compute

PUT /v1/compute/servers/{serverId}/firewall

Replace a server's firewall rules.

All compute endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.restart permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X PUT https://api.zinndigital.com/v1/compute/servers/{serverId}/firewall \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "rules": <ComputeFirewallRule[]> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

⭐ **PUT, and the verb is the contract**: this replaces the entire rule set. The provider's write is atomic, and an add/remove surface layered over an atomic replace is how two people editing at once discard each other's rule with both requests reporting success. ⛔⛔ **This can lock the customer out of their own machine.** A set with no inbound SSH is applied exactly as asked and their next connection is refused. That is why `openComputeServerConsole` exists, and why a client should say so beside this control. Refused when more than one firewall is applied to the machine: the effective policy is their union, so editing one and reporting the result would be false in the dangerous direction. The whole rule set is audit-logged, not a count — when a customer reports being locked out, "12 rules were set" answers nothing. Requires `sites.restart`.

Parameters

NameTypeRequiredWhat it is
serverId (path)UuidYesThe server's id, as `listComputeServers` reports it. **Ours** (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine.

Request body

NameTypeRequiredWhat it is
rulesComputeFirewallRule[]Yes

Response

NameTypeRequiredWhat it is
idstringYesThe provider's firewall id
namestringYesIts name at the provider
attachedbooleanYesWhether a firewall resource is actually applied to this machine.
rulesComputeFirewallRule[]Yes

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503