Skip to content

DNS API

Use a Quant organization API token to read DNS zones and create A records. Keep the token on your server or in private edge-function configuration. Applications do not need Quant’s internal DNS service credentials or AWS keys.

Send Authorization: Bearer <token> to https://dashboard.quantcdn.io/api/v2/organizations/{organization}/dns/zones. The token must have access to the organization and must not be restricted to individual projects: DNS zones belong to organizations.

Operation Token scope Token owner’s organization permission
Read zones and records dns:read Browse domains
Create an A record dns:write Add domains

These DNS routes do not require projects:read. Both scopes and the token owner’s current role are checked. A DNS token has organization-wide access; keep each application’s allowed zone and domain fixed in its server configuration.

Paths below are relative to the base URL above.

Method Path Result
GET / Array of the organization’s zones
GET /{zoneId} Zone details
GET /{zoneId}/records Object containing records and available pagination fields
POST /{zoneId}/records Created A record, HTTP 201

Record reads accept type, name, limit (1–1000), offset and sync. The name filter accepts relative labels or full names within the selected zone, including a trailing dot; the zone domain maps to @, and explicitly absolute names outside the zone are rejected. Set sync=true to read current Route 53 records. A zone belonging to another organization is not accessible through these endpoints.

Create an A record with this JSON body:

{
"name": "dragon-den",
"type": "A",
"value": "203.0.113.10",
"ttl": 60
}

name is relative to the zone, so this creates dragon-den.example.com in an example.com zone. Use @ for the apex. TTL defaults to 300 seconds and must be between 1 and 86400. This API currently creates single-address A records; use the dashboard for other record types, changes, deletions and zone creation. Creating records does not change registrar delegation: the zone’s nameservers must already be configured for its records to resolve publicly.

An existing record at the requested name, a concurrent API write or conflicting provider readback returns HTTP 409. Invalid inputs return 422. Missing scopes or role permissions return 403; unavailable provider operations return 503.

After a lost response, read the record with sync=true before retrying a create. If the single address matches the intended target, the write succeeded. A busy or uncertain write can retain its API lock for up to 120 seconds.

The API serializes its own creates and verifies the resulting address. This is not a Route 53 conditional-create primitive: independent dashboard and backend writers do not share that lock. Give automated namespaces one writer and avoid manual edits to application-managed records. Conflicting values need review; the API does not delete unknown records to recover automatically.