compute
PUT /v1/compute/servers/{serverId}/firewall
Replace a server's firewall rules.
Authentication
Send an API key as a bearer token. The key must carry the sites.restart permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X PUT https://api.zinndigital.com/v1/compute/servers/{serverId}/firewall \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "rules": <ComputeFirewallRule[]> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
⭐ **PUT, and the verb is the contract**: this replaces the entire rule set. The provider's write is atomic, and an add/remove surface layered over an atomic replace is how two people editing at once discard each other's rule with both requests reporting success. ⛔⛔ **This can lock the customer out of their own machine.** A set with no inbound SSH is applied exactly as asked and their next connection is refused. That is why `openComputeServerConsole` exists, and why a client should say so beside this control. Refused when more than one firewall is applied to the machine: the effective policy is their union, so editing one and reporting the result would be false in the dangerous direction. The whole rule set is audit-logged, not a count — when a customer reports being locked out, "12 rules were set" answers nothing. Requires `sites.restart`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
serverId (path) | Uuid | Yes | The server's id, as `listComputeServers` reports it. **Ours** (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine. |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
rules | ComputeFirewallRule[] | Yes | — |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | string | Yes | The provider's firewall id |
name | string | Yes | Its name at the provider |
attached | boolean | Yes | Whether a firewall resource is actually applied to this machine. |
rules | ComputeFirewallRule[] | Yes | — |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429 · 503