SkillAgentSearch skills...

gandi-mcp

MCP server for Gandi LiveDNS — manage DNS records, domains, and zone snapshots from Claude Code or any MCP client.

Install / Use

claude mcp add themkn -- npx -y github:themkn/gandi-mcp

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

78/100

Supported Platforms

Claude Code
Claude Desktop

Tags

Our assessment of gandi-mcp

gandi-mcp scores 78/100 on our quality scale, 3662nd of 4,619 Development & Engineering skills we index.

Its MCP Server is 6.3 KB long, well organised into 13 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
29/30
Structure
20/20
Description
12/15
Adoption
3/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 6 days ago, so gandi-mcp is actively maintained.
  • Our last check on 2026-09-20 found the source still online.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

gandi-mcp compared with similar skills

All 4 of these similar skills score higher than gandi-mcp; compare them before choosing.

SkillScoreStarsUpdatedFormat
gandi-mcp (this skill)by themkn7836d agoMCP Server
Agent-Reachby Panniantong10090.5k19d agoCLAUDE.md
headroomby headroomlabs-ai10074.4ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md
ai-job-searchby MadsLorentzen10044.9k1d agoCLAUDE.md

Frequently asked questions

How do I install gandi-mcp?
Run claude mcp add themkn -- npx -y github:themkn/gandi-mcp. The install tabs above show the steps for each supported agent.
Which AI agents does gandi-mcp work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is gandi-mcp safe to use?
It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is gandi-mcp still maintained?
The repository was last updated 6 days ago, so gandi-mcp is actively maintained.

gandi-mcp — Gandi LiveDNS MCP Server

npm license

An MCP server for Gandi LiveDNS. Manage DNS records, list domains, and take zone snapshots — directly from Claude Code or any MCP-compatible client.

What this gives you

  • 8 MCP tools: list_domains, list_records, get_record, add_record, update_record, delete_record, list_snapshots, create_snapshot
  • Safety by default: every add/update/delete writes a timestamped local JSON backup of the full zone before mutating. Configurable.
  • One-JSON config: no env vars, one file with strict 0600 perms

Prerequisites

  • A Gandi account
  • Node.js 24+

Get a Gandi Personal Access Token

Gandi replaced legacy API keys with Personal Access Tokens (PATs). To create one for gandi-mcp:

  1. Sign in at admin.gandi.net.
  2. Top-right menu → User settings → Authentication options (or visit account.gandi.net/security).
  3. Under Personal Access Tokens, click Create a token.
  4. Give it a name (e.g. gandi-mcp) and pick an expiration (max 1 year — Gandi will email you when it nears expiry).
  5. Scope — which domains: pick Specific organizations or Specific domains and select the ones you want this MCP to manage. Don't grant access to the whole account if you don't need it.
  6. Permissions: enable "Manage domain technical configurations" (covers LiveDNS read + write). If any of your domains are owned by a Gandi organization (not your personal account), also enable "View organization information" so list_domains can discover them — otherwise it will silently fall back to your personal-org domains only. Everything else (billing, transfers, etc.) can stay unchecked.
  7. Click Create. Copy the token immediately — Gandi only shows it once. If you miss it, delete and create a new one.

That token is your apiKey value in the config below.

Install

npm install -g @themkn/gandi-mcp

The binary is gandi-mcp regardless of the scoped package name.

Configure

The server reads a JSON config from ~/.gandi-mcp/config.json. Create it with 0600:

mkdir -p ~/.gandi-mcp
chmod 700 ~/.gandi-mcp
cat > ~/.gandi-mcp/config.json <<'EOF'
{
  "apiKey": "YOUR_GANDI_PAT",
  "defaultDomain": "example.com"
}
EOF
chmod 600 ~/.gandi-mcp/config.json

Full config reference

| Field | Required | Default | Description | |-------|----------|---------|-------------| | apiKey | yes | — | Your Gandi Personal Access Token | | defaultDomain | no | none | Used when a tool call omits domain | | autoBackup | no | true | Write local zone backup before each mutation | | backupDir | no | ~/.gandi-mcp/backups | Where backup files land |

The server refuses to start if the config file is group- or world-readable.

Hook into Claude Code

Add this to your .mcp.json (project-scoped) or ~/.config/claude/mcp.json (global):

{
  "mcpServers": {
    "gandi": {
      "command": "gandi-mcp"
    }
  }
}

Recommended permissions

By default Claude Code asks for permission on every Gandi tool call. A blanket mcp__gandi__* allow works, but it also auto-approves irreversible live DNS changes like delete_record and update_record. A tiered policy keeps the inspection flow frictionless while making destructive zone edits explicit.

Add this to your ~/.claude/settings.json:

{
  "permissions": {
    "allow": [
      "mcp__gandi__list_domains",
      "mcp__gandi__list_records",
      "mcp__gandi__get_record",
      "mcp__gandi__list_snapshots",
      "mcp__gandi__create_snapshot",
      "mcp__gandi__add_record"
    ]
  }
}

What this does:

  • Reads (list_domains, list_records, get_record, list_snapshots) run without prompting — they can't change anything.
  • Additive writes (create_snapshot, add_record) also run without prompting. Snapshots are purely additive, and the server takes an automatic local zone backup before every record mutation, so a stray add_record is easy to recover from.
  • Destructive writes (update_record, delete_record) are not listed, so Claude Code will prompt before each call. The auto-backup helps recover the previous record values, but DNS caches still propagate — a bad change can break a live site for as long as the old TTL lasts. These should be deliberate.

If you want a stricter setup, keep a wildcard allow and add a deny block for the destructive tools — deny blocks the call entirely (no prompt, no override):

{
  "permissions": {
    "allow": ["mcp__gandi__*"],
    "deny": [
      "mcp__gandi__update_record",
      "mcp__gandi__delete_record"
    ]
  }
}

Tool reference

| Tool | What it does | |------|--------------| | list_domains | List LiveDNS-managed domains. Auto-discovers organizations the user belongs to and unions their domains with the personal-org list, deduped by FQDN. Pass sharing_id to scope to a single organization. | | list_records | List records for a domain, with optional type and nameFilter (anchored, case-insensitive glob — * = any, ? = one) | | get_record | Fetch a single record by name + type | | add_record | Add a new record; auto-backup runs first | | update_record | Replace values/TTL on an existing record; auto-backup runs first | | delete_record | Delete a record; auto-backup runs first | | list_snapshots | List Gandi server-side zone snapshots | | create_snapshot | Create a server-side zone snapshot on Gandi |

Mutation tools return the local backup path in their response — reference it if you need to roll back manually.

Backups

Each mutation writes ~/.gandi-mcp/backups/<domain>-<timestamp>.json:

{
  "domain": "example.com",
  "date": "2026-04-24T11:47:03.123Z",
  "records": [ /* full zone */ ]
}

Format matches the gandi CLI's backup shape. Disable via "autoBackup": false in config.

Development

git clone git@github.com:themkn/gandi-mcp.git
cd gandi-mcp
pnpm install
pnpm test
pnpm build

License

MIT

Related Skills

View on GitHub
GitHub Stars3
CategoryDevelopment
Updated6d ago
Forks0

Languages

TypeScript

Trust signals

92/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 low