All endpoints

DocsAPIDomain proof

POST/sites/{siteId}/verification/checks

Check the record now

Looks now instead of waiting for the background check: DNS for the TXT record, then one read of the homepage, which proves the domain by this site's own tag or snippet (site_code), a connected Tag Manager container (tag_manager) or the meta tag.

Auth header

Authorization: Bearer tsk_live_…

The key needssites:write

Parameters

  • siteIdstringin pathrequired

    The site id, from GET /v1/sites.

Request body

  • onlystringoptional

    Check ONE mechanism. dns_txt makes no request to your site and costs a sixth of a full check against the hourly limit, so a poller waiting on DNS should use it. meta_tag is the homepage read, which also proves site_code and tag_manager, so use it after deploying the code. Omit for both.

    One of dns_txt, meta_tag

Example request

curl -X POST "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/verification/checks" \  -H "Authorization: Bearer tsk_live_…" \  -H "Content-Type: application/json" \  -d '{"only":"dns_txt"}'

Response 200

  • statusstringrequired

    One of verified, already_verified, not_found, unreachable, rate_limited

  • verifiedbooleanrequired
  • methodstring | nullrequired

    Which route proved it: site_code (this site's tag or snippet on the homepage), tag_manager (a connected Tag Manager container loaded by it), meta_tag or dns_txt.

    One of dns_txt, meta_tag, site_code, tag_manager

  • detailstringrequired

    One sentence a developer can act on.

  • retryAfterSecondsinteger | nullrequired

Example response

{  "status": "verified",  "verified": false,  "method": "dns_txt",  "detail": "…",  "retryAfterSeconds": 0}
More about this endpoint

Records the attempt. A POST because it makes real DNS queries and fetches the site.

YOU DO NOT NEED THIS FOR site_code OR tag_manager. Installing the code is the proof: the background check described on GET /verification finds it within about 10 minutes. Call this to know sooner, with only: "meta_tag" (the homepage read) after a deploy.

EVERY OUTCOME IS A 200 WITH A STATUS, except a rate limit. not_found (the record is not published yet, or DNS has not propagated) and unreachable (we could not ask) have different next actions, and a caller polling this in a wizard has to tell 'keep waiting' from 'stop and fix something'.

Rate limited: 10 full checks per site per hour, and a 429 carries retry-after in seconds. A dns_txt-only check costs a sixth of a full one. DNS takes minutes to propagate, so polling faster cannot make the record appear sooner.

Errors400 · 401 · 403 · 404 · 429 · 500
  • 400The request did not validate against this operation's schema.
  • 401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.
  • 403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.
  • 404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.
  • 429A rate limit or quota was exceeded. The body names WHICH one.
  • 500Something failed on our side. The requestId in the body is what to quote.

Every error has the same body: { error: { code, message, requestId } }.

From the OpenAPI document, version 2026-08-26. Raw OpenAPI