dnswizdocs

API reference

The complete dnswiz HTTP API. New to it? Start with theQuickstart, it walks the create-zone → add-record → verify thread end to end.

Example requests below assume $DNSWIZ_API_KEY is exported. Mint one in console → Settings → API keys.

Auth & conventions

auth

POST/v1/auth/send

Send a magic-link sign-in email.

Request body
object
Responses
StatusDescriptionSchema
200link sent (always 200, no enumeration leak)object
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/send
POST/v1/auth/verify

Verify a magic-link token and start a session.

If the email is new, a tenant is auto-created with the user as owner and a sample zone is seeded. If the email exists, a session is attached to the existing tenant.

Request body
object
Responses
StatusDescriptionSchema
200session createdobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/verify
POST/v1/auth/logout

Revoke the current session.

Responses
StatusDescriptionSchema
204revoked
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/logout \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/auth/mfa/state

Whether the caller has TOTP MFA enrolled.

Responses
StatusDescriptionSchema
200enrollment stateobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/auth/mfa/state \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/auth/mfa/enroll/start

Begin TOTP enrollment; returns the otpauth URL and one-time recovery codes.

Responses
StatusDescriptionSchema
200enrollment secret and recovery codesobject
409already enrolled (disable first)
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/mfa/enroll/start \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/auth/mfa/enroll/verify

Confirm the first TOTP code to activate enrollment.

Request body
MFACode
Responses
StatusDescriptionSchema
200enrolledobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/mfa/enroll/verify \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/auth/mfa/verify

Clear the MFA gate for the current session with a TOTP code.

Request body
MFACode
Responses
StatusDescriptionSchema
200verifiedobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/mfa/verify \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/auth/mfa/recovery

Clear the MFA gate using a recovery code instead of a TOTP code.

Request body
MFACode
Responses
StatusDescriptionSchema
200verifiedobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/mfa/recovery \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/auth/mfa

Disable MFA for the caller (requires a current TOTP code).

Request body
MFACode
Responses
StatusDescriptionSchema
200disabledobject
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/auth/mfa \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/auth/restorable

List the caller's soft-deleted workspaces still inside the 30-day purge window.

Responses
StatusDescriptionSchema
200restorable workspacesobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/auth/restorable \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/auth/restore/{tenant_id}

Undelete a soft-deleted workspace (owner or admin only).

Responses
StatusDescriptionSchema
200restoredobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/auth/restore/{tenant_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

me

GET/v1/me

Get the current user, tenant, plan, usage, and onboarding state.

Responses
StatusDescriptionSchema
200profileMe
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/me/dashboard

Workspace cockpit, vital signs, top names/zones, certs, incidents.

Responses
StatusDescriptionSchema
200dashboard payloadDashboard
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me/dashboard \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/me/account

Update the current user's display name.

Request body
object
Responses
StatusDescriptionSchema
204updated
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/me/account \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/me/export

Download every zone + record as a ZIP bundle.

Responses
StatusDescriptionSchema
200zip archive
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me/export \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/me/cert-config

Get the tenant's ACME/cert-issuance config (own overrides plus effective values).

Responses
StatusDescriptionSchema
200cert configCertConfig
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me/cert-config \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/me/cert-config

Override the tenant's ACME directory, account email, or EAB credentials.

Request body
CertConfig
Responses
StatusDescriptionSchema
200updated cert configCertConfig
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/me/cert-config \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/me/cert-config

Revert the tenant to the platform default ACME config.

Responses
StatusDescriptionSchema
200reverted cert configCertConfig
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/me/cert-config \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/me/tenant

Update workspace settings (name, billing email, record/SOA/negative-TTL defaults).

Partial update. Empty string clears billing_email/default_soa_rname; a negative default_negative_ttl clears it.

Request body
object
Responses
StatusDescriptionSchema
204updated
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/me/tenant \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/me/tenant

Soft-delete the workspace (30-day grace, then purged).

Requires sudo and a name-match confirmation in the body. The soft-delete cancels Stripe subscriptions immediately and starts the 30-day purge clock.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
object
Responses
StatusDescriptionSchema
204deleted (soft)
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/me/tenant \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

plans

GET/v1/plans

List public pricing tiers.

Responses
StatusDescriptionSchema
200plansPlan[]
defaultProblem
Example request
curl https://api.dnswiz.app/v1/plans

zones

GET/v1/zones

List zones.

Parameters
NameInTypeRequired
cursorquerystringno
limitqueryintegerno
Responses
StatusDescriptionSchema
200page of zonesZonePage
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/zones

Create a zone.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
ZoneCreate
Responses
StatusDescriptionSchema
201createdZone
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/zones \
  -H "Authorization: Bearer $DNSWIZ_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "name": "example.com"
     }'
Example response
{
  "id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "example.com.",
  "active": true,
  "created_at": "2026-05-28T09:00:00Z",
  "updated_at": "2026-05-28T09:00:00Z"
}
GET/v1/zones/{zone_id}

Get a zone.

Responses
StatusDescriptionSchema
200zoneZone
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
Example response
{
  "id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "example.com.",
  "active": true,
  "created_at": "2026-05-28T09:00:00Z",
  "updated_at": "2026-05-28T09:00:00Z"
}
PATCH/v1/zones/{zone_id}

Update a zone (activation and SOA/TTL defaults).

Partial update; send at least one field. Clear sentinels: send a negative `default_ttl` or `negative_ttl` to clear it (inherit the default), and an empty `soa_rname` to clear it.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
ZoneUpdate
Responses
StatusDescriptionSchema
200updatedZone
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/zones/{zone_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
Example response
{
  "id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "example.com.",
  "active": true,
  "created_at": "2026-05-28T09:00:00Z",
  "updated_at": "2026-05-28T09:00:00Z"
}
DELETE/v1/zones/{zone_id}

Delete a zone.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/zones/{zone_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/zones/{zone_id}/health

Zone health report (overall + per-category scores + individual checks).

