Provider connections
Plug in what you already have.
DomainVigil monitors any domain without connecting anything. Connecting your registrar, DNS or server hands the AI the keys to fix things for you — transfer lock, DNS records, SPF and DKIM, certificate. Here are the 37 providers we can connect, and what each one unlocks.
37 providers · 27 with portfolio import
Registrars
Where the domain is bought and renewed: transfer lock, auto-renew, and often the DNS too.
- Portfolio import
OVHcloud
Registrar · DNS · Server
Open the token page at OVHcloudWhere to find the token
- On the OVH page that opens, leave the name and description as they are.
- Rights: tick GET, POST, PUT and DELETE, each on the “/*” path.
- Validity: “Unlimited” — otherwise the connection stops working at expiry, without warning.
- Validate: OVH shows three values (application key, secret, consumer key). Copy all three, they are shown once.
- Portfolio import
Hostinger
Registrar · DNS
Open the token page at HostingerWhere to find the token
- In hPanel, click your profile icon, then “Account Information”.
- In the left menu, open “API”, then “Generate token”.
- Give it a name and an expiry date — avoid a very distant one, but note it down: the connection stops that day.
- Copy the token: it is no longer accessible once the menu is closed.
- Portfolio import
Gandi
Registrar · DNS
Open the token page at GandiWhere to find the token
- On admin.gandi.net, go to “Organizations”, then pick the organization that owns your domains.
- Open the “Sharing” tab, then “Create a token”.
- Name it, choose an expiry (7 days to one year — take the longest, otherwise the connection will drop), and tick the DOMAIN NAMES permission.
- Create, then copy the token: it is shown only once.
- Portfolio import
Infomaniak
Registrar · DNS
Open the token page at InfomaniakWhere to find the token
- On the page that opens (profile → “Token management”), click “Create a token”.
- Product: “Domain”. Validity: leave it “unlimited” — an expiry date would cut the connection without warning.
- Infomaniak asks for your account password again to confirm.
- Copy the token: it is not shown again, and it goes inactive after a year without use.
- Portfolio import
GoDaddy
Registrar · DNS
Open the token page at GoDaddyWhere to find the token
- On the GoDaddy page that opens, click “Create New API Key”.
- Environment: “Production”. An “OTE” key only talks to the sandbox and will see none of your domains.
- GoDaddy shows a Key and a Secret: copy both here.
- Portfolio import
Porkbun
Registrar · DNS
Open the token page at PorkbunWhere to find the token
- On the Porkbun page that opens, create an API key: you get a key and a secret.
- Then, in your domain list, switch on “API Access” for EACH domain to monitor — without it Porkbun rejects the key for that domain, and the error message does not say so.
- Copy both values here.
- Portfolio import
Name.com
Registrar · DNS
Open the token page at Name.comWhere to find the token
- On name.com, click the user icon at the top right, “Settings”, then “API Tokens” under Security.
- If you use two-factor authentication, first switch on “Name.com API Access” in Account Settings → Security: without it the token is rejected.
- “Create API Token”, accept the agreement, name the token, then “Generate new token”.
- Take the one from the PRODUCTION section (not Development), and enter your name.com username here — not your email address.
- Portfolio import
DNSimple
Registrar · DNS
Open the token page at DNSimpleWhere to find the token
- On dnsimple.com, open your account page, then the “API & Access” tab in the left column.
- Click “Add”: prefer an ACCOUNT token to a user token — that is what DNSimple recommends.
- Name it. On the Teams plan or higher, grant at least read access on Domains and Zones; on Solo, the token has full permissions by default.
- “Generate token”, then copy it: it is shown only once.
- Portfolio import
NameSilo
Registrar · DNS
Open the token page at NameSiloWhere to find the token
- On the API Manager page that opens, request a new API key and submit the form.
- Leave the IP address fields empty: a restriction would stop our servers from using it.
- Copy the key straight away: NameSilo never shows it again — if lost, you have to generate a new one.
- Portfolio import
Dynadot
Registrar · DNS
Open the token page at DynadotWhere to find the token
- On dynadot.com, left menu “Tools” → “API”, then unlock the account with the link shown on the page.
