Nextdns for AI agents

NextDNS is a DNS-based security and privacy service that blocks malicious sites, trackers, and ads before they reach a device. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityAPI keyMCP + RESTnextdns.io
AUDIT LOG · NEXTDNSPOLICY: acme-support
09:41:07 · claude · u_8f2read
nextdns.list_profiles
List Profiles✓ allowed · 212ms
09:41:08 · claude · u_8f2read
nextdns.get_logs
Get Logs✓ allowed · 164ms
09:41:09 · claude · u_8f2write
nextdns.create_profile
Create Profile✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
nextdns.delete_config
Delete NextDNS Configuration✕ blocked · policy: deny
EVERY NEXTDNS CALL, ON THE RECORD
01 · USE CASES

What agents do in Nextdns.

01

Check blocked domains analytics

Pull analytics on recently blocked domains for a profile to review activity, read-only.

02

Add a domain to the denylist

Add a known malicious domain to a profile's denylist to block it going forward.

03

Approve before deleting a configuration

Require approval before deleting a NextDNS configuration, since it removes all its blocking rules.

02 · ACTIONS

68 Nextdns actions, graded by risk.

Every Nextdns action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

28

Look things up. Allowed by default.

  • nextdns.get_logs
    Get Logs
  • nextdns.get_profile
    Get Profile Details
  • nextdns.get_rewrites
    Get DNS Rewrites
  • nextdns.get_settings
    Get Profile Settings
  • nextdns.get_allowlist
    Get Allowlist
  • nextdns.list_profiles
    List Profiles
  • nextdns.get_analytics_ips
    Get Analytics IPs
  • nextdns.get_security_tlds
    Get Security TLDs
  • nextdns.get_settings_logs
    Get Logging Settings
  • nextdns.get_analytics_dnssec
    Get Analytics DNSSEC
  • nextdns.get_analytics_status
    Get Analytics Status
  • nextdns.get_parental_control
    Get Parental Control Settings
  • nextdns.get_privacy_settings
    Get Privacy Settings
  • nextdns.get_analytics_domains
    Get Analytics Domains
  • nextdns.list_denylist_domains
    List Denylist Domains
  • nextdns.get_analytics_devices2
    Get Analytics Devices
+ 12 MORE

write

30

Create and change things. Allow, or ask the user first.

  • nextdns.add_rewrite
    Add DNS Rewrite Rule
  • nextdns.create_profile
    Create Profile
  • nextdns.add_blocked_tld
    Add Blocked TLD
  • nextdns.update_settings
    Update Settings
  • nextdns.update_linked_ip
    Update linked IP
  • nextdns.add_privacy_native
    Add Privacy Native Tracker
  • nextdns.add_allowlist_entry
    Add Allowlist Entry
  • nextdns.add_denylist_domain
    Add Denylist Domain
  • nextdns.add_privacy_blocklist
    Add Privacy Blocklist
  • nextdns.update_denylist_entry
    Update Denylist Entry
  • nextdns.update_allowlist_entry
    Update Allowlist Entry
  • nextdns.update_parental_control
    Update Parental Control Settings
  • nextdns.update_privacy_settings
    Update Privacy Settings
  • nextdns.update_security_settings
    Update Security Settings
  • nextdns.update_settings_blockpage
    Update Block Page Settings
  • nextdns.update_performance_settings
    Update Performance Settings
+ 14 MORE

destructive

10

Delete, cancel or archive. Ask first, or deny outright.

  • nextdns.delete_config
    Delete NextDNS Configuration
  • nextdns.delete_rewrite
    Delete DNS Rewrite Rule
  • nextdns.remove_blocked_tld
    Remove Blocked TLD
  • nextdns.delete_privacy_native
    Delete Privacy Native Tracker
  • nextdns.delete_allowlist_entry
    Delete Allowlist Entry
  • nextdns.remove_denylist_domain
    Remove Denylist Domain
  • nextdns.delete_privacy_blocklist
    Delete Privacy Blocklist
  • nextdns.delete_parental_control_service
    Delete Parental Control Service
  • nextdns.delete_parental_control_category
    Delete Parental Control Category
  • nextdns.clear_logs
    Clear Logs
03 · HOW IT WORKS

Nextdns in three steps.

  1. 01Your users connect NextdnsThey add their Nextdns api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Profile” can wait for the user, and “delete NextDNS Configuration” can be denied outright.
  3. 03Any agent can actYour agent calls Nextdns through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('nextdns', {
  read: 'allow',
  write: 'ask',        // create_profile
  destructive: 'deny',  // delete_config
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Nextdns connects.

Users add their Nextdns api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Nextdns connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Nextdns from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Nextdns and Arc0, answered.

Q01

Can I use Nextdns with Claude, ChatGPT or Cursor?

Yes. Connect Nextdns to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Nextdns actions you allow.

Q02

How do users connect Nextdns?

Users add their Nextdns api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Nextdns actions can my agent take?

68 in total: 28 read, 30 write and 10 destructive, such as “create Profile”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Nextdns?

Yes. Actions like “delete NextDNS Configuration” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Nextdns too?

Yes. The same Nextdns connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Nextdns into your agent.

Your users connect Nextdns once, under your brand. Your agent gets 68 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan