[{"slug":"ZV-2026-1197","server_name":"borealhost.ai","severity":"breaking","title":"borealhost.ai: Tool register was removed.","summary":"[breaking] Tool register was removed. [safe] Tool add_mailbox_alias was added. [safe] Tool add_port_forward was added. [safe] Tool browse_backup was added. [safe] Tool clear_mailbox_forwarding was added. [safe] Tool configure_email_dns was added. [safe] Tool create_email_mailbox was added. [safe] Tool create_mailbox_token was added. [safe] Tool delete_email_mailbox was added. [safe] Tool disable_email_domain was added. [safe] Tool enable_email_domain was added. [safe] Tool find_address was added. [safe] Tool get_database_recovery was added. [safe] Tool get_email_domain was added. [safe] Tool get_email_webmail_url was added. [safe] Tool get_file_recovery was added. [safe] Tool get_mailbox was added. [safe] Tool list_email_audit was added. [safe] Tool list_email_domains was added. [safe] Tool list_mailbox_aliases was added. [safe] Tool list_mailboxes was added. [safe] Tool list_port_forwards was added. [safe] Tool logout_mailbox_sessions was added. [safe] Tool recover_backup_database was added. [safe] Tool recover_backup_files was added. [safe] Tool remove_mailbox_alias was added. [safe] Tool remove_port_forward was added. [safe] Tool resend_registrant_verification was added. [safe] Tool reset_email_mailbox_password was added. [safe] Tool restore_mailbox was added. [safe] Tool rotate_email_key was added. [safe] Tool set_mailbox_aliases was added. [safe] Tool update_email_domain was added. [safe] Tool update_mailbox was added. [safe] Description of add_domain_dns changed (24% word delta). [breaking] Field ttl was removed from add_domain_dns input; consumers still sending it may be rejected or silently ignored. [safe] Description of create_api_key changed (25% word delta). [risky] Optional field email_domains was added to create_api_key; may shift model behaviour. [risky] Optional field expires_at was added to create_api_key; may shift model behaviour. [risky] Optional field ip_allowlist was added to create_api_key; may shift model behaviour. [risky] Description of deco","changes":[{"kind":"tool_removed","tool":"register","detail":"Tool `register` was removed.","severity":"breaking"},{"kind":"tool_added","tool":"add_mailbox_alias","detail":"Tool `add_mailbox_alias` was added.","severity":"safe"},{"kind":"tool_added","tool":"add_port_forward","detail":"Tool `add_port_forward` was added.","severity":"safe"},{"kind":"tool_added","tool":"browse_backup","detail":"Tool `browse_backup` was added.","severity":"safe"},{"kind":"tool_added","tool":"clear_mailbox_forwarding","detail":"Tool `clear_mailbox_forwarding` was added.","severity":"safe"},{"kind":"tool_added","tool":"configure_email_dns","detail":"Tool `configure_email_dns` was added.","severity":"safe"},{"kind":"tool_added","tool":"create_email_mailbox","detail":"Tool `create_email_mailbox` was added.","severity":"safe"},{"kind":"tool_added","tool":"create_mailbox_token","detail":"Tool `create_mailbox_token` was added.","severity":"safe"},{"kind":"tool_added","tool":"delete_email_mailbox","detail":"Tool `delete_email_mailbox` was added.","severity":"safe"},{"kind":"tool_added","tool":"disable_email_domain","detail":"Tool `disable_email_domain` was added.","severity":"safe"},{"kind":"tool_added","tool":"enable_email_domain","detail":"Tool `enable_email_domain` was added.","severity":"safe"},{"kind":"tool_added","tool":"find_address","detail":"Tool `find_address` was added.","severity":"safe"},{"kind":"tool_added","tool":"get_database_recovery","detail":"Tool `get_database_recovery` was added.","severity":"safe"},{"kind":"tool_added","tool":"get_email_domain","detail":"Tool `get_email_domain` was added.","severity":"safe"},{"kind":"tool_added","tool":"get_email_webmail_url","detail":"Tool `get_email_webmail_url` was added.","severity":"safe"},{"kind":"tool_added","tool":"get_file_recovery","detail":"Tool `get_file_recovery` was added.","severity":"safe"},{"kind":"tool_added","tool":"get_mailbox","detail":"Tool `get_mailbox` was added.","severity":"safe"},{"kind":"tool_added","tool":"list_email_audit","detail":"Tool `list_email_audit` was added.","severity":"safe"},{"kind":"tool_added","tool":"list_email_domains","detail":"Tool `list_email_domains` was added.","severity":"safe"},{"kind":"tool_added","tool":"list_mailbox_aliases","detail":"Tool `list_mailbox_aliases` was added.","severity":"safe"},{"kind":"tool_added","tool":"list_mailboxes","detail":"Tool `list_mailboxes` was added.","severity":"safe"},{"kind":"tool_added","tool":"list_port_forwards","detail":"Tool `list_port_forwards` was added.","severity":"safe"},{"kind":"tool_added","tool":"logout_mailbox_sessions","detail":"Tool `logout_mailbox_sessions` was added.","severity":"safe"},{"kind":"tool_added","tool":"recover_backup_database","detail":"Tool `recover_backup_database` was added.","severity":"safe"},{"kind":"tool_added","tool":"recover_backup_files","detail":"Tool `recover_backup_files` was added.","severity":"safe"},{"kind":"tool_added","tool":"remove_mailbox_alias","detail":"Tool `remove_mailbox_alias` was added.","severity":"safe"},{"kind":"tool_added","tool":"remove_port_forward","detail":"Tool `remove_port_forward` was added.","severity":"safe"},{"kind":"tool_added","tool":"resend_registrant_verification","detail":"Tool `resend_registrant_verification` was added.","severity":"safe"},{"kind":"tool_added","tool":"reset_email_mailbox_password","detail":"Tool `reset_email_mailbox_password` was added.","severity":"safe"},{"kind":"tool_added","tool":"restore_mailbox","detail":"Tool `restore_mailbox` was added.","severity":"safe"},{"kind":"tool_added","tool":"rotate_email_key","detail":"Tool `rotate_email_key` was added.","severity":"safe"},{"kind":"tool_added","tool":"set_mailbox_aliases","detail":"Tool `set_mailbox_aliases` was added.","severity":"safe"},{"kind":"tool_added","tool":"update_email_domain","detail":"Tool `update_email_domain` was added.","severity":"safe"},{"kind":"tool_added","tool":"update_mailbox","detail":"Tool `update_mailbox` was added.","severity":"safe"},{"kind":"description_changed","tool":"add_domain_dns","after":"Add a DNS record to a domain.\n\nRequires: API key with write scope.\n\nArgs:\n    domain_name: Full domain name (e.g. \"example.com\")\n    record_type: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"TXT\", or \"SRV\"\n    value: Record value (e.g. \"1.2.3.4\" for A, \"mail.example.com\" for MX)\n    subdomain: Subdomain part (e.g. \"www\", \"mail\"). Empty for apex domain.\n    priority: MX priority (required for MX records)\n\n    The DNS provider manages the effective TTL and does not expose a\n    per-record value through this service.\n\nReturns:\n    {\"success\": true, \"record\": {\"id\": \"...\", \"type\": \"A\",\n     \"subdomain\": \"www\", \"value\": \"1.2.3.4\"}}\n\nErrors:\n    VALIDATION_ERROR: Missing value, invalid record type\n    NOT_FOUND: Domain not found\n","before":"Add a DNS record to a domain.\n\nRequires: API key with write scope.\n\nArgs:\n    domain_name: Full domain name (e.g. \"example.com\")\n    record_type: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"TXT\", or \"SRV\"\n    value: Record value (e.g. \"1.2.3.4\" for A, \"mail.example.com\" for MX)\n    subdomain: Subdomain part (e.g. \"www\", \"mail\"). Empty for apex domain.\n    ttl: Time to live in seconds (default: 3600)\n    priority: MX priority (required for MX records)\n\nReturns:\n    {\"success\": true, \"record\": {\"id\": \"...