- Take the PRODUCTION key — not the Sandbox one, which sees none of your domains.
- IP addresses: leave empty, otherwise our servers are refused. Dynadot takes up to ten minutes to apply a change.
- Copy the key here.
- Portfolio import
Namecheap
Registrar · DNS
Open the token page at NamecheapWhere to find the token
- On the Namecheap page that opens (Profile → Tools → API Access), switch the API on, then generate the key — it is shown only once.
- ⚠️ Under “Whitelisted IPs”, add our address: 138.199.145.149. Namecheap only accepts listed addresses; without this line the key is valid but our servers are refused.
- Enter your Namecheap username here (the one you sign in with), not your email address.
- Namecheap opens the API only to accounts with at least 20 domains, $50 of balance or $50 spent in the year: that is their condition, not ours.
- Portfolio import
Amazon Route 53 Domains
Registrar
Open the token page at Amazon Route 53 DomainsWhere to find the token
- In the IAM console that opens, click your name at the top right, then “Security credentials”.
- “Access keys” section → “Create access key”; use case: “Other”, then “Next”, then “Create access key”. Copy both values — the secret is visible only at that moment.
- The IAM user must be allowed the route53domains:ListDomains and route53domains:GetDomainDetail actions. Without them the key is valid but AWS refuses to list your domains.
- This service is the AWS REGISTRAR, different from Route 53 (DNS hosting): if your domains are bought elsewhere, the other entry is the one you need.
DNS hosts
The DNS zone: the tier that unlocks the most repairs — records, SPF, DKIM, DMARC, certificate.
- Portfolio import
Cloudflare
DNS
Open the token page at CloudflareWhere to find the token
- On the page that opens, choose “Create Custom Token” (the first block) — none of the templates fits.
- Permissions, three rows to add: Zone · DNS · Edit — Zone · Zone Settings · Edit — Zone · Zone · Read.
- Zone Resources: “Include” · “All zones”, or only the domains you entrust to us.
- Continue, then “Create Token”, and copy it: Cloudflare shows it only once.
- Portfolio import
Hetzner DNS
DNS
Open the token page at Hetzner DNSWhere to find the token
- Hetzner DNS now lives in the Hetzner Console (console.hetzner.com), with the same token as Hetzner Cloud: enter the project holding your DNS zones.
- “Security” menu → “API tokens” tab → “Generate API token”, with “Read & Write” rights.
- Copy the token: it is shown only once.
- A zone still on the old dns.hetzner.com console must be migrated there first: old tokens stopped working in November 2025.
- Portfolio import
deSEC
DNS
Open the token page at deSECWhere to find the token
- On desec.io, sign in and open the “Token Management” tab.
- Click the “+” button to create a token and give it a name.
- Leave the advanced settings as they are: IP restrictions would stop our servers from using it.
- Copy the token: it is not shown again.
- Portfolio import
Bunny.net
DNS
Open the token page at Bunny.netWhere to find the token
- The page that opens shows the account API key directly: there is only one, and it stays visible.
- Copy it here.
- On a sub-account the key does not appear: ask the main account holder for it.
- Portfolio import
IONOS
DNS
Open the token page at IONOSWhere to find the token
- On the IONOS page that opens, click “Create new key” and give it a name.
- IONOS shows TWO parts: a public prefix and a secret.
- Paste both here joined by a dot, as prefix.secret — that is the complete key we expect.
- Write them down straight away: the secret cannot be viewed after you close the page.
- Portfolio import
Google Cloud DNS
DNS
Open the token page at Google Cloud DNSWhere to find the token
- On the page that opens, pick the project holding your DNS zones, then “Create service account” and give it a name.
- Once created, open it, “Keys” tab → “Add key” → “Create new key” → JSON format. A file downloads.
- In “IAM & Admin” → “IAM”, grant that service account the “DNS Reader” role (roles/dns.reader) on the project.
- Open the downloaded file in a text editor and paste its WHOLE CONTENT here, from the first brace to the last. We read the project, the account address and the key from it.
- Portfolio import
Azure DNS
DNS
Open the token page at Azure DNSWhere to find the token
- On the page that opens (Microsoft Entra → App registrations), click “New registration”, give it a name (for example “DomainVigil”), and confirm.
