security

POST /v1/ip-allow

Allow an address or range.

Alle security Endpunkte

Authentifizierung

Senden Sie einen API-Schlüssel als Bearer-Token. Dieser Endpunkt gibt in der Spezifikation keine spezifische Berechtigung an. Versehen Sie Ihren Schlüssel daher mit den minimal erforderlichen Rechten und prüfen Sie die Antwort, anstatt Annahmen zu treffen.

Hier kommt Ihre Organisations-ID hin

Dieser Endpunkt akzeptiert org_id als Abfrageparameter. Lassen Sie ihn weg, erfasst der Aufruf Ihren gesamten Mandanten-Unterbaum; übergeben Sie ihn, um den Aufruf auf eine Organisation einzugrenzen.

Die ID Ihrer Organisation finden Sie im Dashboard auf dem Bildschirm für API-Schlüssel direkt neben dem Schlüssel selbst. Sie ist bei jedem Ihrer Aufrufe dieselbe.

Ausprobieren

Ersetzen Sie alles in spitzen Klammern durch Ihre eigenen Werte und den Platzhalter für den Schlüssel durch einen Schlüssel aus Ihrem Dashboard.

curl -X POST https://api.zinndigital.com/v1/ip-allow \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "cidr": <string>, "label": <string> }'

Angemeldet? Die API-Konsole in Ihrem Dashboard trägt automatisch Ihre echte Organisations-ID sowie Ihren eigenen Schlüssel ein und führt die Anfrage gegen die Live-API aus, sodass Sie die tatsächliche Antwort sehen können. Öffnen Sie diesen Endpunkt in der API-Konsole

Details

Adds one entry. A bare address is normalised to a host network (`203.0.113.7` becomes `203.0.113.7/32`) so the list holds one shape and you cannot add the same fact twice in two spellings. `0.0.0.0/0` and `::/0` are refused, and so is any prefix broader than /8 (IPv4) or /32 (IPv6): an entry that admits the whole internet is the same as having no allow-list, while reading on screen as though something is protected.

Parameter

NameTypErforderlichWas es ist
org_id (query)stringNeinThe organization to act on. Omitted (or empty) means your own. A reseller managing a client org must name it - defaulting silently would edit the reseller's own list while the s…

Anfragekörper

NameTypErforderlichWas es ist
cidrstringJaAn address or a CIDR range. `0.0.0.0/0` and `::/0` are refused, as is anything broader than /8 (IPv4) or /32 (IPv6). Both families are checked - rejecting only the IPv4 literal…
labelstringJa
expires_atstringNein
enabledbooleanNein

Antwort

NameTypErforderlichWas es ist
idstringJa
scopestring<staff_infra, staff_site, customer_site>Ja
cidrstringJaCanonical CIDR. A bare address is stored as a host network (`/32`, or `/128` for IPv6) so one column answers both "is this a range" and "does it contain X".
labelstringJaRequired. An unlabelled range is one nobody dares remove, which is how a list grows until it stops being a control.
expires_atstringNeinnull = permanent. An expired entry is NOT deleted - it stays visible and greyed so an operator can see what lapsed and re-add it.
enabledbooleanJa
expiredbooleanJaComputed server-side. Two surfaces deriving "is this still in force?" from a raw timestamp is two implementations of one decision, and they disagree on the boundary second.
in_forcebooleanJaenabled AND not expired - the only field that decides anything.
created_bystringJaAudit ref of whoever added it (`user:<id>` / `apikey:<id>`).
created_atstringJa