Support

Attach and detach custom domains from a hosted application.

GET
/apps/{appId}/domains

Authorization

oauth2 hosting.domain:read
AuthorizationBearer <token>

GoDaddy OAuth 2.0 access token. The scope(s) listed on each operation are enforced per-operation. A token requires at least one of the scopes listed for that operation.

In: header

Scope: hosting.domain:read

Path Parameters

appId*string

Application identifier in {PRODUCT}-{id} form. The prefix is the application type in upper case — an upper-case letter followed by any number of upper-case letters, digits, or underscores — then a hyphen, then the identifier. For NODEJS, the suffix is a 10-character nanoid. Example: NODEJS-aBcDeFgHiJ.

Match^[A-Z][A-Z0-9_]*-[A-Za-z0-9_-]+$

Header Parameters

traceparent?string

W3C Trace Context identifier for this request. Clients should send a traceparent on every request so the trace can be correlated across services. See https://www.w3.org/TR/trace-context/ for the format.

Match^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/apps/string/domains"
{  "totalItems": 0,  "totalPages": 0,  "links": [    {      "href": "http://example.com",      "rel": "string",      "title": "string",      "targetMediaType": "string",      "targetSchema": null,      "method": "string",      "submissionMediaType": "application/json",      "submissionSchema": null    }  ],  "items": [    {      "domainId": "string",      "hostname": "www.example.com",      "role": "PRIMARY",      "verificationStatus": "PENDING",      "certificateValidationCname": "_acme-challenge.example.com.validation.example.net",      "anycastIp": "192.0.2.10",      "cdnStatus": "INIT",      "domainType": "PREFIX",      "links": [        {          "href": "http://example.com",          "rel": "string",          "title": "string",          "targetMediaType": "string",          "targetSchema": null,          "method": "string",          "submissionMediaType": "application/json",          "submissionSchema": null        }      ]    }  ]}
POST
/apps/{appId}/domains

Authorization

oauth2 hosting.domain:write
AuthorizationBearer <token>

GoDaddy OAuth 2.0 access token. The scope(s) listed on each operation are enforced per-operation. A token requires at least one of the scopes listed for that operation.

In: header

Scope: hosting.domain:write

Path Parameters

appId*string

Application identifier in {PRODUCT}-{id} form. The prefix is the application type in upper case — an upper-case letter followed by any number of upper-case letters, digits, or underscores — then a hyphen, then the identifier. For NODEJS, the suffix is a 10-character nanoid. Example: NODEJS-aBcDeFgHiJ.

Match^[A-Z][A-Z0-9_]*-[A-Za-z0-9_-]+$

Header Parameters

Idempotency-Key?string

Client-generated UUID that makes a request safe to retry. Supplying the same key on a retry with an identical request body returns the original response without triggering a second operation. Retrying with the same key while the first request is still in flight returns 409 Conflict. Reusing a key with a different request body returns 422 Unprocessable Entity with details[].issue IDEMPOTENCY_KEY_MISMATCH. Keys are retained for 24 hours after the operation completes, after which the key may be reused.

Formatuuid
traceparent?string

W3C Trace Context identifier for this request. Clients should send a traceparent on every request so the trace can be correlated across services. See https://www.w3.org/TR/trace-context/ for the format.

Match^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Request Body

application/json

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/apps/string/domains" \  -H "Content-Type: application/json" \  -d '{    "hostname": "www.example.com"  }'
{  "domainId": "string",  "hostname": "www.example.com",  "role": "PRIMARY",  "verificationStatus": "PENDING",  "certificateValidationCname": "_acme-challenge.example.com.validation.example.net",  "anycastIp": "192.0.2.10",  "cdnStatus": "INIT",  "domainType": "PREFIX",  "links": [    {      "href": "http://example.com",      "rel": "string",      "title": "string",      "targetMediaType": "string",      "targetSchema": null,      "method": "string",      "submissionMediaType": "application/json",      "submissionSchema": null    }  ]}
GET
/apps/{appId}/domains/{domainId}

Authorization

oauth2 hosting.domain:read
AuthorizationBearer <token>

GoDaddy OAuth 2.0 access token. The scope(s) listed on each operation are enforced per-operation. A token requires at least one of the scopes listed for that operation.

In: header

Scope: hosting.domain:read

Path Parameters

appId*string

Application identifier in {PRODUCT}-{id} form. The prefix is the application type in upper case — an upper-case letter followed by any number of upper-case letters, digits, or underscores — then a hyphen, then the identifier. For NODEJS, the suffix is a 10-character nanoid. Example: NODEJS-aBcDeFgHiJ.

Match^[A-Z][A-Z0-9_]*-[A-Za-z0-9_-]+$
domainId*string

Domain attachment identifier returned in the domainId field of POST /apps/{appId}/domains.

Header Parameters

traceparent?string

W3C Trace Context identifier for this request. Clients should send a traceparent on every request so the trace can be correlated across services. See https://www.w3.org/TR/trace-context/ for the format.

Match^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/apps/string/domains/string"
{  "domainId": "string",  "hostname": "www.example.com",  "role": "PRIMARY",  "verificationStatus": "PENDING",  "certificateValidationCname": "_acme-challenge.example.com.validation.example.net",  "anycastIp": "192.0.2.10",  "cdnStatus": "INIT",  "domainType": "PREFIX",  "links": [    {      "href": "http://example.com",      "rel": "string",      "title": "string",      "targetMediaType": "string",      "targetSchema": null,      "method": "string",      "submissionMediaType": "application/json",      "submissionSchema": null    }  ]}
DELETE
/apps/{appId}/domains/{domainId}

Authorization

oauth2 hosting.domain:write
AuthorizationBearer <token>

GoDaddy OAuth 2.0 access token. The scope(s) listed on each operation are enforced per-operation. A token requires at least one of the scopes listed for that operation.

In: header

Scope: hosting.domain:write

Path Parameters

appId*string

Application identifier in {PRODUCT}-{id} form. The prefix is the application type in upper case — an upper-case letter followed by any number of upper-case letters, digits, or underscores — then a hyphen, then the identifier. For NODEJS, the suffix is a 10-character nanoid. Example: NODEJS-aBcDeFgHiJ.

Match^[A-Z][A-Z0-9_]*-[A-Za-z0-9_-]+$
domainId*string

Domain attachment identifier returned in the domainId field of POST /apps/{appId}/domains.

Header Parameters

traceparent?string

W3C Trace Context identifier for this request. Clients should send a traceparent on every request so the trace can be correlated across services. See https://www.w3.org/TR/trace-context/ for the format.

Match^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X DELETE "https://example.com/apps/string/domains/string"
Empty

Agent & Automation Notes

Scopeshosting.application:read, hosting.application:create, hosting.application:update, hosting.application:delete, hosting.source:write, hosting.deployment:execute, hosting.secret:write, hosting.log:read
Rate limit10–120 req/min per client IP depending on operation
On failureCreate app returns 202 with a job. Poll GET /app-operations/{operationId} until app is ready. Upload source and deployments return 202 with an operation ID. Poll the matching status endpoint until complete. GET operations are safe to retry. Do not resubmit writes without checking current state.

Last updated on

How is this guide?