Use Bonafido: Business Domain Verification API MCP with Windsurf (Devin Desktop)
Bonafido: is a domain a real business site? Verdict, trust score, risk flags.
Remote MCP server (Streamable HTTP), nothing to install. Free: 20 free calls/day, no key · Paid: Check $19/month; Team $49/month; Business $99/month; Check yearly $190/year; Team yearly $490/year; Business yearly $990/year
Set it up
- In the Cascade panel, open the … (Actions) menu and click Open MCP config file in the MCPs section.
- Add the server under "mcpServers" with "serverUrl" and save.
- Check the MCPs section in Cascade for the server and its tools.
- Ask Cascade a question the tools can answer.
Add to ~/.config/devin/mcp_config.json:
{
"mcpServers": {
"bonafido": {
"serverUrl": "https://bonafido.cybermaxtools.com/mcp?via=use-with-windsurf"
}
}
}With a paid key:
{
"mcpServers": {
"bonafido": {
"serverUrl": "https://bonafido.cybermaxtools.com/mcp?via=use-with-windsurf",
"headers": {
"x-api-key": "YOUR_KEY"
}
}
}
}Keep this file out of shared folders and repositories if it holds a key.
- ~/.config/devin/mcp_config.json (macOS and Linux)
- %APPDATA%\devin\mcp_config.json (Windows)
Tools you get
Endpoint checked 2026-10-09: https://bonafido.cybermaxtools.com/mcp answered an MCP initialize (protocol 2025-06-18) and tools/list with 1 tool, all marked read-only. No key was used and no tool was called.
| Tool | What it does | Required inputs |
|---|---|---|
verify_domain | Verify a business domain, URL or email domain: does it resolve, how old is it (RDAP), mail setup (MX/SPF/DMARC), live homepage vs parked/for-sale page, redirects, contact details, company-name match, Wikidata official website and look-alike detection. Returns verdict (verified/likely_legit/unverified/suspicious/not_found), trustScore 0-100, riskFlags and evidence. Pass company_name to check the domain belongs to that company. Up to 5 domains via "domains". | none |
Test the endpoint from a terminal
This lists the tools without a key and without calling any of them:
curl -s https://bonafido.cybermaxtools.com/mcp \
-H 'content-type: application/json' \
-H 'accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'If it does not work
- Windsurf's documentation (docs.windsurf.com) now redirects to Devin Desktop's at docs.devin.ai; these steps follow that page.
- The documented remote field is "serverUrl" (the docs say "url" is also accepted).
- The free tier has a daily limit (see the pricing line above); a paid key raises it.
Bonafido: Business Domain Verification API in other clients
More MCP servers for Windsurf (Devin Desktop)
All Bonafido: Business Domain Verification API setups · All Windsurf (Devin Desktop) setups · All