Skip to content

hetzner-dns-mcpYour DNS, through the assistant

An MCP server for the Hetzner Cloud DNS API — 22 tools for zones, record sets, zone files, TTLs and protection, and a person asked before anything that decides who answers for a name.

The confirmation flow, in 15 seconds ​

Listing the tools, a refused set_records call, and the same call succeeding with the confirmation token it returned — the fallback path, as a client that cannot show a dialog sees it

How it fits together ​

Architecture of hetzner-dns-mcpAn MCP client speaks JSON-RPC over stdio to hetzner-dns-mcp, which validates arguments, puts destructive calls to a person first, and calls the Hetzner Cloud API over HTTPS. Responses pass back through a sanitizer.MCP clientClaude Code, Desktop,Codex, Inspectorhetzner-dns-mcpzod schemas · path guardsasks a personredact · truncate · markHetzner Cloudapi.hetzner.cloud/v1/zonesstdioresultsHTTPSJSON
Arguments are validated before they reach a URL; results are sanitized before they reach the model.

In one command ​

bash
claude mcp add hetzner-dns -s user \
  -e HETZNER_API_TOKEN=your-token \
  -- npx -y hetzner-dns-mcp

Then ask for what you want — "what does the www record for example.com point at?", "add an AAAA record for the new host", "export the zone file before we touch anything". See Getting started for the token, and Connecting clients for Claude Desktop, Codex, the Inspector and Docker.

Running it elsewhere ​

A client that cannot spawn a local process — ChatGPT connectors, Claude on the web, Cursor, LibreChat — cannot start hetzner-dns-mcp the way Claude Code does. mcp-hub is the bridge: one container serves many stdio MCP servers over Streamable HTTP, with an OAuth 2.1 login behind a single password and long-lived tokens for the clients that cannot do OAuth. Its /hub endpoint puts every server behind six meta-tools, so one connector reaches all of them without N×tool schemas in the model's context, and it speaks both protocol revisions — a question this server asks travels through it to the person at the far end instead of ending at the gateway.

Its configuration is Claude Code's mcpServers format, so the entry you already have is the entry it takes: Through mcp-hub.

Released under the MIT License.