
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
Free developer subdomains, DNS, disposable email, webhook capture, and MCP tools for Claude and Cursor
CLI and MCP server for PNTR — free *.pntr.dev subdomains
for developers, with DNS records, a disposable email inbox, and native
MCP integration.
Use one memorable hostname to point at a deployment, receive signup and OTP emails, or capture Stripe and GitHub webhook requests. Manage the same workflow from a terminal, Claude Code, Claude Desktop, Cursor, or another MCP client.
npx @pntr/cli setup-mcp
This signs you in (device flow) and configures PNTR as an MCP server for the AI clients detected on your machine (Claude Desktop, Claude Code, Cursor). After that, you can ask your assistant to register subdomains, add DNS records, check an inbox, or inspect a captured webhook.
pntr login Authenticate with PNTR using the device flow
pntr logout Clear stored credentials
pntr status Show authentication status
pntr serve Start the stdio MCP server (used by AI clients)
pntr setup-mcp Configure MCP for detected AI clients
npx @pntr/cli setup-mcp
PNTR also runs a remote MCP server with GitHub OAuth. Point any streamable-HTTP client at:
https://api.pntr.dev/mcp
For Claude Code:
claude mcp add --transport http pntr https://api.pntr.dev/mcp
For Claude Desktop / Cursor (mcpServers config):
{
"mcpServers": {
"pntr": { "url": "https://api.pntr.dev/mcp" }
}
}
Your client opens a browser window to sign in with GitHub on first
connection. An SSE endpoint (https://api.pntr.dev/mcp/sse) exists for
older clients.
npx @pntr/cli login
npx @pntr/cli serve # speaks MCP over stdio, proxies the PNTR API
Or as an mcpServers config block:
{
"mcpServers": {
"pntr": {
"command": "npx",
"args": ["-y", "@pntr/cli", "serve"]
}
}
}
The server starts and lists tools without credentials; run npx @pntr/cli login (or set PNTR_TOKEN) before calling tools that touch your account.
list_domains - List available parent domainscheck_subdomain - Check whether a name is availablelist_subdomains - List your subdomains with DNS recordsregister_subdomain - Register a subdomain, optionally with an initial DNS recordupdate_subdomain - Set or replace DNS records, update descriptiondelete_dns_record - Delete a single DNS recordtoggle_subdomain - Enable or disable a subdomaindelete_subdomain - Delete a subdomaintoggle_email - Enable or disable the disposable inboxlist_emails - List received emails (kept 48 hours, 90 days on premium)read_email - Read a received email's full contenttoggle_capture - Turn a subdomain into an HTTP request binlist_requests - List captured HTTP requestsread_request - Read a captured request's headers and bodytoggle_wildcard - Enable wildcard DNS (*.name.pntr.dev, premium)Ask your assistant things like "register storm.pntr.dev pointing at 203.0.113.10", "enable email on storm and watch for the verification code", or "read the latest email on storm.pntr.dev".
FAQs
Free developer subdomains, DNS, disposable email, webhook capture, and MCP tools for Claude and Cursor
The npm package @pntr/cli receives a total of 225 weekly downloads. As such, @pntr/cli popularity was classified as not popular.
We found that @pntr/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.