MCP for classic Timeweb hosting domains
timeweb-mcp-server
A lightweight MCP for domains and DNS records on classic Timeweb hosting, requiring two-factor authentication to be disabled on the account
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Requires two-factor authentication to be disabled on the account, weakening login and password protection
- The account password is passed directly as an environment variable alongside the app key
Install
Manual install
npm install && npm run buildBuild before connecting to an MCP client.
This is third-party code. Review the repository files before installing.
What it does
A TypeScript server provides tools for the classic Timeweb hosting API (not Timeweb Cloud): listing domains, viewing a domain, reading DNS records, adding A, AAAA, CNAME, MX, TXT and SRV records, deleting a DNS record, and adding and deleting subdomains. For non-TXT types, the subdomain is auto-created in the Timeweb panel on first use; TXT records set the subdomain inline with no separate entity. Authorization uses a triple of TIMEWEB_USERNAME, TIMEWEB_PASSWORD and TIMEWEB_APPKEY, where the app key is issued by Timeweb support, and two-factor authentication on the account must be disabled for API access.
Who it is for. For owners of classic (non-cloud) Timeweb hosting who want to manage DNS records from an agent.
Good fit when
- You have classic Timeweb hosting, not Timeweb Cloud, and want agent access to its API
- You need to add, read and delete DNS records of the common types
- You are willing to disable two-factor authentication on the account for API access
Not a fit when
- You are not willing to disable two-factor authentication: the README states it as a requirement for API access
- You need name-server management: the README states plainly no public endpoint was found for it, so change it through the panel
- You need to update an existing DNS record: the API has no PUT, only delete and re-add
Example request
Add an A record for the api subdomain of my domain pointing to 203.0.113.10Limitations
The repository has no license. Explicit README limitations: no NS-record management (the endpoint returns 500 for type NS), no name-server read or update, no single-call DNS record update, no domain registration, renewal or mailbox management, no proxy support. The main access requirement: two-factor authentication on the Timeweb account must be disabled, which weakens the account's own security.
How to disable. Remove the timeweb entry from your MCP client config, change TIMEWEB_PASSWORD, and importantly, re-enable two-factor authentication on the account.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| TIMEWEB_USERNAME required | Classic Timeweb hosting account login |
| TIMEWEB_PASSWORD required, secret | Account password; requires two-factor authentication to be disabled |
| TIMEWEB_APPKEY required, secret | App key, issued by Timeweb support |
Security check
- Requires two-factor authentication to be disabled on the account, weakening login and password protection
- The account password is passed directly as an environment variable alongside the app key
README in short
The short README splits tools into reads, DNS writes and subdomains, describes the subdomain auto-creation behavior and the special case for TXT records, gives npm installation and an MCP client config with the TIMEWEB_USERNAME, TIMEWEB_PASSWORD, TIMEWEB_APPKEY triple, honestly lists five v1 limitations, and links to separate spec and plan files under docs/superpowers.
FAQ
Why does two-factor authentication need to be disabled?
The README states it explicitly as a requirement for classic Timeweb hosting API access; requests fail without disabling it.
Can an existing DNS record be updated in one call?
No, the API has no update method; you have to delete the old record and add a new one.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring