Overview
Register.gy is an accredited .gy domain registrar. The developer platform exposes the same tools customers use in the Client Area, so an assistant or an app can:
- Check availability of .gy, .com.gy, .co.gy, .net.gy and .org.gy names, with price and a registration link. No sign-in needed.
- List a customer's domains and read their DNS records.
- Connect a website: send the records a website builder shows (Lovable, Bolt, Replit, v0, Netlify, Shopify…), get a preview, then apply. Every change can be undone for 7 days.
- Check that a site is live: DNS visibility and https.
By design the platform never changes email (MX) records or nameservers, transfers domains or touches payments. Registry-level changes are applied by the Register.gy team.
| REST base URL | https://register.gy/wp-json/rgy/v1 |
|---|---|
| MCP server | https://register.gy/wp-json/rgy/v1/mcp |
| OpenAPI | https://register.gy/wp-json/rgy/v1/openapi.json |
| OAuth metadata | https://register.gy/.well-known/oauth-authorization-server |
| Summary for AI tools | https://register.gy/llms.txt |
Quickstart
1. Check a name (no key)
curl "https://register.gy/wp-json/rgy/v1/availability?domain=mybakery.gy" 2. Create an API key
Log in to the Client Area, open API & AI assistants and click Create API key. It is shown once.
3. List your domains
curl -H "Authorization: Bearer rgy_live_YOUR_KEY" https://register.gy/wp-json/rgy/v1/domains 4. Preview, then connect a website
curl -X POST https://register.gy/wp-json/rgy/v1/domains/mybakery.gy/connect/preview \
-H "Authorization: Bearer rgy_live_YOUR_KEY" -H "Content-Type: application/json" \
-d '{"records":[{"type":"A","name":"@","value":"185.158.133.1"},{"type":"TXT","name":"_lovable","value":"lovable_verify=…"}]}' If the preview looks right, send the same body to /connect/apply. Undo with /connect/undo within 7 days.
Connect an AI assistant
Register.gy runs a remote MCP server (the standard way assistants use outside tools). Assistants that support sign-in will open a Register.gy window: the customer enters their email, types the 6-digit code we send, and approves what the assistant may do.
Claude
Add a custom connector with this address, then sign in:
https://register.gy/wp-json/rgy/v1/mcpChatGPT
Where ChatGPT lets you add a custom connector or app (developer mode), use the same address and choose OAuth sign-in:
https://register.gy/wp-json/rgy/v1/mcpClaude Code
claude mcp add --transport http register-gy https://register.gy/wp-json/rgy/v1/mcpThen run /mcp in Claude Code to sign in. Or skip sign-in with a key: add --header "Authorization: Bearer rgy_live_YOUR_KEY".
Cursor and other MCP clients
{
"mcpServers": {
"register-gy": {
"url": "https://register.gy/wp-json/rgy/v1/mcp",
"headers": { "Authorization": "Bearer rgy_live_YOUR_KEY" }
}
}
}Clients that support OAuth can leave out headers and sign in instead.
Then ask, for example: "Is mybakery.gy available?" or "Connect my Lovable site to mybakery.gy." The assistant shows the planned changes and asks before applying them.
Public, search-only endpoint (no sign-in): https://register.gy/wp-json/rgy/v1/mcp/public
Authentication
OAuth 2.1 (recommended for assistants and apps used by other people)
- Authorization code flow with PKCE (S256 only). Public and confidential clients.
- Dynamic client registration (RFC 7591) at
https://register.gy/oauth/register. Redirect URIs must be https, or http on localhost. - Discovery:
/.well-known/oauth-authorization-server(RFC 8414) and/.well-known/oauth-protected-resource(RFC 9728). The MCP endpoint answers unauthenticated requests with401and aWWW-Authenticateheader pointing to the resource metadata. - Access tokens last 1 hour; refresh tokens 30 days and rotate on every use. Reusing an old refresh token ends the whole connection.
- Revocation:
https://register.gy/oauth/revoke(RFC 7009). Customers can also disconnect apps in the Client Area.
| Scope | Allows |
|---|---|
domains:read | See your .gy domains and their DNS records |
websites:write | Connect your websites (change website records only, with 7-day undo) |
API keys (your own scripts and tools)
Create up to 5 keys in the Client Area. Send them as Authorization: Bearer rgy_live_… or X-API-Key: rgy_live_…. Keys have both scopes. They are stored hashed, and the owner is emailed when one is created.
