Inspiration
Domain portfolios rot in silence. Auto-renew is off on the name that actually matters. WHOIS privacy is off on another. Three names resolve to nothing and still renew every year. You only find out when a customer hits a dead site — or when the name is already gone.
Registrar dashboards are inventory lists. They do not tell you what is dying, what is wasting money, or what to do next. We wanted an operator: score every domain, say the risk in one sentence, fix it through the same API you already pay for, and leave a signed record behind.
name.com CORE v1 made that possible. Nutrient made the record something you would actually file.
What it does
Portfolio Pulse is the health layer for a name.com domain portfolio.
It pulls live inventory through CORE — domains, DNS, URL forwarding, auto-renew, WHOIS privacy, transfer lock — and scores each name Healthy, Warning, or Critical. Critical means the name is about to drop with auto-renew off, or it has no DNS and no forward (you are paying for air). Warnings cover exposed WHOIS, an unlocked transfer, or a renewal coming due.
Groq writes a one-sentence verdict per problem domain. The sentence starts with the exact name, names the issue, and recommends a real action: enable auto-renew, enable privacy, lock the domain, or redirect it to your main site.
Then you act. One domain at a time, or Fix All. Pulse PATCHes settings and creates URL forwards through CORE while an activity log streams each call. The summary bar updates. Dollars “saved” are renewal waste and loss risk you no longer carry — not a refund.
Need a replacement? Search a keyword, check availability, register. New names come in with auto-renew, privacy, and lock already on.
When the portfolio is clean enough to document, Nutrient Document Web Services turns it into a signed audit. One /build converts the scored portfolio from HTML into a Letter PDF and redacts email and phone numbers. You download the draft, read it, then Approve & sign. That second click is Nutrient /sign — a CMS CAdES signature on the last page. Contacts never enter the PDF; it is a health record, not a WHOIS dump. A person has to approve before anything is stamped.
How we built it
Three APIs, one loop: name.com CORE owns the portfolio, Groq owns the language, Nutrient owns the file you keep.
- Next.js App Router, TypeScript, React. One dashboard. Route handlers for portfolio load, per-domain PATCH, DNS, URL forwarding, search, availability, register, Fix All (server-sent events), and a two-step audit.
- name.com CORE v1 (
@namecom/core-api): list, get, DNS records, URL forwarding, PATCH auto-renew / privacy / lock, search, availability, register. - Health engine. Expiry windows, auto-renew, “in use” (records or a forward), privacy, lock. At-risk dollars use each domain’s
renewalPrice. - Groq (
openai/gpt-oss-120b) with JSON responses and a tight action allow-list so verdicts stay executable. - Fix All as an event stream: score → remediate → re-score → report risk that left the books.
- Nutrient DWS Processor (
@nutrient-sdk/dws-client-typescript,api.nutrient.io). Redaction presets for email and phone in a single/build. Signing is a separate/sign(cms, CAdES-B-B) placed on the last page from the PDF’s own page count and MediaBox. Registrant contacts are stripped before Groq or Nutrient ever see the payload.
Challenges we ran into
- Health is not a dashboard metric. The useful part is mapping issues onto CORE writes. Idle names do not need “add DNS” advice — they need a redirect or they need to stop renewing.
- Money on screen has to mean something. We refused to imply a registrar refund. The number is avoided waste and loss risk, using real
renewalPricewhen CORE provides it. - Language models invent work. We constrained Groq: JSON only, start with the exact domain name, actions from a closed list. Otherwise you get poetry instead of a PATCH.
- A PDF is not an audit until a human has seen it. Signing inside
/buildwould have been fewer clicks and a worse product. Export draft and Approve & sign are two Nutrient calls on purpose. - Redaction only works if the document contains the right strings — and not the wrong ones. We strip WHOIS contacts from the live payload, then give Nutrient email/phone presets real review-contact text to black out.
- CORE fan-out is expensive if you are naive. Each domain needs get + records + forwards. We cap concurrency so the portfolio loads as one pass, not a timeout.
Accomplishments that we're proud of
- CORE is the product: list, inspect, PATCH, forward, search, check, register — wired into one operator surface.
- Fix All you can watch, then a portfolio that actually changes.
- Verdicts that sound like an on-call, not an alert banner.
- Nutrient as a workflow: HTML → redacted PDF → human review → CMS-signed audit. That is the file you attach to a ticket.
What we learned
- A registrar API is wide enough to run a real ops tool, not just a “hello domain” sample.
- Domain health is a handful of booleans and dates. Product quality is the actions those checks unlock.
- Constraining the model matters more than picking a clever one.
- Document APIs want a human in the loop. Splitting Nutrient
/buildand/signis the difference between a watermark and a record. - Strip real PII. Plant only what you intend to redact.
What's next for Portfolio Pulse
- Alerts before the 30-day critical window — email or webhook, not another dashboard visit.
- Recurring Nutrient audits: a signed monthly PDF as inventory, not a one-off export.
- DNS that can tell a parked page from a live site.
- Team / multi-account view.
- Transfer-in and nameserver changes as first-class remediations.
Built With
- ai
- name.com
- nextjs
- nutrient
- nutrient-dws
- typescript
Log in or sign up for Devpost to join the conversation.