hosting
GET /v1/sites/{siteId}/registry
What the public registry says about a hosted site's domain.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/registry \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The WHOIS card for a site: registration dates, the registrar, the EPP status set and the DNSSEC flag, read from the registry's own **RDAP** service. Same response shape as `getDomainRegistry`, reached from the site instead of from a `Domain` row. ⭐ **It answers for a domain registered somewhere else**, which is the whole point: RDAP needs no credential, so a site whose name was registered at a registrar we have never integrated still returns its real expiry date and transfer lock. Nothing is spent and no allowance is consumed, which is why this is affordable on every site when a paid authority reading would not be. ⛔ The site's `primary_domain` is a **hostname** and may sit below the registration — `blog.example.com` has no registry record of its own. The name that answered is returned in `fqdn`, so a client should render that rather than assuming it matches the site's hostname. Every field is nullable and `null` means the registry did not publish it, never that the domain lacks it — `transfer_locked: null` is "we did not read a status set", not "unlocked". No registrant, admin or technical contact is returned, by decision. A registry that does not answer is a `503`, never an empty body and never a `404`. A site with no domain name yet is also a `503`, with a message saying so.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
fqdn | string | Yes | The name this record is about, normalised to lower case. |
checked_at | string | Yes | When we read the registry. Answers are cached for a few hours, so this is the age of the reading and not the time of the request. |
registrar | string | Yes | The registrar of record, as the registry publishes it. |
registrar_iana_id | string | Yes | The registrar's IANA id — stable where the display name is not. |
registered_at | string | Yes | When the domain was first registered. |
expires_at | string | Yes | When the registration lapses. ⭐ This is the **registry's** date, not our billing date, and on a domain the customer renews elsewhere it is the only true one we have. |
last_changed_at | string | Yes | When the registry record last changed. A renewal, a nameserver edit or a lock change all move it, so it is a useful "something happened" marker and not a statement of what. |
statuses | string[] | Yes | The EPP status set, lower-cased as RDAP publishes it. An empty array means the registry published none — not that the domain has none. |
nameservers | string[] | Yes | The nameservers the **registry** holds. May legitimately differ from the public delegation mid-propagation — compare with `Delegation.nameservers`, which is what the internet ac… |
dnssec | boolean | Yes | Whether the delegation is signed. `null` when the registry published no `secureDNS` block at all, which many do not. |
transfer_locked | boolean | Yes | Whether a client transfer prohibition is set. `null` when no status set was published — ⛔ not `false`, for the reason in this schema's description. |
lapsed | boolean | Yes | Whether the registration is in a redemption or pending-delete window right now. Worth surfacing loudly: those windows are short, cost a fee to reverse, and end with the name bei… |
Errors this endpoint can return
401 · 403 · 404 · 503