hosting

GET /v1/sites/{siteId}/registry

What the public registry says about a hosted site's domain.

All hosting endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/registry \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The WHOIS card for a site: registration dates, the registrar, the EPP status set and the DNSSEC flag, read from the registry's own **RDAP** service. Same response shape as `getDomainRegistry`, reached from the site instead of from a `Domain` row. ⭐ **It answers for a domain registered somewhere else**, which is the whole point: RDAP needs no credential, so a site whose name was registered at a registrar we have never integrated still returns its real expiry date and transfer lock. Nothing is spent and no allowance is consumed, which is why this is affordable on every site when a paid authority reading would not be. ⛔ The site's `primary_domain` is a **hostname** and may sit below the registration — `blog.example.com` has no registry record of its own. The name that answered is returned in `fqdn`, so a client should render that rather than assuming it matches the site's hostname. Every field is nullable and `null` means the registry did not publish it, never that the domain lacks it — `transfer_locked: null` is "we did not read a status set", not "unlocked". No registrant, admin or technical contact is returned, by decision. A registry that does not answer is a `503`, never an empty body and never a `404`. A site with no domain name yet is also a `503`, with a message saying so.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
fqdnstringYesThe name this record is about, normalised to lower case.
checked_atstringYesWhen we read the registry. Answers are cached for a few hours, so this is the age of the reading and not the time of the request.
registrarstringYesThe registrar of record, as the registry publishes it.
registrar_iana_idstringYesThe registrar's IANA id — stable where the display name is not.
registered_atstringYesWhen the domain was first registered.
expires_atstringYesWhen the registration lapses. ⭐ This is the **registry's** date, not our billing date, and on a domain the customer renews elsewhere it is the only true one we have.
last_changed_atstringYesWhen the registry record last changed. A renewal, a nameserver edit or a lock change all move it, so it is a useful "something happened" marker and not a statement of what.
statusesstring[]YesThe EPP status set, lower-cased as RDAP publishes it. An empty array means the registry published none — not that the domain has none.
nameserversstring[]YesThe nameservers the **registry** holds. May legitimately differ from the public delegation mid-propagation — compare with `Delegation.nameservers`, which is what the internet ac…
dnssecbooleanYesWhether the delegation is signed. `null` when the registry published no `secureDNS` block at all, which many do not.
transfer_lockedbooleanYesWhether a client transfer prohibition is set. `null` when no status set was published — ⛔ not `false`, for the reason in this schema's description.
lapsedbooleanYesWhether the registration is in a redemption or pending-delete window right now. Worth surfacing loudly: those windows are short, cost a fee to reverse, and end with the name bei…

Errors this endpoint can return

401 · 403 · 404 · 503