Dnsfilter for AI agents

DNSFilter is cloud-based DNS security software that blocks malicious sites and filters content across an organization's networks, used by IT teams protecting employees and managed customers. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityAPI keyMCP + RESTdnsfilter.com
AUDIT LOG · DNSFILTERPOLICY: acme-support
09:41:07 · claude · u_8f2read
dnsfilter.list_billing
List Billing✓ allowed · 212ms
09:41:08 · claude · u_8f2read
dnsfilter.get_user
Get User✓ allowed · 164ms
09:41:09 · claude · u_8f2write
dnsfilter.create_api_keys
Create API Keys✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
dnsfilter.delete_api_key
Delete API Key✕ blocked · policy: deny
EVERY DNSFILTER CALL, ON THE RECORD
01 · USE CASES

What agents do in Dnsfilter.

01

Check a policy's blocklist

Read the domains and categories blocked under a policy before troubleshooting a user's access issue.

02

Add a domain to a policy

Add a newly flagged domain to the blocklist for a specific policy after a security review.

03

Confirm before deleting policies

Require approval before deleting policies in bulk, since it removes filtering rules across the affected networks.

02 · ACTIONS

170 Dnsfilter actions, graded by risk.

Every Dnsfilter action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

116

Look things up. Allowed by default.

  • dnsfilter.get_user
    Get User
  • dnsfilter.get_notes
    Get Notes
  • dnsfilter.get_api_keys
    Get API Key
  • dnsfilter.get_category
    Get Category
  • dnsfilter.get_policies
    Get Policy
  • dnsfilter.list_billing
    List Billing
  • dnsfilter.get_policy_ip
    Get Policy IP
  • dnsfilter.list_api_keys
    List API Keys
  • dnsfilter.list_invoices
    List Invoices
  • dnsfilter.list_policies
    List Policies
  • dnsfilter.get_ip_address
    Get IP Address
  • dnsfilter.list_users_all
    List All Users
  • dnsfilter.get_mac_address
    Get MAC Address
  • dnsfilter.list_policy_ips
    List Policy IPs
  • dnsfilter.list_qp_methods
    List QP Methods
  • dnsfilter.get_organization
    Get Organization
+ 100 MORE

write

36

Create and change things. Allow, or ask the user first.

  • dnsfilter.create_api_keys
    Create API Keys
  • dnsfilter.create_networks
    Create Networks
  • dnsfilter.create_policies
    Create Policies
  • dnsfilter.update_policies
    Update Policies
  • dnsfilter.create_ip_address
    Create IP Address
  • dnsfilter.update_ip_address
    Update IP Address
  • dnsfilter.create_mac_address
    Create MAC Address
  • dnsfilter.update_current_user
    Update Current User
  • dnsfilter.add_whitelist_domain
    Add Whitelist Domain
  • dnsfilter.create_networks_bulk
    Bulk Create Networks
  • dnsfilter.update_mac_addresses
    Update MAC Address
  • dnsfilter.update_networks_bulk
    Bulk Update Networks
  • dnsfilter.update_organizations
    Update Organizations
  • dnsfilter.update_billing_address
    Update Billing Address
  • dnsfilter.add_allowed_application
    Add Allowed Application
  • dnsfilter.add_blocked_application
    Add Blocked Application
+ 20 MORE

destructive

18

Delete, cancel or archive. Ask first, or deny outright.

  • dnsfilter.delete_api_key
    Delete API Key
  • dnsfilter.delete_policies
    Delete Policies
  • dnsfilter.delete_ip_address
    Delete IP Address
  • dnsfilter.delete_mac_address
    Delete MAC Address
  • dnsfilter.cancel_organization
    Cancel Organization
  • dnsfilter.delete_networks_bulk
    Delete Networks (Bulk)
  • dnsfilter.delete_scheduled_report
    Delete Scheduled Report
  • dnsfilter.remove_blocklist_domains
    Remove Blocklist Domains
  • dnsfilter.delete_scheduled_policies
    Delete Scheduled Policies
  • dnsfilter.remove_blacklist_category
    Remove Blacklist Category
  • dnsfilter.remove_allowed_application
    Remove Allowed Application
  • dnsfilter.remove_blocked_application
    Remove Blocked Application
  • dnsfilter.remove_blacklist_domain_from_policy
    Remove Blacklist Domain From Policy
  • dnsfilter.remove_whitelist_domain_from_policy
    Remove Whitelist Domain from Policy
  • dnsfilter.remove_allowlist_domains_from_policies
    Remove Allowlist Domains from Policies
  • dnsfilter.list_all_block_pages
    List All Block Pages
+ 2 MORE
03 · HOW IT WORKS

Dnsfilter in three steps.

  1. 01Your users connect DnsfilterThey add their Dnsfilter api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create API Keys” can wait for the user, and “delete API Key” can be denied outright.
  3. 03Any agent can actYour agent calls Dnsfilter through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('dnsfilter', {
  read: 'allow',
  write: 'ask',        // create_api_keys
  destructive: 'deny',  // delete_api_key
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Dnsfilter connects.

Users add their Dnsfilter api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Dnsfilter connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Dnsfilter from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Dnsfilter and Arc0, answered.

Q01

Can I use Dnsfilter with Claude, ChatGPT or Cursor?

Yes. Connect Dnsfilter to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Dnsfilter actions you allow.

Q02

How do users connect Dnsfilter?

Users add their Dnsfilter api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Dnsfilter actions can my agent take?

170 in total: 116 read, 36 write and 18 destructive, such as “create API Keys”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Dnsfilter?

Yes. Actions like “delete API Key” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Dnsfilter too?

Yes. The same Dnsfilter connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Dnsfilter into your agent.

Your users connect Dnsfilter once, under your brand. Your agent gets 170 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan