DNSMentor

Supported provider

OVHcloud DNS, in the same place as everything else.

Does DNSMentor support OVHcloud?

Yes. DNSMentor manages OVHcloud DNS through its API, showing its zones alongside the other 25 supported providers in a single estate view. Every OVHcloud change goes through the same 56 pre-flight checks, approval policy, independent verification and tamper-evident audit trail as every other provider.

Connecting OVHcloud

  1. Create the credential in OVHcloud Create all three keys in one go at https://api.ovh.com/createToken/ (Canada: https://ca.api.ovh.com/createToken/, US: https://api.us.ovhcloud.com/createToken/) and copy the Application Key from the page it returns. Grant exactly these rights, or DNSMentor cannot do its job: GET /domain/zone, GET /domain/zone/*, POST /domain/zone/*, PUT /domain/zone/* and DELETE /domain/zone/*. Set the validity to unlimited unless you intend to re-enter the keys on a schedule.
  2. Add the connection in DNSMentor Go to Admin → Providers & API keys, choose OVHcloud, and paste the credential. DNSMentor stores it encrypted and strips it from every log and export.
  3. Sync the estate DNSMentor discovers every zone the OVHcloud account holds and imports every record in them. This is a read operation — nothing is written to any zone.
  4. Group by client and start working Assign the imported domains to client portfolios, and the estate view, health scoring, checks and audit trail apply from that point on.

What OVHcloud asks you for

The exact fields DNSMentor needs, and where in OVHcloud to create them. Every secret is encrypted at rest and stripped by name from logs, exports and the audit trail.

Application Key secret

Create all three keys in one go at https://api.ovh.com/createToken/ (Canada: https://ca.api.ovh.com/createToken/, US: https://api.us.ovhcloud.com/createToken/) and copy the Application Key from the page it returns. Grant exactly these rights, or DNSMentor cannot do its job: GET /domain/zone, GET /domain/zone/*, POST /domain/zone/*, PUT /domain/zone/* and DELETE /domain/zone/*. Set the validity to unlimited unless you intend to re-enter the keys on a schedule.

Application Secret secret

Shown once, on the same page as the Application Key, and never again. If you did not keep it, create a new token rather than trying to recover this one.

Consumer Key secret

Also returned by https://api.ovh.com/createToken/, below the other two. This is the key that carries the rights you granted, so a change of rights means a new consumer key. The POST right matters more than it looks: without POST on /domain/zone/* DNSMentor can save a change but cannot publish it.

API Region not secret

eu, ca or us — the region your OVHcloud account was opened in, shown in the address of your control panel. Leave blank for eu. Regions are separate installations: keys created in one are rejected by the other two, which is the usual explanation for a credential that looks correct and fails immediately.

The sharp edge in OVHcloud's API

Every provider API has one behaviour that catches integrations out. This is OVHcloud's, and DNSMentor's adapter is written around it — the sort of thing you would otherwise discover during a migration.

The `$1$`+SHA1 signature, then that the zone `refresh` call actually fires — without it a change is stored and never served, and the customer sees nothing happen.

What you get on top of the OVHcloud console

One estate, not one provider

OVHcloud zones sit beside every other provider your clients came with, grouped by the client who pays for them and searchable in one place.

56 checks before apply

The OVHcloud console will accept a second SPF record or an MX pointing at an address without comment. DNSMentor will not.

Approval and audit

A second pair of eyes where policy requires it, and a hash-chained record of who changed what — neither of which a provider console offers.

OVHcloud questions

Can I manage OVHcloud DNS alongside my other providers?

Yes. DNSMentor connects OVHcloud through its API and shows its zones in the same estate view as every other provider you connect — 26 are supported in total. Your engineers work in one interface instead of switching between provider portals, and the same checks, approval policy and audit trail apply regardless of which provider a domain happens to be with.

What credentials does DNSMentor need for OVHcloud?

DNSMentor needs Application Key, Application Secret, Consumer Key, API Region for OVHcloud. Create all three keys in one go at https://api.ovh.com/createToken/ (Canada: https://ca.api.ovh.com/createToken/, US: https://api.us.ovhcloud.com/createToken/) and copy the Application Key from the page it returns. Grant exactly these rights, or DNSMentor cannot do its job: GET /domain/zone, GET /domain/zone/*, POST /domain/zone/*, PUT /domain/zone/* and DELETE /domain/zone/*. Set the validity to unlimited unless you intend to re-enter the keys on a schedule.

Does DNSMentor move my zones away from OVHcloud?

No. Your zones stay hosted at OVHcloud and remain authoritative there. DNSMentor reads and writes through the OVHcloud API, so nothing about your resolution path changes, and if you stop using DNSMentor the zones carry on exactly as they are.

Does DNSMentor validate OVHcloud changes before applying them?

Yes. All 56 checks run against the zone as it would exist after the change, whichever provider hosts it. The change is then simulated, routed for approval if policy requires it, written through the OVHcloud API after re-reading live state, and independently verified in public DNS afterwards.

Other providers DNSMentor manages

Connect OVHcloud in about five minutes.

Paste one credential, sync, and see every zone in that account. It is a read operation — nothing is written until somebody presses apply.

No card. No trial clock. UK-hosted, and we will tell you which providers we have actually proven before you ask.

Last updated