The calling node's profile document (node side).
const url = 'https://api.opdns.io/v1/nodes/self/profile';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.opdns.io/v1/nodes/self/profile \ --header 'Authorization: Bearer <token>'The full profile document as published to the edge (docs/engineering.md), with
the list artifact to use (the latest fleet manifest, lists/latest.json).
ETag is opaque and changes with the profile version and the list version
("<profile version>" or "<profile version>-<list version>"); If-None-Match
with it answers 304. Date is set on 200 and 304 as a clock reference. Fetched
on enrolment and on every ProfileChanged over the link.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”Responses
Section titled “Responses”Profile. lists_url and lists_sha256 are deprecated: the response carries Deprecation and Sunset.
object
The profile document published to the edge and nodes (docs/engineering.md).
object
Public 6-character id; never 000000.
The profile’s display name (renames republish the document).
object
object
object
object
object
object
EDNS Client Subnet (RFC 7871) forwarded to authoritative servers. off sends none (an explicit /0 opt-out). anonymised sends the client’s network truncated to /24 (IPv4) or /56 (IPv6). full sends the client’s address itself (/32 and /128 by default; the operator may cap it lower, commonly /64 for IPv6), so the client’s IP address reaches every authoritative server queried on its behalf: better CDN steering, less privacy. A client’s own ECS option is forwarded no wider than the mode allows, and its /0 opt-out is always honoured.
How long opdns holds this profile’s logs for its self-hosted node while the node is offline (log destination self-hosted or both), in hours; 24 at most. 0 holds nothing: records made while the node is offline are dropped (with both the cloud copy is still kept). Records older than the window are never delivered. retention_days is the cloud log retention, a different setting. Profiles saved before 0.9.0 read as 24.
Where opdns stores this profile’s query logs in the cloud (log destination cloud or both). ca: Canada (the control plane at OVH Beauharnois, Québec), the only region available today and the default. eu is announced but not yet accepted: the API refuses it with a 422 problem (settings.log_region) until the region exists. A self-hosted node’s own logs stay on the node. Profiles saved before 0.10.0 read as ca.
List artifact to load; absent when none is known.
object
Artifact version; 0 when only configured by flag.
Absolute artifact URL (lists/v
Hex SHA-256 of the artifact; may be empty.
Same as lists.url (empty when absent); removed after one release.
Same as lists.sha256; removed after one release.
List signing public key; empty when not configured.
Base64 Ed25519 signature of profile by the key profile_key_id, over
"opdns-profile-sig/1\n" + id + "\n" + version + "\n" + compact JSON of profile (threat model G-1). Absent when the cloud does not sign.
Key id of the signing key (first 8 bytes of its SHA-256, hex).
Every hex Ed25519 key the cloud signs profiles with (rotation), the signing key first.
Example
{ "profile": { "settings": { "block_mode": "nxdomain", "log_destination": "cloud", "ecs": "off", "node_queue_hours": 0, "log_region": "ca" } }}Headers
Section titled “Headers”Profile version as a strong ETag, e.g. "3".
RFC 9745: the response uses a deprecated field or endpoint; the value is when it was deprecated, @<unix seconds>.
RFC 8594: the HTTP date after which the deprecated field or endpoint may be removed.
Not modified.
Headers
Section titled “Headers”Profile version as a strong ETag, e.g. "3".
Missing or unknown node token (unauthenticated) or revoked node (node_revoked).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/node_revoked", "title": "Unauthorized", "status": 401, "code": "node_revoked", "detail": "the node was revoked", "request_id": "5f2c9a0e7b1d4c38"}Not found (also for resources of another organisation).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/not_found", "title": "Not Found", "status": 404, "code": "not_found", "detail": "resource not found", "request_id": "5f2c9a0e7b1d4c38"}Rate limited (rate_limited).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/rate_limited", "title": "Too Many Requests", "status": 429, "code": "rate_limited", "detail": "too many requests", "request_id": "5f2c9a0e7b1d4c38", "retry_after": 6}