security

POST /v1/ip-allow

Allow an address or range.

모든 security 엔드포인트

인증

Bearer 토큰으로 API 키를 전송하세요. 이 엔드포인트는 명세에 특정 권한을 명시하지 않으므로, 가정하기보다는 키에 필요한 최소한의 권한을 부여하고 응답을 확인하세요.

조직 ID가 들어가는 위치

이 엔드포인트는 org_id을(를) 쿼리 매개변수로 사용합니다. 생략하면 테넌트 하위 트리 전체가 호출 대상이 되며, 값을 전달하면 특정 조직으로 호출 범위를 좁힐 수 있습니다.

조직 ID는 대시보드의 API 키 화면에서 키 바로 옆에 있습니다. 이는 실행하는 모든 호출에서 동일한 ID입니다.

무료 체험하기

대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.

curl -X POST https://api.zinndigital.com/v1/ip-allow \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "cidr": <string>, "label": <string> }'

로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요

상세 정보

Adds one entry. A bare address is normalised to a host network (`203.0.113.7` becomes `203.0.113.7/32`) so the list holds one shape and you cannot add the same fact twice in two spellings. `0.0.0.0/0` and `::/0` are refused, and so is any prefix broader than /8 (IPv4) or /32 (IPv6): an entry that admits the whole internet is the same as having no allow-list, while reading on screen as though something is protected.

매개변수

이름유형필수설명
org_id (query)string아니요The organization to act on. Omitted (or empty) means your own. A reseller managing a client org must name it - defaulting silently would edit the reseller's own list while the s…

요청 본문

이름유형필수설명
cidrstringAn address or a CIDR range. `0.0.0.0/0` and `::/0` are refused, as is anything broader than /8 (IPv4) or /32 (IPv6). Both families are checked - rejecting only the IPv4 literal…
labelstring
expires_atstring아니요
enabledboolean아니요

응답

이름유형필수설명
idstring
scopestring<staff_infra, staff_site, customer_site>
cidrstringCanonical CIDR. A bare address is stored as a host network (`/32`, or `/128` for IPv6) so one column answers both "is this a range" and "does it contain X".
labelstringRequired. An unlabelled range is one nobody dares remove, which is how a list grows until it stops being a control.
expires_atstring아니요null = permanent. An expired entry is NOT deleted - it stays visible and greyed so an operator can see what lapsed and re-add it.
enabledboolean
expiredbooleanComputed server-side. Two surfaces deriving "is this still in force?" from a raw timestamp is two implementations of one decision, and they disagree on the boundary second.
in_forcebooleanenabled AND not expired - the only field that decides anything.
created_bystringAudit ref of whoever added it (`user:<id>` / `apikey:<id>`).
created_atstring