dynadot_get_transfer_auth_code
Retrieve the authorization (EPP) code for transferring a domain away.
This record as markdown: /tools/eyalm321-dynadot-mcp/dynadot-get-transfer-auth-code.md
What dynadot_get_transfer_auth_code does on Dynadot
AI agents call dynadot_get_transfer_auth_code to retrieve information from Dynadot without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.
Why dynadot_get_transfer_auth_code is rated Low
While this tool only retrieves data without modifying it, making it categorically a Read operation, the severity is elevated to 'medium' rather than 'low' because the EPP code is sensitive authentication material. Unauthorized retrieval of EPP codes could enable domain theft or unauthorized transfers if an AI agent misuses this tool with insufficient authorization checks.
From the tool's definition Tool description states 'Retrieve the authorization (EPP) code for transferring a domain away.' The verb 'Retrieve' and the read-only nature of obtaining an EPP code (no data is modified or deleted) clearly indicate this is a Read operation.
Attacks that exploit this kind of access
The rule that runs dynadot_get_transfer_auth_code safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Dynadot, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For dynadot_get_transfer_auth_code, this is the rule to start with:
dynadot_get_transfer_auth_code is read-only, so it stays allowed. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Dynadot, apply this rule, and every dynadot_get_transfer_auth_code call is checked against it from then on.
Questions about dynadot_get_transfer_auth_code
Retrieve the authorization (EPP) code for transferring a domain away. It is categorised as a Read tool in the Dynadot MCP Server, which means it retrieves data without modifying state.
Register the Dynadot MCP server in PolicyLayer and add a rule for dynadot_get_transfer_auth_code: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Dynadot. Nothing to install.
dynadot_get_transfer_auth_code is a Read tool with low risk. Read-only tools are generally safe to allow by default.
Yes. Add a rate_limit block to the dynadot_get_transfer_auth_code rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for dynadot_get_transfer_auth_code. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
dynadot_get_transfer_auth_code is provided by the Dynadot MCP server (eyalm321/dynadot-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Dynadot, and thousands of servers like it.
This server
Across the catalogue