We keep the theme, your answer to this notice and the domain cart in your own browser. No advertising, no third-party tracking. Learn more

Skip to content

Let your AI
run your sites and servers.

Connect Claude —or whichever MCP client you use— to your account and ask for what you would do yourself: see which sites you have, create one with its database, adjust PHP or line up a domain renewal. With rails: anything that costs money you confirm in your own panel, and to delete something it has to show you first what will be lost.

Read-only by default · No extra cost · Nothing to install

tools
24
charges without your confirmation
0
steps to delete
2

You create the key, and you revoke it

Not a mockup: this is the panel, on a sample account. This is where the key that connects the assistant comes from, with its permission written next to it.

my.hostbrid.com
The panel’s “AI keys” screen: a key called “Claude en mi portátil”, marked active, showing only its prefix, with the permission label “sitios:leer”, its creation date, a note saying it has not been used yet and a “Revoke” button; below, a “How to connect” block with the MCP server address and the authorization header.
“Let an AI assistant check your Hostbrid account without giving it your password”. Only the key’s prefix is shown, what it is allowed to do is written on it —here, “sitios:leer”— and “Revoke” kills it. Below, the MCP server address and the header you paste into the assistant.
What you can ask for

In your words, not ours

There are no commands to learn. Your AI picks the tool and works with the data in your account, not with what it imagines.

  • Which sites do I have hosted, and which ones have no SSL?

  • Create shop.example.com with PHP 8.3 and its database.

  • Raise the PHP memory on the shop, it keeps running out.

  • Add the DNS record my mail provider is asking for.

  • What would it cost to renew example.com? Line it up for me.

  • Delete the test site — but first tell me what I am about to lose.

The levels

Not everything undoes the same way

The border between one level and the next is not how scary it feels: it is whether there is a way back. One site too many can be deleted. A domain you bought cannot be returned. Neither can a deleted mailbox.

  1. 01

    Look

    Your sites, your domains, the names and users of your databases, how much plan you have left and how your machines are doing.

    It is the only thing the self-service screen offers: a key you create yourself can only look.

    • sitios:leer
    • maquinas:leer
  2. 02

    Do

    Create a site, a database, a mailbox or a DNS record, and change the PHP version and settings.

    It just happens, because all of this has a way back and costs nothing. Every change is recorded with its key and its timestamp.

    • sitios:escribir
  3. 03

    Line the order up

    Buy or renew a domain, change plan and order a VPS: it tells you whether it can be done and what it costs.

    None of the four charges anything. They return the order with its amount and the link in your panel where you confirm it, with your session and your card.

    • facturacion:pedir
  4. 04

    Delete, in two steps

    A site, a database, a mailbox, or cancelling the whole plan. Never in a single call.

    First it tells you specifically what will be lost —name, how many files and when the last backup was— and mints a token that lasts five minutes, works once and is tied to that exact object. Without that token, the second call deletes nothing.

    • sitios:borrar

Every key is born in the first level. The other three are asked for.

How it is built

An agent that gets it wrong does not refund you

That is why this is not “an API with permissions”. Everything the AI can do sits in a level, and every level has its rail: what is reversible just happens; what costs money you confirm; what destroys goes in two steps.

A new key only looks

The panel screen offers read permissions and nothing else. Writing or deleting has to be asked for, and we grant it by hand, account by account.

  • sólo lectura

Creating and deleting are separate permissions

You can let your agent create things without letting it destroy them. One site too many can be deleted; the site that was not the one cannot be brought back.

  • sitios:escribir
  • sitios:borrar

Nothing goes through the till

Anything that costs money is left prepared, with its amount and a link to your panel. You confirm the payment, with your session and your card.

  • facturacion:pedir

The AI cannot make up the confirmation

The delete token is only minted by showing you first what will be lost. It lasts five minutes, works once, and only for that object.

  • 5 min
  • un solo uso

Every change leaves a line

Which tool, with which key, when, and on what. The record cannot be forgotten because it is not written by hand: it wraps the tool.

  • auditoría

A retry does not duplicate your site

If your MCP client times out and repeats the call, you do not end up with two. A unique database index holds that, not an “if it already exists”.

  • idempotencia
How to connect

Three steps and one header

Nothing to install on your machine, no port to open, no process to keep running. It is an address and a key.

  1. 1Create it in your panelUnder “AI keys”, you pick what it can see and give it a name. The key is shown once only, so copy it right then; if you lose it, revoke it and create another.
  2. 2Paste it into your clientThe server address and the key in the «Authorization» header. It works in Claude desktop, in Claude Code and in any agent that speaks MCP over HTTP.
  3. 3Ask for what you needYour AI only sees the tools your key opens. The ones you did not grant never even show up in its list.
my.hostbrid.com/mcp
{
  "mcpServers": {
    "hostbrid": {
      "type": "http",
      "url": "https://my.hostbrid.com/mcp",
      "headers": {
        "Authorization": "Bearer nxp_your_key"
      }
    }
  }
}

The key starts with nxp_ and travels in the header, never in the address: whatever goes in the URL ends up in the server logs.

The catalogue

All 24, one by one

This is all of it. There is none hiding behind a permission: the list is this, and it ends here.

Look

sitios:leermaquinas:leer
  • hostbrid_listar_sitios

    The sites in the account: domain, IP address, whether they have SSL and whether they are active.

  • hostbrid_ver_sitio

    The detail of one specific site, from its identifier.

