Skip to content
op
dns
docs
Search the docs
Ctrl
K
Cancel
Status
Source on GitHub
Menu
Get started
What op
dns
is
Create an account and a profile
Your endpoints
Check it works
Set up a device
Android
iOS and iPadOS
macOS
Windows 11
Linux (systemd-resolved)
ChromeOS
Tested clients
Browsers
Firefox
Chrome
Edge
Brave
Set up a network
OpenWrt
pfSense and OPNsense
UniFi
Any router (DHCP and IPv6)
Linked IP and DDNS
Dashboard guide
Profiles
Security
Privacy blocklists
Parental control
Denylist, allowlist and rewrites
Settings
Logs
Analytics
Devices
Nodes
Account
Self-hosted node
Overview
Install with Docker
Install the static binary
Enrol a node
Standalone mode
Network access
Configuration reference
Logs on your node
Offline behaviour and troubleshooting
Upgrade and back up
How it works
Architecture and the log model
Identification
Policy evaluation order
Block answers and EDE codes
The public resolver path
API
Authentication, tokens and scopes
Errors and rate limits
API versioning and deprecation
Reference
Overview
auth
Overview
Read the current public signup mode.
GET
Create an account and its organisation.
POST
Request a waitlist confirmation email.
POST
Confirm a waitlist email address.
GET
Confirm an email address with the emailed token.
POST
Send a new email verification token.
POST
Log in with email and password.
POST
End the current session.
POST
The authenticated account.
GET
Delete the account after a cooling-off (session only).
DELETE
Cancel a pending account deletion (session only).
POST
The account's recent data exports, newest first (session only).
GET
Start an export of the account's data (session only).
POST
An export's status and, when ready, its download URL (session only).
GET
Download a ready export archive (session only).
GET
The account's preferences, defaults filled in (session only).
GET
Change preferences (session only).
PATCH
Signed-in sessions of the account (session only).
GET
Sign out every other session (session only).
DELETE
The organisation's audit log, newest first.
GET
Sign out one session (session only).
DELETE
Email a password reset link.
POST
Set a new password with an emailed reset token.
POST
Email an account recovery link (lost sign-in methods).
POST
Recover an account with the emailed token and a recovery code.
POST
Change (or set) the account's password (session only).
POST
Start authenticator app (TOTP) enrolment (session only, step-up).
POST
Finish TOTP enrolment with a first valid code (session only).
POST
Turn TOTP off (session only, step-up).
POST
How many recovery codes are left (session only).
GET
Replace the recovery codes (session only, step-up).
POST
The account's passkeys (session only).
GET
Remove a passkey (session only, step-up).
DELETE
Rename a passkey (session only).
PATCH
Start registering a passkey (session only, step-up).
POST
Verify and store a new passkey (session only).
POST
Start a passkey sign-in.
POST
Verify a passkey assertion and sign in.
POST
tokens
Overview
List API tokens of the account.
GET
Create an API token (session only).
POST
Revoke an API token (session only).
DELETE
profiles
Overview
List the organisation's profiles.
GET
Create a profile.
POST
Get a profile.
GET
Delete a profile.
DELETE
Update name and settings (partial).
PATCH
Deny, allow and rewrite rules.
GET
Replace every rule (one version bump).
PUT
Enabled catalogue lists.
GET
Set the enabled lists.
PUT
Linked IPv4 addresses (Do53 identification).
GET
Link an address, or create an empty DDNS slot.
POST
Unlink an address.
DELETE
lists
Overview
The blocklist catalogue with sources and licences.
GET
Parental-control categories a profile can block (parental.categories).
GET
Blockable services (parental.services) with their domains and collateral-damage notes.
GET
The profile's list reports, newest first.
GET
Report a list false positive or false negative.
POST
nodes
Overview
Self-hosted nodes of the profile.
GET
Create a node and its one-time enrolment code.
POST
Revoke a node.
DELETE
Exchange an enrolment code for a node token (node side).
POST
The calling node's identity (node side).
GET
Revoke the calling node (node side, `op
dns
-node unenrol`).
DELETE
Rotate the calling node's token (node side, `op
dns
-node rotate-token`).
POST
The calling node's profile document (node side).
GET
devices
Overview
List the profile's devices.
GET
Get one device.
GET
Forget a device.
DELETE
Set a device's display name, kind or notes.
PATCH
logs
Overview
Query log tail or search.
GET
Live log tail as server-sent events.
GET
Analytics aggregate.
GET
ddns
Overview
The DDNS update URL of a linked IP.
GET
Replace the DDNS token; the old URL stops working at once.
POST
Set the linked IP owning the token to the caller's IPv4 address.
GET
meta
Overview
This document.
GET
Deployment facts for clients.
GET
What this deployment supports.
GET
The PoP catalogue.
GET
The caller's public IP address as the API sees it.
GET
Report a dashboard error.
POST
Send feedback from the dashboard.
POST
data-rights
Overview
Delete the account after a cooling-off (session only).
DELETE
Cancel a pending account deletion (session only).
POST
The account's recent data exports, newest first (session only).
GET
Start an export of the account's data (session only).
POST
An export's status and, when ready, its download URL (session only).
GET
Download a ready export archive (session only).
GET
Delete an account on its owner's behalf (admin).
POST
Cancel a pending account deletion on its owner's behalf (admin).
DELETE
admin
Overview
The list report triage queue, newest first (admin).
GET
The list compiler's sources and their last fetch (admin).
GET
The list builds the compiler judged, newest first (admin).
GET
Delete an account on its owner's behalf (admin).
POST
Cancel a pending account deletion on its owner's behalf (admin).
DELETE
A profile's suspension state (admin).
GET
Suspend or reinstate a profile (admin).
PATCH
Accept or reject a list report (admin).
PATCH
Operator-level domain blocks (admin).
GET
Add an operator-level domain block (admin).
POST
Remove an operator-level domain block (admin).
DELETE
Abusive-source blocks (admin).
GET
Block an abusive source prefix (admin).
POST
Remove an abusive-source block (admin).
DELETE
Every organisation's audit log, newest first (admin).
GET
Dashboard error reports of the last 30 days, newest first (admin).
GET
Feedback of the last 365 days, newest first (admin).
GET
setup
Overview
Setup values or an Apple configuration profile for a profile.
GET
op
dns
compared with NextDNS and ControlD
Operator (admin only)
Operator and source blocks
List rollouts
Profile propagation
Resolver operations
Fleet operations
Backups and restore
Alerting
GeoIP and owner classification
Admin tools
Contributing
The development environment
Legal and project
Licensing
Policies
Changelog
Service status
Status
Source on GitHub
Overview
data-rights
Section titled “data-rights”
Account export and deletion (GDPR).
Operations
Section titled “Operations”
DELETE
/v1/auth/me
POST
/v1/auth/me/undelete
GET
/v1/auth/me/export
POST
/v1/auth/me/export
GET
/v1/auth/me/export/{id}
GET
/v1/auth/me/export/{id}/download
POST
/v1/admin/accounts/{id}/deletion
DELETE
/v1/admin/accounts/{id}/deletion
Home
Status