> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create domain record

> **Token scope:** `account` · `org` — read-only tokens refused (not a GET).

Add a DNS record to a bought domain's zone. Omitted, `host` is the domain itself and `ttl` is 300 seconds. Routing (A, AAAA, ANAME, CNAME) and delegation (NS) are refused at a hostname an attach serves — those are the platform's — and an NS above one, which would delegate it away; attaching a hostname later replaces the routing records at that host.



## OpenAPI

````yaml /openapi/org.json post /orgs/{orgId}/domains/{domainName}/records
openapi: 3.1.0
info:
  title: InstaCloud API — Organization level
  version: 0.1.0
  description: >-
    Endpoints under `/orgs/{orgId}`: members, projects, billing, domains.
    Callable with an account-wide token or a token bound to that organization.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Organization
    description: 'The organization itself: name, members, invitations.'
  - name: Projects
    description: Projects inside an organization.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
paths:
  /orgs/{orgId}/domains/{domainName}/records:
    post:
      tags:
        - Domains
      summary: Create domain record
      description: >-
        **Token scope:** `account` · `org` — read-only tokens refused (not a
        GET).


        Add a DNS record to a bought domain's zone. Omitted, `host` is the
        domain itself and `ttl` is 300 seconds. Routing (A, AAAA, ANAME, CNAME)
        and delegation (NS) are refused at a hostname an attach serves — those
        are the platform's — and an NS above one, which would delegate it away;
        attaching a hostname later replaces the routing records at that host.
      operationId: createDomainRecord
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: orgId
          required: true
        - schema:
            type: string
          in: path
          name: domainName
          required: true
      requestBody:
        content:
          application/json:
            schema:
              required:
                - type
                - answer
              type: object
              properties:
                type:
                  $ref: '#/components/schemas/DnsRecordType'
                host:
                  description: >-
                    relative to the domain: "@" for the domain itself, "api" for
                    api.<domain>; the full hostname is accepted too
                  type: string
                answer:
                  description: >-
                    an IPv4 (A) or IPv6 (AAAA) address; a hostname (CNAME,
                    ANAME, NS, MX); "<weight> <port> <target>" (SRV); text
                    (TXT). "." is the null MX and the no-service SRV target
                  type: string
                ttl:
                  minimum: 300
                  maximum: 604800
                  description: seconds
                  type: integer
                priority:
                  minimum: 0
                  maximum: 65535
                  description: required for MX and SRV, refused for every other type
                  type: integer
        required: true
      responses:
        '201':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DnsRecord'
        '400':
          description: >-
            the record does not fit its type, the zone cannot hold it (a CNAME
            or NS at the domain itself), or the registrar refused it — with its
            own sentence
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                description: >-
                  the record does not fit its type, the zone cannot hold it (a
                  CNAME or NS at the domain itself), or the registrar refused it
                  — with its own sentence
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            the host serves a compute service through InstaCloud, or an NS there
            would delegate one away
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                description: >-
                  the host serves a compute service through InstaCloud, or an NS
                  there would delegate one away
        '502':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    DnsRecordType:
      type: string
      enum:
        - A
        - AAAA
        - ANAME
        - CNAME
        - MX
        - NS
        - SRV
        - TXT
    DnsRecord:
      type: object
      properties:
        id:
          description: the registrar's id for the record; the handle every write takes
          type: integer
        type:
          $ref: '#/components/schemas/DnsRecordType'
        host:
          description: >-
            relative to the domain: "@" is the domain itself, "api" is
            api.<domain>
          type: string
        fqdn:
          type: string
        answer:
          type: string
        ttl:
          description: seconds
          type: integer
        priority:
          description: MX and SRV only
          type: integer
        managed:
          description: >-
            published by InstaCloud: read-only while `hostname` names the
            attached hostname it serves; without one, a leftover no hostname
            claims, which may be deleted
          type: boolean
        hostname:
          description: the attached hostname a managed record serves
          type: string
      required:
        - id
        - type
        - host
        - fqdn
        - answer
        - ttl
        - managed
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````