Recomputed on every request; not persisted.

Responses
StatusDescriptionSchema
200health reportZoneHealth
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id}/health \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/zones/{zone_id}/health/ack

Acknowledge (mute) a health check with a reason.

Request body
object
Responses
StatusDescriptionSchema
204acknowledged
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/zones/{zone_id}/health/ack \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/zones/{zone_id}/health/ack/{check_id}

Clear a health-check acknowledgement.

Responses
StatusDescriptionSchema
204cleared
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/zones/{zone_id}/health/ack/{check_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

records

GET/v1/zones/{zone_id}/records

List records in a zone.

Parameters
NameInTypeRequired
cursorquerystringno
limitqueryintegerno
Responses
StatusDescriptionSchema
200page of recordsRecordPage
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id}/records \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/zones/{zone_id}/records

Create a record.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
RecordCreate
Responses
StatusDescriptionSchema
201createdRecord
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/zones/{zone_id}/records \
  -H "Authorization: Bearer $DNSWIZ_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "name": "www",
       "type": "A",
       "ttl": 300,
       "data": {
         "value": "203.0.113.10"
       }
     }'
Example response
{
  "id": "11111111-0000-0000-0000-000000000000",
  "zone_id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "www",
  "fqdn": "www.example.com.",
  "type": "A",
  "ttl": 300,
  "ttl_inherit": false,
  "data": {
    "value": "203.0.113.10"
  },
  "active": true,
  "created_at": "2026-05-28T09:01:00Z",
  "updated_at": "2026-05-28T09:01:00Z"
}
GET/v1/records/{record_id}

Get a record.

Responses
StatusDescriptionSchema
200recordRecord
defaultProblem
Example request
curl https://api.dnswiz.app/v1/records/{record_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
Example response
{
  "id": "11111111-0000-0000-0000-000000000000",
  "zone_id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "www",
  "fqdn": "www.example.com.",
  "type": "A",
  "ttl": 300,
  "ttl_inherit": false,
  "data": {
    "value": "203.0.113.10"
  },
  "active": true,
  "created_at": "2026-05-28T09:01:00Z",
  "updated_at": "2026-05-28T09:01:00Z"
}
PATCH/v1/records/{record_id}

Update a record.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
RecordUpdate
Responses
StatusDescriptionSchema
200updatedRecord
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/records/{record_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
Example response
{
  "id": "11111111-0000-0000-0000-000000000000",
  "zone_id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "www",
  "fqdn": "www.example.com.",
  "type": "A",
  "ttl": 300,
  "ttl_inherit": false,
  "data": {
    "value": "203.0.113.10"
  },
  "active": true,
  "created_at": "2026-05-28T09:01:00Z",
  "updated_at": "2026-05-28T09:01:00Z"
}
DELETE/v1/records/{record_id}

Delete a record.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/records/{record_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/records/{record_id}/test

Live-dig, resolve the record from the dnswiz edge fleet and return raw answers.

Request body
object
Responses
StatusDescriptionSchema
200dig resultLiveDig
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/records/{record_id}/test \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/records/{record_id}/canary/abort

Snap a CANARY record back to its primary (set ramp to 0%).

Responses
StatusDescriptionSchema
200abortedRecord
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/records/{record_id}/canary/abort \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
Example response
{
  "id": "11111111-0000-0000-0000-000000000000",
  "zone_id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "www",
  "fqdn": "www.example.com.",
  "type": "A",
  "ttl": 300,
  "ttl_inherit": false,
  "data": {
    "value": "203.0.113.10"
  },
  "active": true,
  "created_at": "2026-05-28T09:01:00Z",
  "updated_at": "2026-05-28T09:01:00Z"
}
POST/v1/records/{record_id}/canary/resume

Resume a paused CANARY record from its current percentage.

Responses
StatusDescriptionSchema
200resumedRecord
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/records/{record_id}/canary/resume \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
Example response
{
  "id": "11111111-0000-0000-0000-000000000000",
  "zone_id": "a1b2c3d4-0000-0000-0000-000000000000",
  "name": "www",
  "fqdn": "www.example.com.",
  "type": "A",
  "ttl": 300,
  "ttl_inherit": false,
  "data": {
    "value": "203.0.113.10"
  },
  "active": true,
  "created_at": "2026-05-28T09:01:00Z",
  "updated_at": "2026-05-28T09:01:00Z"
}
GET/v1/records/{record_id}/target-stats

Observed per-endpoint answer share for a GSLB record over a window.

Parameters
NameInTypeRequired
windowquerystringno
Responses
StatusDescriptionSchema
200target statsRecordTargetStats
defaultProblem
Example request
curl https://api.dnswiz.app/v1/records/{record_id}/target-stats \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/zones/{zone_id}/records/import

Import a BIND-style zonefile (preview, or commit the parsed records).

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
RecordImport
Responses
StatusDescriptionSchema
200import preview or commit resultRecordImportResult
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/zones/{zone_id}/records/import \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

pools

GET/v1/pools

List pools.

Parameters
NameInTypeRequired
cursorquerystringno
limitqueryintegerno
Responses
StatusDescriptionSchema
200page of poolsPoolPage
defaultProblem
Example request
curl https://api.dnswiz.app/v1/pools \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/pools

Create a pool.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
PoolCreate
Responses
StatusDescriptionSchema
200createdPool
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/pools \
  -H "Authorization: Bearer $DNSWIZ_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "name": "api-us-east",
       "health_monitor_id": "9a000000-0000-0000-0000-000000000000",
       "selection_method": "active-passive"
     }'
GET/v1/pools/memberships

List every pool membership across the workspace (endpoint to pool, with weight).

