The UltraDNS REST API doesn’t support accounts with Two Factor Mobile Authentication enabled. Use a dedicated
API user, or disable Two Factor Mobile Authentication for the user you connect with.
Prepare an UltraDNS user
1
Create a user for Infisical
Sign in to the UltraDNS Portal and go to Account → Users, then add a user
that Infisical will authenticate as. You can then revoke its access without affecting anyone else.
2
Grant zone and record permissions
Assign the user a role that can read zones and read, create, update, and delete resource records in the zones you
want Infisical to manage. For ACME certificate issuance, Infisical writes a TXT record at
_acme-challenge.<your-domain> and removes it once the certificate authority has validated the domain.3
Confirm the zone type
Only zones of type Primary are available to Infisical, because secondary zones can’t accept record changes.
4
Allow Infisical's IP addresses
Skip this step unless your UltraDNS account limits REST API access to allowed IP ranges. With that limit in place,
UltraDNS rejects every request from an address outside the ranges, including the credential check when you create
the connection. Add Infisical’s outbound IP addresses to the allowed ranges:
- Infisical Cloud: the addresses for your region, listed in Infisical IP addresses.
- Self-hosted Infisical: the public IP address your Infisical server uses for outbound traffic.
Setup UltraDNS connection in Infisical
1
Navigate to App Connections
In Certificate Manager, go to Settings → App Connections.

2
Add Connection
Select the UltraDNS Connection option from the connection options modal.
3
Input Credentials
Enter the username and password of your UltraDNS user, choose the Environment to connect to, and select
Connect to UltraDNS. Infisical verifies the credentials against the UltraDNS API before saving the connection.Choose Production for
api.ultradns.com and Test for the UltraDNS customer test environment at
test-api.ultradns.com. The two environments have separate accounts and separate zones, so a connection is only
valid against the one its credentials belong to.4
Connection Created
Your UltraDNS Connection is now available for use in Certificate Manager.