RedirectBoss
क्लॉड और अन्य AI सहायकों से होस्ट, रीडायरेक्ट, SSL और ट्रैफिक एनालिटिक्स प्रबंधित करें।
दस्तावेज़
Overview
The RedirectBoss MCP server lets AI assistants such as Claude manage your redirects on your behalf. It implements the Model Context Protocol (MCP), an open standard for connecting AI models to external tools. When you authorize the server, the AI assistant can list and modify hosts and redirects in your account, and pull analytics on traffic and per-redirect performance, by calling our public API under the hood.
Server URL: https://mcp.redirectboss.com/mcp
Authentication: OAuth 2.1 (authorization code + PKCE, Client ID Metadata Documents)
Transport: Streamable HTTP
Requirements
- A RedirectBoss account on a plan that includes API access. See pricing for plan details.
- An MCP client that supports Client ID Metadata Documents (the current MCP spec), such as Claude, VS Code, and ChatGPT. Clients that do not yet implement Client ID Metadata Documents cannot connect.
Available Tools
The server exposes the tools listed below. Read-only tools are safe to run without confirmation; write tools modify your account; destructive tools are irreversible and most MCP clients will prompt for confirmation before running them.
Host management
- list_hosts: list all hosts with SSL/DNS status (read-only)
- get_host: get detailed info for a single host (read-only)
- create_host: add a new source domain (write)
- update_host: update host settings, e.g. www handling (write)
- delete_host: remove a host and deactivate its redirects (destructive)
- check_dns: run a live DNS resolution check (read-only)
- check_ssl: check SSL provisioning status (read-only)
- enable_ssl: trigger SSL certificate provisioning via Let's Encrypt (write)
Redirect management
- list_redirects: list redirect rules with filtering (read-only)
- get_redirect: get a single redirect rule (read-only)
- create_redirect: create a new redirect rule (write)
- update_redirect: update fields on an existing redirect (write)
- delete_redirect: permanently delete a redirect rule (destructive)
Analytics
- get_hosts_analytics: per-host rollup of redirect counts, hits, and average response time (read-only)
- get_traffic_trends: account-wide hits over time with daily or monthly granularity (read-only)
- get_host_traffic_trends: hits over time scoped to a single host (read-only)
- get_redirect_analytics: total hits, average response time, and daily breakdown for one redirect (read-only)
- get_redirect_traffic_trends: hits over time for one redirect with configurable granularity (read-only)
Permission Scopes
When you authorize an MCP client, you'll see a consent screen listing the scopes the client is requesting. Each tool requires one of the following scopes:
- read:hosts: required for
list_hosts,get_host,check_dns,check_ssl - write:hosts: required for
create_host,update_host,delete_host,enable_ssl - read:redirects: required for
list_redirects,get_redirect - write:redirects: required for
create_redirect,update_redirect,delete_redirect - read:analytics: required for
get_hosts_analytics,get_traffic_trends,get_host_traffic_trends,get_redirect_analytics,get_redirect_traffic_trends
Tokens issued to an MCP client are scoped to your own account. Whether a tool call succeeds still depends on your plan. See pricing for plans that include API access.
Quickstart
Claude.ai and Claude Desktop
Add RedirectBoss as a custom connector from your Claude settings:
- Open Claude settings and navigate to the Connectors section.
- Add a new custom connector.
- Set the server URL to
https://mcp.redirectboss.com/mcp. - When prompted, sign in to your RedirectBoss account and approve the requested scopes on the consent screen.
Once connected, the tools listed above become available to Claude. You can issue natural-language requests like "list all my hosts", "create a 301 redirect from /old to https://new.com/new on example.com", "check whether DNS and SSL are working for shop.example.com", or "show me my traffic trends for this month" and Claude will call the appropriate tools.
Claude Code
Add the server to a project's MCP configuration:
{
"mcpServers": {
"redirectboss": {
"url": "https://mcp.redirectboss.com/mcp"
}
}
}
Save this as .mcp.json in your project, or add the server via claude mcp add. On first use, Claude Code will open your browser to complete the OAuth authorization flow.
Other MCP clients
The patterns above (a server URL for hosted clients, or a JSON config entry pointing at https://mcp.redirectboss.com/mcp for CLI-style clients) work with any client that speaks the Streamable HTTP transport and identifies itself with a Client ID Metadata Document. Refer to your client's MCP documentation for the exact setup steps.
How Authorization Works
Authorization follows the OAuth 2.1 authorization code flow with PKCE, using Client ID Metadata Documents for client identity:
- The MCP client discovers our authorization server via OAuth protected resource metadata published by the MCP server.
- The client identifies itself with its own Client ID Metadata Document, an HTTPS URL it controls. That URL serves JSON declaring its name, its website, and the redirect destinations it is allowed to use, and it is the client identifier; there is nothing for the client to register with us.
- You sign in to RedirectBoss and see a consent screen showing the client's name and the URL of its metadata document, the redirect destination you will be sent back to, and the scopes it is requesting. You can approve or deny.
- On approval, the client exchanges the authorization code for an access token scoped to your account, proving with PKCE that it holds the secret the flow began with.
- The access token is included on every subsequent MCP request and validated server-side. Access tokens are short-lived; clients hold a refresh token to obtain new ones without sending you back through sign-in.
Check the metadata document URL on the consent screen before approving: it is the part of a client's identity it cannot fake, because it must serve the document from that address. The name beside it is whatever the client says it is. Access tokens are scoped to your account only, and no passwords or long-term secrets are ever sent to the MCP client.
Building an MCP client? Our own monitoring client's document is a worked example: /.well-known/oauth/mcp-smoke-client.json.
Rate Limits
MCP calls share the same rate limits as direct API access:
- 5,000 requests per hour (across reads and writes)
- 1,000 write operations per day
Exceeding these limits returns an HTTP 429 response, which the MCP client will surface as an error and retry after the Retry-After interval.
Reviewing and Revoking Access
You can see every MCP client authorized on your account and revoke access at any time from your dashboard under Preferences → Connected Apps. Revoking a client ends your authorization for it: its refresh token stops working straight away, and any access token already issued can take up to 10 minutes to stop being accepted. Revocation applies to your own account. It does not affect other users who have authorized the same client, and it covers every place you use that client, because they all use the same grant for your account. See the Privacy Policy section on third-party access for the full policy.
Troubleshooting
"API access not allowed"
Your current plan does not include API access. See our pricing page for plans that support it, then contact support@redirectboss.com to change your plan.
Consent screen shows wrong scopes
The scopes shown on the consent screen are the ones the MCP client requested. You can approve a subset if your client supports it, or decline the request and raise the issue with the client vendor.
Tool call returns 403 "insufficient scope"
The authorized client does not hold the scope required for that tool, usually because a narrower set was approved on the consent screen. Reconnect the client and approve the scopes the tools you want need.
Support
Questions or issues integrating the MCP server? Email support@redirectboss.com. For the underlying REST API, see the API reference.