Responses
StatusDescriptionSchema
200membershipsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/pools/memberships \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/pools/gslb-services

List GSLB records (POOL/GEO/CANARY) and the pools they route to.

Paged: a workspace with a hundred services, each with its pools and members, is a large response on a short refresh, and the caller cannot bound what it has already been sent. Default order puts the services least able to answer first, so what is broken is on the first page.

Parameters
NameInTypeRequired
qquerystringno
onlyquerystring (silent)no
sortquerystring (health | name)no
limitqueryintegerno
offsetqueryintegerno
Responses
StatusDescriptionSchema
200gslb servicesobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/pools/gslb-services \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/pools/gslb-services

Create a load-balanced name and everything under it in one transaction.

Serving one name from several addresses otherwise means creating a health check, an endpoint per address, a pool, a member per endpoint and a DNS record, in an order that is not guessable, each able to fail and leave the rest behind. This creates them together or not at all. Give either `answers` to build a new pool from, or `pool_ids` that already exist; both together is refused rather than guessed at.

Request body
GSLBServiceCreate
Responses
StatusDescriptionSchema
200createdGSLBServiceCreated
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/pools/gslb-services \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/pools/{id}

Get a pool (aggregate health and member counts; members are a sub-resource).

Responses
StatusDescriptionSchema
200poolPool
defaultProblem
Example request
curl https://api.dnswiz.app/v1/pools/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/pools/{id}

Update pool name, description, health monitor, or selection method.

Request body
PoolUpdate
Responses
StatusDescriptionSchema
200updatedPool
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/pools/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/pools/{id}

Delete a pool. Fails (409) if any record still references it.

Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/pools/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/pools/{id}/members

List a pool's members.

Responses
StatusDescriptionSchema
200membersobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/pools/{id}/members \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/pools/{id}/members

Attach an existing endpoint as a pool member (idempotent; re-adding updates weight).

Request body
object
Responses
StatusDescriptionSchema
200attachedPoolMember
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/pools/{id}/members \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/pools/{id}/members/inline

Create an endpoint and attach it as a member in one call.

Request body
PoolMemberInline
Responses
StatusDescriptionSchema
200created and attachedobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/pools/{id}/members/inline \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/pools/{id}/records

List the DNS records that reference this pool.

Responses
StatusDescriptionSchema
200recordsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/pools/{id}/records \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/pools/{id}/members/{member_id}

Update member weight or priority.

Request body
object
Responses
StatusDescriptionSchema
200updatedPoolMember
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/pools/{id}/members/{member_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/pools/{id}/members/{member_id}

Detach a member from a pool.

Responses
StatusDescriptionSchema
204detached
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/pools/{id}/members/{member_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/pools/{id}/members/{member_id}/enabled

Flip member enabled (drain / un-drain without deleting).

Request body
object
Responses
StatusDescriptionSchema
200updatedPoolMember
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/pools/{id}/members/{member_id}/enabled \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

endpoints

GET/v1/endpoints

List health-checked endpoints.

Parameters
NameInTypeRequired
cursorquerystringno
limitqueryintegerno
Responses
StatusDescriptionSchema
200page of endpointsEndpointPage
defaultProblem
Example request
curl https://api.dnswiz.app/v1/endpoints \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/endpoints

Create an endpoint.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
EndpointCreate
Responses
StatusDescriptionSchema
201createdEndpoint
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/endpoints \
  -H "Authorization: Bearer $DNSWIZ_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "name": "api-us-east-1",
       "kind": "https",
       "target": "https://api-us-east.example.com/healthz",
       "value": "203.0.113.10",
       "expected_status": 200
     }'
GET/v1/endpoints/{id}

Get an endpoint with current health + recent incidents.

Responses
StatusDescriptionSchema
200endpointEndpoint
defaultProblem
Example request
curl https://api.dnswiz.app/v1/endpoints/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/endpoints/{id}

Update an endpoint.

Request body
EndpointCreate
Responses
StatusDescriptionSchema
200updatedEndpoint
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/endpoints/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "name": "api-us-east-1",
       "kind": "https",
       "target": "https://api-us-east.example.com/healthz",
       "value": "203.0.113.10",
       "expected_status": 200
     }'
DELETE/v1/endpoints/{id}

Delete an endpoint (also removes pool memberships).

Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/endpoints/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/endpoints/{id}/detail

Endpoint detail with uptime buckets and incident history over a window.

Parameters
NameInTypeRequired
windowquerystring (24h | 7d | 30d | 90d)no
Responses
StatusDescriptionSchema
200endpoint detailEndpointDetail
defaultProblem
Example request
curl https://api.dnswiz.app/v1/endpoints/{id}/detail \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

health-monitors

GET/v1/health-monitors

List reusable probe policies.

Responses
StatusDescriptionSchema
200monitorsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/health-monitors \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/health-monitors

Create a named monitor (interval/timeout/thresholds/expected status).

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
HealthMonitorCreate
Responses
StatusDescriptionSchema
201createdHealthMonitor
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/health-monitors \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/health-monitors/{id}

Get a monitor.

Responses
StatusDescriptionSchema
200monitorHealthMonitor
defaultProblem
Example request
curl https://api.dnswiz.app/v1/health-monitors/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/health-monitors/{id}

Update a monitor (changes propagate to every attached member on next probe tick).

