domains
GET /v1/domains/{domainId}/registrar-guide
Where and how to change this domain's nameservers.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/domains/{domainId}/registrar-guide \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
*"Where do I actually go to change my nameservers?"* — the question a customer asks after being handed two hostnames. This answers it **without asking them which registrar they use**: the public registry already publishes the sponsoring registrar and its IANA id, so the answer is read from the same RDAP record the WHOIS card renders. `slug` is the instruction set to render — `godaddy`, `namecheap`, `porkbun`, `cloudflare`, `squarespace` or `generic`. ⛔ It is a **slug and never step text**: a client renders its own localized steps from it, because English instructions returned from an API cannot be translated for 58 locales. ⭐ `generic` is a real answer, not a failure. There are roughly 2,500 accredited registrars and "set these two nameservers wherever you bought the domain" is correct at every one of them. `self_serve` says whether we can make the change **for** the customer with an API key they supply, and it is derived from which delegation adapters exist rather than stated per registrar. `locked` says the domain **cannot** be delegated elsewhere at all — true for Cloudflare Registrar, which requires its own nameservers. Those two are different states and need different copy: `self_serve: false` means "you will have to do this by hand", `locked: true` means "there is nothing to do and no setting to look for". `expected` is the pair to set, resolved from the **zone's own** nameservers first rather than a fleet-wide constant — a footprint-free domain gets a provider-assigned pair. `nameservers` is where the registry says the domain points right now, so a client can say "already done" instead of repeating an instruction. Requires `sites.view`, RLS-scoped. A registry that does not answer is a `503`, never a generic card: both mean "we do not know your registrar" and only one of them says so.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
domainId (path) | Uuid | Yes | The domain's id. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
slug | string<godaddy, namecheap, porkbun, cloudflare, squarespace, generic> | Yes | Which instruction set to render. ⛔ A slug, never step text — a client supplies its own localized steps. `generic` is a real answer covering every registrar. |
registrar | string | Yes | The registrar exactly as the registry names it, or `null` when none was published. ⛔ Never inferred from `slug`: showing a brand name the registry did not state would present ou… |
panel_url | string | Yes | A deep link into that registrar's own nameserver screen, where known. |
self_serve | boolean | Yes | Can we make the change for the customer with an API key they supply? Derived from which delegation adapters exist, never stated per registrar. |
locked | boolean | Yes | The domain cannot be delegated anywhere else — true for Cloudflare Registrar. ⛔ A STATE, not a failure, and not the same as `self_serve: false`. |
expected | string[] | Yes | The nameservers this domain should be set to. Resolved from the zone's own nameservers first, so a provider-assigned pair is reported rather than a fleet-wide constant. |
nameservers | string[] | Yes | Where the registry says the domain delegates right now. |
Errors this endpoint can return
401 · 403 · 404 · 429 · 503