> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify a domain

> Check the required DNS records and begin SSL provisioning when they match.

Check the routing and TXT ownership records for one domain. Requires **Custom
domains: Write** (`custom_domains.update`). Send an empty JSON object or no
body; no fields are accepted.

```bash theme={null}
curl --request POST \
  --url https://biq.li/api/v1/domain/biq_dom_01M18D4A8QRJY5G6K3N2W7X9TZ/verify \
  --header 'Authorization: Bearer biqli_your_workspace_api_key' \
  --header 'Accept: application/json' \
  --header 'Content-Type: application/json' \
  --data '{}'
```

## Successful verification

When both records match, Biqli marks DNS verified and queues SSL provisioning:

```json theme={null}
{
  "verified": true,
  "records": {"dns": true, "txt": true},
  "domain": {
    "id": "biq_dom_01M18D4A8QRJY5G6K3N2W7X9TZ",
    "host": "go.example.com",
    "status": "provisioning_ssl",
    "dns_status": "verified",
    "ssl_status": "processing",
    "dns_verified": true,
    "active": false
  },
  "status": "success"
}
```

The actual domain object is complete; it is abbreviated above. DNS verification
does not mean HTTPS is ready. Retrieve the domain until `status` and `ssl_status`
are both `active` before publishing links that depend on it.

## DNS not ready

If either record is missing or has not propagated, the endpoint returns
`422 dns_verification_failed`:

```json theme={null}
{
  "error": {
    "code": "dns_verification_failed",
    "message": "The required DNS records were not found or have not propagated yet.",
    "details": {
      "verified": false,
      "records": {"dns": true, "txt": false},
      "dns_config": {
        "host": "go.example.com",
        "is_subdomain": true,
        "records": [
          {"type":"CNAME","name":"go","value":"biq.li","ttl":"auto"},
          {"type":"TXT","name":"_verify.example.com","value":"domain-verify=...","ttl":"auto"}
        ]
      }
    }
  },
  "request_id": "ae437f49-30a3-4d55-bca6-dc523f2efcb3"
}
```

The two booleans identify which requirement is missing without exposing other
DNS records found during lookup. DNS propagation can take time; correct the
records, wait, and retry. Verification is idempotent, and repeated successful
checks do not queue duplicate active SSL operations.

## Shared API behavior

Authentication is workspace-scoped; see [Authentication](/docs/api-reference/authentication). Errors use the standard envelope and request IDs described in [Errors](/docs/api-reference/errors), and requests are subject to [Rate limits](/docs/api-reference/rate-limits).