Request body
HealthMonitorCreate
Responses
StatusDescriptionSchema
200updatedHealthMonitor
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/health-monitors/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/health-monitors/{id}

Delete a monitor. Members that referenced it fall back to defaults.

Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/health-monitors/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/health-monitors/{id}/clone

Clone a monitor (including a preset) into a new editable monitor.

Request body
object
Responses
StatusDescriptionSchema
201createdHealthMonitor
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/health-monitors/{id}/clone \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

policies

GET/v1/me/policies

List tenant-default policies (apply across every zone unless overridden).

Responses
StatusDescriptionSchema
200policiesPolicy[]
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me/policies \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/me/policies/{kind}

Update a tenant-default policy (enable/disable, set config).

Request body
PolicyUpdate
Responses
StatusDescriptionSchema
200updatedPolicy
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/me/policies/{kind} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/zones/{zone_id}/security

List per-zone policies (firewall, hijack monitor) with their effective config.

Responses
StatusDescriptionSchema
200policiesPolicy[]
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id}/security \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/zones/{zone_id}/security/{kind}

Update a per-zone policy (overrides tenant default).

Request body
PolicyUpdate
Responses
StatusDescriptionSchema
200updatedPolicy
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/zones/{zone_id}/security/{kind} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/zones/{zone_id}/security/hijack-probes

Recent hijack-probe results (every 5 min from 8 public resolvers).

Responses
StatusDescriptionSchema
200probesHijackProbe[]
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id}/security/hijack-probes \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

certs

GET/v1/certs

List issued certificates (most recent 500; not paginated).

Responses
StatusDescriptionSchema
200issued certificatesobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/certs \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/certs/issue

Issue (or re-issue) a TLS cert via ACME DNS-01. Returns the signed cert + chain.

Two flows: send a `csr` (you keep the private key; the response omits key_pem) or send `names` (dnswiz generates the keypair and returns key_pem once). Supply exactly one. dnswiz solves the DNS-01 challenge against its own authoritative zones.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
CertIssueRequest
Responses
StatusDescriptionSchema
200issuedCertIssueResponse
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/certs/issue \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/certs/coverage

Names that resolve to a public IP but have no covering TLS cert (gap detector).

Responses
StatusDescriptionSchema
200coverageCertCoverage
defaultProblem
Example request
curl https://api.dnswiz.app/v1/certs/coverage \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

firewall

GET/v1/me/firewall/refused

Live ring buffer of recent firewall refusals (in-memory, ~1h, ≤200/tenant).

Parameters
NameInTypeRequired
limitqueryintegerno
Responses
StatusDescriptionSchema
200refusals, newest firstobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me/firewall/refused \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

insights

GET/v1/zones/{zone_id}/insights

Query stats, top names, latency, and qtype/rcode/country breakdowns for a zone.

Parameters
NameInTypeRequired
windowquerystring (1h | 24h | 7d | 30d)no
Responses
StatusDescriptionSchema
200insights payloadInsights
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id}/insights \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/zones/{zone_id}/records/query-counts

Per-record query counts for a zone over a window (keyed by owner label).

Parameters
NameInTypeRequired
windowquerystring (1h | 24h | 7d | 30d)no
Responses
StatusDescriptionSchema
200query countsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/zones/{zone_id}/records/query-counts \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

notifications

GET/v1/notifications

List webhook notification channels.

Responses
StatusDescriptionSchema
200channelsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/notifications \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/notifications

Create a webhook notification channel (returns the signing secret once).

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
NotificationChannelCreate
Responses
StatusDescriptionSchema
201createdNotificationChannel
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/notifications \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/notifications/log

List every notification raised for the workspace, subscribed to or not.

The history of what the platform noticed, independent of whether any channel was subscribed. Paged on the id of the oldest row returned: pass it back as `before` to continue. An offset would skip or repeat rows, because the log grows at the head while it is being read.

Parameters
NameInTypeRequired
eventquerystringno
beforequeryinteger <int64>no
limitqueryintegerno
Responses
StatusDescriptionSchema
200notificationsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/notifications/log \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/notifications/{id}

Get a notification channel.

Responses
StatusDescriptionSchema
200channelNotificationChannel
defaultProblem
Example request
curl https://api.dnswiz.app/v1/notifications/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/notifications/{id}

Update a notification channel.

Request body
NotificationChannelUpdate
Responses
StatusDescriptionSchema
200updatedNotificationChannel
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/notifications/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/notifications/{id}

Delete a notification channel.

Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/notifications/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/notifications/{id}/test

Send a synthetic test event to the channel.

Responses
StatusDescriptionSchema
200queuedobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/notifications/{id}/test \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

team

GET/v1/team/members

List workspace members.

Responses
StatusDescriptionSchema
200membersobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/team/members \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
PATCH/v1/team/members/{user_id}

Change a member's role (cannot target or set owner).

Request body
object
Responses
StatusDescriptionSchema
204updated
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/team/members/{user_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/team/members/{user_id}

Remove a member from the workspace.

Responses
StatusDescriptionSchema
204removed
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/team/members/{user_id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
GET/v1/team/invitations

List pending invitations.

Responses
StatusDescriptionSchema
200invitationsobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/team/invitations \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/team/invitations

Invite someone by email.

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
object
Responses
StatusDescriptionSchema
201invitedInvitation
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/team/invitations \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/team/invitations/accept

Accept an invitation by token; joins the workspace and returns a session scoped to it.

Request body
object
Responses
StatusDescriptionSchema
200joinedobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/team/invitations/accept \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/team/invitations/{id}

Revoke a pending invitation.

Responses
StatusDescriptionSchema
204revoked
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/team/invitations/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

billing

GET/v1/me/billing

Current plan and subscription status.