\", \"type\": \"A\",\n     \"subdomain\": \"www\", \"value\": \"1.2.3.4\", \"ttl\": 3600}}\n\nErrors:\n    VALIDATION_ERROR: Missing value, invalid record type\n    NOT_FOUND: Domain not found\n","detail":"Description of `add_domain_dns` changed (24% word delta).","severity":"safe","descriptionDelta":0.23611111111111116},{"kind":"input_property_removed","path":"inputSchema.properties.ttl","tool":"add_domain_dns","before":{"type":"integer","title":"Ttl","default":3600},"detail":"Field `ttl` was removed from `add_domain_dns` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"description_changed","tool":"create_api_key","after":"Create a new API key with specified scopes.\n\nCannot create keys with higher scopes than the current key.\nSite-scoped keys restrict access to a single site.\nemail_domains restricts the key to email tools on the named domains; use\nemail:read, email:write and optionally email:signon scopes. expires_at is\nan ISO timestamp; ip_allowlist accepts IP addresses and CIDR networks.\n\nRequires: API key with write scope.\n\nArgs:\n    name: Human-readable name for the key (1-100 chars)\n    scopes: Comma-separated scopes. Options: \"read\", \"read,write\",\n            \"read,write,admin\". Default: \"read\"\n    site_slug: Optional — restrict the key to a single site.\n               Omit for account-wide access.\n\nReturns:\n    {\"api_key\": \"bh_...\", \"key_id\": \"uuid\", \"prefix\": \"bh_...\",\n     \"name\": \"My Key\", \"scopes\": [\"read\", \"write\"],\n     \"message\": \"Store this API key securely — it will not be shown again.\"}\n\nErrors:\n    VALIDATION_ERROR: Invalid name, scopes, or max 25 active keys\n    FORBIDDEN: Cannot create keys with higher scopes than current key\n","before":"Create a new API key with specified scopes.\n\nCannot create keys with higher scopes than the current key.\nSite-scoped keys restrict access to a single site.\n\nRequires: API key with write scope.\n\nArgs:\n    name: Human-readable name for the key (1-100 chars)\n    scopes: Comma-separated scopes. Options: \"read\", \"read,write\",\n            \"read,write,admin\". Default: \"read\"\n    site_slug: Optional — restrict the key to a single site.\n               Omit for account-wide access.\n\nReturns:\n    {\"api_key\": \"bh_...\", \"key_id\": \"uuid\", \"prefix\": \"bh_...\",\n     \"name\": \"My Key\", \"scopes\": [\"read\", \"write\"],\n     \"message\": \"Store this API key securely — it will not be shown again.\"}\n\nErrors:\n    VALIDATION_ERROR: Invalid name, scopes, or max 25 active keys\n    FORBIDDEN: Cannot create keys with higher scopes than current key\n","detail":"Description of `create_api_key` changed (25% word delta).","severity":"safe","descriptionDelta":0.2471910112359551},{"kind":"input_property_added","path":"inputSchema.properties.email_domains","tool":"create_api_key","after":{"anyOf":[{"type":"array","items":{"type":"string"}},{"type":"null"}],"title":"Email Domains","default":null},"detail":"Optional field `email_domains` was added to `create_api_key`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.expires_at","tool":"create_api_key","after":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Expires At","default":null},"detail":"Optional field `expires_at` was added to `create_api_key`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.ip_allowlist","tool":"create_api_key","after":{"anyOf":[{"type":"array","items":{"type":"string"}},{"type":"null"}],"title":"Ip Allowlist","default":null},"detail":"Optional field `ip_allowlist` was added to `create_api_key`; may shift model behaviour.","severity":"risky"},{"kind":"description_changed","tool":"decommission","after":"Delete a site and schedule resource cleanup (7-day grace period).\n\nWARNING: This is destructive. The site will be inaccessible immediately.\nAfter the grace period, its active service data is deleted. A final backup\nremains recoverable for 30 days; immutable copies may remain until their\nretention locks expire.