## OpenAPI

````yaml POST /v1/domain/{domain}/verify
openapi: 3.1.0
info:
  title: Biqli API
  version: 1.0.0
  description: Workspace-scoped REST API for Biqli.
servers:
  - url: https://biq.li/api
security:
  - bearerAuth: []
paths:
  /v1/domain/{domain}/verify:
    post:
      tags:
        - Domains
      summary: Verify a domain
      description: >-
        Checks routing and ownership DNS records and queues SSL provisioning
        after both match. Requires custom_domains.update.
      operationId: domain.verify
      parameters:
        - $ref: '#/components/parameters/DomainId'
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              maxProperties: 0
      responses:
        '200':
          description: DNS was verified and SSL is active or provisioning.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VerifyDomainResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/UnprocessableEntity'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    DomainId:
      name: domain
      in: path
      required: true
      description: Public custom-domain ID. Numeric IDs and hosts are not accepted.
      schema:
        type: string
        pattern: ^biq_dom_[0-9A-HJKMNP-TV-Z]{26}$
  schemas:
    VerifyDomainResponse:
      type: object
      additionalProperties: false
      required:
        - verified
        - records
        - domain
        - status
      properties:
        verified:
          type: boolean
          const: true
        records:
          type: object
          additionalProperties: false
          required:
            - dns
            - txt
          properties:
            dns:
              type: boolean
              const: true
            txt:
              type: boolean
              const: true
        domain:
          $ref: '#/components/schemas/Domain'
        status:
          type: string
          const: success
    Domain:
      type: object
      additionalProperties: false
      required:
        - id
        - host
        - url
        - status
        - dns_status
        - ssl_status
        - dns_verified
        - active
        - is_subdomain
        - links_count
        - claim_expires_at
        - dns_last_checked_at
        - dns_verified_at
        - ssl_last_checked_at
        - use_default_redirect
        - default_redirect_url
        - use_not_found_redirect
        - not_found_redirect_url
        - use_expired_redirect
        - expired_redirect_url
        - created_at
        - updated_at
      properties:
        id:
          type: string
          pattern: ^biq_dom_[0-9A-HJKMNP-TV-Z]{26}$
        host:
          type: string
          examples:
            - go.example.com
        url:
          type: string
          format: uri
        status:
          type: string
          enum:
            - pending_dns
            - verifying_dns
            - dns_failed
            - provisioning_ssl
            - ssl_failed
            - active
        dns_status:
          type: string
          enum:
            - pending
            - verifying
            - verified
            - failed
        ssl_status:
          type: string
          enum:
            - pending
            - processing
            - active
            - failed
        dns_verified:
          type: boolean
        active:
          type: boolean
        is_subdomain:
          type: boolean
        links_count:
          type: integer
          minimum: 0
          description: Links using this domain in the API key's workspace only.
        claim_expires_at:
          type:
            - string
            - 'null'
          format: date-time
        dns_last_checked_at:
          type:
            - string
            - 'null'
          format: date-time
        dns_verified_at:
          type:
            - string
            - 'null'
          format: date-time
        ssl_last_checked_at:
          type:
            - string
            - 'null'
          format: date-time
        use_default_redirect:
          type: boolean
        default_redirect_url:
          type:
            - string
            - 'null'
          format: uri
        use_not_found_redirect:
          type: boolean
        not_found_redirect_url:
          type:
            - string
            - 'null'
          format: uri
        use_expired_redirect:
          type: boolean
        expired_redirect_url:
          type:
            - string
            - 'null'
          format: uri
        created_at:
          type:
            - string
            - 'null'
          format: date-time
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
    ApiError:
      type: object
      required:
        - error
        - request_id
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              enum:
                - invalid_token
                - insufficient_scope
                - upgrade_required
                - quota_exceeded
                - resource_not_found
                - domain_taken
                - alias_taken
                - external_id_taken
                - folder_name_taken
                - tag_name_taken
                - pixel_name_taken
                - biolink_name_taken
                - method_not_allowed
                - url_blocked
                - dns_verification_failed
                - validation_error
                - rate_limit_exceeded
                - internal_server_error
            message:
              type: string
            details:
              type: object
              additionalProperties: true
        request_id:
          type: string
          description: Request identifier to include when contacting support.
  responses:
    Unauthorized:
      $ref: '#/components/responses/ApiErrorResponse'
      description: The workspace API key is missing, invalid, or revoked.
    Forbidden:
      $ref: '#/components/responses/ApiErrorResponse'
      description: >-
        The key lacks a required scope, the workspace must upgrade, or its quota
        is exhausted.
    NotFound:
      $ref: '#/components/responses/ApiErrorResponse'
      description: >-
        The requested resource or referenced public ID is unavailable in the
        key's workspace.
    UnprocessableEntity:
      $ref: '#/components/responses/ApiErrorResponse'
      description: >-
        The payload is invalid, a destination was blocked, or domain DNS
        verification is not ready.
    RateLimited:
      description: The workspace exceeded its plan's API rate limit.
      headers:
        RateLimit-Policy:
          description: Current IETF HTTPAPI quota policy as a structured field.
          schema:
            type: string
            example: '"workspace-api";q=1000;w=60'
        RateLimit:
          description: Current IETF HTTPAPI service limit as a structured field.
          schema:
            type: string
            example: '"workspace-api";r=0;t=17'
        Retry-After:
          description: Seconds to wait before retrying the request.
          schema:
            type: integer
            minimum: 0
            example: 17
        X-RateLimit-Limit:
          description: Legacy maximum request count for the current window.
          schema:
            type: integer
            minimum: 1
            example: 1000
        X-RateLimit-Remaining:
          description: Legacy remaining request count.
          schema:
            type: integer
            minimum: 0
            example: 0
        X-RateLimit-Reset:
          description: Legacy reset time as a UTC Unix timestamp.
          schema:
            type: integer
            format: int64
            example: 1788126519
        X-Biq-Request-Id:
          description: Request identifier for support and tracing.
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    InternalError:
      $ref: '#/components/responses/ApiErrorResponse'
      description: The request failed unexpectedly.
    ApiErrorResponse:
      description: API error.
      headers:
        X-Biq-Request-Id:
          description: Request identifier for support and tracing.
          schema:
            type: string
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Workspace API key
      description: A workspace API key beginning with biqli_.

````