MCP server
Streamable HTTP transport, JSON responses (no event stream), protocol versions 2025-06-18, 2025-03-26, 2024-11-05.
| Tool | What it does | Changes data? |
|---|---|---|
search_domain | Check whether a .gy domain (.gy, .com.gy, .co.gy, .net.gy or .org.gy) is available at Register.gy, with the yearly price and a link to register it. | No |
list_my_domains | List the user's .gy domains at Register.gy, with expiry date and whether each can be connected to a website now. | No |
get_dns_records | Show the current DNS records of one of the user's .gy domains. | No |
connect_website | Point one of the user's .gy domains at their website by setting the DNS records their website builder (Lovable, Bolt, Replit, v0/Vercel, Netlify, Webflow, Shopify…) shows on its custom-domain screen. Use the builder's real values, never guesses. ALWAYS call with apply=false first and show the user the preview; call again with apply=true only after the user clearly confirms. Email (MX) and nameserver records are never changed. The change can be undone for 7 days. | Yes, after confirmation |
check_live | Check whether the website records of a .gy domain are visible on the internet and whether https works yet. | No |
undo_last_change | Put back the website records that were in place before the last connect_website change on this domain (available for 7 days). Ask the user first. | Yes, after confirmation |
REST API
Base URL https://register.gy/wp-json/rgy/v1. JSON in, JSON out. Errors look like {"error":{"code":"not_found","message":"…"}}.
| Method | Path | Description | Auth |
|---|---|---|---|
| GET | /availability | Is a .gy domain available? | None |
| GET | /health | Service status for uptime monitors | None |
| GET | /me | Who this key belongs to | Key or token |
| GET | /domains | Your .gy domains | Key or token |
| GET | /domains/{domain} | One domain | Key or token |
| GET | /domains/{domain}/records | Current DNS records | Key or token |
| POST | /domains/{domain}/connect/preview | Preview connecting a website (changes nothing) | Key or token |
| POST | /domains/{domain}/connect/apply | Connect a website (after the user confirms the preview) | Key or token |
| POST | /domains/{domain}/connect/undo | Undo the last connect | Key or token |
| GET | /domains/{domain}/live | Is the site live (DNS + https)? | Key or token |
| POST | /mcp | MCP endpoint for AI assistants (JSON-RPC 2.0, Streamable HTTP) | Key or token |
Connect request body
Either a list of records, or the raw text your builder shows (a table or list). Only A, AAAA, CNAME (ALIAS) and TXT are set; anything else is listed under skipped with the reason.
{
"records": [
{ "type": "A", "name": "@", "value": "185.158.133.1" },
{ "type": "CNAME", "name": "www", "value": "mysite.netlify.app" }
]
} Limits and errors
| Requests | 300 per key or connection every 10 minutes |
|---|---|
| Changes | 60 every 10 minutes per customer (shared with the Client Area) |
| Availability | 30 checks per minute per IP address |
| Records per connect | 15 |
| Status | Meaning |
|---|---|
| 400 | Bad request (the message says what to fix) |
| 401 | Missing, invalid or expired key or token |
| 403 | Not allowed (for example a read-only connection trying to change records, or a domain managed by our team) |
| 404 | Not on this account, or unknown endpoint |
| 429 | Too many requests; wait and retry |
| 503 | A dependency (DNS or the availability check) is not responding; retry later |
Security
- Keys and tokens are stored only as SHA-256 hashes. Sign-in codes are single-use, expire in 10 minutes and are rate limited.
- Each key or connection only sees the domains of the customer who created it.
- Every change through the API is logged and can be undone for 7 days. Website records are set DNS-only so builders can issue their https certificates.
- Found a security problem? Email contact@iis.gy with "Security" in the subject. Please give us a chance to fix it before telling others.
Changelog
- 8 Oct 2026 OAuth 2.1 sign-in (PKCE, dynamic client registration, refresh rotation), connected apps in the Client Area, public search-only MCP endpoint.
- 8 Oct 2026 REST API and MCP server launched: availability, domains, records, connect preview/apply/undo, live check. API keys in the Client Area.
Support and terms
Questions, ideas or partnership requests: contact@iis.gy or +592-623-1721.
Use of the API is covered by our privacy policy. Dedicated API terms are being finalised.