\n\nBest practice: create a snapshot before decommissioning.\n\nRequires: API key with admin scope.\n\nArgs:\n    slug: Site identifier\n\nReturns:\n    {\"success\": true, \"message\": \"Site scheduled for deletion\",\n     \"grace_period_days\": 7}\n\nErrors:\n    NOT_FOUND: Unknown slug\n","before":"Delete a site and schedule resource cleanup (7-day grace period).\n\nWARNING: This is destructive. The site will be inaccessible immediately\nbut data is retained for 7 days before permanent deletion.\n\nBest practice: create a snapshot before decommissioning.\n\nRequires: API key with admin scope.\n\nArgs:\n    slug: Site identifier\n\nReturns:\n    {\"success\": true, \"message\": \"Site scheduled for deletion\",\n     \"grace_period_days\": 7}\n\nErrors:\n    NOT_FOUND: Unknown slug\n","detail":"Description of `decommission` changed (31% word delta).","severity":"risky","descriptionDelta":0.3142857142857143},{"kind":"description_changed","tool":"domain_settings","after":"Update domain settings (auto-renew, WHOIS privacy, registrar lock).\n\nOnly provided (non-None) fields are updated.\n\nRequires: API key with write scope.\n\nArgs:\n    domain_name: Full domain name (e.g. \"example.com\")\n    auto_renew: Optional bool enabling/disabling automatic renewal\n    whois_privacy: Optional bool. False disables saved proxy service. Paid activation via True is refused; request an activation quote through Support.\n    locked: Optional bool enabling/disabling registrar lock (prevents unauthorized transfers)\n\nReturns:\n    {\"success\": true, \"domain\": \"example.com\",\n     \"auto_renew\": true, \"whois_privacy\": true, \"locked\": true}\n\nErrors:\n    NOT_FOUND: Domain not found or not owned by account\n","before":"Update domain settings (auto-renew, WHOIS privacy, registrar lock).\n\nOnly provided (non-None) fields are updated.\n\nRequires: API key with write scope.\n\nArgs:\n    domain_name: Full domain name (e.g. \"example.com\")\n    auto_renew: Enable/disable automatic renewal\n    whois_privacy: Enable/disable WHOIS privacy protection\n    locked: Enable/disable registrar lock (prevents unauthorized transfers)\n\nReturns:\n    {\"success\": true, \"domain\": \"example.com\",\n     \"auto_renew\": true, \"whois_privacy\": true, \"locked\": true}\n\nErrors:\n    NOT_FOUND: Domain not found or not owned by account\n","detail":"Description of `domain_settings` changed (31% word delta).","severity":"risky","descriptionDelta":0.3098591549295775},{"kind":"description_changed","tool":"execute_query","after":"Run ONE bounded read against a site's database.\n\nOne statement, beginning with SELECT, SHOW, DESCRIBE or EXPLAIN, with no\nsecond statement and no data-modifying clause anywhere in it. The container\nproves the statement is a read before running it and caps the result: 200\nrows by default, 1000 maximum, 2 MB of cell data. `truncated` in the\nresponse says whether a cap was reached.\n\n⚠ THIS TOOL CANNOT CHANGE ANYTHING, AND RETRYING WITH DIFFERENT WORDING WILL\nNOT MAKE IT. Anything that is not a single bounded read is refused with\nREAD_ONLY and nothing runs. To change data or schema, use the tool for the\njob: optimize_database, database_search_replace, manage_db_user,\nlist_databases, list_tables — and for creating, altering, dropping,\nimporting or exporting tables, the database manager in the control panel,\nwhich has no tool here.\n\nRequires: API key with write scope (unchanged — the scope is the customer's\npublished permission for this operation, not a claim about what it does).\n\nArgs:\n    slug: Site identifier\n    database: Database name\n    query: One read statement\n\nReturns:\n    {\"columns\": [\"id\", \"user_email\"], \"rows\": [[1, \"a@example.com\"], ...],\n     \"row_count\": 1, \"truncated\": false, \"execution_time_ms\": 12.0}\n\nErrors:\n    READ_ONLY: Not a single bounded read. The error text carries the\n        explanation and names the operation to use instead.