CustomDomain™ docs
Api referenceConnections

One-click sync return (public; authenticated by the signed state)

GET
/connect/dc/return/{state}

Where the DNS provider sends the browser after the user approves or cancels a one-click sync apply. It is the redirect_uri the signed apply_url carries, not a bearer-authenticated endpoint. The signed single-use state rides in the path because some providers (Cloudflare) drop the separate state parameter. It records a provider-reported error on the connection, runs the propagation check at once, and returns the same HTML finish page as the OAuth callback, which postMessages { type: "customdomain:oauth", payload } to the origin vetted at start. A clean return never marks the connection live by itself: only the records appearing in public DNS do.

Path Parameters

state*string

Query Parameters

error?string

OAuth 2.0 error code the provider reports (access_denied when the user cancels).

error_description?string

Response Body

curl -X GET "https://example.com/connect/dc/return/string"
Empty
Empty
Empty