What connecting it does for you
Connecting Gcore WAAP (Gcore's web application and API protection) lets you see the domains your own Gcore WAAP protects, and switch each domain's firewall mode, from your Zinn® dashboard.
Before you start
A Gcore account of your own, with WAAP enabled on it. This is bring-your-own only: we do not resell WAAP, so the product, the contract and the bill are between you and Gcore, and what you run there is charged to your Gcore account, not to your Zinn® plan.
1. Create the key at Gcore
In the Gcore Customer Portal, open your avatar at the top right, then Profile → API tokens → Create token. Name it, choose Never expire or an expiry date, and give it a role for each product it needs. Gcore shows the token once; copy it then.
The same token works for every Gcore product you connect, so if you have already connected one Gcore product you can paste the same token again — provided its roles cover this product too. A token cannot be given a higher role than your own login has.
2. Connect it here
Open Integrations in your dashboard and choose Connect an account. Pick Web app firewall as the group and Gcore WAAP as the account, fill in API token, and press Connect account.
We test what you paste before anything is saved. A key that does not work is never stored, and the answer says what was wrong with it. A key that works is kept encrypted in our secrets vault — never in our database — and is never shown again, not even to you.
What happens next
- Your protected domains, and the mode each one is in, are listed under **Your own
services, reached from the connection's Open your own services button on Integrations**.
- You can switch a domain between block (matching requests are refused), monitor
(matches are only logged and traffic still gets through) and off. What we show and record is the mode Gcore reports after the change, not the one requested.
- ⚠️ Monitor is not protection. It is useful while you check a rule would not refuse real
visitors, and nothing is blocked while a domain is in it.
If it does not connect
It says the product is not enabled. The token is valid, but WAAP is not switched on for that Gcore account — Gcore then refuses every read. Enable it in the Gcore Customer Portal (or ask Gcore to), then connect again. A token whose role does not include WAAP produces the same refusal; create one that does.
A domain says locked. Gcore locks a domain's mode itself, usually for an account or billing reason, and a locked mode cannot be changed from here. Resolve it in Gcore's own control panel.
It says the key was rejected. Almost always one of three things: a space or a line break copied with it, a key that has expired, or a key that was revoked or regenerated after you copied it. Create a fresh one and paste it again.
It connects, but something later fails. The key authenticates but lacks a permission the action needs. Create a new key with the permissions listed above, then disconnect the old connection and connect the new key.
Disconnecting
Open Integrations, find the account and press Disconnect. That deletes the stored key at once. Anything that was using it stops at its next action, and the screens that depended on it say so rather than failing quietly.
Disconnecting does not undo what was already done — records, deployments or settings we changed on your account stay as they are. If you think the key itself may have leaked, also revoke it at the vendor; disconnecting removes our copy, not theirs.
لم تتم ترجمة هذه المقالة إلى لغتك بعد، لذا فأنت تقرأ النسخة الإنجليزية.