\n","before":"Execute a SQL query on a site's database.\n\nSupports SELECT, INSERT, UPDATE, DELETE, and DDL statements.\nResults are limited to 1000 rows for SELECT queries.\n\nRequires: API key with write scope.\n\nArgs:\n    slug: Site identifier\n    database: Database name\n    query: SQL query string\n\nReturns:\n    {\"columns\": [\"id\", \"title\"], \"rows\": [[1, \"Hello\"], ...],\n     \"affected_rows\": 0, \"query_time_ms\": 12}\n","detail":"Description of `execute_query` changed (82% word delta).","severity":"risky","descriptionDelta":0.815068493150685},{"kind":"description_changed","tool":"list_domain_dns","after":"List all DNS records for a domain.\n\nReturns DNS records at the domain level (independent of site-level\nmanage_dns). Use this for domains that may not be linked to a site.\n\nRequires: API key with read scope.\n\nArgs:\n    domain_name: Full domain name (e.g. \"example.com\")\n\nReturns:\n    [{\"id\": \"record-id\", \"type\": \"A\", \"subdomain\": \"www\",\n      \"value\": \"1.2.3.4\"}]\n\nThe DNS provider manages the effective TTL and does not expose a\nper-record value through this service.\n\nErrors:\n    NOT_FOUND: Domain not found or not owned by account\n","before":"List all DNS records for a domain.\n\nReturns DNS records at the domain level (independent of site-level\nmanage_dns). Use this for domains that may not be linked to a site.\n\nRequires: API key with read scope.\n\nArgs:\n    domain_name: Full domain name (e.g. \"example.com\")\n\nReturns:\n    [{\"id\": \"record-id\", \"type\": \"A\", \"subdomain\": \"www\",\n      \"value\": \"1.2.3.4\", \"ttl\": 3600}]\n\nErrors:\n    NOT_FOUND: Domain not found or not owned by account\n","detail":"Description of `list_domain_dns` changed (15% word delta).","severity":"safe","descriptionDelta":0.1515151515151515},{"kind":"description_changed","tool":"manage_dns","after":"Create or delete DNS records for a site.\n\nRequires: API key with write scope.\n\nArgs:\n    slug: Site identifier\n    action: \"create\" or \"delete\"\n    record_type: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"TXT\", or \"SRV\"\n    subdomain: Subdomain part (e.g. \"www\", \"mail\"). Leave empty for\n               the apex/root domain.\n    value: Record value. Required for \"create\". Examples:\n           A: \"1.2.3.4\", CNAME: \"example.com\", MX: \"mail.example.com\",\n           TXT: \"v=spf1 include:_spf.google.com ~all\"\n    The DNS provider manages the effective TTL and does not expose a\n    per-record value through this service.\n\nReturns:\n    {\"success\": true, \"record\": {\"type\": \"A\", \"subdomain\": \"www\",\n     \"value\": \"1.2.3.4\"}}\n\nErrors:\n    VALIDATION_ERROR: Missing value for create, invalid record type\n    NOT_FOUND: Unknown slug\n","before":"Create or delete DNS records for a site.\n\nRequires: API key with write scope.\n\nArgs:\n    slug: Site identifier\n    action: \"create\" or \"delete\"\n    record_type: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"TXT\", or \"SRV\"\n    subdomain: Subdomain part (e.g. \"www\", \"mail\"). Leave empty for\n               the apex/root domain.\n    value: Record value. Required for \"create\". Examples:\n           A: \"1.2.3.4\", CNAME: \"example.com\", MX: \"mail.example.com\",\n           TXT: \"v=spf1 include:_spf.google.com ~all\"\n    ttl: Time to live in seconds (default: 3600)\n\nReturns:\n    {\"success\": true, \"record\": {\"type\": \"A\", \"subdomain\": \"www\",\n     \"value\": \"1.2.3.4\", \"ttl\": 3600}}\n\nErrors:\n    VALIDATION_ERROR: Missing value for create, invalid record type\n    NOT_FOUND: Unknown slug\n","detail":"Description of `manage_dns` changed (22% word delta).","severity":"safe","descriptionDelta":0.2222222222222222},{"kind":"input_property_removed","path":"inputSchema.properties.ttl","tool":"manage_dns","before":{"type":"integer","title":"Ttl","default":3600},"detail":"Field `ttl` was removed from `manage_dns` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"description_changed","tool":"register_domain","after":"Register a new domain with WHOIS contact info and Stripe billing.