قاعدة المعرفة

Protect your sites with your own Gcore WAAP

Connect a Gcore API token from an account with WAAP enabled, then see your protected domains and switch each one's firewall mode from your dashboard.

What connecting it does for you

Connecting Gcore WAAP (Gcore's web application and API protection) lets you see the domains your own Gcore WAAP protects, and switch each domain's firewall mode, from your Zinn® dashboard.

Before you start

A Gcore account of your own, with WAAP enabled on it. This is bring-your-own only: we do not resell WAAP, so the product, the contract and the bill are between you and Gcore, and what you run there is charged to your Gcore account, not to your Zinn® plan.

1. Create the key at Gcore

In the Gcore Customer Portal, open your avatar at the top right, then Profile → API tokens → Create token. Name it, choose Never expire or an expiry date, and give it a role for each product it needs. Gcore shows the token once; copy it then.

The same token works for every Gcore product you connect, so if you have already connected one Gcore product you can paste the same token again — provided its roles cover this product too. A token cannot be given a higher role than your own login has.

2. Connect it here

Open Integrations in your dashboard and choose Connect an account. Pick Web app firewall as the group and Gcore WAAP as the account, fill in API token, and press Connect account.

We test what you paste before anything is saved. A key that does not work is never stored, and the answer says what was wrong with it. A key that works is kept encrypted in our secrets vault — never in our database — and is never shown again, not even to you.

What happens next

  • Your protected domains, and the mode each one is in, are listed under **Your own
  • services, reached from the connection's Open your own services button on Integrations**.

  • You can switch a domain between block (matching requests are refused), monitor
  • (matches are only logged and traffic still gets through) and off. What we show and record is the mode Gcore reports after the change, not the one requested.

  • ⚠️ Monitor is not protection. It is useful while you check a rule would not refuse real
  • visitors, and nothing is blocked while a domain is in it.

If it does not connect

It says the product is not enabled. The token is valid, but WAAP is not switched on for that Gcore account — Gcore then refuses every read. Enable it in the Gcore Customer Portal (or ask Gcore to), then connect again. A token whose role does not include WAAP produces the same refusal; create one that does.

A domain says locked. Gcore locks a domain's mode itself, usually for an account or billing reason, and a locked mode cannot be changed from here. Resolve it in Gcore's own control panel.

It says the key was rejected. Almost always one of three things: a space or a line break copied with it, a key that has expired, or a key that was revoked or regenerated after you copied it. Create a fresh one and paste it again.

It connects, but something later fails. The key authenticates but lacks a permission the action needs. Create a new key with the permissions listed above, then disconnect the old connection and connect the new key.

Disconnecting

Open Integrations, find the account and press Disconnect. That deletes the stored key at once. Anything that was using it stops at its next action, and the screens that depended on it say so rather than failing quietly.

Disconnecting does not undo what was already done — records, deployments or settings we changed on your account stay as they are. If you think the key itself may have leaked, also revoke it at the vendor; disconnecting removes our copy, not theirs.

لم تتم ترجمة هذه المقالة إلى لغتك بعد، لذا فأنت تقرأ النسخة الإنجليزية.

أحدث المقالات من المدونة

ما كتبناه حول الاستضافة، وتحسين محركات البحث، وإدارة المواقع على نطاق واسع.

تحسين محركات البحث وبناء الروابط من طبقة الاستضافة: رؤية مشغل لعام 2026

كيف تؤثر الاستضافة على الفهرسة وقيمة الروابط في 2026: الحفاظ على فهرسة الصفحات، وفحص النطاقات القديمة قبل البناء عليها، وبناء الروابط بدون أثر، ورأي صريح حول ما يمكن للبنية التحتية فعله وما لا يمكنها فعله لتحسين محركات البحث (SEO).

قراءة المنشور

تسريع WordPress وتأمينه: قائمة تدقيق للأداء والإضافات

قائمة تحقق عملية للحصول على موقع WordPress سريع وآمن: التخزين المؤقت على مستوى الخادم، وذاكرة تخزين مؤقت للكائنات لكل موقع، ومجموعة الإضافات القليلة التي تستحق التشغيل، والحفاظ على تحديث الحزمة، صفحات WooCommerce التي يجب ألا تقوم بالتخزين المؤقت لها أبداً.

قراءة المنشور

كيفية اختيار الاستضافة المدارة في عام 2026: دليل المشتري

ما الذي يُميز الاستضافة المُدارة حقاً عن المساحة الرخيصة المزودة لوحة تحكم — عمليات النقل، والنسخ الاحتياطي، والعزل، والتخزين المؤقت الحقيقي، والتوسيع الصادق — وكيفية تقييمها قبل أن تلتزم.

قراءة المنشور

قراءة المدونة

ما زلت تواجه مشكلة؟

الدعم مشمول في كل خطة، ومكتب الدعم مفتوح 24 ساعة في اليوم، ويمكنك مراسلتنا بأي لغة من لغاتنا البالغ عددها 58 لغة — وسنرد عليك بلغتك.

الاتصال بالدعم جميع المقالات