Responses
StatusDescriptionSchema
200billing summaryobject
defaultProblem
Example request
curl https://api.dnswiz.app/v1/me/billing \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/me/billing/checkout

Start a Stripe Checkout session for a plan upgrade.

Request body
object
Responses
StatusDescriptionSchema
200redirect targetobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/me/billing/checkout \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/me/billing/portal

Start a Stripe Customer Portal session.

Responses
StatusDescriptionSchema
200redirect targetobject
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/me/billing/portal \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

api-keys

GET/v1/api-keys

List API keys (not paginated).

Responses
StatusDescriptionSchema
200api keysApiKey[]
defaultProblem
Example request
curl https://api.dnswiz.app/v1/api-keys \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/api-keys

Create an API key (returns the plaintext secret exactly once).

Parameters
NameInTypeRequired
Idempotency-Keyheaderstringno
Request body
ApiKeyCreate
Responses
StatusDescriptionSchema
201createdApiKeyWithSecret
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/api-keys \
  -H "Authorization: Bearer $DNSWIZ_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "name": "ci-runner",
       "allowed_ips": []
     }'
PATCH/v1/api-keys/{id}

Update a key's source IP allow-list.

Request body
object
Responses
StatusDescriptionSchema
204updated
defaultProblem
Example request
curl -X PATCH https://api.dnswiz.app/v1/api-keys/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
DELETE/v1/api-keys/{id}

Delete an API key permanently.

Responses
StatusDescriptionSchema
204deleted
defaultProblem
Example request
curl -X DELETE https://api.dnswiz.app/v1/api-keys/{id} \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/api-keys/{id}/revoke

Revoke a key (idempotent; the key stops authenticating immediately).

Responses
StatusDescriptionSchema
204revoked
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/api-keys/{id}/revoke \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"
POST/v1/api-keys/{id}/regenerate

Roll a key's secret, returning the new plaintext exactly once.

Responses
StatusDescriptionSchema
200regeneratedApiKeyWithSecret
defaultProblem
Example request
curl -X POST https://api.dnswiz.app/v1/api-keys/{id}/regenerate \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

audit

GET/v1/audit

List audit events.

Parameters
NameInTypeRequired
cursorquerystringno
limitqueryintegerno
resourcequerystringno
actionquerystringno
Responses
StatusDescriptionSchema
200page of audit eventsAuditEventPage
defaultProblem
Example request
curl https://api.dnswiz.app/v1/audit \
  -H "Authorization: Bearer $DNSWIZ_API_KEY"

public

GET/v1/public/check

Free failover-readiness checker; pass a host, get a DNS + latency audit + score.

Parameters
NameInTypeRequired
hostquerystringyes
Responses
StatusDescriptionSchema
200audit resultReadinessCheck
defaultProblem
Example request
curl https://api.dnswiz.app/v1/public/check

system

GET/healthz

Liveness probe.

Responses
StatusDescriptionSchema
200aliveobject
Example request
curl https://api.dnswiz.app/healthz
GET/readyz

Readiness probe (DB reachable).

Responses
StatusDescriptionSchema
200ready
503not ready
Example request
curl https://api.dnswiz.app/readyz

Schemas

Object shapes referenced by the operations above.

ApiKey
FieldTypeRequired
idstring <uuid>yes
namestringyes
prefixstringyes
scopesstring[]yes
allowed_ipsstring[]yes
last_used_atstring <date-time>no
expires_atstring <date-time>no
revoked_atstring <date-time>no
created_atstring <date-time>yes
ApiKeyCreate
FieldTypeRequired
namestringyes
scopesstring[]no
allowed_ipsstring[]no
expires_atstring <date-time>no
ApiKeyWithSecret
AuditEvent
FieldTypeRequired
idinteger <int64>yes
user_idstring <uuid>no
actorstringyes
api_key_idstring <uuid>no
api_key_namestringno
ipstringno
request_idstringno
resourcestringyes
resource_idstring <uuid>no
actionstringyes
beforeobjectno
afterobjectno
occurred_atstring <date-time>yes
AuditEventPage
FieldTypeRequired
itemsAuditEvent[]yes
next_cursorstringyes
CertConfig

Per-tenant ACME override. The bare fields are the tenant's own overrides (empty when not set); the effective_* fields are what issuance actually uses (override, else platform default). The has_*/customized booleans and eab_hmac_b64/clear_eab_hmac are write-once or request-only knobs for the EAB secret.

FieldTypeRequired
directory_urlstringno
account_emailstringno
eab_kidstringno
effective_directory_urlstringno
effective_account_emailstringno
effective_eab_kidstringno
customizedbooleanno
has_own_account_keybooleanno
has_eab_hmacbooleanno
eab_hmac_b64stringno
clear_eab_hmacbooleanno
CertCoverage
FieldTypeRequired
total_namesintegeryes
covered_namesintegeryes
gapsCertCoverageGap[]yes
CertCoverageGap
FieldTypeRequired
namestringyes
record_typestringyes
zone_idstring <uuid>no
zone_namestringno
CertIssuance

A successfully issued certificate. Rows exist only after issuance (there is no pending/failed state).

FieldTypeRequired
idstring <uuid>yes
namestringyes
san_namesstring[]yes
issuerstringyes
serialstringyes
issued_atstring <date-time>yes
expires_atstring <date-time>yes
days_to_expiryintegeryes
CertIssueRequest

Supply exactly one of csr or names.

FieldTypeRequired
csrstringno
namesstring[]no
CertIssueResponse
FieldTypeRequired
key_pemstringno
cert_pemstringyes
issuer_pemstringyes
fullchain_pemstringyes
serialstringyes
expires_atstring <date-time>yes
sansstring[]yes
DNSRow
FieldTypeRequired
valuestringno
ttlintegerno
Dashboard

Workspace cockpit payload. The response is wide and may gain fields over time; the stable, documented ones are below.