\n\nFirst request a quote (quote_only=True), present registration_cad,\nprivacy_cad, total_cad, term and privacy choice, and obtain customer consent.\nThen repeat the same input with quote_only=False and the quote_token.\nNever automatically accept a replacement token after a price change.\nIncluded annual registration covers registration only; selected privacy\nuses the same BoC daily USD/CAD rate, rounded to CAD cents, no markup.\nRegistration/renewal convert their actual operation-specific USD cost first,\nthen apply 10% and round up to CAD .95. Rates older than four days refuse.\n\nRequires: API key with write scope.\n\nArgs:\n    whois_privacy: Explicit privacy choice; defaults selected only for supported paid TLDs.\n    quote_only: True returns a quote without registration or payment.\n    quote_token: Signed five-minute quote accepted by the customer.\n    domain: Full domain name (e.g. \"example.ca\", \"mybusiness.com\")\n    first_name: Registrant first name\n    last_name: Registrant last name\n    email: Registrant email address\n    phone: Phone number in E.164 format: \"+1.5145551234\"\n    address1: Street address (e.g. \"123 Rue Principale\")\n    city: City (e.g. \"Montreal\")\n    state: Province/state code (e.g. \"QC\", \"ON\", \"BC\")\n    postal_code: Postal/ZIP code (e.g. \"H2X 1Y4\")\n    country: ISO 3166-1 alpha-2 country code (default: \"CA\")\n    period: Registration period in years (1–10, default: 1)\n    usage_mode: What the domain points at.\n                \"site\" (default) links it to the billing subscription's\n                site with automatic DNS + Nginx + SSL.\n                \"external_ns\" delegates it to `nameservers` — the domain is\n                registered here but hosted elsewhere; we manage no DNS.\n                \"dns_only\" keeps it on our DNS with no site behind it.\n                \"forward\" redirects visitors to `forward_url`.\n    nameservers: Ordered list of 2–6 nameserver hostnames. Required when\n                 usage_mode=\"external_ns\" (e.g. [\"ns1.other.com\", \"ns2.other.com\"])\n    forward_url: Redirect target, required when usage_mode=\"forward\"\n                 (e.g. \"https://example.org\")\n    forward_type: \"301\" permanent (default) or \"302\" temporary\n    forward_include_path: Append the visitor's path to the target (default: True)\n    ca_legal_type: Required for .ca domains. CIRA legal types:\n                   \"CCT\" (Canadian citizen), \"RES\" (permanent resident),\n                   \"CCO\" (corporation), \"GOV\" (government), \"EDU\" (education),\n                   \"ASS\" (association), \"HOP\" (hospital), \"PRT\" (partnership),\n                   \"TDM\" (trademark), \"TRD\" (trade union), \"PLT\" (political party),\n                   \"LAM\" (library/archive/museum), \"MAJ\" (Her Majesty),\n                   \"INB\" (Indian band), \"ABO\" (Aboriginal peoples),\n                   \"LGR\" (legal representative)\n\nReturns:\n    Quote request: {\"quote\": {\"registration_cad\": \"...\",\n      \"privacy_cad\": \"...\", \"total_cad\": \"...\", \"currency\": \"CAD\",\n      \"period\": 1, \"whois_privacy\": false, \"expires_at\": \"iso8601\"},\n      \"quote_token\": \"...\", \"privacy_explanation\": \"...\"}\n    Purchase: {\"name\": \"example.ca\", \"status\": \"registered\",\n      \"last_pricing_quote\": {...}, ...