Golzak DevelopersGolzak Domains API · v1

Authentication, idempotency and limits

API key

Every call sends your key as a bearer token:

Authorization: Bearer <your API key>

Idempotency keys

Every POST needs an Idempotency-Key header (428 idempotency_key_required without one). Use a new random value, such as a UUID v4, for each action you intend, and store it with the action before you send the request.

You send You get
A new key The call runs normally.
The same key and the same body (a retry) The first answer again, with Idempotent-Replayed: true. Nothing is ordered twice.
The same key while the first call still runs 409 idempotency_key_in_use. Wait and retry.
The same key with a different body 422 idempotency_key_reused. Use a new key for a new action.

Keys are kept for 24 hours. After a timeout or a 502, always retry with the same key: that is what makes a retry safe. PUT /domains/{name}/nameservers accepts an Idempotency-Key too (optional).

Rate limits

Each key has a request rate limit (60 requests per minute unless your contract says otherwise). Every answer carries:

Header Meaning
RateLimit-Limit Requests allowed per window
RateLimit-Remaining Requests left in this window
RateLimit-Reset Seconds until the window resets

Over the limit you get 429 rate_limited with Retry-After (seconds). Wait that long, then retry.

Daily spending cap

Golzak can set a daily spending cap on a key: the most it may spend per UTC day (00:00 to 24:00 UTC). An order that would go over it answers 403 daily_spend_cap_reached and is not placed. GET /balance shows the cap, spent_today and when the cap resets. Refunds do not lower spent_today. To change the cap, ask Golzak.

Request IDs

Every answer has a Request-Id header, also in error bodies as request_id. Quote it when you contact Golzak.