# Make your first API request

Start with a read-only DNS request from the real Dashio OpenAPI export.

## Before you begin

The reference uses the supplied **Dashio API 2026.8.0** OpenAPI 3.1 export. Start with [List DNS records](/api/operations/listDomainRecords), a read-only operation, and use a domain that belongs to a Space you can access.

The export’s only server is a local development URL. Reference examples use the documentation’s configured API origin; set the origin to the deployment you intend to call. The domain route needs a fully qualified domain name, not its database ID.

## Understand authentication

This operation declares `bearerAuth`. Send a valid access token using `Authorization: Bearer <access-token>` and keep the token out of URLs, source control, and shared logs.

The export does not define `bearerAuth` under `components.securitySchemes`. It also does not document token issuance or promise a public API-key workflow. Obtain the appropriate authorized access token for your integration before calling the API; do not assume that a missing security declaration on another operation means anonymous access.

## Send a request

Review the generated examples in [List DNS records](/api/operations/listDomainRecords). Replace `{domain}` and `YOUR_ACCESS_TOKEN` before running one.

A cURL request has this form:

```bash
curl --request GET \
  'https://dashio.net/api/v1/spaces/assets/domains/{domain}/records' \
  --header 'Authorization: Bearer YOUR_ACCESS_TOKEN'
```

The reference also supplies JavaScript, TypeScript, Python, PHP, and Go HTTP-client examples. It does not require an invented Dashio SDK and does not execute requests for you.

## Read the response

The exported success status is **200**, with a `records` array. Each record declares `id`, `type`, `name`, `value`, and `ttl` as required fields. The record schema also describes nullable `priority` and `comment` fields.

The export lists **400** for an invalid domain, **404** for a missing domain, and **500** when records cannot be loaded. Those error responses have descriptions but no body schemas; handle the HTTP status and inspect the actual response instead of assuming an error object that was never documented.

## Create a record after the read succeeds

Use [Create DNS record](/api/operations/createDomainRecord) when you are ready to make a change. Its request body wraps the record fields in a `record` object. The nested `type`, `name`, `value`, and `ttl` fields are required.

The supplied contract declares **200** for creation. Schema-generated examples contain placeholders, not values guaranteed to pass DNS validation. Use the values supplied by your DNS service and review [Manage DNS records](/guides/domains/manage-dns-records) before changing a live zone.

## Check contract gaps

Read [Use the OpenAPI document](/developers/openapi) before generating a client. The export is a versioned snapshot, and the website can include newer features that are not in this file.
