curl --request POST \
--url "https://directory.example.com/personas/example.com/dns-challenges" \
--header "Content-Type: application/json" \
--data '{
"operator_did": "did:openpayload:1111111111111111111111",
"action": "register_persona"
}'
Personas
Create a Persona DNS challenge
Request the TXT record needed to prove control of a Persona domain
curl --request POST \
--url "https://directory.example.com/personas/example.com/dns-challenges" \
--header "Content-Type: application/json" \
--data '{
"operator_did": "did:openpayload:1111111111111111111111",
"action": "register_persona"
}'
Create a short-lived DNS challenge before registering or renewing a Persona. The Directory does not create or renew a Persona until it observes the exact TXT value and the chain accepts the attested proof.
Registration first checks finalized chain state for uniqueness. An existing canonical Persona returns
The name must be fully qualified and contain at least two DNS labels. URLs, paths, ports, wildcard names, IP addresses, and names whose top-level label is numeric-only are rejected.
Publish
409 persona_conflict; a renewal requires the currently registered operator DID.
Request
string
required
A DNS name, URL-encoded when necessary. The Directory returns its canonical lowercase ASCII IDNA form.
string
required
The DID that will operate the Persona.
string
register_persona or renew_persona. Defaults to register_persona.curl --request POST \
--url "https://directory.example.com/personas/example.com/dns-challenges" \
--header "Content-Type: application/json" \
--data '{
"operator_did": "did:openpayload:1111111111111111111111",
"action": "register_persona"
}'
Response
201 Response
{
"challenge_id": "<challenge-id>",
"persona": "example.com",
"operator_did": "did:openpayload:1111111111111111111111",
"action": "register_persona",
"challenge_nonce": "0",
"operator_nonce": "0",
"record_name": "_openpayload-persona.example.com",
"record_type": "TXT",
"record_value": "openpayload-persona-v1=<challenge>",
"expires_at": "2026-09-17T18:00:00Z"
}
record_value exactly at record_name. DNS responses can be cached, so wait for propagation before submitting the Persona update.
Straight to the point
POST /personas/{persona}/dns-challenges
- Does not register the Persona
- Challenge is bound to the action, Persona, operator DID, network, and nonce
- Challenge is single-use and expires at
expires_at

