Account API reference
Every Account endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.
30 endpoints, 13 of them read-only. Every one is also a command in the orbit CLI, a method in the SDKs and a tool on the MCP server.
| Endpoint | Scope | Parameters | CLI · MCP tool |
|---|---|---|---|
GET /dns/listsThe blocklist catalogue | read | — | orbit dns listsdns_lists |
| Endpoint | Scope | Parameters | CLI · MCP tool |
|---|---|---|---|
GET /dns/zonesList zones | read | ?limit integer?offset integer?service_id integer | orbit dns zones listdns_zones_list |
POST /dns/zonesCreate a zone | write | body: service_id* integer, name* string, mode zone | host | orbit dns zones createdns_zones_create |
GET /dns/zones/{id}Get a zone | read | id integer | orbit dns zones get <id>dns_zones_get |
PATCH /dns/zones/{id}Enable/disable or set secondary master | write | id integerbody: enabled boolean, secondary_master string, negative_ttl integer | orbit dns zones patch <id>dns_zones_patch |
DELETE /dns/zones/{id}Delete a zone (and its records, Shield sites, rules) | write | id integer | orbit dns zones delete <id>dns_zones_delete |
POST /dns/zones/{id}/verifyCheck NS delegation; activates the zone when it points at ns1/ns2 | write | id integer | orbit dns zones verify <id>dns_zones_verify |
GET /dns/zones/{id}/dnssecDNSSEC status with DS / DNSKEY | read | id integer | orbit dns zones dnssec get <id>dns_zones_dnssec_get |
PUT /dns/zones/{id}/dnssecEnable or disable DNSSEC (online-signed ECDSA P-256) | write | id integerbody: enabled* boolean | orbit dns zones dnssec put <id>dns_zones_dnssec_put |
GET /dns/zones/{id}/grantsPeople this zone is shared with | read | id integer | orbit dns zones grants list <id>dns_zones_grants_list |
PUT /dns/zones/{id}/grants/{email}Share the zone with a person (viewer or operator) | write | id integeremail stringbody: role* viewer | operator | orbit dns zones grants put <id> <email>dns_zones_grants_put |
DELETE /dns/zones/{id}/grants/{email}Stop sharing the zone with a person | write | id integeremail string | orbit dns zones grants delete <id> <email>dns_zones_grants_delete |
GET /dns/zones/{id}/transferOutbound AXFR allowlist, NOTIFY targets, TSIG | read | id integer | orbit dns zones transfer get <id>dns_zones_transfer_get |
PUT /dns/zones/{id}/transferSet transfer settings | write | id integerbody: allow string[], notify string[], tsig boolean | orbit dns zones transfer put <id>dns_zones_transfer_put |
GET /dns/zones/{id}/analyticsQuery analytics merged across PoPs | read | id integer | orbit dns zones analytics <id>dns_zones_analytics |
GET /dns/zones/{id}/exportExport as a BIND zone file | read | id integer | orbit dns zones export <id>dns_zones_export |
POST /dns/zones/{id}/importImport a BIND zone file (preview or apply); SOA and apex NS are ignored, exact duplicates skipped | write | id integerbody: text* string, mode preview | apply, replace boolean | orbit dns zones import <id>dns_zones_import |
POST /dns/zones/{id}/migration/planWhere is this zone served today, and how can it move to Orbit | read | id integer | orbit dns zones migration plan <id>dns_zones_migration_plan |
POST /dns/zones/{id}/migration/applyImport the zone (AXFR from the current master, or a zone file), then follow the registrar steps | write | id integerbody: mode* axfr | zonefile | fresh, master_ip string, zonefile string | orbit dns zones migration apply <id>dns_zones_migration_apply |
| Endpoint | Scope | Parameters | CLI · MCP tool |
|---|---|---|---|
GET /dns/zones/{id}/rangesAddress-range grants in a reverse zone | read | id integer | orbit dns ranges list <id>dns_ranges_list |
POST /dns/zones/{id}/rangesGrant an address range inside a reverse zone | write | id integerbody: prefix* string, owner string, external_ref string, note string | orbit dns ranges create <id>dns_ranges_create |
PATCH /dns/zones/{id}/ranges/{rid}Move a grant to another range or owner | write | id integerrid integerbody: prefix string, owner string, note string, enabled boolean | orbit dns ranges patch <id> <rid>dns_ranges_patch |
DELETE /dns/zones/{id}/ranges/{rid}Withdraw a grant (records are left alone) | write | id integerrid integer | orbit dns ranges delete <id> <rid>dns_ranges_delete |
GET /dns/rangesEvery address range granted to you, across zones | read | — | orbit dns ranges minedns_ranges_mine |
POST /dns/rangesGrant an address range without naming a zone; the covering reverse zone is found for you | write | body: prefix* string, owner string, external_ref string, note string | orbit dns ranges grantdns_ranges_grant |
| Endpoint | Scope | Parameters | CLI · MCP tool |
|---|---|---|---|
GET /dns/zones/{id}/recordsList records | read | id integer?limit integer?offset integer | orbit dns records list <id>dns_records_list |
POST /dns/zones/{id}/recordsAdd a record | write | id integerbody: name string, type* A | AAAA | PTR | CNAME | TXT | MX | NS | SRV | CAA | ALIAS | HTTPS | SVCB, ttl integer, content* string, weight integer, health_check string | orbit dns records create <id>dns_records_create |
GET /dns/zones/{id}/records/{rid}Get a record | read | id integerrid integer | orbit dns records get <id> <rid>dns_records_get |
PATCH /dns/zones/{id}/records/{rid}Update a record (content, TTL, steering, enabled, proxied) | write | id integerrid integerbody: content string, ttl integer, weight integer, health_check string, enabled boolean, proxied boolean | orbit dns records patch <id> <rid>dns_records_patch |
DELETE /dns/zones/{id}/records/{rid}Delete a record | write | id integerrid integer | orbit dns records delete <id> <rid>dns_records_delete |
Every Account endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.
Every Organization endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.
Every Services endpoint in the Orbit API (15): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.