> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Retrieve a domain

> Retrieve the complete public state and redirect configuration for one custom domain.

Retrieve one domain attached to the API key's workspace.

## Authentication and permission

Requires **Custom domains: Read** (`custom_domains.view`). Only a public
`biq_dom_...` ID is accepted; numeric IDs and hosts are not path identifiers.

```bash theme={null}
curl --request GET \
  --url https://biq.li/api/v1/domain/biq_dom_01M18D4A8QRJY5G6K3N2W7X9TZ \
  --header 'Authorization: Bearer biqli_your_workspace_api_key' \
  --header 'Accept: application/json'
```

## Response

`200 OK` returns the complete safe domain resource:

```json theme={null}
{
  "domain": {
    "id": "biq_dom_01M18D4A8QRJY5G6K3N2W7X9TZ",
    "host": "go.example.com",
    "url": "https://go.example.com",
    "status": "active",
    "dns_status": "verified",
    "ssl_status": "active",
    "dns_verified": true,
    "active": true,
    "is_subdomain": true,
    "links_count": 42,
    "claim_expires_at": null,
    "dns_last_checked_at": "2026-08-30T03:00:00+00:00",
    "dns_verified_at": "2026-08-30T03:00:00+00:00",
    "ssl_last_checked_at": "2026-08-30T03:02:00+00:00",
    "use_default_redirect": true,
    "default_redirect_url": "https://example.com",
    "use_not_found_redirect": true,
    "not_found_redirect_url": "https://example.com/not-found",
    "use_expired_redirect": false,
    "expired_redirect_url": null,
    "created_at": "2026-08-30T02:30:00+00:00",
    "updated_at": "2026-08-30T03:02:00+00:00"
  },
  "status": "success"
}
```

`links_count` includes only links in the API key's workspace, even when the
same verified domain is attached to another workspace.

| `status`           | Meaning                                          |
| ------------------ | ------------------------------------------------ |
| `pending_dns`      | Waiting for the required DNS records.            |
| `verifying_dns`    | A DNS check is in progress.                      |
| `dns_failed`       | The last DNS check did not find both records.    |
| `provisioning_ssl` | DNS passed and SSL is pending or processing.     |
| `ssl_failed`       | The most recent SSL provisioning attempt failed. |
| `active`           | DNS is verified and SSL is active.               |

The response never exposes numeric user/workspace IDs, verification internals,
raw DNS lookup results, SSL errors, or cleanup state. Use
[Retrieve DNS configuration](/docs/api-reference/domains/dns-config) for the exact
records the owner must publish.

Malformed, deleted, or cross-workspace IDs all return the same
`404 resource_not_found` response to prevent resource disclosure.

## Shared API behavior

Authentication is workspace-scoped; see [Authentication](/docs/api-reference/authentication). Errors use the standard envelope and request IDs described in [Errors](/docs/api-reference/errors), and requests are subject to [Rate limits](/docs/api-reference/rate-limits).


