/sites/{siteId}/verificationHow to prove you own this domain
Whether this domain is proved, which route proved it (method), and the token for the two routes that need one: a DNS TXT record, or a meta tag in the site's <head>.
Auth header
Authorization: Bearer tsk_live_…The key needssites:read
Parameters
siteIdstringin pathrequiredThe site id, from GET /v1/sites.
Example request
curl "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/verification" \ -H "Authorization: Bearer tsk_live_…"Response 200
siteIdstringrequireddomainstringrequiredverifiedbooleanrequiredverifiedAtstring | nullrequiredmethodstring | nullrequiredWhich route proved it; null until one has.
One of
dns_txt,meta_tag,site_code,tag_managertokenstringrequireddnsTxtobjectrequiredThe DNS route. Slower to propagate, and the one to prefer for a domain you control the zone for, because it survives a redeploy of the site.
dnsTxt.namesarray of stringrequireddnsTxt.valuestringrequiredThe exact TXT value to paste.
metaTagobjectrequiredThe HTML route. Instant, and it needs a deploy.
metaTag.htmlstringrequiredThe exact line to paste into <head>.
metaTag.checkedUrlstringrequiredThe page we fetch, over https, and nothing else.
methodsarray of objectrequiredEvery route that proves a domain, the automatic ones first.
methods[].methodstringrequiredOne of
dns_txt,meta_tag,site_code,tag_managermethods[].automaticbooleanrequiredTrue when installing is the whole proof: our background check reads the homepage and finds it, with no call from you.
methods[].howstringrequiredWhat proves the domain by this route.
Example response
{ "siteId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "domain": "silverpine.example", "verified": false, "verifiedAt": "2026-09-26T14:02:00.000Z", "method": "dns_txt", "token": "…", "dnsTxt": { "names": [ "_ga" ], "value": "…" }, "metaTag": { "html": "…", "checkedUrl": "https://silverpine.example/" }, "methods": [ { "method": "dns_txt", "automatic": false, "how": "…" } ]}More about this endpoint
USUALLY NOTHING TO DO. Once this site's tag or snippet (site_code), or a Tag Manager container connected to it with edit access (tag_manager), is in the homepage's HTML, we find it ourselves: a background check reads the homepage every 10 minutes for the first hour after this site's code or token was first handed out, hourly for a day, then daily for 30 days. methods lists all four routes and which need a call.
WHY THIS BLOCKS A BANNER. An unverified domain is refused before its configuration is even read, so it serves no banner to anyone. Serving one is a claim about a domain, and we do not make that claim for somebody who has not shown they control it.
The token is returned in clear and that is not a leak: it proves control by appearing where only the owner could put it. Knowing the string buys nothing.
Prefer DNS for a domain whose zone you control -- it survives a redeploy. Prefer the meta tag when you want it done in one deploy, or when the zone is somebody else's. A tag injected only by JavaScript is not in the server's HTML, so it needs one of these two.
Errors401 · 403 · 404 · 500
401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.500Something failed on our side. The requestId in the body is what to quote.
Every error has the same body: { error: { code, message, requestId } }.
From the OpenAPI document, version 2026-08-26. Raw OpenAPI