  • hostbrid_listar_dominios

    The domains in the account, and which ones have their DNS managed at Hostbrid.

  • hostbrid_listar_bases_de_datos

    The name and the user of each database. The password does not come out of here.

  • hostbrid_ver_plan

    Plan usage and limits: sites, databases, domains, mailboxes and disk.

  • hostbrid_estado_maquinas

    The virtual machines: up or down, resources and IP address.

Do

sitios:escribir
  • hostbrid_crear_sitio

    Provisions a website with its domain, its SSL and its DNS zone.

  • hostbrid_crear_base_de_datos

    Creates a database with its user, within the plan quota.

  • hostbrid_crear_buzon

    Creates a mailbox on one of your domains.

  • hostbrid_crear_registro_dns

    Adds a record to a DNS zone you manage here.

  • hostbrid_cambiar_version_php

    Changes a site’s PHP version.

  • hostbrid_cambiar_ajustes_php

    Adjusts a site’s PHP values, such as memory or upload size.

Line the order up

facturacion:pedir
  • hostbrid_pedir_compra_de_dominio

    Checks whether a domain is free, says the price and prepares the purchase.

  • hostbrid_pedir_renovacion_de_dominio

    Prepares the renewal of one of your domains, with its price and its years.

  • hostbrid_pedir_cambio_de_plan

    Prepares a change to another plan and states the price difference.

  • hostbrid_pedir_vps

    Prepares a VPS order at the size you ask for.

Delete, in two steps

sitios:borrar
  • hostbrid_ver_lo_que_pierdo_al_borrar_un_sitiohostbrid_borrar_sitio

    A website, with its files. First it tells you how many there are and when they were last backed up.

  • hostbrid_ver_lo_que_pierdo_al_borrar_una_base_de_datoshostbrid_borrar_base_de_datos

    A database, with everything inside it.

  • hostbrid_ver_lo_que_pierdo_al_borrar_un_buzonhostbrid_borrar_buzon

    A mailbox, with its mail.

  • hostbrid_ver_lo_que_pierdo_al_darme_de_bajahostbrid_dar_de_baja

    Cancelling the whole plan. The biggest of the four, on the same rail.

The deletions are eight tools and not four because each one is two calls: the one that shows you what will be lost, and the one that executes.

Each one is announced to the client with its risk level, which is what Claude and friends read to decide whether to ask you before running it. Lying there would be the worst thing we could do.

What it does not do

What your AI cannot do here

A list of limits is more useful than a list of promises. These are not settings that can be flipped from outside: they are tools that do not exist.

The write, order and delete permissions are not on the self-service screen: we grant them by hand, account by account. A checkbox saying “let the AI delete things” would get ticked by plenty of people without reading it, and opening that up is a decision that has not been taken yet.

  • It does not charge. Not one of the 24 goes through the till: what costs money is left prepared for you to confirm.
  • It does not delete in one go. Without the preview token, the call that deletes does not delete.
  • It serves no passwords. Not the database ones, not FTP, not mailboxes.
  • It does not power machines on or off. It only says how they are.
  • It touches nothing in other accounts, not even if whoever is asking works at Hostbrid.
  • It is not a back door: if an account is suspended, it does not answer here either.
Price

It comes with your plan

It is not a separate product nor an add-on that gets invoiced. If you have a Hostbrid account, you create the key yourself in a minute.

  • No extra cost, whichever plan you are on.
  • Queries consume no disk, site or database quota.
  • 60 requests per minute per key, so a looping agent cannot bother anybody.
  • You revoke the key from the panel and it stops working immediately.
Frequently asked questions

Questions about the MCP server

Can my AI break something?
What it can do is up to you. A freshly created key only looks. If you also grant it write access, it can create sites, databases, mailboxes and DNS records, all of which have a way back. Deleting needs a separate permission, and even with it the AI has to show you first what will be lost and use a token that expires in five minutes.
Can it spend my money?
No. None of the 24 tools charges anything. The ones that involve money check whether it can be done, say what it costs and return the link in your panel for you to confirm. An agent that gets it wrong does not refund you, so that step is not left to it.
I want it to write. How do I get that?
Write to us. The write, prepare-order and delete permissions we grant by hand on your key, which is also how there is a record of who was given them. The “AI keys” screen only offers the read ones, and that is deliberate while this is new.
Which AI does it work with?
Any client that speaks MCP over HTTP and lets you set an authorization header: Claude desktop, Claude Code and the agents you build yourself. We publish the server; the client is your choice.
Does it work with ChatGPT?
That depends on your client, not on us. If it lets you add a remote MCP server with an «Authorization» header, yes. Connectors that only accept OAuth do not yet: today the server authenticates with a long-lived key.
Does it see my passwords?
No. A database gives you its name and its user, never the password. FTP, mailbox and shell passwords do not come out at all.
Where do I see what my agent has lined up?
When it prepares an order it returns its number and a direct link to the screen where it is confirmed. There is no “pending orders” inbox in the panel yet: that is the missing piece and it is on the list.
What if my key leaks?
Go into “AI keys” and revoke it: it stops working immediately. In the meantime a key can only do what you granted it, so a read key cannot touch anything.
How much does it cost?
Nothing on top. It is included in the plan you already have.

Create your key and connect it

You do it from your panel, under “AI keys”, and it takes a minute. If you also want it to write, tell us.

Manage your sites, servers and email.

Forgot your password?

Free, and it takes a minute.

At least 8 characters. Not all digits, not a common one.

We'll email you to confirm the account.