hosting

GET /v1/sites/{siteId}/cdn/security

Read a site's CDN security and bot settings.

모든 hosting 엔드포인트

모든 개발자 문서

인증

Bearer 토큰으로 API 키를 전송하세요. 키는 반드시 sites.view 권한을 가지고 있어야 하며, 권한이 없는 키는 404가 아닌 403으로 거부됩니다.

이 엔드포인트는 조직 ID를 받지 않습니다. 사용자의 키가 이미 속한 조직을 식별하며, 응답은 해당 조직으로 한정됩니다.

무료 체험하기

대괄호 안에 있는 모든 내용을 사용자 지정 값으로 바꾸고, 키 플레이스홀더는 대시보드의 키로 바꾸세요.

curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/cdn/security \
  -H "Authorization: Bearer zdk_live_…"

로그인하셨나요? 대시보드의 API 콘솔이 실제 조직 ID와 본인의 키를 자동으로 채우고 라이브 API를 대상으로 요청을 실행하므로 실제 응답을 확인할 수 있습니다. API 콘솔에서 이 엔드포인트를 여세요

상세 정보

How hard the edge is on suspicious traffic, and how it treats AI crawlers: security level, bot fight mode, Cloudflare's AI-bot and crawler controls, Always Use HTTPS, automatic HTTPS rewrites, opportunistic encryption and the minimum TLS version. Separate from /cdn/settings, which is about caching and the origin TLS leg, because these are a different question with a different blast radius — turning the cache off makes a site slow, while under_attack puts an interstitial in front of every visitor and crawler_protection can remove a site from search results. They are also different provider APIs behind different token scopes, so a customer's own credential may carry one and not the other. A provider with no equivalent vocabulary answers 200 with supported: false and defaults, never a 404. Requires sites.view.

매개변수

이름유형필수설명
siteId (path)UuidSite ID (UUIDv7).

응답

이름유형필수설명
site_idUuidUUIDv7 identifier — sortable by creation time (docs/02 §8).
supportedbooleanWhether the CDN serving this site can express these settings at all. false for a provider with no equivalent vocabulary; the other fields then carry defaults and a client should…
unreadablestring[]아니요Fields the CDN account's credential could not read, so their values here are defaults, not the zone's state. A client renders each listed control disabled and says it could not be…
protection_tierstringThe protection level this organisation's plan sells (protection_tier). Absent from a plan means the floor — every site with a CDN already has the provider's baseline protection…
bot_management_includedbooleanWhether that tier reaches bot management — enabling bot_fight_mode, or setting ai_bots_protection/crawler_protection to block or managed_challenge. Derived server-side…
security_levelCdnSecurityLevelThe provider's own security-level vocabulary, passed through. Not ordered the way it readsessentially_off sits between off and low — so nothing may treat it as a…
bot_fight_modebooleanChallenge traffic the provider classifies as automated. Read from the provider's bot-management resource, not from a zone setting — the zone setting of that name does not exist.
ai_bots_protectionCdnAiBotModeHow the edge treats AI crawlers. disabled leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engines…
crawler_protectionCdnAiBotModeHow the edge treats AI crawlers. disabled leaves them alone. This is the control on the screen most able to cost a site traffic, in either direction: blocking AI answer engines…
always_use_httpsbooleanRedirect every plain-HTTP request to HTTPS at the edge.
automatic_https_rewritesbooleanRewrite insecure sub-resource URLs in HTML to HTTPS where possible.
opportunistic_encryptionbooleanAdvertise HTTP/2 over TLS to clients that arrive over plain HTTP.
min_tls_versionCdnMinTlsVersionThe oldest TLS version the edge will negotiate. A string — 1.10 is not a version.

이 엔드포인트가 반환할 수 있는 오류

401 · 403 · 404 · 429 · 502 · 503