Skip to content

Hostilo is opening soon. You cannot order yet.Join the list

hostilo
← Help centre

Connect your own AI agent to Hostilo

How to give Claude, Cursor or any MCP agent access to your Hostilo services, and how to keep that access safe.

What this is

Hostilo speaks MCP, the Model Context Protocol. That is the standard AI assistants use to reach outside tools. Connect yours and you can ask it things like "is my hosting close to full?" or "add a TXT record for Google verification" without opening the dashboard.

You find it under AI agents in your dashboard.

Setting it up

  1. 1Go to AI agents and click Create key. Give it a name that says which agent it is for, like "Claude on my laptop". One key per agent, so you can cut one off without disturbing the others.
  2. 2Decide whether it may make changes. Leave the box unticked and the agent can only look at things. Tick it and the agent can edit DNS, add mailboxes, change quotas and switch auto-renew on or off.
  3. 3Copy the key. It is shown once, on that screen, and never again. We store only a hash of it, so nobody at Hostilo can read it back to you.
  4. 4Pick your agent from the tabs, copy the snippet, paste it into that agent's config and restart it.

The endpoint is https://app.hostilo.co.za/api/mcp and the key goes in an Authorization: Bearer header.

What an agent can do

Reading is always allowed:

  • List your domains, hosting, mailboxes and unpaid invoices
  • Read the DNS records on a domain
  • Read your billing history, with VAT shown separately
  • See which add-ons are available and which are already on
  • Ask our support assistant a question

These need a key with changes enabled:

  • Add or update a DNS record
  • Turn auto-renew on or off
  • Create a mailbox
  • Change a mailbox quota

What an agent cannot do

  • Touch another company's services, even one you also belong to. Each organisation needs its own key.
  • Do anything your own role cannot. If you are on a read-only role, every key you make is read-only.
  • Pay, cancel or refund anything. Invoices are readable, never payable.
  • Delete a domain or close an account. Those stay with a person.

Keeping it safe

Treat the key like a password. Anyone holding it can do what it allows, so do not paste it into a shared document or a chat.

If a laptop goes missing or you stop using an agent, open AI agents and click Revoke next to that key. It stops working straight away, and the other keys carry on.

Each key shows when it was last used, which is the quickest way to spot one you have forgotten about.

If the agent says it cannot connect

  • Check the key has not been revoked.
  • Check the header reads Authorization: Bearer hos_... with the whole key, including the hos_ at the front.
  • Restart the agent. Most only read their config at startup.
  • If the agent says a tool does not exist, the key is probably read-only and you are asking it to change something. Make a new key with changes enabled.
Still stuck?

Ask Hostiy in the corner. It can see your account, so it will give you the answer for your setup rather than the general one. Anything it cannot answer goes to a person.