hosting

GET /v1/sites/{siteId}/geo-restriction

Which countries may reach this site.

All hosting endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/geo-restriction \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The site's country rule and what each enforcement layer is doing about it. **Not under `/cdn/`, deliberately.** A country rule is a *site* control with up to two enforcement points — the CDN edge and the origin server — and a site with no CDN still gets it at the origin. It applies on every product line. **The edge state is read from the provider, not from our record.** "We asked for it" and "it is set" are different claims: they diverge when a customer edits the rule in their own CDN dashboard, after a CDN switch, or after a failed apply. Read `edge` and `origin` separately — a rule live at one layer only is a real, partial state, and `enforcing: false` with a `detail` means the layer is not protecting the site whatever `mode` says. Requires `sites.view`.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).

Response

NameTypeRequiredWhat it is
modestring<off, allow, block>Yes`allow` admits **only** the listed countries and refuses everywhere else; `block` refuses the listed ones and serves everywhere else; `off` is no rule at all.
countriesstring[]YesISO-3166 alpha-2, upper-case. Empty when `mode` is `off`.
exempt_search_enginesbooleanYesWhether verified search-engine crawlers were asked to bypass the rule.
search_engines_exempt_at_edgebooleanYesWhether that exemption is actually **in force**, which is not the same as whether it was requested — only a provider that verifies a crawler by forward/reverse DNS can carry it.…
edgeGeoRestrictionLayerYesWhat ONE enforcement layer can do, and what it is doing right now. Four fields rather than one flag because "this provider cannot do it" and "it failed this morning" need differ…
originGeoRestrictionLayerYesWhat ONE enforcement layer can do, and what it is doing right now. Four fields rather than one flag because "this provider cannot do it" and "it failed this morning" need differ…

Errors this endpoint can return

401 · 403 · 404 · 429