The API lets you manage DNS from your own scripts or from infrastructure tooling. Keys are created under API keys in the portal.
Available on Business and Enterprise, with five keys each.
The key is shown once
A new key is displayed when it is created and cannot be retrieved afterwards — only its label and its metadata remain. Copy it into your secret store at that moment. If you lose it, revoke it and create another; there is no recovery path, by design.
One key per consumer
Create a separate key for each script, machine or pipeline rather than sharing one everywhere.
The reason is revocation. When a laptop is lost or a contractor leaves, a per-consumer key is one revocation and nothing else stops working. A shared key means either revoking everything or revoking nothing, and the second is what usually happens.
Label them so the label still means something to somebody else in a year — ci-deploy-prod, not key2.
Revoking and deleting
Revoking stops the key working immediately. Do it the moment a key might have been exposed; it is free and reversible only in the sense that you can create a new one.
Deleting removes the record of it as well.
Revoke first, investigate afterwards. A key in a public repository is being used by somebody else within minutes.
What a key can do
A key acts on your account's zones, with the same plan limits the portal applies. It is not an administrative credential and cannot reach another account.
Treating it properly
- Environment variables or a secret manager — not in the repository.
- Not in a CI log. Mask it in the job configuration.
- Rotate on a schedule you actually keep, and on any staff change.
- If it appears in a commit, revoking it is the fix. Rewriting history is not.
See Getting started with the API.
Last reviewed 2026-08-19.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.