Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
List the custom domains in your workspace with their status and dnsRecords. Results are sorted by ID and paginated. When pagination.hasMore is true, pass pagination.cursor back with --cursor. Add --output=json to see the pagination object. Every filter is optional. With none, you get every domain in the workspace. --project, --app, and --environment each narrow the list, and the most specific one wins. A filter that matches nothing returns an empty list, not a 404. In large workspaces, use filters: if a page would need to look through more than 10,000 domains, the call fails with 503 and The domain scan limit was reached. Narrow the project, app, environment, or search filters and retry.

Usage

Flags

string
App ID or slug to filter by.
string
Pagination cursor from a previous response.
string
Environment ID or slug to filter by.
integer
default:"100"
Maximum domains per page, from 1 to 100.
string
Project ID or slug to filter by. Both forms resolve to the same project.
Case-insensitive filter on domain ID or name.

Shared flags

Every unkey api command accepts these; CLI output and shared flags describes them in full.
string
A JSON document sent as the request body instead of building it from the flags above. It is mutually exclusive with the request-building flags, and unknown fields are rejected locally. See Send a raw body.
string
Root key for the request. Falls back to UNKEY_ROOT_KEY, then to the config file written by unkey auth login. See CLI authentication.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the TOML file that unkey auth login writes. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. Set json to print the full response envelope (meta and data) for piping; any other value prints the request ID followed by data.

Required permissions

Your root key needs the workspace-wide environment.*.read_domain. A grant for one environment doesn’t work here. A key without the permission isn’t rejected. It gets an empty list instead of a 403, so an empty result doesn’t always mean you have no domains. See Root key permissions for the full catalog.

Examples

List every domain in the workspace:
List the domains of one environment:
Filter and page:

API endpoint

The command calls POST /v2/domains.listDomains and prints its response. The request fields carry the same names as the flags in camelCase, which is the shape --body expects.

Custom domains

DNS records, verification, and certificates for your own hostnames.
Last modified on September 29, 2026