Namecheap Api Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Namecheap Api Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for the [Namecheap API](https://www.namecheap.com/support/api/intro/) — manage domains, DNS, contacts, registrar locks, and view SSL certificates and pricing, straight from your AI assistant.
Built for Claude Code and any MCP-compatible AI tool.
Part of [The SEO Engine](https://lanternrow.com) toolkit by Lantern Row — AI-powered SEO and social media tooling for agencies and businesses.
This server ships read + safe-write tools only. It can read your account and change DNS / nameserver / forwarding / lock configuration (all reversible), but it deliberately excludes anything that spends money or is irreversible: no domain registration, renewal, reactivation, transfers, SSL purchase/activation, add-funds, or account/address mutation. You can fork and add those if you need them.
1011150).{
"mcpServers": {
"namecheap": {
"command": "npx",
"args": ["-y", "namecheap-api-mcp"],
"env": {
"NAMECHEAP_API_USER": "your_username",
"NAMECHEAP_API_KEY": "your_api_key",
"NAMECHEAP_CLIENT_IP": "your.whitelisted.ip.v4"
}
}
}
}git clone https://github.com/lanternrow/namecheap-api-mcp.git
cd namecheap-api-mcp
npm install
npm run buildThen point your client at node /path/to/namecheap-api-mcp/dist/index.js. For local credentials you can keep a gitignored .env (copy .env.example) and launch with Node's native flag: node --env-file=.env dist/index.js.
| Variable | Required | Description |
|---|---|---|
NAMECHEAP_API_USER | Yes | Your Namecheap account username (API user). |
NAMECHEAP_API_KEY | Yes | API key from Profile → Tools → API Access. Secret. |
NAMECHEAP_CLIENT_IP | Yes | The whitelisted public IPv4 of this machine. |
NAMECHEAP_USERNAME | No | Defaults to NAMECHEAP_API_USER; differs only for reseller sub-users. |
NAMECHEAP_ENVIRONMENT | No | production (default) or sandbox. |
| Tool | Description |
|---|---|
check_connection | Verify credentials + IP whitelist; returns the account balance summary. |
list_domains | List domains with expiry, lock, auto-renew, and WhoisGuard status (paged/searchable). |
get_domain_info | Detailed info for one domain. |
check_domains | Check availability + premium pricing (up to 50 at once). |
get_domain_contacts | Registrant / Tech / Admin / AuxBilling contacts. |
get_registrar_lock | Registrar lock status. |
get_dns_hosts | All DNS host records for a domain. |
get_nameservers | Nameservers and whether Namecheap DNS is in use. |
get_email_forwarding | Email forwarding rules. |
get_pricing | Namecheap pricing for a product type (cache the results). |
list_ssl_certificates | SSL certificates with type, host, status, expiry. |
| Tool | Description |
|---|---|
set_dns_hosts | Replace all host records (destructive: omitted records are deleted — send the full set). |
set_default_dns | Switch a domain to Namecheap's default nameservers. |
set_custom_nameservers | Point a domain at custom nameservers. |
set_email_forwarding | Set email forwarding rules. |
set_registrar_lock | Lock / unlock a domain at the registrar. |
setHosts deletes every record not included in the call. Always read current records first (get_dns_hosts), merge your change, then send the complete set.Status="ERROR"), not the HTTP status. This server parses that and throws a real error with the Namecheap error number + message.MIT © Lantern Row
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.