list_domains
This token is project-scoped. Pass projectId to list_sites, or call list_projects to discover the bound project. List a project's custom domains and their binding state. Returns every workable domain the project owns (status: available | binding | bound | failed, plus which siteId it's bound to a...
This record as markdown: /tools/a3plus-mcp/list-domains.md
What list_domains does on A3plus
AI agents call list_domains to permanently remove resources in A3plus, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.
| Parameter | Type | Required | Description |
|---|---|---|---|
projectId | string | Yes | The A3Plus project ID (from list_projects). |
Parameters from the server's own tool schema.
Why list_domains is rated Critical
An AI agent that decides to call list_domains doesn't hesitate, doesn't double-check, and doesn't stop at one. Whatever it removes from A3plus is gone. There is no undo for destructive operations.
Risk signalsBulk/mass operation — affects multiple targets
Attacks that exploit this kind of access
The rule that runs list_domains safely
PolicyLayer is an MCP gateway: it sits between your AI agents and A3plus, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For list_domains, this is the rule to start with:
list_domains is removed from the agent's tool list entirely, so the agent never calls it. The rest of the server keeps working.
The button opens the PolicyLayer dashboard: create your workspace, connect A3plus, apply this rule, and every list_domains call is checked against it from then on.
Questions about list_domains
This token is project-scoped. Pass projectId to list_sites, or call list_projects to discover the bound project. List a project's custom domains and their binding state. Returns every workable domain the project owns (status: available | binding | bound | failed, plus which siteId it's bound to and any lastError), a separate blockedDomains list, and the project's sites with their currently bound domain — everything needed to plan a bind_domain / unbind_domain move. Domains in status available can be bound immediately; binding means NS propagation is still in progress (re-check in a few minutes); failed rows are auto-recycled when you bind them again. blockedDomains are BANNED (burned/deindexed) — NEVER offer or retry them for binding; they are permanently unusable. It is categorised as a Destructive tool in the A3plus MCP Server, which means it can permanently delete or destroy data. Block by default and require explicit approval.
list_domains accepts 1 parameter: projectId. Required: projectId. The full parameter table on this page comes from the server's own tool schema.
Register the A3plus MCP server in PolicyLayer and add a rule for list_domains: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches A3plus. Nothing to install.
list_domains is a Destructive tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.
Yes. Add a rate_limit block to the list_domains rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for list_domains. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
list_domains is provided by the A3plus MCP server (a3plus-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on A3plus, and thousands of servers like it.
Across the catalogue