FieldTypeRequired
live_qpsnumberno
queries_todayinteger <int64>no
queries_yesterdayinteger <int64>no
queries_monthinteger <int64>no
downtime_prevented_secinteger <int64>no
incidents_count_30dintegerno
zones_healthyintegerno
zones_totalintegerno
top_names_24hobject[]no
countries_24hobject[]no
certsobjectno
generated_atstring <date-time>no
Endpoint

A machine a pool can answer with. `address` is both what DNS returns and what the health check connects to. List and get responses also carry current `health` and 30-day `uptime`.

FieldTypeRequired
idstring <uuid>yes
namestringyes
kindstring (http | https | tcp)yes
addressstringyes
probe_portintegeryes
probe_hoststringno
expected_statusintegeryes
interval_secondsintegeryes
timeout_secondsintegeryes
healthy_afterintegeryes
unhealthy_afterintegeryes
health_monitor_idstring <uuid>no
healthEndpointHealthno
uptimeUptimeno
created_atstring <date-time>yes
updated_atstring <date-time>yes
EndpointCreate
FieldTypeRequired
namestringyes
kindstring (http | https | tcp)yes
addressstringno
probe_portintegerno
expected_statusintegerno
interval_secondsintegerno
timeout_secondsintegerno
healthy_afterintegerno
unhealthy_afterintegerno
health_monitor_idstring <uuid>no
EndpointDetail
FieldTypeRequired
endpointEndpointyes
healthEndpointHealthyes
windowstringyes
uptimeUptimeyes
bucketsobject[]yes
incidentsobject[]yes
EndpointHealth
FieldTypeRequired
endpoint_idstring <uuid>yes
statusstring (up | down | unknown)yes
consecutive_passesintegerno
consecutive_failsintegerno
last_checked_atstring <date-time>no
last_status_change_atstring <date-time>no
last_latency_msintegerno
last_errorstringno
EndpointPage
FieldTypeRequired
itemsEndpoint[]yes
next_cursorstringyes
FlatMembership
FieldTypeRequired
endpoint_idstring <uuid>yes
pool_idstring <uuid>yes
pool_namestringyes
weightintegeryes
GSLBPoolMember
FieldTypeRequired
member_idstring <uuid>yes
endpoint_idstring <uuid>yes
namestringyes
addressstringno
statusstring (up | down | unknown)yes
weightintegeryes
priorityintegeryes
enabledbooleanyes
latency_msintegerno
last_errorstringno
edges_upintegerno
edges_totalintegerno
GSLBPoolRef
FieldTypeRequired
pool_idstring <uuid>yes
pool_namestringyes
rolestringno
missingbooleanno
selection_methodstring (weighted | active-passive | round-robin)no
health_scoreintegeryes
enabled_upintegeryes
enabled_totalintegeryes
membersGSLBPoolMember[]no
GSLBService
FieldTypeRequired
record_idstring <uuid>yes
zone_idstring <uuid>yes
zone_namestringyes
namestringyes
fqdnstringyes
typeRecordTypeyes
ttlintegeryes
poolsGSLBPoolRef[]yes
GSLBServiceCreate
FieldTypeRequired
zone_idstring <uuid>yes
namestringyes
ttlintegerno
selection_methodstring (weighted | active-passive | round-robin)no
answersobject[]no
pool_idsstring <uuid>[]no
checkobjectno
GSLBServiceCreated
FieldTypeRequired
record_idstring <uuid>yes
pool_idsstring <uuid>[]yes
endpoint_idsstring <uuid>[]yes
monitor_idstring <uuid>no
fqdnstringyes
GslbTarget

A GSLB destination used by GEO and CANARY records. Supply exactly one of: an endpoint (`endpoint_id` plus a `value` IP) or a pool (`pool_id`).

FieldTypeRequired
endpoint_idstring <uuid>no
valuestringno
pool_idstring <uuid>no
HealthMonitor

A reusable probe policy (the "what": protocol, path, thresholds). The target host/port lives on the pool member that references it.

FieldTypeRequired
idstring <uuid>yes
namestringyes
is_presetbooleanyes
kindHealthMonitorKindyes
pathstringyes
expected_statusintegeryes
interval_secondsintegeryes
timeout_secondsintegeryes
healthy_afterintegeryes
unhealthy_afterintegeryes
created_atstring <date-time>yes
updated_atstring <date-time>yes
HealthMonitorCreate

Numeric fields left at zero take server defaults on create. On update, zero/empty leaves the field unchanged (so a field cannot be set to 0).

FieldTypeRequired
namestringyes
kindHealthMonitorKindyes
pathstringno
expected_statusintegerno
interval_secondsintegerno
timeout_secondsintegerno
healthy_afterintegerno
unhealthy_afterintegerno
HealthMonitorKind

Probe protocol. udp-dns and udp-ntp are the two UDP probes; there is no ICMP/ping probe.

HijackProbe
FieldTypeRequired
idstring <uuid>yes
probed_atstring <date-time>yes
resolverstringyes
qnamestringyes
qtypestringyes
expectedstringno
observedstringno
divergedbooleanyes
errstringno
Insights

Per-zone insights payload. Latency percentiles are in microseconds.

