---
title: "Protected Setup Domain"
method: POST
path: "/api/websites/{website_id}/setup-domain"
tags: ["Websites - Protected"]
---

# Protected Setup Domain

`POST /api/websites/{website_id}/setup-domain`

Kick off full domain setup (SSL via acme.sh + Nginx + CloudFront) in the
background and return immediately.

The acme.sh DNS-01 issue waits ~60s for DNS propagation — longer than the
browser will hold the request — so this returns {status: 'running'} right
away and the BO polls GET /setup-status until 'done' or 'error'. The work
itself is the same idempotent, self-healing state machine (see
_do_domain_setup).

## Path parameters

- `website_id` integer, required

## Headers

- `x-api-token` string, nullable

## Response `200`

Successful Response

- unknown

## Other responses

- `422` — Validation Error

---

[API](https://skmtc.dev/multigest/apis/multigest-protected-api.md) · [All operations](https://skmtc.dev/multigest/apis/multigest-protected-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/multigest/multigest-protected-api/revisions/4b44eb76b3ee/schema)
