DNS
The Cloudflare token the panel writes records with, and which every server’s Traefik gets a wildcard certificate with. No answer ever contains it.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
GET /api/dns
Section titled “GET /api/dns”Whether a token is set, and each server’s wildcard certificate and Traefik.
- Level: Read only
- Returns:
{provider, token: {configured, setAt, envDiffers}, wildcardServerId, servers[]}
POST /api/dns/check
Section titled “POST /api/dns/check”What a token reaches - the one given, or the stored one - without keeping it.
- Level: Full
- Notes: Not over MCP
- Input:
{token?} - Returns:
{ok, error, zones[], zoneCount, devDomains[]}
PUT /api/dns/token
Section titled “PUT /api/dns/token”Replace the token; refused unless Cloudflare takes it. Every server’s Traefik gets it.
- Level: Full
- Notes: Destructive · Not over MCP
- Input:
{token} - Returns:
{...GET /api/dns, check}
DELETE /api/dns/token
Section titled “DELETE /api/dns/token”Remove the token; dev sites sharing a wildcard certificate get their own.
- Level: Full
- Notes: Destructive · Not over MCP
- Returns:
{...GET /api/dns, rebuilding[], busy[]} - one site.reconcile per rebuilt site
PUT /api/dns/servers/:id/wildcard
Section titled “PUT /api/dns/servers/:id/wildcard”Switch a server’s wildcard certificate; off rebuilds the dev sites that share it.
- Level: Full
- Notes: Destructive
- Input:
{on: boolean} - Returns:
{...GET /api/dns, rebuilding[], busy[]}; 409 when the token does not reach the dev domain's records