Support

About Authentication

View as Markdown

How GoDaddy API authentication works — credential types, PAT scopes, and account eligibility requirements.

Overview

GoDaddy APIs support Bearer authentication through scoped Personal Access Tokens (PATs). Domains v3 requires a PAT.

The legacy sso-key credential remains required for Auctions and supported for Domains v1/v2. It is scheduled for Domains deprecation and does not work with v3.

Go to How to Authenticate for credential setup.

Credential types

CredentialFormatWorks withStatus
Personal Access Token (PAT)Authorization: Bearer $GODADDY_PATDomains v3, Hosting, Shopping, and other PAT-enabled APIs; not accepted by AuctionsRecommended
Classic Developer KeyAuthorization: sso-key $GODADDY_KEY:$GODADDY_SECRETAuctions API (required); Domains v1/v2Deprecated for Domains (through 2026); required for Auctions

The Shopping API accepts PATs for direct API integrations.

A PAT has capability scopes, an optional expiration, and independent revocation. For most integrations, choose a PAT with the minimum required scopes.

Account requirements

Some operations require the account to meet specific eligibility rules regardless of credential type. A valid credential on an ineligible account is still refused with a 403 Forbidden response and an Error code that distinguishes the reason from a missing scope. Check the code field on the response body, not just the HTTP status, to determine the reason. Go to Handle errors for the full error envelope and status code reference.

Operation groupRequirement
Domain management (list, DNS, contacts, renewals, lock, privacy)Account holds at least one domain, OR is on a plan that grants management access.
Registration, renewal, transfer (any operation that costs money in production)Account has a valid billing method on file or a funded Good as Gold balance. Go to Set up a payment profile.

PAT scopes

A PAT is scoped to specific capabilities at generation time. Each scope enables a set of operations on a specific resource. A write scope satisfies read operations for the same resource; a read scope is refused on writes. Go to Generate a PAT for step-by-step instructions.

Commerce

Commerce APIs use the same PAT and grant model as Domains. When you generate a token, the Commerce categories display in the scope picker next to Domains & DNS. These cover catalog, orders, customers, tax, transactions, store, and channel operations. Select a category or expand it to grant a subset (for example commerce.order:read, commerce.product:write). Go to Commerce API scopes for the complete scope-to-endpoint reference.

Domains

When you generate a token, the Domains & DNS bundle in the scope picker selects all scopes below. You can expand it to grant a subset instead.

ScopeRequired to
domains.domain:readRead domain records, availability, suggestions, quotes, and operations
domains.domain:createRegister domains
domains.domain:updateModify domain settings
domains.domain:deleteDelete or cancel domains
domains.dns:updateCreate, update, and delete DNS zone records
domains.nameserver:updateReplace authoritative nameservers for a domain
domains.host:updateModify domain host records
domains.forward:updateConfigure domain forwarding
domains.contact:updateUpdate registrant, admin, or tech contacts
domains.transfer:executeInitiate an inbound domain transfer
domains.transfer:updateModify a transfer in progress

Email

ScopeRequired to
email.mailbox:readList and look up email mailboxes
email.mailbox:createCreate email mailboxes

Shopping

ScopeRequired to
shopping.catalog:readSearch products, look up variants by ID, retrieve product detail
shopping.checkout:executeCreate, retrieve, update, and complete checkout sessions
shopping.order:readRetrieve completed order detail

Go to About the Shopping API for Shopping authentication and header requirements.

For hosting.* scopes used by the Hosting API, go to Hosting core concepts for the full scope list.

Agent & Automation Notes

PermissionsAny account
Scopesdomains.domain:read, commerce.store:read, shopping.catalog:read
Rate limitAPI calls with PAT: rate-limited per credential per window. Go to /docs/api-users/rate-limits for current values.
IdempotentYes
DestructiveNo
On failurePAT reveals once at creation — if lost, revoke and regenerate. Revocation is instant across all edges.

Last updated on

How is this guide?

On this page