← Docs

Give teammates access to your PrimeDNS account without sharing a login or handing out full admin rights. Access can be scoped both by role (what they can do) and zone (which domains they can do it to) — a contractor can get write access to one staging zone and nothing else.

Roles

RoleAccess
AdminFull access except billing. Can invite members.
BillingBilling and invoices only.
DNS ManagerRead/write DNS records.
DNS ViewerRead-only DNS records.
MonitoringObservability and alerts, read-only.

Admin and Billing are always account-wide (billing operates on the account, not individual zones; admin has full access by definition). DNS Manager, DNS Viewer and Monitoring can optionally be restricted to a single zone.

Inviting someone

In Team → Invitations, enter their email, pick a role, and optionally restrict it to one zone. The invitee needs an existing PrimeDNS account under that email; they get an email invite, and once accepted, can switch between their own account and yours from their Team page.

Send invitation form with email, role select and zone scope dropdown

Managing existing members

In Team → Members, each row shows the role, zone scope, join date and who invited them. Edit changes a member's role or zone inline; you can also grant a member access to an additional zone without removing their existing scope — useful for someone who starts on one project and picks up a second.

Current members table with inline role edit and Add zone access form expanded

Multi-account access

If you belong to more than one team, Teams you belong to at the top of the page lists them all with your role in each, and Switch to changes which account's zones you're currently acting on — no separate logins needed.

Programmatic access (API)

Team membership is scriptable via the API too, useful for onboarding automation:

curl -X POST https://api.primedns.net/v1/team/invite \
  -H "X-API-Key: pdns_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "Ten adres pocztowy jest chroniony przed spamowaniem. Aby go zobaczyć, konieczne jest włączenie w przeglądarce obsługi JavaScript.",
    "role": "dns_manager",
    "zone_id": null
  }'
curl https://api.primedns.net/v1/team \
  -H "X-API-Key: pdns_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
Note: a member's actions still go through their own account — combined with the Audit Log, every change a team member makes is attributed to them by username, not lumped under the account owner.