> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Core concepts

> Learn the resource hierarchy, ownership boundaries, and names used throughout Aptranet.

## Resource hierarchy

```text theme={null}
Organization
├── Members and organization roles
├── Billing profile, contracts, invoices, and subscription
└── Projects
    ├── Project member permissions
    ├── Quotas
    ├── API keys
    ├── Cloud CDN origin groups and distributions
    ├── Cloud DNS zones and record sets
    ├── Cloud Shield protected domains and security configuration
    └── TLS Manager certificate inventory
```

## Definitions

<AccordionGroup>
  <Accordion title="Organization">
    The customer and billing boundary. An account can belong to multiple organizations with a different role in each.
  </Accordion>

  <Accordion title="Project">
    The resource and authorization boundary inside an organization. A project owns its API keys, quotas, CDN resources, DNS resources, Cloud Shield configuration, and TLS certificates.
  </Accordion>

  <Accordion title="API key">
    A non-human credential containing an access key, a secret, a status, and project permissions. The Gateway resolves the project from the key.
  </Accordion>

  <Accordion title="Origin group">
    One or more sources from which a Cloud CDN distribution retrieves content. Origins can be primary or backup and can use failover conditions.
  </Accordion>

  <Accordion title="Distribution">
    A Cloud CDN delivery resource with an edge hostname, an origin group, and configuration for cache, network, TLS, headers, origin behavior, security, and images.
  </Accordion>

  <Accordion title="Zone">
    An authoritative Cloud DNS namespace such as `example.com`. It contains SOA settings and record sets.
  </Accordion>

  <Accordion title="Record set">
    Records sharing the same owner name and type, plus a TTL, routing pickers, optional health-check metadata, and one or more resource records.
  </Accordion>
</AccordionGroup>

## Console and API context

Browser requests select an organization and project. The console sends `Aptranet-Organization-ID` and selects the project through the `project` query parameter on project-scoped requests. API-key requests do not send these headers: the project is bound to the key at creation time.

<Note>
  Product API paths use `/cloud-cdn`, `/cloud-dns`, `/shield`, and `/tls-manager`. The older `/cdn` and `/dns` aliases exist for compatibility, but new integrations should use the canonical paths.
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.