hosting
GET /v1/sites/{siteId}/geo-restriction
Which countries may reach this site.
Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/geo-restriction \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The site's country rule and what each enforcement layer is doing about it. **Not under `/cdn/`, deliberately.** A country rule is a *site* control with up to two enforcement points — the CDN edge and the origin server — and a site with no CDN still gets it at the origin. It applies on every product line. **The edge state is read from the provider, not from our record.** "We asked for it" and "it is set" are different claims: they diverge when a customer edits the rule in their own CDN dashboard, after a CDN switch, or after a failed apply. Read `edge` and `origin` separately — a rule live at one layer only is a real, partial state, and `enforcing: false` with a `detail` means the layer is not protecting the site whatever `mode` says. Requires `sites.view`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
mode | string<off, allow, block> | Yes | `allow` admits **only** the listed countries and refuses everywhere else; `block` refuses the listed ones and serves everywhere else; `off` is no rule at all. |
countries | string[] | Yes | ISO-3166 alpha-2, upper-case. Empty when `mode` is `off`. |
exempt_search_engines | boolean | Yes | Whether verified search-engine crawlers were asked to bypass the rule. |
search_engines_exempt_at_edge | boolean | Yes | Whether that exemption is actually **in force**, which is not the same as whether it was requested — only a provider that verifies a crawler by forward/reverse DNS can carry it.… |
edge | GeoRestrictionLayer | Yes | What ONE enforcement layer can do, and what it is doing right now. Four fields rather than one flag because "this provider cannot do it" and "it failed this morning" need differ… |
origin | GeoRestrictionLayer | Yes | What ONE enforcement layer can do, and what it is doing right now. Four fields rather than one flag because "this provider cannot do it" and "it failed this morning" need differ… |
Errors this endpoint can return
401 · 403 · 404 · 429