hosting

PUT /v1/sites/{siteId}/cdn/security

Change a site's CDN security and bot settings.

Tous les points de terminaison hosting

Authentification

Envoyez une clé API en tant que jeton du porteur. La clé doit posséder l'autorisation hosting.cdn.manage ; une clé qui ne l'a pas est refusée avec le code 403, et non 404.

Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.

Essayer

Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.

curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/cdn/security \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API

Détails

A **merge**: only the fields present are changed. A full-object write would turn a customer's AI-crawler policy off every time they changed their security level. The body carries settings and nothing else — `additionalProperties: false`, for the reason `PUT /v1/sites/{siteId}/cdn/settings` gives: these are pooled CDN accounts and a Cloudflare zone resolves by name alone, so a body key named `domain` or `zone_id` must be refused rather than discarded. The result is read back from the provider rather than echoed, because the provider silently ignores a bot control a zone's plan does not include — "we asked" and "it changed" are different facts. Requires `hosting.cdn.manage`. **Bot management is a sold entitlement (`protection_tier`).** Turning `bot_fight_mode` on, or setting `ai_bots_protection`/`crawler_protection` to `block` or `managed_challenge`, needs a plan that includes it and otherwise answers a plan refusal naming the tier held and the tier needed. Three things are deliberately NOT gated. Turning any control **off** is free on every plan — a customer whose plan changed must always be able to reach the floor rather than be stranded with a setting they cannot undo. `allow` is an explicit relaxation, not protection, so it is free too. And `security_level: under_attack` is free on every plan, for ever: it is the emergency DDoS response, and refusing it to a customer under active attack because of their plan is not a product decision this platform will make.

Paramètres

NomTypeObligatoireQu'est-ce que c'est
siteId (path)UuidOuiSite ID (UUIDv7).

Corps de la requête

NomTypeObligatoireQu'est-ce que c'est
security_levelCdnSecurityLevelNonThe provider's own security-level vocabulary, passed through. **Not ordered the way it reads** — `essentially_off` sits between `off` and `low` — so nothing may treat it as a sc…
bot_fight_modebooleanNon
ai_bots_protectionCdnAiBotModeNonHow the edge treats AI crawlers. `disabled` leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engine…
crawler_protectionCdnAiBotModeNonHow the edge treats AI crawlers. `disabled` leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engine…
always_use_httpsbooleanNon
automatic_https_rewritesbooleanNon
opportunistic_encryptionbooleanNon
min_tls_versionCdnMinTlsVersionNonThe oldest TLS version the edge will negotiate. A string — `1.10` is not a version.

Réponse

NomTypeObligatoireQu'est-ce que c'est
site_idUuidOuiUUIDv7 identifier — sortable by creation time (docs/02 §8).
supportedbooleanOuiWhether the CDN serving this site can express these settings at all. `false` for a provider with no equivalent vocabulary; the other fields then carry defaults and a client shou…
protection_tierstringOuiThe protection level this organisation's plan sells (`protection_tier`). Absent from a plan means the floor — every site with a CDN already has the provider's baseline protectio…
bot_management_includedbooleanOuiWhether that tier reaches bot management — enabling `bot_fight_mode`, or setting `ai_bots_protection`/`crawler_protection` to `block` or `managed_challenge`. Derived server-side…
security_levelCdnSecurityLevelOuiThe provider's own security-level vocabulary, passed through. **Not ordered the way it reads** — `essentially_off` sits between `off` and `low` — so nothing may treat it as a sc…
bot_fight_modebooleanOuiChallenge traffic the provider classifies as automated. Read from the provider's bot-management resource, not from a zone setting — the zone setting of that name does not exist.
ai_bots_protectionCdnAiBotModeOuiHow the edge treats AI crawlers. `disabled` leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engine…
crawler_protectionCdnAiBotModeOuiHow the edge treats AI crawlers. `disabled` leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engine…
always_use_httpsbooleanOuiRedirect every plain-HTTP request to HTTPS at the edge.
automatic_https_rewritesbooleanOuiRewrite insecure sub-resource URLs in HTML to HTTPS where possible.
opportunistic_encryptionbooleanOuiAdvertise HTTP/2 over TLS to clients that arrive over plain HTTP.
min_tls_versionCdnMinTlsVersionOuiThe oldest TLS version the edge will negotiate. A string — `1.10` is not a version.

Erreurs que cet point de terminaison peut renvoyer

401 · 403 · 404 · 422 · 429 · 503