DNS API reference

DNS API.

30 endpoints, 13 of them read-only. Every one is also a command in the orbit CLI, a method in the SDKs and a tool on the MCP server.

01

General

EndpointScopeParametersCLI · MCP tool
GET /dns/lists
The blocklist catalogue
read—orbit dns lists
dns_lists
02

zones

EndpointScopeParametersCLI · MCP tool
GET /dns/zones
List zones
read?limit integer
?offset integer
?service_id integer
orbit dns zones list
dns_zones_list
POST /dns/zones
Create a zone
writebody: service_id* integer, name* string, mode zone | hostorbit dns zones create
dns_zones_create
GET /dns/zones/{id}
Get a zone
readid integerorbit dns zones get <id>
dns_zones_get
PATCH /dns/zones/{id}
Enable/disable or set secondary master
writeid integer
body: enabled boolean, secondary_master string, negative_ttl integer
orbit dns zones patch <id>
dns_zones_patch
DELETE /dns/zones/{id}
Delete a zone (and its records, Shield sites, rules)
writeid integerorbit dns zones delete <id>
dns_zones_delete
POST /dns/zones/{id}/verify
Check NS delegation; activates the zone when it points at ns1/ns2
writeid integerorbit dns zones verify <id>
dns_zones_verify
GET /dns/zones/{id}/dnssec
DNSSEC status with DS / DNSKEY
readid integerorbit dns zones dnssec get <id>
dns_zones_dnssec_get
PUT /dns/zones/{id}/dnssec
Enable or disable DNSSEC (online-signed ECDSA P-256)
writeid integer
body: enabled* boolean
orbit dns zones dnssec put <id>
dns_zones_dnssec_put
GET /dns/zones/{id}/grants
People this zone is shared with
readid integerorbit dns zones grants list <id>
dns_zones_grants_list
PUT /dns/zones/{id}/grants/{email}
Share the zone with a person (viewer or operator)
writeid integer
email string
body: role* viewer | operator
orbit dns zones grants put <id> <email>
dns_zones_grants_put
DELETE /dns/zones/{id}/grants/{email}
Stop sharing the zone with a person
writeid integer
email string
orbit dns zones grants delete <id> <email>
dns_zones_grants_delete
GET /dns/zones/{id}/transfer
Outbound AXFR allowlist, NOTIFY targets, TSIG
readid integerorbit dns zones transfer get <id>
dns_zones_transfer_get
PUT /dns/zones/{id}/transfer
Set transfer settings
writeid integer
body: allow string[], notify string[], tsig boolean
orbit dns zones transfer put <id>
dns_zones_transfer_put
GET /dns/zones/{id}/analytics
Query analytics merged across PoPs
readid integerorbit dns zones analytics <id>
dns_zones_analytics
GET /dns/zones/{id}/export
Export as a BIND zone file
readid integerorbit dns zones export <id>
dns_zones_export
POST /dns/zones/{id}/import
Import a BIND zone file (preview or apply); SOA and apex NS are ignored, exact duplicates skipped
writeid integer
body: text* string, mode preview | apply, replace boolean
orbit dns zones import <id>
dns_zones_import
POST /dns/zones/{id}/migration/plan
Where is this zone served today, and how can it move to Orbit
readid integerorbit dns zones migration plan <id>
dns_zones_migration_plan
POST /dns/zones/{id}/migration/apply
Import the zone (AXFR from the current master, or a zone file), then follow the registrar steps
writeid integer
body: mode* axfr | zonefile | fresh, master_ip string, zonefile string
orbit dns zones migration apply <id>
dns_zones_migration_apply
03

ranges

EndpointScopeParametersCLI · MCP tool
GET /dns/zones/{id}/ranges
Address-range grants in a reverse zone
readid integerorbit dns ranges list <id>
dns_ranges_list
POST /dns/zones/{id}/ranges
Grant an address range inside a reverse zone
writeid integer
body: prefix* string, owner string, external_ref string, note string
orbit dns ranges create <id>
dns_ranges_create
PATCH /dns/zones/{id}/ranges/{rid}
Move a grant to another range or owner
writeid integer
rid integer
body: prefix string, owner string, note string, enabled boolean
orbit dns ranges patch <id> <rid>
dns_ranges_patch
DELETE /dns/zones/{id}/ranges/{rid}
Withdraw a grant (records are left alone)
writeid integer
rid integer
orbit dns ranges delete <id> <rid>
dns_ranges_delete
GET /dns/ranges
Every address range granted to you, across zones
read—orbit dns ranges mine
dns_ranges_mine
POST /dns/ranges
Grant an address range without naming a zone; the covering reverse zone is found for you
writebody: prefix* string, owner string, external_ref string, note stringorbit dns ranges grant
dns_ranges_grant
04

records

EndpointScopeParametersCLI · MCP tool
GET /dns/zones/{id}/records
List records
readid integer
?limit integer
?offset integer
orbit dns records list <id>
dns_records_list
POST /dns/zones/{id}/records
Add a record
writeid integer
body: name string, type* A | AAAA | PTR | CNAME | TXT | MX | NS | SRV | CAA | ALIAS | HTTPS | SVCB, ttl integer, content* string, weight integer, health_check string
orbit dns records create <id>
dns_records_create
GET /dns/zones/{id}/records/{rid}
Get a record
readid integer
rid integer
orbit dns records get <id> <rid>
dns_records_get
PATCH /dns/zones/{id}/records/{rid}
Update a record (content, TTL, steering, enabled, proxied)
writeid integer
rid integer
body: content string, ttl integer, weight integer, health_check string, enabled boolean, proxied boolean
orbit dns records patch <id> <rid>
dns_records_patch
DELETE /dns/zones/{id}/records/{rid}
Delete a record
writeid integer
rid integer
orbit dns records delete <id> <rid>
dns_records_delete
Next

Related

Account API reference

Every Account endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.

Organization API reference

Every Organization endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.

Services API reference

Every Services endpoint in the Orbit API (15): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.

← All documentation