Getting started
How an Orbit account is organised, what lives where in the console, and the shortest path from signing in to serving a name from our network.
The command line tool, the SDKs, the MCP server and the API reference are generated from the same definition as the API itself, so each of them covers every endpoint the day it ships.
One file, no dependencies. It needs Node.js 22.18 or later.
curl -fsSLo orbit.mjs https://orbit.yunzheng.space/cli/orbit.mjs
node orbit.mjs --helpCommands are grouped by product: dns, shield, pages, link, verify, mail, meet, vgate and the rest. node orbit.mjs dns --help lists a product's commands; add --help to any command for its fields.
Create a token on the API page of the console, then save it as a profile. A read-only token is enough for everything that only looks.
node orbit.mjs login --token orb_…
node orbit.mjs whoami| Where | |
|---|---|
| Token | --token, then ORBIT_TOKEN, then the saved profile |
| Profiles | ~/.config/orbit/config.json; pick one with --profile or ORBIT_PROFILE |
node orbit.mjs dns zones list
node orbit.mjs dns records create 42 --name www --type A --content 192.0.2.10 --ttl 300
node orbit.mjs dns records list 42 --all --json
node orbit.mjs shield sites purge 7 --urls /index.html,/app.js--json prints the answer as it came; --all follows every page of a list.--yes in scripts.Describe zones, records and Shield sites in a file kept with your code. plan shows what would change; apply makes the account match.
export default {
zones: [{
name: "example.com",
records: [
{ name: "www", type: "A", content: "192.0.2.10", ttl: 300 },
{ name: "@", type: "MX", content: "10 mx.example.com" },
],
}],
sites: [{ hostname: "www.example.com", origin: "192.0.2.10", force_https: true }],
};node orbit.mjs plan -f orbit.config.ts
node orbit.mjs apply -f orbit.config.tsprune: true.plan exits with code 2 when there are changes, so a pipeline can stop on drift.apply asks before changing anything; --yes skips the question.orbit.config.json.The MCP server offers every endpoint as a tool. Add it to any client that supports remote MCP servers, with your token as the Authorization header.
{
"mcpServers": {
"orbit": {
"url": "https://dash.yunzheng.space/mcp",
"headers": { "Authorization": "Bearer orb_…" }
}
}
}?readonly=1 to the address to keep a write token read-only for this client.?products=dns,shield.In a browser with an agent built in, the console offers tools for the page you are on: list, add and delete records on a zone, show a Shield site and purge its cache. They act with your own sign-in, and deleting or purging asks you on screen first.
All of them. Commands, SDK methods, MCP tools and the reference pages are generated from the API definition, and a check fails the build when any of them falls behind it.
A write tool on the MCP server only runs when called with an explicit confirmation, after a preview. Use a read-only token, or add ?readonly=1 to the address, and it cannot change anything at all.
How an Orbit account is organised, what lives where in the console, and the shortest path from signing in to serving a name from our network.
Add a zone, point your registrar at our name servers, manage records: weighted answers, health-checked records, ALIAS at the apex, zone-file import.
Delegate the whole domain, delegate one hostname, or add a CNAME and leave your DNS where it is. What each one costs you and when to pick it.