## OpenAPI

````yaml GET /v1/domain/{domain}
openapi: 3.1.0
info:
  title: Biqli API
  version: 1.0.0
  description: Workspace-scoped REST API for Biqli.
servers:
  - url: https://biq.li/api
security:
  - bearerAuth: []
paths:
  /v1/domain/{domain}:
    get:
      tags:
        - Domains
      summary: Retrieve a domain
      description: >-
        Returns the complete safe state of one workspace domain. Requires
        custom_domains.view.
      operationId: domain.show
      parameters:
        - $ref: '#/components/parameters/DomainId'
      responses:
        '200':
          description: Domain returned successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DomainResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    DomainId:
      name: domain
      in: path
      required: true
      description: Public custom-domain ID. Numeric IDs and hosts are not accepted.
      schema:
        type: string
        pattern: ^biq_dom_[0-9A-HJKMNP-TV-Z]{26}$
  schemas:
    DomainResponse:
      type: object
      additionalProperties: false
      required:
        - domain
        - status
      properties:
        domain:
          $ref: '#/components/schemas/Domain'
        status:
          type: string
          const: success
    Domain:
      type: object
      additionalProperties: false
      required:
        - id
        - host
        - url
        - status
        - dns_status
        - ssl_status
        - dns_verified
        - active
        - is_subdomain
        - links_count
        - claim_expires_at
        - dns_last_checked_at
        - dns_verified_at
        - ssl_last_checked_at
        - use_default_redirect
        - default_redirect_url
        - use_not_found_redirect
        - not_found_redirect_url
        - use_expired_redirect
        - expired_redirect_url
        - created_at
        - updated_at
      properties:
        id:
          type: string
          pattern: ^biq_dom_[0-9A-HJKMNP-TV-Z]{26}$
        host:
          type: string
          examples:
            - go.example.com
        url:
          type: string
          format: uri
        status:
          type: string
          enum:
            - pending_dns
            - verifying_dns
            - dns_failed
            - provisioning_ssl
            - ssl_failed
            - active
        dns_status:
          type: string
          enum:
            - pending
            - verifying
            - verified
            - failed
        ssl_status:
          type: string
          enum:
            - pending
            - processing
            - active
            - failed
        dns_verified:
          type: boolean
        active:
          type: boolean
        is_subdomain:
          type: boolean
        links_count:
          type: integer
          minimum: 0
          description: Links using this domain in the API key's workspace only.
        claim_expires_at:
          type:
            - string
            - 'null'
          format: date-time
        dns_last_checked_at:
          type:
            - string
            - 'null'
          format: date-time
        dns_verified_at:
          type:
            - string
            - 'null'
          format: date-time
        ssl_last_checked_at:
          type:
            - string
            - 'null'
          format: date-time
        use_default_redirect:
          type: boolean
        default_redirect_url:
          type:
            - string
            - 'null'
          format: uri
        use_not_found_redirect:
          type: boolean
        not_found_redirect_url:
          type:
            - string
            - 'null'
          format: uri
        use_expired_redirect:
          type: boolean
        expired_redirect_url:
          type:
            - string
            - 'null'
          format: uri
        created_at:
          type:
            - string
            - 'null'
          format: date-time
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
    ApiError:
      type: object
      required:
        - error
        - request_id
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              enum:
                - invalid_token
                - insufficient_scope
                - upgrade_required
                - quota_exceeded
                - resource_not_found
                - domain_taken
                - alias_taken
                - external_id_taken
                - folder_name_taken
                - tag_name_taken
                - pixel_name_taken
                - biolink_name_taken
                - method_not_allowed
                - url_blocked
                - dns_verification_failed
                - validation_error
                - rate_limit_exceeded
                - internal_server_error
            message:
              type: string
            details:
              type: object
              additionalProperties: true
        request_id:
          type: string
          description: Request identifier to include when contacting support.
  responses:
    Unauthorized:
      $ref: '#/components/responses/ApiErrorResponse'
      description: The workspace API key is missing, invalid, or revoked.
    Forbidden:
      $ref: '#/components/responses/ApiErrorResponse'
      description: >-
        The key lacks a required scope, the workspace must upgrade, or its quota
        is exhausted.
    NotFound:
      $ref: '#/components/responses/ApiErrorResponse'
      description: >-
        The requested resource or referenced public ID is unavailable in the
        key's workspace.
    RateLimited:
      description: The workspace exceeded its plan's API rate limit.
      headers:
        RateLimit-Policy:
          description: Current IETF HTTPAPI quota policy as a structured field.
          schema:
            type: string
            example: '"workspace-api";q=1000;w=60'
        RateLimit:
          description: Current IETF HTTPAPI service limit as a structured field.
          schema:
            type: string
            example: '"workspace-api";r=0;t=17'
        Retry-After:
          description: Seconds to wait before retrying the request.
          schema:
            type: integer
            minimum: 0
            example: 17
        X-RateLimit-Limit:
          description: Legacy maximum request count for the current window.
          schema:
            type: integer
            minimum: 1
            example: 1000
        X-RateLimit-Remaining:
          description: Legacy remaining request count.
          schema:
            type: integer
            minimum: 0
            example: 0
        X-RateLimit-Reset:
          description: Legacy reset time as a UTC Unix timestamp.
          schema:
            type: integer
            format: int64
            example: 1788126519
        X-Biq-Request-Id:
          description: Request identifier for support and tracing.
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    InternalError:
      $ref: '#/components/responses/ApiErrorResponse'
      description: The request failed unexpectedly.
    ApiErrorResponse:
      description: API error.
      headers:
        X-Biq-Request-Id:
          description: Request identifier for support and tracing.
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Workspace API key
      description: A workspace API key beginning with biqli_.

````