release flow: bump version in package.json (keep the mcpName field — io.github.Thingscorp/thatmgmt-mcp), push to main, then create the tag/release. The tag must match package.json; the registry validates the published npm metadata, so ship a new version for new fields.

Reviews

No reviews yet

Be the first to review this server!