> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create org zone record

> **Token scope:** `account` · `org` — read-only tokens refused (not a GET).

The pre-cutover REPAIR door: create a record the provider's scan missed, directly in the delegated zone, BEFORE switching the nameservers (the door closes at activation). Types beyond the registrar model are accepted where the review needs them (CAA). The record is yours, not the platform's — attach-published records are still managed for you. Gated — zone.delegate. (admin+)



## OpenAPI

````yaml /openapi/org.json post /orgs/{orgId}/zones/{domainName}/records
openapi: 3.1.0
info:
  title: InstaCloud API — Organization level
  version: 0.1.0
  description: >-
    Endpoints under `/orgs/{orgId}`: members, projects, billing, domains.
    Callable with an account-wide token or a token bound to that organization.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Organization
    description: 'The organization itself: name, members, invitations.'
  - name: Projects
    description: Projects inside an organization.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
paths:
  /orgs/{orgId}/zones/{domainName}/records:
    post:
      tags:
        - Domains
      summary: Create org zone record
      description: >-
        **Token scope:** `account` · `org` — read-only tokens refused (not a
        GET).


        The pre-cutover REPAIR door: create a record the provider's scan missed,
        directly in the delegated zone, BEFORE switching the nameservers (the
        door closes at activation). Types beyond the registrar model are
        accepted where the review needs them (CAA). The record is yours, not the
        platform's — attach-published records are still managed for you. Gated —
        zone.delegate. (admin+)
      operationId: createOrgZoneRecord
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: orgId
          required: true
        - schema:
            type: string
          in: path
          name: domainName
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                type:
                  type: string
                host:
                  type: string
                answer:
                  type: string
                ttl:
                  type: number
                priority:
                  type: number
              required:
                - type
                - answer
        required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrgZoneRecord'
        '202':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApprovalRequired'
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            the zone already serves (the repair window closed at activation), or
            the provider refused
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                description: >-
                  the zone already serves (the repair window closed at
                  activation), or the provider refused
        '501':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '502':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    OrgZoneRecord:
      type: object
      properties:
        type:
          type: string
        host:
          description: '"@" is the domain itself'
          type: string
        answer:
          type: string
        ttl:
          type: integer
        priority:
          type: integer
        proxied:
          type: boolean
      required:
        - type
        - host
        - answer
    ApprovalRequired:
      type: object
      properties:
        status:
          type: string
          enum:
            - approval_required
        approvalId:
          format: uuid
          type: string
        action:
          description: the gated action, or a comma-joined compound set — prefer `actions`
          type: string
        actions:
          description: every capability this approval covers
          type: array
          items:
            type: string
        message:
          type: string
        url:
          description: the console page where a project admin reviews this request
          type: string
        nextActions:
          type: array
          items:
            $ref: '#/components/schemas/NextAction'
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    NextAction:
      type: object
      properties:
        op:
          description: >-
            Neutral logical action id, e.g. "service.add" — NOT an operationId
            or a CLI/MCP tool name; each client maps it to its own surface.
          type: string
        reason:
          description: Natural-language, human/LLM-facing "why do this now".
          type: string
        args:
          description: >-
            Suggested, flat named arguments; "<placeholder>"s where a value is
            unknown.
          type: object
          additionalProperties: true
        gated:
          description: True if the action passes a governance gate.
          type: boolean
      required:
        - op
        - reason
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````