> ## Documentation Index
> Fetch the complete documentation index at: https://docs.app.strix.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify a domain through a connected DNS provider

> Creates the _strix-verification TXT record through the organization's connected DNS provider (Vercel or Cloudflare) and runs the DNS verification check. Requires an organization admin to have connected the provider in the dashboard first.



## OpenAPI

````yaml /openapi.json post /domains/{domainId}/auto-verify
openapi: 3.1.0
info:
  title: Strix API
  version: 1.0.0
  description: >-
    Public REST API for the Strix autonomous penetration testing platform.
    Manage scans, vulnerabilities, assets, schedules, API tokens, and webhooks.
servers:
  - url: /api/v1
    description: Strix v1 API
security:
  - BearerAuth: []
tags:
  - name: Scans
    description: Launch, monitor, and manage security scans.
  - name: Vulnerabilities
    description: View and triage discovered vulnerabilities.
  - name: Assets
    description: Domains and repositories registered for scanning.
  - name: Schedules
    description: Recurring scan schedules (Pro plan).
  - name: Tokens
    description: Manage API tokens for authentication.
  - name: Webhooks
    description: Configure webhook subscriptions for real-time event notifications.
  - name: Organization
    description: Workspace configuration for the authenticated organization.
  - name: Members
    description: Manage organization members and roles.
  - name: Invitations
    description: List and revoke organization invitations.
  - name: PR Reviews
    description: Automated security review of pull requests.
  - name: Connectors
    description: Network connectors for scanning internal/private targets.
  - name: Knowledge
    description: >-
      Organization knowledge base: documents, policies, and repo profiles that
      steer the agent.
  - name: Uploads
    description: Upload source/code/documentation archives for whitebox scans.
  - name: Integrations
    description: Third-party integrations (GitLab, Bitbucket, ticketing).
  - name: Chat
    description: Conversational agent sessions.
  - name: Analytics
    description: Aggregate dashboard analytics.
  - name: Test Users
    description: >-
      Per-domain test accounts (with optional MFA) the agent authenticates as
      during scans.
  - name: License
    description: Self-hosted license state, entitlements, and aggregate usage.
  - name: Supply Chain
    description: >-
      SBOM inventory, supply-chain findings, scans, and policy for connected
      repositories.
paths:
  /domains/{domainId}/auto-verify:
    post:
      tags:
        - Assets
      summary: Verify a domain through a connected DNS provider
      description: >-
        Creates the _strix-verification TXT record through the organization's
        connected DNS provider (Vercel or Cloudflare) and runs the DNS
        verification check. Requires an organization admin to have connected the
        provider in the dashboard first.
      operationId: autoVerifyDomain
      parameters:
        - name: domainId
          in: path
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - provider
              properties:
                provider:
                  type: string
                  enum:
                    - vercel
                    - cloudflare
                  description: >-
                    Connected DNS provider to create the verification record
                    with.
      responses:
        '200':
          description: Auto-verification result.
          content:
            application/json:
              schema:
                type: object
                properties:
                  domain:
                    $ref: '#/components/schemas/Domain'
                  verified:
                    type: boolean
                  record_created:
                    type: boolean
                    description: >-
                      Whether the verification TXT record was created (or
                      already existed) at the provider.
                  error:
                    type: string
                    description: Human-readable reason when verification did not complete.
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - BearerAuth:
            - assets:write
components:
  schemas:
    Domain:
      type: object
      properties:
        id:
          type: string
          format: uuid
        organization_id:
          type: string
        domain:
          type: string
        verified:
          type: boolean
        tags:
          type: array
          items:
            type: string
          description: Enterprise asset labels used for RBAC scoping.
        business_unit:
          type:
            - string
            - 'null'
          description: Enterprise asset label used for RBAC scoping.
        created_at:
          type: string
          format: date-time
        last_scan_at:
          type:
            - string
            - 'null'
          format: date-time
      required:
        - id
        - organization_id
        - domain
        - verified
        - created_at
    ErrorResponse:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable explanation of the error.
        code:
          type: string
          description: >-
            Stable machine-readable error code. `insufficient_scope` means the
            token does not hold the scope that this endpoint requires.
        required_scope:
          $ref: '#/components/schemas/ApiV1Scope'
          description: >-
            Scope that the caller must add to the token. Returned with the
            `insufficient_scope` code.
        docs:
          type: string
          format: uri
          description: Documentation page that explains how to resolve the error.
      required:
        - detail
    ApiV1Scope:
      type: string
      enum:
        - scans:read
        - scans:write
        - vulnerabilities:read
        - vulnerabilities:write
        - dependencies:read
        - schedules:read
        - schedules:write
        - assets:read
        - assets:write
        - organizations:read
        - organizations:write
        - members:read
        - members:write
        - invitations:read
        - invitations:write
        - webhooks:read
        - webhooks:write
        - tokens:write
        - audit:read
        - pr_reviews:read
        - pr_reviews:write
        - connectors:read
        - connectors:write
        - knowledge:read
        - knowledge:write
        - uploads:write
        - integrations:read
        - integrations:write
        - chat:read
        - chat:write
        - scans:message
        - analytics:read
        - llm:read
        - llm:write
        - test_users:read
        - test_users:write
        - license:read
        - supply_chain:read
        - supply_chain:write
  responses:
    BadRequest:
      description: Bad request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Missing or invalid API token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Forbidden:
      description: >-
        Insufficient permissions or missing scope. A missing scope returns the
        `insufficient_scope` code and the `required_scope` field, so a client
        can request the correct scope and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    NotFound:
      description: Resource not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    InternalError:
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token obtained from the Tokens endpoint. Include as `Authorization:
        Bearer <token>`.

````