Authentication
Send an API key as a bearer token. The key must carry the reseller.manage permission; a key without it is refused with 403, not 404.
Where your organisation id goes
This endpoint takes org_id as a query parameter. Leave it out and the call covers your whole tenancy subtree; send it to narrow the call to one organisation.
Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X PUT https://api.zinndigital.com/v1/reseller/nameservers \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "domain": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
From `acme-hosting.com` we build `ns1.acme-hosting.com` and `ns2.acme-hosting.com`, served from Zinn Digital®'s own anycast DNS estate. Requires `reseller.manage` and white-label on your plan. ⛔ Claiming serves **nothing** yet. The glue records live in *your* domain, at *your* registrar, so only you can create them — publish the `A` records this returns, then call `/verify`. Until that measurement passes, your clients' zones keep the platform nameservers, because delegating a live domain to a nameserver that does not answer takes that domain off the internet. A domain Zinn® already operates is refused with `422`; a domain another reseller already holds ⇒ `409`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
org_id (query) | Uuid | No | The organization this call acts on. Optional for a caller with exactly one direct membership; **required** for anyone with more than one — which is every reseller and every agen… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
domain | string | Yes | Just the domain you own — `acme-hosting.com`, with no scheme and no `ns1.` prefix. We add `ns1` and `ns2`. A domain Zinn® operates is refused. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
domain | string | Yes | The reseller's own domain, or `""` when they have not claimed one. |
hostnames | string[] | Yes | Derived from `domain` — `ns1.acme-hosting.com`, `ns2.acme-hosting.com`. Two, because registries reject a single-nameserver delegation. |
glue | ResellerNameserverGlue[] | Yes | The `A` records the reseller must register at THEIR registrar. Nothing we hold can create them: they are a registry operation on a domain we do not sponsor. |
serving | boolean | Yes | — |
status | string | Yes | One sentence from the last check, for the screen and for support. |
vendor | string | Yes | Which of our anycast DNS providers serves these hostnames. |
checked_at | string | No | When it was last CHECKED, whatever the outcome. `null` means nobody has looked — a different fact from "checked and not serving". |
checked | boolean | No | Verify responses only. `false` means our resolver could not answer and **nothing was changed** — not that the glue is missing. The two send a reseller to opposite actions. |
supported_vendors | string[] | No | The anycast providers that can serve a nameserver brand of your own. |
Errors this endpoint can return
401 · 403 · 409 · 422 · 429