> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ohmyho.st/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For account actions, read https://ohmyho.st/skills/ohmyhost-get-started/SKILL.md and use the authenticated ohmyho.st CLI, local product MCP or supported remote OAuth MCP. Read the current project source binding before choosing GitHub or managed versions. Mintlify search only reads documentation. Preserve the customer’s selected project, environment and authentication provider; keep private application values in the portal or local stdin flow.

# Start project-scoped Cloudflare DNS authorization

> Creates or replays one short-lived authorization URL for the customer Cloudflare zone bound to the project's Paid domain. Pending requests replay the original handoff. Expired or consumed requests return cloudflare_authorization_closed (409); read current DNS authorization status and reuse a valid matching grant, or request a fresh authorization with a new key. No provider credential is returned.



## OpenAPI

````yaml /openapi.json post /v1/projects/{project_id}/cloudflare-dns/authorization
openapi: 3.1.2
info:
  title: ohmyho.st API
  version: 0.0.0
  description: >-
    Public REST API for ohmyho.st hosting, projects, domains, email, credits and
    exports.
servers:
  - url: https://app.ohmyho.st
    description: Production control API
  - url: https://dev.app.ohmyho.st
    description: Development control API
security:
  - BearerAuth: []
paths:
  /v1/projects/{project_id}/cloudflare-dns/authorization:
    post:
      summary: Start project-scoped Cloudflare DNS authorization
      description: >-
        Creates or replays one short-lived authorization URL for the customer
        Cloudflare zone bound to the project's Paid domain. Pending requests
        replay the original handoff. Expired or consumed requests return
        cloudflare_authorization_closed (409); read current DNS authorization
        status and reuse a valid matching grant, or request a fresh
        authorization with a new key. No provider credential is returned.
      operationId: createCloudflareDnsAuthorization
      parameters:
        - $ref: '#/components/parameters/RequestId'
        - $ref: '#/components/parameters/ProjectId'
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateCloudflareDnsAuthorizationRequest'
      responses:
        '201':
          description: A short-lived Cloudflare authorization URL.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CloudflareDnsAuthorization'
        '400':
          $ref: '#/components/responses/Problem'
        '401':
          $ref: '#/components/responses/Problem'
        '403':
          $ref: '#/components/responses/Problem'
        '404':
          $ref: '#/components/responses/ResourceNotFound'
        '409':
          $ref: '#/components/responses/Problem'
        '413':
          $ref: '#/components/responses/Problem'
        '429':
          $ref: '#/components/responses/Problem'
        '503':
          $ref: '#/components/responses/Problem'
components:
  parameters:
    RequestId:
      name: X-Request-Id
      in: header
      description: Optional caller-provided correlation identifier.
      required: false
      schema:
        type: string
        minLength: 1
        maxLength: 128
    ProjectId:
      name: project_id
      in: path
      description: Project identifier.
      required: true
      schema:
        $ref: '#/components/schemas/Ulid'
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      description: Identifies one mutation and its canonical request payload.
      required: true
      schema:
        type: string
        minLength: 1
        maxLength: 128
  schemas:
    CreateCloudflareDnsAuthorizationRequest:
      type: object
      additionalProperties: false
      required:
        - zone
      properties:
        zone:
          type: string
          minLength: 4
          maxLength: 253
          pattern: >-
            ^(?=.{1,253}$)(?:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?\.)+[a-z]{2,63}$
    CloudflareDnsAuthorization:
      type: object
      description: >-
        Short-lived credential-free redirect information for one Cloudflare
        OAuth authorization.
      additionalProperties: false
      required:
        - authorization_id
        - authorization_url
        - expires_at
      properties:
        authorization_id:
          $ref: '#/components/schemas/Ulid'
        authorization_url:
          type: string
          format: uri
          minLength: 20
          maxLength: 4096
          pattern: ^https://dash\.cloudflare\.com/oauth2/auth\?
        expires_at:
          type: string
          format: date-time
    Ulid:
      type: string
      pattern: ^[0-9A-HJKMNP-TV-Z]{26}$
    ProblemDetails:
      type: object
      description: RFC 9457 Problem Details extended with stable ohmyhost recovery fields.
      additionalProperties: false
      required:
        - type
        - title
        - status
        - code
        - request_id
        - retryable
        - suggested_action
      properties:
        type:
          type: string
          format: uri-reference
        title:
          type: string
          minLength: 1
        status:
          type: integer
          minimum: 400
          maximum: 599
        detail:
          type: string
        instance:
          type: string
          format: uri-reference
        code:
          type: string
          enum:
            - invalid_request
            - unauthenticated
            - forbidden
            - organization_required
            - resource_not_found
            - idempotency_key_reused
            - project_handle_unavailable
            - project_identity_unavailable
            - deployment_plan_expired
            - deployment_plan_incompatible
            - confirmation_expired
            - confirmation_invalid
            - etag_mismatch
            - promotion_source_stale
            - promotion_target_stale
            - promotion_invalid_target
            - mail_domain_conflict
            - mail_domain_required
            - mail_capacity_unavailable
            - storage_jurisdiction_conflict
            - shared_data_requires_promotion
            - production_deployment_required
            - framework_conversion_required
            - repository_configuration_missing
            - migration_filename_noncanonical
            - environment_secret_mutation_blocked
            - workers_runtime_incompatible
            - project_handle_invalid
            - project_handle_taken
            - project_handle_unchanged
            - project_rename_blocked
            - payload_too_large
            - rate_limited
            - insufficient_organization_credits
            - paid_plan_required
            - project_budget_exceeded
            - compute_performance_paid_required
            - compute_performance_unavailable
            - database_write_pending
            - database_access_limit
            - compute_change_pending
            - compute_change_conflict
            - billing_purchase_conflict
            - billing_recharge_conflict
            - github_connection_required
            - github_connection_revoked
            - repository_not_installed
            - cloudflare_zone_not_bound
            - cloudflare_authorization_closed
            - project_notes_conflict
            - project_export_not_ready
            - powered_by_flag_required
            - interactive_login_required
            - api_key_creation_uncertain
            - api_key_permissions_unavailable
            - reconciliation_exhausted
            - service_unavailable
            - source_commit_not_found
            - domain_hostname_taken
            - domain_dns_conflict
            - data_change_blocked
            - data_change_in_progress
            - data_change_not_applicable
            - rollback_target_data_changed
            - project_domain_delete_required
        request_id:
          type: string
          minLength: 1
          maxLength: 128
        retryable:
          type: boolean
        retry_after_seconds:
          type: integer
          minimum: 1
          maximum: 86400
          description: >-
            Optional machine-readable retry delay for a rate limit, matching
            Retry-After.
        suggested_action:
          type: string
          minLength: 1
  headers:
    XRequestId:
      description: Correlates the request with operations, events, logs, and audit records.
      required: true
      schema:
        type: string
        minLength: 1
        maxLength: 128
  responses:
    Problem:
      description: The request failed.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    ResourceNotFound:
      description: >-
        The resource does not exist or is not visible to the authenticated
        principal.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            resourceNotFound:
              value:
                type: https://docs.ohmyho.st/errors/resource-not-found
                title: Resource not found
                status: 404
                code: resource_not_found
                request_id: req_01J00000000000000000000000
                retryable: false
                suggested_action: Check the resource identifier and your access scope.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        WorkOS access JWT or a user-owned WorkOS API key. User keys are bound to
        one organization and restricted to their enabled product permissions.
        Session-only onboarding and session revocation require an interactive
        access JWT. No cookie session is assumed.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.