> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fingerprint.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Domain Connect URL

> Create a signed Domain Connect URL that redirects to a Fingerprint CLI loopback callback. The returned URL is specific to this CLI session and is not stored on the subdomain. Open it in your browser, then use the verify endpoint to check DNS and certificate progress. The redirect targets `http://127.0.0.1:{port}/domain-connect/callback`; the client must listen on the supplied port before opening the URL.

Use the returned URL to authorize DNS changes at the subdomain's DNS provider. Start a local HTTP listener at `http://127.0.0.1:{port}/domain-connect/callback` and send its port in the request body. Keep the listener running while you open the URL and complete authorization in your browser. Remote sessions require port forwarding so your browser can reach the listener.

The URL is specific to that callback listener and isn't stored on the subdomain. The `dns_provider` display name is optional and may be omitted from the response.

This endpoint returns `409` if Domain Connect is unavailable for this subdomain or it is no longer awaiting DNS validation. A public `pending` status doesn't guarantee availability: DNS may already be validated while certificate issuance is still in progress. If Domain Connect is unavailable, add the DNS records manually.

Authorization doesn't mean the subdomain is ready to use. Call [Verify subdomain](/reference/subdomainscontroller_verify), then poll [Get subdomain](/reference/subdomainscontroller_findone) (`GET /subdomains/{id}`) until the status is `active` before updating your application's endpoints. Respect the verification rate limit.


## OpenAPI

````yaml reference/management-api_2025-11-20.json POST /subdomains/{id}/domain-connect
openapi: 3.0.0
info:
  title: Management API
  description: >-
    Managment API allows you to manage your Fingerprint account and applications
    programmatically from a server environment.
  version: '2025-11-20'
  contact: {}
servers:
  - url: https://management-api.fpjs.io
security:
  - Management-API-key: []
tags: []
paths:
  /subdomains/{id}/domain-connect:
    post:
      tags:
        - subdomains
      summary: Create Domain Connect URL
      description: >-
        Create a signed Domain Connect URL that redirects to a Fingerprint CLI
        loopback callback. The returned URL is specific to this CLI session and
        is not stored on the subdomain. Open it in your browser, then use the
        verify endpoint to check DNS and certificate progress. The redirect
        targets `http://127.0.0.1:{port}/domain-connect/callback`; the client
        must listen on the supplied port before opening the URL.
      operationId: SubdomainsController_createDomainConnectUrl
      parameters:
        - name: id
          required: true
          in: path
          schema:
            type: string
        - name: X-API-Version
          in: header
          description: Management API version.
          example: '2025-11-20'
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateDomainConnectUrlDto'
      responses:
        '200':
          description: Signed Domain Connect URL.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DomainConnectUrlApiResponseDto'
        '401':
          description: 'Error: Invalid API key.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiExceptionDto'
        '404':
          description: Subdomain with the given ID was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiExceptionDto'
        '409':
          description: >-
            Subdomain is no longer pending DNS validation, or Domain Connect is
            unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiExceptionDto'
        '422':
          description: Invalid CLI loopback port.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationApiExceptionDto'
        '429':
          description: 'Error: API key has exceeded its rate limit.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiExceptionDto'
components:
  schemas:
    CreateDomainConnectUrlDto:
      type: object
      properties:
        port:
          type: integer
          description: >-
            Local loopback port where the CLI is listening for the Domain
            Connect callback.
          example: 8976
          minimum: 1
          maximum: 65535
      required:
        - port
    DomainConnectUrlApiResponseDto:
      type: object
      properties:
        data:
          $ref: '#/components/schemas/DomainConnectUrlResponseDto'
      required:
        - data
    ApiExceptionDto:
      type: object
      properties:
        error:
          $ref: '#/components/schemas/BaseApiExceptionDto'
      required:
        - error
    ValidationApiExceptionDto:
      type: object
      properties:
        error:
          $ref: '#/components/schemas/BaseValidationApiExceptionDto'
      required:
        - error
    DomainConnectUrlResponseDto:
      type: object
      properties:
        domain_connect_url:
          type: string
          description: >-
            Signed Domain Connect URL. Open it in your browser while the
            matching loopback callback is listening.
        dns_provider:
          type: string
          description: Best-effort DNS provider display name.
          example: Cloudflare
      required:
        - domain_connect_url
    BaseApiExceptionDto:
      type: object
      properties:
        message:
          type: string
          description: Verbal description of the error.
        code:
          type: string
          description: Error code.
      required:
        - message
        - code
    BaseValidationApiExceptionDto:
      type: object
      properties:
        message:
          type: string
          description: Verbal description of the error.
        code:
          type: string
          description: Error code.
        violations:
          description: List of validation violations.
          type: array
          items:
            $ref: '#/components/schemas/BaseValidationApiExceptionViolationDto'
      required:
        - message
        - code
    BaseValidationApiExceptionViolationDto:
      type: object
      properties:
        property:
          type: string
          description: Property that has failed validation.
        message:
          type: string
          description: Description of the violation.
      required:
        - property
        - message
  securitySchemes:
    Management-API-key:
      scheme: bearer
      bearerFormat: JWT
      type: http

````