- On the application page, note the “Application (client) ID” and the “Directory (tenant) ID”: those are the first two values to enter here.
- “Certificates & secrets” menu → “New client secret” → create it, then copy the “Value” column (not “Secret ID”): it is readable only at that moment.
- Last step, the one most often missed: on your SUBSCRIPTION (Access control IAM → Add role assignment), give this application the “Reader” role — or “DNS Zone Contributor” if you want us to repair your records. Without a role the credentials are valid but Azure shows nothing.
ClouDNS
DNS
Open the token page at ClouDNSWhere to find the token
- On ClouDNS, open the “API & Resellers” section of your panel, then “Add new user” to create an API user.
- ClouDNS then shows a numeric id (auth-id) and a password: those are the two values we expect here.
- Leave the IP address restriction empty: a restriction would stop our servers from using it.
- The API user is separate from your account: disabling it cuts the connection without touching your usual access.
- Portfolio import
Vercel
DNS
Open the token page at VercelWhere to find the token
- On the page that opens (Account Settings → Tokens), click “Create”.
- Name the token and pick its scope: your personal account, or the Team that holds your domains.
- “Create Token”, then copy it: Vercel does not show it again.
- Portfolio import
Netlify
DNS
Open the token page at NetlifyWhere to find the token
- On the page that opens (User settings → Applications → Personal access tokens), click “New access token”.
- Name it and pick the furthest expiry: when it passes, the connection stops without warning.
- “Generate token”, then copy it: it is no longer visible once you leave the page.
- Resetting your Netlify password invalidates every token: you would have to create a new one.
- Portfolio import
Amazon Route 53
DNS
Open the token page at Amazon Route 53Where to find the token
- In the IAM console that opens, click your name at the top right, then “Security credentials”.
- “Access keys” section → “Create access key”; use case: “Other”, then “Next”, then “Create access key”.
- AWS shows an Access key ID and a Secret access key: copy both — the secret is visible only at that moment.
- The IAM user must carry the AmazonRoute53ReadOnlyAccess policy (or more): without it the key is valid but Route 53 refuses to list your zones.
Servers and clouds
The machine serving the site: reverse DNS, availability, and the DNS when the cloud hosts it too.
Hetzner Cloud
Server
Open the token page at Hetzner CloudWhere to find the token
- In the Hetzner Cloud console, enter the project holding your servers.
- “Security” menu → “API tokens” tab → “Generate API token”.
- Rights: “Read & Write”. Read-only is enough to see, not to fix.
- Copy the token: it is shown only once.
- Portfolio import
Scaleway
Server · DNS
Open the token page at ScalewayWhere to find the token
- In the Scaleway console, open the top-right menu, then “IAM & API keys” → “API keys” tab.
- “Generate API key”, bearer: yourself, and leave the longest expiry available.
- Scaleway shows an access key AND a secret key. Paste the SECRET key here — that is what authenticates; the access key is only an identifier.
- The secret key is shown only once.
- Portfolio import
DigitalOcean
Server · DNS
Open the token page at DigitalOceanWhere to find the token
- On the DigitalOcean page that opens (Account → API → Tokens tab), click “Generate New Token”.
- Name the token and choose the longest expiry: once it passes, the token stops working and disappears from the account.
- Scopes: grant READ and WRITE on Domains. Without write we can see but not fix, and scopes cannot be changed after creation.
- Copy the token: it is shown only once.
- Portfolio import
Vultr
Server · DNS
Open the token page at VultrWhere to find the token
- On the Vultr page that opens (Account → API), click “Enable API” if the API is not active yet.
- Copy the Personal Access Token shown.
- ⚠️ Under “Access Control”, add our address: 138.199.145.149 with subnet 32. Vultr only allows listed addresses — without this line the key is valid but our servers are refused.
- Vultr only whitelists the address you enabled the API from: ours has to be added by hand.
- Portfolio import
Akamai / Linode
Server · DNS
Open the token page at Akamai / LinodeWhere to find the token
- In the Cloud Manager (Akamai/Linode), open your profile at the top right, then “API Tokens”.
- “Create a Personal Access Token”, add a label and the longest expiry.
