> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Delegate purchased domain

> **Token scope:** `account` · `org` — read-only tokens refused (not a GET).

Managed delegation: host this domain's zone on an InstaCloud-managed Cloudflare zone and keep publishing its DNS there. Nothing goes dark — the zone carries every published record before the nameservers move — and attach keeps working, apexes included. Gated — domain.delegate. (admin+)



## OpenAPI

````yaml /openapi/org.json post /orgs/{orgId}/domains/{domainName}/delegate
openapi: 3.1.0
info:
  title: InstaCloud API — Organization level
  version: 0.1.0
  description: >-
    Endpoints under `/orgs/{orgId}`: members, projects, billing, domains.
    Callable with an account-wide token or a token bound to that organization.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Organization
    description: 'The organization itself: name, members, invitations.'
  - name: Projects
    description: Projects inside an organization.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
paths:
  /orgs/{orgId}/domains/{domainName}/delegate:
    post:
      tags:
        - Domains
      summary: Delegate purchased domain
      description: >-
        **Token scope:** `account` · `org` — read-only tokens refused (not a
        GET).


        Managed delegation: host this domain's zone on an InstaCloud-managed
        Cloudflare zone and keep publishing its DNS there. Nothing goes dark —
        the zone carries every published record before the nameservers move —
        and attach keeps working, apexes included. Gated — domain.delegate.
        (admin+)
      operationId: delegatePurchasedDomain
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: orgId
          required: true
        - schema:
            type: string
          in: path
          name: domainName
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PurchasedDomain'
        '202':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApprovalRequired'
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '501':
          description: managed DNS delegation is not enabled on this deployment
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                description: managed DNS delegation is not enabled on this deployment
        '502':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    PurchasedDomain:
      type: object
      properties:
        domainName:
          type: string
        status:
          type: string
          enum:
            - registered
            - attaching
            - active
            - attach_failed
            - detached
          description: >-
            detached: every service its hostnames named is gone — attach it
            again
        hostnames:
          type: array
          items:
            $ref: '#/components/schemas/DomainHostnameState'
        registeredAt:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        expiresAt:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        autorenew:
          type: boolean
        privacy:
          type: boolean
        locked:
          description: >-
            the registrar transfer lock: while it is on, no other registrar can
            pull the domain away. Turn it off to move the domain out. What the
            last write reported, or what registration asked for — nothing reads
            it back
          type: boolean
        nameservers:
          description: >-
            what the registrar holds. Empty means never written — only a
            nameserver write fills it in
          type: array
          items:
            type: string
        delegated:
          description: >-
            the zone is answered by nameservers InstaCloud cannot write to
            (custody `foreign`), so nothing published resolves and an attach is
            refused. A MANAGED delegation reads false: the platform still
            publishes there
          type: boolean
        custody:
          type: string
          enum:
            - registrar
            - managed
            - foreign
          description: >-
            who answers the domain's zone: the registrar's own nameservers, a
            managed InstaCloud zone (delegated, still platform-published), or
            somewhere the platform cannot write
        transferLockExpiresAt:
          description: >-
            ICANN 60-day lock after registration: no transfer out before this,
            whatever `locked` says
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        orderId:
          anyOf:
            - format: uuid
              type: string
            - type: 'null'
      required:
        - domainName
        - status
        - hostnames
        - registeredAt
        - expiresAt
        - autorenew
        - privacy
        - locked
        - nameservers
        - delegated
        - custody
        - transferLockExpiresAt
        - orderId
    ApprovalRequired:
      type: object
      properties:
        status:
          type: string
          enum:
            - approval_required
        approvalId:
          format: uuid
          type: string
        action:
          description: the gated action, or a comma-joined compound set — prefer `actions`
          type: string
        actions:
          description: every capability this approval covers
          type: array
          items:
            type: string
        message:
          type: string
        url:
          description: the console page where a project admin reviews this request
          type: string
        nextActions:
          type: array
          items:
            $ref: '#/components/schemas/NextAction'
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    DomainHostnameState:
      type: object
      properties:
        hostname:
          type: string
        state:
          type: string
          enum:
            - pending
            - attached
            - active
            - failed
        reason:
          type: string
        service:
          description: >-
            the compute service this hostname serves; each hostname of a domain
            can serve a different one
          anyOf:
            - type: string
            - type: 'null'
      required:
        - hostname
        - state
        - service
    NextAction:
      type: object
      properties:
        op:
          description: >-
            Neutral logical action id, e.g. "service.add" — NOT an operationId
            or a CLI/MCP tool name; each client maps it to its own surface.
          type: string
        reason:
          description: Natural-language, human/LLM-facing "why do this now".
          type: string
        args:
          description: >-
            Suggested, flat named arguments; "<placeholder>"s where a value is
            unknown.
          type: object
          additionalProperties: true
        gated:
          description: True if the action passes a governance gate.
          type: boolean
      required:
        - op
        - reason
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````