Connecting Gandi lets us point your domains at the sites you host with us, and keep them pointed there when things change — no copying nameservers by hand.
1. Create the key at Gandi
In Gandi, open Organizations, choose your organization, open the Sharing tab and select Create a token. Give it a name, choose an expiry, restrict it to your domains if you like, tick the permission to manage domain technical settings, then Create and Copy.
2. Connect it here
Open Integrations in your dashboard, choose Connect an account, pick Gandi under Where your domains are registered, paste what you created and press Connect account. We test the key before saving it; an invalid key is never stored, and the checklist beside the connection shows which permissions we could confirm.
⚠️ A Gandi token always expires — choose 1 year. When it lapses, the Linked registrars screen shows the key as rejected; create a new token and reconnect.
⚠️ If a domain uses Gandi Premium DNS, changing its nameservers switches that service off.
What happens next
- Within the hour we import the domains in the account. They appear under **Domains → Linked
registrars**, with each domain's expiry and whether it points where its site needs.
- When you add a site to one of those domains, we set its nameservers for you.
- When something on our side changes which nameservers a site needs — you switch CDN,
change DNS provider, move the site, change plan or rename the domain — we update the registrar again, automatically.
- If you ever point a domain somewhere else yourself, we do not overwrite your choice. The
domain shows as not pointing at its site, and you can press Update nameservers now on the domain's page whenever you want us to put it back.
What the key lets us do — and what it never does
We use it for exactly two things: listing the domains in the account, and changing a domain's nameservers so it points at the site you host with us. We never transfer, renew, unlock or delete a domain, and we never change its contacts. Those operations are refused in our code for every registrar connection, not merely unused.
The key is stored encrypted in our secrets vault, never in our database, and you can disconnect it at any time from Integrations — disconnecting deletes the stored key.