hosting

GET /v1/sites/{siteId}/cdn/security

Read a site's CDN security and bot settings.

Tutti gli endpoint hosting

Autenticazione

Invia una chiave API come token di tipo bearer. La chiave deve disporre dell'autorizzazione sites.view; una chiave sprovvista di tale autorizzazione viene rifiutata con 403 anziché 404.

Questo endpoint non richiede alcun ID organizzazione. La tua chiave identifica già l'organizzazione a cui appartiene e la risposta è limitata ad essa.

Provalo

Sostituisci qualsiasi elemento tra parentesi angolari con i tuoi valori e il segnaposto key con una chiave dalla tua dashboard.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/cdn/security \
  -H "Authorization: Bearer zdk_live_…"

Hai effettuato l'accesso? La console API nella tua dashboard inserisce il tuo ID organizzazione reale e la tua chiave personale, ed esegue la richiesta sull'API live in modo da poter vedere la risposta effettiva. Apri questo endpoint nella console API

Dettagli

How hard the edge is on suspicious traffic, and how it treats AI crawlers: security level, bot fight mode, Cloudflare's AI-bot and crawler controls, Always Use HTTPS, automatic HTTPS rewrites, opportunistic encryption and the minimum TLS version. Separate from `/cdn/settings`, which is about caching and the origin TLS leg, because these are a different question with a different blast radius — turning the cache off makes a site slow, while `under_attack` puts an interstitial in front of every visitor and `crawler_protection` can remove a site from search results. They are also different provider APIs behind different token scopes, so a customer's own credential may carry one and not the other. A provider with no equivalent vocabulary answers `200` with `supported: false` and defaults, never a `404`. Requires `sites.view`.

Parametri

NomeTipoObbligatorioChe cos'è
siteId (path)UuidSite ID (UUIDv7).

Risposta

NomeTipoObbligatorioChe cos'è
site_idUuidUUIDv7 identifier — sortable by creation time (docs/02 §8).
supportedbooleanWhether the CDN serving this site can express these settings at all. `false` for a provider with no equivalent vocabulary; the other fields then carry defaults and a client shou…
protection_tierstringThe protection level this organisation's plan sells (`protection_tier`). Absent from a plan means the floor — every site with a CDN already has the provider's baseline protectio…
bot_management_includedbooleanWhether that tier reaches bot management — enabling `bot_fight_mode`, or setting `ai_bots_protection`/`crawler_protection` to `block` or `managed_challenge`. Derived server-side…
security_levelCdnSecurityLevelThe provider's own security-level vocabulary, passed through. **Not ordered the way it reads** — `essentially_off` sits between `off` and `low` — so nothing may treat it as a sc…
bot_fight_modebooleanChallenge traffic the provider classifies as automated. Read from the provider's bot-management resource, not from a zone setting — the zone setting of that name does not exist.
ai_bots_protectionCdnAiBotModeHow the edge treats AI crawlers. `disabled` leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engine…
crawler_protectionCdnAiBotModeHow the edge treats AI crawlers. `disabled` leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engine…
always_use_httpsbooleanRedirect every plain-HTTP request to HTTPS at the edge.
automatic_https_rewritesbooleanRewrite insecure sub-resource URLs in HTML to HTTPS where possible.
opportunistic_encryptionbooleanAdvertise HTTP/2 over TLS to clients that arrive over plain HTTP.
min_tls_versionCdnMinTlsVersionThe oldest TLS version the edge will negotiate. A string — `1.10` is not a version.

Errori che questo endpoint può restituire

401 · 403 · 404 · 429 · 503