If your domain’s DNS zone lives at Gandi LiveDNS, you no longer have to copy records by hand. You store a Personal Access Token under Connections; once a project has domains, MainPath writes the records into the matching zone.
Manual DNS is still possible. See Configure a DNS record.
Access at Gandi
MainPath talks to the Gandi LiveDNS API (api.gandi.net/v5/livedns).
- Sign in to your Gandi account and open Account → Security → Personal Access Tokens.
- Create a PAT with LiveDNS rights.
- Copy the token. It is shown only once.
The domain must use Gandi nameservers (*.gandi.net).
Connection in MainPath
- Open Connections and Add connection.
- Under DNS, choose the Gandi tile.
- Paste the token and save. MainPath checks whether it is valid and which zones it can see.
Several Gandi connections in one organization are allowed. If a hostname matches more than one zone, MainPath uses the most specific one.
What is written
MainPath uses the same hosts you see under Domains.
- Records are only written when a real server address already exists.
- Existing records of the same name and type are updated; the whole zone is never replaced.
- Changes usually show up quickly.
flowchart LR org["Gandi connection"] domains["Domains in MainPath"] zone["Gandi LiveDNS zone"] server["Your server"] org --> zone domains -->|"A / CNAME"| zone zone --> server
After you save a project, MainPath tries to align missing or mismatched records. You can see the check status in the domain overview.
SSL via DNS-01 (optional)
If Let’s Encrypt cannot reach the server (no public HTTP/443, firewall, internal IP), open this connection’s details and tick the affected domains. MainPath then writes the _acme-challenge TXT record into this zone. Unticked domains keep the existing TLS-ALPN challenge on the server.
Troubleshooting
- Invalid token: Create a Personal Access Token with LiveDNS. An old Production API key is the wrong type.
- No record at Gandi: The domain is not in this account, or it uses other nameservers.
- Zone visible, domain unreachable: The zone exists at Gandi, but the nameservers point elsewhere. Point the nameservers at the registrar to Gandi (
*.gandi.net). - Status in MainPath still red: DNS often takes a few minutes, or the server does not have a known address yet.