The assignment was unconditional, so exporting DNSMint_Api did nothing - the
plugin reset it to the default every time it was sourced. Every neighbouring
plugin with an _Api variable treats it as an override; this one only looked
like it did.
Found while writing the dnsapi2 entry: the sentence documenting the override
would have been false.
DNSMint mints hostnames on domains it operates and serves from its own
authoritative nameservers, so records are published through its API
rather than a zone you run.
An ACME challenge goes to the DNS-01 endpoint, which derives the hostname
from the challenge name: no root zone to detect, no record id to track,
and the value published is the value removed. Wildcards work because the
API keeps the two newest values for a name.
Any other TXT name is an ordinary record under a hostname and goes to the
records endpoint instead, which is why the add and rm functions branch on
the _acme-challenge label. Issuing certificates needs only the dns01:write
scope; the record endpoint needs hostnames:read and hostnames:write.
Tested against Let's Encrypt staging for a wildcard plus its apex, and
the non-challenge TXT path against the live API.
DNSMint mints hostnames on domains it operates and serves from its own
authoritative nameservers, so a customer has no zone of their own and the
challenge is published through its API.
The hostname is derived server-side from the challenge name, so there is
no root zone to detect and no record id to track: the value published is
the value removed. Wildcards work because the API keeps the two newest
values for a name, which is what the apex and wildcard pair needs.
Tested against Let's Encrypt staging for a wildcard plus its apex.