}\n\nErrors:\n    VALIDATION_ERROR: Missing required fields, invalid phone format,\n                      missing ca_legal_type for .ca domains\n    NOT_FOUND: Domain not available (already registered by someone else)\n","before":"Register a new domain with WHOIS contact info and Stripe billing.\n\nThe domain cost is charged to the user's active subscription.\nFree domain if plan includes free_domain_annual + annual billing + first domain.\n\nRequires: API key with write scope.\n\nArgs:\n    domain: Full domain name (e.g. \"example.ca\", \"mybusiness.com\")\n    first_name: Registrant first name\n    last_name: Registrant last name\n    email: Registrant email address\n    phone: Phone number in E.164 format: \"+1.5145551234\"\n    address1: Street address (e.g. \"123 Rue Principale\")\n    city: City (e.g. \"Montreal\")\n    state: Province/state code (e.g. \"QC\", \"ON\", \"BC\")\n    postal_code: Postal/ZIP code (e.g. \"H2X 1Y4\")\n    country: ISO 3166-1 alpha-2 country code (default: \"CA\")\n    period: Registration period in years (1–10, default: 1)\n    usage_mode: What the domain points at.\n                \"site\" (default) links it to the billing subscription's\n                site with automatic DNS + Nginx + SSL.\n                \"external_ns\" delegates it to `nameservers` — the domain is\n                registered here but hosted elsewhere; we manage no DNS.\n                \"dns_only\" keeps it on our DNS with no site behind it.\n                \"forward\" redirects visitors to `forward_url`.\n    nameservers: Ordered list of 2–6 nameserver hostnames. Required when\n                 usage_mode=\"external_ns\" (e.g. [\"ns1.other.com\", \"ns2.other.com\"])\n    forward_url: Redirect target, required when usage_mode=\"forward\"\n                 (e.g. \"https://example.org\")\n    forward_type: \"301\" permanent (default) or \"302\" temporary\n    forward_include_path: Append the visitor's path to the target (default: True)\n    ca_legal_type: Required for .ca domains. CIRA legal types:\n                   \"CCO\" (Canadian citizen), \"RES\" (permanent resident),\n                   \"CCT\" (corporation), \"GOV\" (government), \"EDU\" (education),\n                   \"ASS\" (association), \"HOP\" (hospital), \"PRT\" (partnership),\n                   \"TDM\" (trademark), \"TRD\" (trade union), \"PLT\" (political party),\n                   \"LAM\" (library/archive/museum), \"MAJ\" (Her Majesty),\n                   \"INB\" (Indian band), \"ABO\" (Aboriginal peoples),\n                   \"LGR\" (legal representative)\n\nReturns:\n    {\"domain\": \"example.ca\", \"status\": \"registered\",\n     \"expires_at\": \"iso8601\", \"message\": \"Domain registered successfully\"}\n\nErrors:\n    VALIDATION_ERROR: Missing required fields, invalid phone format,\n                      missing ca_legal_type for .ca domains\n    NOT_FOUND: Domain not available (already registered by someone else)\n","detail":"Description of `register_domain` changed (30% word delta).","severity":"risky","descriptionDelta":0.2992700729927007},{"kind":"input_property_added","path":"inputSchema.properties.quote_only","tool":"register_domain","after":{"type":"boolean","title":"Quote Only","default":true},"detail":"Optional field `quote_only` was added to `register_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.quote_token","tool":"register_domain","after":{"type":"string","title":"Quote Token","default":""},"detail":"Optional field `quote_token` was added to `register_domain`; may shift model behaviour.","severity":"risky"},{"kind":"input_property_added","path":"inputSchema.properties.whois_privacy","tool":"register_domain","after":{"anyOf":[{"type":"boolean"},{"type":"null"}],"title":"Whois Privacy","default":null},"detail":"Optional field `whois_privacy` was added to `register_domain`; may shift model behaviour.","severity":"risky"},{"kind":"description_changed","tool":"rotate_key","after":"Rotate an API key, optionally keeping the old key valid for up to 1,440 minutes.