FieldTypeRequired
window_hoursintegeryes
totalinteger <int64>yes
previous_totalinteger <int64>no
time_seriesobject[]yes
by_qtypeLabeledCount[]yes
by_rcodeLabeledCount[]yes
by_countryLabeledCount[]no
top_namesLabeledCount[]yes
latencyobjectyes
recentobject[]no
generated_atstring <date-time>yes
Invitation
FieldTypeRequired
idstring <uuid>yes
tenant_idstring <uuid>yes
emailstring <email>yes
rolestring (admin | editor | viewer)yes
invited_bystring <uuid>no
expires_atstring <date-time>yes
accepted_atstring <date-time>no
revoked_atstring <date-time>no
created_atstring <date-time>yes
LabeledCount
FieldTypeRequired
labelstringyes
countinteger <int64>yes
LiveDig

Result of resolving a record live from the dnswiz edge fleet.

FieldTypeRequired
questionobjectyes
rcodestringyes
answersobject[]yes
duration_msinteger <int64>yes
picked_endpoint_idstringno
picked_labelstringno
MFACode
FieldTypeRequired
codestringyes
Me
FieldTypeRequired
userobjectyes
tenantobjectyes
rolestring (owner | admin | editor | viewer)yes
planPlanyes
usageobjectyes
onboardingobjectyes
nameserversstring[]yes
Member
FieldTypeRequired
user_idstring <uuid>yes
emailstring <email>yes
namestringyes
rolestring (owner | admin | editor | viewer)yes
joined_atstring <date-time>yes
NotificationChannel

An outbound webhook channel. dnswiz POSTs signed events to `target` for the subscribed `events`.

FieldTypeRequired
idstring <uuid>yes
namestringyes
kindstring (webhook)yes
targetstringyes
secretstringno
eventsstring[]yes
activebooleanyes
created_atstring <date-time>yes
updated_atstring <date-time>yes
NotificationChannelCreate
FieldTypeRequired
namestringyes
kindstring (webhook)yes
targetstringyes
eventsstring[]yes
NotificationChannelUpdate

Partial update; omitted fields are left unchanged.

FieldTypeRequired
namestringno
targetstringno
eventsstring[]no
activebooleanno
NotificationLogEntry
FieldTypeRequired
idinteger <int64>yes
eventstringyes
severitystring (info | warning | critical)yes
occurred_atstring <date-time>yes
dataobjectyes
channels_matchedintegeryes
channels_deliveredintegeryes
channels_failedintegeryes
Plan
FieldTypeRequired
idstring (free | pro | business | enterprise)yes
display_namestringyes
monthly_price_centsintegerno
yearly_price_centsintegerno
max_zonesintegeryes
max_records_per_zoneintegeryes
included_monthly_queriesinteger <int64>yes
gslb_enabledbooleanyes
sso_enabledbooleanyes
audit_export_enabledbooleanyes
byok_enabledbooleanyes
is_enterprisebooleanyes
Policy
FieldTypeRequired
kindstring (hijack_monitor | query_firewall)yes
enabledbooleanyes
configobjectyes
PolicyUpdate
FieldTypeRequired
enabledbooleanno
configobjectno
Pool

A named group of endpoints with a selection method. The body carries aggregate health only; members are a separate sub-resource under /v1/pools/{id}/members.

FieldTypeRequired
idstring <uuid>yes
namestringyes
descriptionstringno
health_monitor_idstring <uuid>yes
selection_methodSelectionMethodyes
member_countintegeryes
health_scoreintegeryes
enabled_upintegeryes
enabled_totalintegeryes
created_atstring <date-time>yes
updated_atstring <date-time>yes
PoolCreate
FieldTypeRequired
namestringyes
descriptionstringno
health_monitor_idstring <uuid>yes
selection_methodno
PoolMember
FieldTypeRequired
idstring <uuid>yes
pool_idstring <uuid>yes
endpoint_idstring <uuid>yes
weightintegeryes
priorityintegeryes
enabledbooleanyes
created_atstring <date-time>yes
PoolMemberInline

Create an endpoint and attach it in one call. Prefer monitor_id (the member inherits the pool's monitor when omitted). The legacy check_url/expected_status/... fields are a fallback used only when monitor_id is empty.

FieldTypeRequired
labelstringyes
hoststringyes
portintegerno
monitor_idstring <uuid>no
weightintegerno
enabledbooleanno
valuestringno
check_urlstringno
expected_statusintegerno
interval_secondsintegerno
timeout_secondsintegerno
healthy_afterintegerno
unhealthy_afterintegerno
PoolPage
FieldTypeRequired
itemsPool[]yes
next_cursorobjectno
PoolRecordRef
FieldTypeRequired
record_idstring <uuid>yes
zone_idstring <uuid>yes
zone_namestringyes
namestringyes
typeRecordTypeyes
PoolUpdate

Partial update; omitted fields are left unchanged.

FieldTypeRequired
namestringno
descriptionstringno
health_monitor_idstring <uuid>no
selection_methodSelectionMethodno
Problem
FieldTypeRequired
typestring <uri>yes
titlestringyes
statusintegeryes
detailstringno
instancestringno
codestringno
errorsobjectno
Rdata

Record data envelope. The concrete shape depends on the sibling `type` field; see the per-type Rdata* schemas below.

RdataANAME

ANAME (apex CNAME-flattening). `target` is the hostname to follow.

FieldTypeRequired
targetstringyes
RdataAddress

A and AAAA. `value` is an IPv4 (A) or IPv6 (AAAA) literal.

FieldTypeRequired
valuestringyes
RdataCAA

CAA. `value` is a single space-joined string "<flag> <tag> <value>"; flag 0-255, tag is issue | issuewild | iodef.

FieldTypeRequired
valuestringyes
RdataCanary

CANARY. Ramps traffic from `primary` to `canary` over `ramp_seconds` starting at `started_at`. Set `aborted_at` plus `aborted_pct` to freeze the ramp at a percentage.

