Your zone can also be maintained programmatically. The interface is compatible with the PowerDNS API — tools that know it work unchanged. The most common case is the automatic issuing of certificates via a DNS query.

API access view with API address, Server ID and the list of stored keys API access view with API address, Server ID and the list of stored keys Address, Server ID and the stored keys.

Creating a key

Under API access you assign a label — ideally the name of the system that uses it — and create the key.

The key is shown exactly once. After that it can no longer be retrieved, only replaced. So store it immediately where it is needed.

For every key you see when it was created and when it was last used. A key that has gone unused for months should be revoked.

What a key may do — and what it may not

A key is valid only for this one zone. It cannot see or change any other domains, not even your own from other contracts. Inside the zone the same rules apply as in the user interface: only the record types enabled in your plan, the same limits for time to live (TTL) and for the number of records, and the zone header and the name servers stay locked.

The limit on changes in the last hour applies here as well. If it is exceeded, the interface responds with status 429, and the calling tool tries again later.

Example: certificates with acme.sh

For a DNS-based certificate request you need three pieces of information, all of which are shown in the API access view:

export PDNS_Url="https://<address from the view>"
export PDNS_ServerId="localhost"
export PDNS_Token="<your key>"

acme.sh --issue --dns dns_pdns -d musterfirma.at -d '*.musterfirma.at'

acme.sh creates the required TXT record itself, waits for the check and then removes it again. You see these operations on the Information page under Recent activity.

If something doesn't work

ResponseMeaning
401Key unknown or revoked. Check that it was copied over in full.
403The request addressed a zone other than the one the key belongs to.
422The record violates a rule — for example a type that is not enabled or a TTL that is not permitted. The response states the reason in plain text.
429Too many changes in a short time. Try again later.
Was this answer helpful? 0 Users Found This Useful (0 Votes)