- Scopes: set “No Access” everywhere, then “Read/Write” on Domains only. That is the strict minimum.
- Create, then copy the token: it is never displayed again.
UpCloud
Server
Open the token page at UpCloudWhere to find the token
- In the UpCloud Hub (hub.upcloud.com), open the account’s API access settings and create an API token.
- Name it, pick the longest expiry (one year at most) and no IP address restriction.
- Copy the token — it starts with ucat_ — : it is shown only once.
- If UpCloud refuses the connection, allow the API first: “Account” page → “Allow API connections” (or, for a sub-account, People → Permissions).
AWS Lightsail
Server
Open the token page at AWS LightsailWhere to find the token
- In the IAM console that opens, click your name at the top right, then “Security credentials”.
- “Access keys” section → “Create access key”; use case: “Other”, then “Next”, then “Create access key”. Copy both values — the secret is visible only at that moment.
- The region: it is written at the top right of the Lightsail console, in the form eu-west-3, us-east-1, eu-central-1… Servers in another region will not be seen — add a second connection if you have some elsewhere.
- The IAM user must be allowed the lightsail:GetInstances action (the AmazonLightsailReadOnlyAccess policy is enough). Without it the key is valid but AWS refuses to list your servers.
- Portfolio import
cPanel (o2switch, mutualisés)
Server · DNS
Open the token page at cPanel (o2switch, mutualisés)Where to find the token
- In your cPanel, “Security” section → “Manage API Tokens” → “Create”. Name it and copy it straight away: it is not shown again.
- Find your server address: it is in cPanel, “General information” box (for example chabot.o2switch.net), and in your host's welcome email. It is not your website address.
- Enter your cPanel username here, an at sign, then that address — for example: myaccount@chabot.o2switch.net
- An API token is revoked from cPanel without changing your password: cutting the access costs you nothing.
Plesk
Server
Open the token page at PleskWhere to find the token
- In your Plesk, go to “Tools & Settings” → “Remote API (REST)”, then open “API Reference and Playground” (it will ask for your administrator password again — that password stays with Plesk).
- In that reference, run the “POST /api/v2/auth/keys” call with an empty body { }: Plesk answers with a key, like 5c6f1a8a-1263-7444-24e5-fcfd7b4dcdc6. That key is what we ask for, never your password.
- The server address is your Plesk panel address, without https:// and without :8443 — for example server.myhost.com. It is not your website address.
- The key is revoked from the same reference (“DELETE /api/v2/auth/keys”) without touching your password: cutting the access costs you nothing.
Fly.io
Server
Open the token page at Fly.ioWhere to find the token
- On the page that opens (fly.io → Tokens), create a PERSONAL access token.
- Take the personal token, not a deploy token: a token limited to one app cannot see the rest of the account.
- Copy it: Fly does not show it again.
Render
Server
Open the token page at RenderWhere to find the token
- On the page that opens (Account Settings), open “API Keys” then “Create API Key”.
- Name the key and create it.
- Copy it: Render shows it only once.
Railway
Server
Open the token page at RailwayWhere to find the token
- On the page that opens (Account → Tokens), click “Create Token” and name it.
- Do NOT pick a team or a project in the list: a token limited to one scope is refused on the request that identifies the account.
- Create, then copy the token: it is shown only once.
Heroku
Server
Open the token page at HerokuWhere to find the token
- On the page that opens (Account Settings), scroll to “API Key” and click “Reveal”.
- Copy the key shown.
- Avoid “Regenerate API Key”: the previous key stops working immediately, here and everywhere else.
Scalingo
Server
Open the token page at ScalingoWhere to find the token
- On the page that opens (my profile → “API tokens”), click “Generate new token” and name it.
- Copy it straight away: Scalingo never shows it again.
- Both regions (osc-fr1 and osc-secnum-fr1) are tried automatically: you have nothing to choose.
Every token is tried against the provider's API before it is accepted, then encrypted. A read, never a write, to verify.
Your provider is not listed?
Your domains are monitored exactly the same: the six watchers need no access. For a repair, DomainVigil shows you the exact record to copy and opens your provider's page. And tell us which one you need: that is how the list grows.
Suggest a provider