\n\nCreates a new key with the same name, scopes, and rate limits.\nThe new key is returned once — store it immediately.\n\nRequires: API key with write scope.\n\nArgs:\n    key_id: UUID of the API key to rotate (get from whoami())\n\nReturns:\n    {\"api_key\": \"bh_...\", \"key_id\": \"uuid\", \"prefix\": \"bh_...\",\n     \"scopes\": [\"read\", \"write\"], \"message\": \"Key rotated. Store securely.\"}\n\nExpiry and all restrictions are preserved. Without a grace period the old\nkey stops working immediately.\n","before":"Atomically rotate an API key. Old key is immediately invalidated.\n\nCreates a new key with the same name, scopes, and rate limits.\nThe new key is returned once — store it immediately.\n\nRequires: API key with write scope.\n\nArgs:\n    key_id: UUID of the API key to rotate (get from whoami())\n\nReturns:\n    {\"api_key\": \"bh_...\", \"key_id\": \"uuid\", \"prefix\": \"bh_...\",\n     \"scopes\": [\"read\", \"write\"], \"message\": \"Key rotated. Store securely.\"}\n\nNote: The old key stops working immediately. Update BOREALHOST_API_KEY\nright away.\n","detail":"Description of `rotate_key` changed (35% word delta).","severity":"risky","descriptionDelta":0.3484848484848485},{"kind":"input_property_added","path":"inputSchema.properties.grace_minutes","tool":"rotate_key","after":{"type":"integer","title":"Grace Minutes","default":0},"detail":"Optional field `grace_minutes` was added to `rotate_key`; may shift model behaviour.","severity":"risky"},{"kind":"description_changed","tool":"search_domain","after":"Check domain availability and get pricing.\n\nRequires: API key with read scope.\n\nArgs:\n    domain: Full domain name (e.g. \"example.com\", \"mybiz.ca\")\n\nReturns:\n    {\"domain\": \"example.com\", \"available\": true,\n     \"registration_estimate_cad\": \"15.99\", \"currency\": \"CAD\",\n     \"price_cad_includes_privacy\": false, \"total_cad\": null,\n     \"quote_required\": true}\n\nNote: .ca domains require ca_legal_type when registering.\n","before":"Check domain availability and get pricing.\n\nRequires: API key with read scope.\n\nArgs:\n    domain: Full domain name (e.g. \"example.com\", \"mybiz.ca\")\n\nReturns:\n    {\"domain\": \"example.com\", \"available\": true,\n     \"price\": {\"amount\": 15.99, \"currency\": \"CAD\", \"period\": \"1 year\"},\n     \"premium\": false}\n\nNote: .ca domains require ca_legal_type when registering.\n","detail":"Description of `search_domain` changed (24% word delta).","severity":"safe","descriptionDelta":0.23913043478260865},{"kind":"description_changed","tool":"set_api_key","after":"Set your BorealHost API key for this session.\n\nCall this if you already have an API key (from checkout completion,\nthe BorealHost panel, or a container claim). All subsequent tool calls\nwill use this key for authentication.\n\nArgs:\n    api_key: Your BorealHost API key (format: bh_<48 hex chars>)\n\nReturns:\n    {\"success\": true, \"message\": \"API key set for this session\",\n     \"key_prefix\": \"bh_...\"}\n","before":"Set your BorealHost API key for this session.\n\nCall this if you already have an API key (from a previous registration,\ncheckout completion, or the BorealHost panel). All subsequent tool calls\nwill use this key for authentication.\n\nNo need to call this after register() — the key is set automatically.\n\nArgs:\n    api_key: Your BorealHost API key (format: bh_<48 hex chars>)\n\nReturns:\n    {\"success\": true, \"message\": \"API key set for this session\",\n     \"key_prefix\": \"bh_...\"}\n","detail":"Description of `set_api_key` changed (22% word delta).","severity":"safe","descriptionDelta":0.21568627450980393}],"published_at":"2026-09-19T13:28:13.495Z"}]