> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update purchased domain

> **Token scope:** `account` · `org` — read-only tokens refused (not a GET).

Turn renewal or the transfer lock on or off for a domain this org bought. A field left out keeps its value. (admin+ for the lock)



## OpenAPI

````yaml /openapi/org.json patch /orgs/{orgId}/domains/{domainName}
openapi: 3.1.0
info:
  title: InstaCloud API — Organization level
  version: 0.1.0
  description: >-
    Endpoints under `/orgs/{orgId}`: members, projects, billing, domains.
    Callable with an account-wide token or a token bound to that organization.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Organization
    description: 'The organization itself: name, members, invitations.'
  - name: Projects
    description: Projects inside an organization.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
paths:
  /orgs/{orgId}/domains/{domainName}:
    patch:
      tags:
        - Domains
      summary: Update purchased domain
      description: >-
        **Token scope:** `account` · `org` — read-only tokens refused (not a
        GET).


        Turn renewal or the transfer lock on or off for a domain this org
        bought. A field left out keeps its value. (admin+ for the lock)
      operationId: updatePurchasedDomain
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: orgId
          required: true
        - schema:
            type: string
          in: path
          name: domainName
          required: true
      requestBody:
        content:
          application/json:
            schema:
              minProperties: 1
              type: object
              properties:
                autorenew:
                  description: renew the domain each year before it expires
                  type: boolean
                locked:
                  description: >-
                    the registrar transfer lock. Turn it off to move the domain
                    to another registrar; the ICANN lock in
                    `transferLockExpiresAt` still refuses a transfer until it
                    passes
                  type: boolean
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PurchasedDomain'
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '502':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    PurchasedDomain:
      type: object
      properties:
        domainName:
          type: string
        status:
          type: string
          enum:
            - registered
            - attaching
            - active
            - attach_failed
            - detached
          description: >-
            detached: every service its hostnames named is gone — attach it
            again
        hostnames:
          type: array
          items:
            $ref: '#/components/schemas/DomainHostnameState'
        registeredAt:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        expiresAt:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        autorenew:
          type: boolean
        privacy:
          type: boolean
        locked:
          description: >-
            the registrar transfer lock: while it is on, no other registrar can
            pull the domain away. Turn it off to move the domain out. What the
            last write reported, or what registration asked for — nothing reads
            it back
          type: boolean
        nameservers:
          description: >-
            what the registrar holds. Empty means never written — only a
            nameserver write fills it in
          type: array
          items:
            type: string
        delegated:
          description: >-
            the zone is answered by nameservers InstaCloud cannot write to
            (custody `foreign`), so nothing published resolves and an attach is
            refused. A MANAGED delegation reads false: the platform still
            publishes there
          type: boolean
        custody:
          type: string
          enum:
            - registrar
            - managed
            - foreign
          description: >-
            who answers the domain's zone: the registrar's own nameservers, a
            managed InstaCloud zone (delegated, still platform-published), or
            somewhere the platform cannot write
        transferLockExpiresAt:
          description: >-
            ICANN 60-day lock after registration: no transfer out before this,
            whatever `locked` says
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        orderId:
          anyOf:
            - format: uuid
              type: string
            - type: 'null'
      required:
        - domainName
        - status
        - hostnames
        - registeredAt
        - expiresAt
        - autorenew
        - privacy
        - locked
        - nameservers
        - delegated
        - custody
        - transferLockExpiresAt
        - orderId
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    DomainHostnameState:
      type: object
      properties:
        hostname:
          type: string
        state:
          type: string
          enum:
            - pending
            - attached
            - active
            - failed
        reason:
          type: string
        service:
          description: >-
            the compute service this hostname serves; each hostname of a domain
            can serve a different one
          anyOf:
            - type: string
            - type: 'null'
      required:
        - hostname
        - state
        - service
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````