DNS API
Use a Quant organization API token to read DNS zones and create A records. Keep the token on your server or in private edge-function configuration. Applications do not need Quant’s internal DNS service credentials or AWS keys.
Authentication and permissions
Section titled “Authentication and permissions”Send Authorization: Bearer <token> to
https://dashboard.quantcdn.io/api/v2/organizations/{organization}/dns/zones.
The token must have access to the organization and must not be restricted to
individual projects: DNS zones belong to organizations.
| Operation | Token scope | Token owner’s organization permission |
|---|---|---|
| Read zones and records | dns:read |
Browse domains |
| Create an A record | dns:write |
Add domains |
These DNS routes do not require projects:read. Both scopes and the token
owner’s current role are checked. A DNS token has organization-wide access;
keep each application’s allowed zone and domain fixed in its server configuration.
Endpoints
Section titled “Endpoints”Paths below are relative to the base URL above.
| Method | Path | Result |
|---|---|---|
| GET | / |
Array of the organization’s zones |
| GET | /{zoneId} |
Zone details |
| GET | /{zoneId}/records |
Object containing records and available pagination fields |
| POST | /{zoneId}/records |
Created A record, HTTP 201 |
Record reads accept type, name, limit (1–1000), offset and sync.
The name filter accepts relative labels or full names within the selected zone,
including a trailing dot; the zone domain maps to @, and explicitly absolute
names outside the zone are rejected.
Set sync=true to read current Route 53 records. A zone belonging to another
organization is not accessible through these endpoints.
Create an A record with this JSON body:
{ "name": "dragon-den", "type": "A", "value": "203.0.113.10", "ttl": 60}name is relative to the zone, so this creates dragon-den.example.com in
an example.com zone. Use @ for the apex. TTL defaults to 300 seconds and
must be between 1 and 86400. This API currently creates single-address A records;
use the dashboard for other record types, changes, deletions and zone creation.
Creating records does not change registrar delegation: the zone’s nameservers
must already be configured for its records to resolve publicly.
Conflicts and retries
Section titled “Conflicts and retries”An existing record at the requested name, a concurrent API write or conflicting provider readback returns HTTP 409. Invalid inputs return 422. Missing scopes or role permissions return 403; unavailable provider operations return 503.
After a lost response, read the record with sync=true before retrying a create.
If the single address matches the intended target, the write succeeded. A busy
or uncertain write can retain its API lock for up to 120 seconds.
The API serializes its own creates and verifies the resulting address. This is not a Route 53 conditional-create primitive: independent dashboard and backend writers do not share that lock. Give automated namespaces one writer and avoid manual edits to application-managed records. Conflicting values need review; the API does not delete unknown records to recover automatically.
