/sites/{siteId}/verification/checksCheck the record now
Looks now instead of waiting for the background check: DNS for the TXT record, then one read of the homepage, which proves the domain by this site's own tag or snippet (site_code), a connected Tag Manager container (tag_manager) or the meta tag.
Auth header
Authorization: Bearer tsk_live_…The key needssites:write
Parameters
siteIdstringin pathrequiredThe site id, from GET /v1/sites.
Request body
onlystringoptionalCheck ONE mechanism.
dns_txtmakes no request to your site and costs a sixth of a full check against the hourly limit, so a poller waiting on DNS should use it.meta_tagis the homepage read, which also provessite_codeandtag_manager, so use it after deploying the code. Omit for both.One of
dns_txt,meta_tag
Example request
curl -X POST "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/verification/checks" \ -H "Authorization: Bearer tsk_live_…" \ -H "Content-Type: application/json" \ -d '{"only":"dns_txt"}'Response 200
statusstringrequiredOne of
verified,already_verified,not_found,unreachable,rate_limitedverifiedbooleanrequiredmethodstring | nullrequiredWhich route proved it:
site_code(this site's tag or snippet on the homepage),tag_manager(a connected Tag Manager container loaded by it),meta_tagordns_txt.One of
dns_txt,meta_tag,site_code,tag_managerdetailstringrequiredOne sentence a developer can act on.
retryAfterSecondsinteger | nullrequired
Example response
{ "status": "verified", "verified": false, "method": "dns_txt", "detail": "…", "retryAfterSeconds": 0}More about this endpoint
Records the attempt. A POST because it makes real DNS queries and fetches the site.
YOU DO NOT NEED THIS FOR site_code OR tag_manager. Installing the code is the proof: the background check described on GET /verification finds it within about 10 minutes. Call this to know sooner, with only: "meta_tag" (the homepage read) after a deploy.
EVERY OUTCOME IS A 200 WITH A STATUS, except a rate limit. not_found (the record is not published yet, or DNS has not propagated) and unreachable (we could not ask) have different next actions, and a caller polling this in a wizard has to tell 'keep waiting' from 'stop and fix something'.
Rate limited: 10 full checks per site per hour, and a 429 carries retry-after in seconds. A dns_txt-only check costs a sixth of a full one. DNS takes minutes to propagate, so polling faster cannot make the record appear sooner.
Errors400 · 401 · 403 · 404 · 429 · 500
400The request did not validate against this operation's schema.401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.429A rate limit or quota was exceeded. The body names WHICH one.500Something failed on our side. The requestId in the body is what to quote.
Every error has the same body: { error: { code, message, requestId } }.
From the OpenAPI document, version 2026-08-26. Raw OpenAPI