FieldTypeRequired
primaryGslbTargetyes
canaryGslbTargetyes
from_pctintegerno
to_pctintegerno
ramp_secondsintegerno
started_atstring <date-time>no
aborted_atstring <date-time>no
aborted_pctintegerno
RdataGeo

GEO. Per-continent selection. Each region and the required `default` is a GslbTarget; region codes are unique.

FieldTypeRequired
regions[]yes
defaultGslbTargetyes
RdataHostname

CNAME, NS, and PTR. `value` is a hostname; a trailing dot is added if omitted.

FieldTypeRequired
valuestringyes
RdataMX

MX. A mail-exchanger host plus a preference number.

FieldTypeRequired
valuestringyes
priorityintegerno
RdataPool

POOL. Points the name at a GSLB pool; the engine answers with a healthy member.

FieldTypeRequired
pool_idstring <uuid>yes
RdataSRV

SRV. `value` is a single space-joined string "<priority> <weight> <port> <target>".

FieldTypeRequired
valuestringyes
RdataTXT

TXT. Free text, up to 4096 bytes, no NUL byte.

FieldTypeRequired
valuestringyes
ReadinessCheck

Failover-readiness audit for a host (the public checker Report).

FieldTypeRequired
hoststringyes
resolversobject[]yes
recordsobjectyes
scoreintegeryes
gradestring (A | B | C | D | F)yes
findingsobject[]yes
generated_atstring <date-time>yes
Record

A DNS record. The `data` field is a typed rdata envelope whose shape is set by `type` (see the Rdata* schemas): address types carry `{value}`, MX/SRV/CAA/TXT carry a packed `value` string, ANAME carries `{target}`, and the GSLB types POOL/GEO/CANARY carry pool and endpoint references. `name` is "@" at the apex. `fqdn` is present on every record response except the canary abort/resume actions.

FieldTypeRequired
idstring <uuid>yes
zone_idstring <uuid>yes
namestringyes
fqdnstringno
typeRecordTypeyes
ttlintegeryes
ttl_inheritbooleanyes
dataRdatayes
activebooleanyes
commentstringno
created_atstring <date-time>yes
updated_atstring <date-time>yes
RecordCreate

`data` must match `type` (see Rdata). If `ttl` is omitted or <= 0, or `ttl_inherit` is true, the server resolves the effective TTL from the zone default, then the tenant default, then 300.

FieldTypeRequired
namestringyes
typeRecordTypeyes
ttlintegerno
ttl_inheritbooleanno
dataRdatayes
commentstringno
RecordImport
FieldTypeRequired
zonefilestringyes
modestring (preview | commit)yes
RecordImportResult

Parse result. `rows` and `stats` describe the parsed zonefile (per-line outcome and aggregate counts); `inserted` is the number of records written (0 in preview mode).

FieldTypeRequired
insertedintegeryes
statsobjectno
rowsobject[]no
RecordPage
FieldTypeRequired
itemsRecord[]yes
next_cursorstringyes
RecordTargetStats

Observed answer distribution across a GSLB record's endpoints.

FieldTypeRequired
windowstringyes
totalinteger <int64>yes
targetsobject[]yes
RecordType

Standard DNS types plus dnswiz GSLB types. ANAME is apex CNAME-flattening; POOL points a name at a GSLB pool; GEO selects a target per continent; CANARY ramps traffic between two targets.

RecordUpdate

Partial update. `type` is immutable. Omitted fields are left unchanged; an empty `comment` clears it.

FieldTypeRequired
namestringno
ttlintegerno
ttl_inheritbooleanno
dataRdatano
activebooleanno
commentstringno
RefusedQuery
FieldTypeRequired
tenant_idstring <uuid>yes
zone_idstring <uuid>yes
qnamestringno
qtypestringyes
source_ipstringno
countrystringno
reasonstringyes
piistringno
checked_at_msinteger <int64>yes
RestorableTenant
FieldTypeRequired
idstring <uuid>yes
namestringyes
slugstringyes
deleted_atstring <date-time>yes
purge_afterstring <date-time>yes
rolestring (owner | admin | editor | viewer)yes
SelectionMethod

GSLB routing algorithm. weighted picks a healthy member at random by weight; active-passive picks the lowest-priority healthy member (1 is primary); round-robin rotates fairly across healthy members.

Uptime
FieldTypeRequired
pct_30dnumberno
incident_count_30dintegerno
last_incident_atstring <date-time>no
current_down_sincestring <date-time>no
Zone

A DNS zone. `default_ttl`, `soa_rname`, and `negative_ttl` are omitted when unset (the engine falls back to its defaults).

FieldTypeRequired
idstring <uuid>yes
namestringyes
activebooleanyes
default_ttlintegerno
soa_rnamestringno
negative_ttlintegerno
created_atstring <date-time>yes
updated_atstring <date-time>yes
ZoneCreate
FieldTypeRequired
namestringyes
ZoneHealth

Zone health report. Categories present only when they have checks.

FieldTypeRequired
overallintegeryes
categoriesobjectyes
resultsZoneHealthCheck[]yes
ZoneHealthCheck
FieldTypeRequired
idstringyes
categorystring (security | performance | email)yes
statusstring (pass | warn | fail | skip)yes
summarystringyes
detailstringyes
auto_fixablebooleanyes
ackobjectno
ZonePage
FieldTypeRequired
itemsZone[]yes
next_cursorstringyes
ZoneUpdate

Partial update; at least one field required. Use a negative `default_ttl`/`negative_ttl` or an empty `soa_rname` to clear that field and inherit the default.

FieldTypeRequired
activebooleanno
default_ttlintegerno
soa_rnamestringno
negative_ttlintegerno