v1

latestOpenAPI 3.0.32026-07-134103031.5 MB
Domains

Create Domain

post/domains/

Request body

hostnamestring required

Domain name with an associated IP address or an IP address itself.
For example, "my.example.com", "example.com", or "37.139.17.48".
The maximum length is 256 characters.

idstring required

A unique Base58 value identifying this object.

verification_tokenstring uuid required

Token used to verify the domain.
Read-only.

verification_datestring date-time nullable required

Date and time of the verification of the domain, in ISO 8601 UTC format.
For example, "2023-08-09T13:27:43.8208302"

verification_method'file' | 'back_office' | 'existing_domain' | 'dns_txt' | 'dns' | 'dns_cname' | 'meta_tag' | 'whitelist' | 'email' | 'aws_route53' | 'cloudflare' | 'waved' | 'akamai' required

Method used in the domain verification:

  • file - Verifies the domain against a text file in the root directory of the website. Learn more in this article.

  • back_office - Automatically set if manually verified in the back-office. Read-only.

  • existing_domain - Automatically set if the upper-level domain is verified. For example, "my.example.com" is automatically verified if "example.com" is verified. Read-only.

  • dns_txt - Verifies the domain against a TXT record in the Domain Name System (DNS). Learn more in this article.

  • dns - Same as dns_txt.

  • dns_cname - Verifies the domain against a CNAME record in the Domain Name System (DNS). Learn more in this article.

  • meta_tag - Verifies the domain against a meta tag in the index page of the website. Learn more in this article.

  • whitelist - Automatically verifies if the domain is in the whitelist

  • email - Automatically verifies a domain if the user's email is in the same domain as the target

  • aws_route53 - Automatically verifies a domain if the hostname exists as an AWS Route53 Zone.

  • cloudflare - Automatically verifies a domain if the host name exists and is verified as a CloudflareZone.

  • waved - Automatically verifies a domain if there is a waver agreement.

  • akamai - Automatically verifies a domain if the host name exists as an AkamaiHost.

verification_last_errorstring nullable required

Error of the last verification of the domain.
Empty if no error occurred.

verifiedboolean required

If true, the domain is verified.
Read-only.

basic_auth_usernamestring nullable

Username used for basic authentication.

basic_auth_passwordstring nullable

Password used for basic authentication.

basic_auth_password_is_sensitiveboolean

Controls sensitivity and obfuscation of basic_auth_password field.
If true the field is masked on Interfaces and Audit logs.
When account's Secrets Obfuscation setting is also enabled, the API's field output will be OBFUSCATED_<HASH>.

portinteger nullable

IP Port to send the requests to.
If not defined, uses the default ports for HTTPS and HTTP (if the verification method requires making HTTP requests).

discovery_enabledboolean

If true, the domain is available for use in Asset Discovery.
If false, the domain can only be used in targets.
This parameter is only applicable if you are entitled to use Asset Discovery. You can contact Snyk API & Web's support to enable the feature.
Learn more about Asset Discovery in the Overview of Asset Discovery.
Defaults to true.

Response

hostnamestring required

Domain name with an associated IP address or an IP address itself.
For example, "my.example.com", "example.com", or "37.139.17.48".
The maximum length is 256 characters.

idstring required

A unique Base58 value identifying this object.

verification_tokenstring uuid required

Token used to verify the domain.
Read-only.

verification_datestring date-time nullable required

Date and time of the verification of the domain, in ISO 8601 UTC format.
For example, "2023-08-09T13:27:43.8208302"

verification_method'file' | 'back_office' | 'existing_domain' | 'dns_txt' | 'dns' | 'dns_cname' | 'meta_tag' | 'whitelist' | 'email' | 'aws_route53' | 'cloudflare' | 'waved' | 'akamai' required

Method used in the domain verification:

  • file - Verifies the domain against a text file in the root directory of the website. Learn more in this article.

  • back_office - Automatically set if manually verified in the back-office. Read-only.

  • existing_domain - Automatically set if the upper-level domain is verified. For example, "my.example.com" is automatically verified if "example.com" is verified. Read-only.

  • dns_txt - Verifies the domain against a TXT record in the Domain Name System (DNS). Learn more in this article.

  • dns - Same as dns_txt.

  • dns_cname - Verifies the domain against a CNAME record in the Domain Name System (DNS). Learn more in this article.

  • meta_tag - Verifies the domain against a meta tag in the index page of the website. Learn more in this article.

  • whitelist - Automatically verifies if the domain is in the whitelist

  • email - Automatically verifies a domain if the user's email is in the same domain as the target

  • aws_route53 - Automatically verifies a domain if the hostname exists as an AWS Route53 Zone.

  • cloudflare - Automatically verifies a domain if the host name exists and is verified as a CloudflareZone.

  • waved - Automatically verifies a domain if there is a waver agreement.

  • akamai - Automatically verifies a domain if the host name exists as an AkamaiHost.

verification_last_errorstring nullable required

Error of the last verification of the domain.
Empty if no error occurred.

verifiedboolean required

If true, the domain is verified.
Read-only.

basic_auth_usernamestring nullable

Username used for basic authentication.

basic_auth_passwordstring nullable

Password used for basic authentication.

basic_auth_password_is_sensitiveboolean

Controls sensitivity and obfuscation of basic_auth_password field.
If true the field is masked on Interfaces and Audit logs.
When account's Secrets Obfuscation setting is also enabled, the API's field output will be OBFUSCATED_<HASH>.

portinteger nullable

IP Port to send the requests to.
If not defined, uses the default ports for HTTPS and HTTP (if the verification method requires making HTTP requests).

discovery_enabledboolean

If true, the domain is available for use in Asset Discovery.
If false, the domain can only be used in targets.
This parameter is only applicable if you are entitled to use Asset Discovery. You can contact Snyk API & Web's support to enable the feature.
Learn more about Asset Discovery in the Overview of Asset Discovery.
Defaults to true.