# Set DNS with Gandi

Connect a Gandi Personal Access Token once. MainPath writes A and CNAME records into your LiveDNS zones.

> Source: https://www.mainpath.ai/en/docs/dns-gandi/

If your domain's DNS zone lives at [Gandi](https://www.gandi.net/) LiveDNS, you no longer have to copy records by hand. You store a Personal Access Token under **Connections**; once a project has domains, MainPath writes the records into the matching zone.

Manual DNS is still possible. See [Configure a DNS record]({{< relref "domain-how-to" >}}).

## Access at Gandi

MainPath talks to the **Gandi LiveDNS API** (`api.gandi.net/v5/livedns`).

1. Sign in to your Gandi account and open **Account → Security → Personal Access Tokens**.
2. Create a PAT with LiveDNS rights.
3. Copy the token. It is shown only once.

The domain must use Gandi nameservers (`*.gandi.net`).

## Connection in MainPath

1. Open **Connections** and **Add connection**.
2. Under **DNS**, choose the **Gandi** tile.
3. Paste the token and save. MainPath checks whether it is valid and which zones it can see.

Several Gandi connections in one organization are allowed. If a hostname matches more than one zone, MainPath uses the most specific one.

## What is written

MainPath uses the same hosts you see under **Domains**.

- Records are only written when a real server address already exists.
- Existing records of the same name and type are updated; the whole zone is never replaced.
- Changes usually show up quickly.

```mermaid
flowchart LR
  org["Gandi connection"]
  domains["Domains in MainPath"]
  zone["Gandi LiveDNS zone"]
  server["Your server"]
  org --> zone
  domains -->|"A / CNAME"| zone
  zone --> server
```

After you save a project, MainPath tries to align missing or mismatched records. You can see the check status in the domain overview.

## SSL via DNS-01 (optional)

If Let's Encrypt cannot reach the server (no public HTTP/443, firewall, internal IP), open this connection's details and tick the affected domains. MainPath then writes the `_acme-challenge` TXT record into this zone. Unticked domains keep the existing TLS-ALPN challenge on the server.

## Troubleshooting

- **Invalid token**: Create a Personal Access Token with LiveDNS. An old Production API key is the wrong type.
- **No record at Gandi**: The domain is not in this account, or it uses other nameservers.
- **Zone visible, domain unreachable**: The zone exists at Gandi, but the nameservers point elsewhere. Point the nameservers at the registrar to Gandi (`*.gandi.net`).
- **Status in MainPath still red**: DNS often takes a few minutes, or the server does not have a known address yet.

## See also

- [Domain setup]({{< relref "domain" >}})
- [Configure a DNS record]({{< relref "domain-how-to" >}})
- [Connections]({{< relref "connections" >}})

