Authenticatie
Stuur een API-sleutel mee als bearer token. Dit eindpunt vermeldt geen specifieke toestemming in de specificatie, dus geef uw sleutel de minimale rechten die nodig zijn en controleer het antwoord in plaats van zomaar wat aan te nemen.
Waar je organisatie-id komt te staan
Dit eindpunt accepteert org_id als queryparameter. Laat deze achterwege en de aanroep destilleert je gehele tenant-substructie; stuur deze mee om de aanroep te beperken tot één organisatie.
Uw organisatie-id staat op het scherm met API-sleutels in uw dashboard, naast de sleutel zelf. Dit is in elke aanroep die u doet dezelfde id.
Probeer het
Vervang alles tussen punthaakjes door uw eigen waarden en de sleutelplaatsvervanger door een sleutel uit uw dashboard.
curl -X POST https://api.zinndigital.com/v1/ip-allow \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "cidr": <string>, "label": <string> }'Ingelogd? De API-console in je dashboard vult je echte organisatie-id en je eigen sleutel in, en voert het verzoek uit tegen de live API zodat je de daadwerkelijke respons kunt zien. Open dit eindpunt in de API-console
Details
Adds one entry. A bare address is normalised to a host network (`203.0.113.7` becomes `203.0.113.7/32`) so the list holds one shape and you cannot add the same fact twice in two spellings. `0.0.0.0/0` and `::/0` are refused, and so is any prefix broader than /8 (IPv4) or /32 (IPv6): an entry that admits the whole internet is the same as having no allow-list, while reading on screen as though something is protected.
Parameters
| Naam | Type | Verplicht | Wat dit is |
|---|---|---|---|
org_id (query) | string | Nee | The organization to act on. Omitted (or empty) means your own. A reseller managing a client org must name it - defaulting silently would edit the reseller's own list while the s… |
Aanvraaglichaam
| Naam | Type | Verplicht | Wat dit is |
|---|---|---|---|
cidr | string | Ja | An address or a CIDR range. `0.0.0.0/0` and `::/0` are refused, as is anything broader than /8 (IPv4) or /32 (IPv6). Both families are checked - rejecting only the IPv4 literal… |
label | string | Ja | — |
expires_at | string | Nee | — |
enabled | boolean | Nee | — |
Reactie
| Naam | Type | Verplicht | Wat dit is |
|---|---|---|---|
id | string | Ja | — |
scope | string<staff_infra, staff_site, customer_site> | Ja | — |
cidr | string | Ja | Canonical CIDR. A bare address is stored as a host network (`/32`, or `/128` for IPv6) so one column answers both "is this a range" and "does it contain X". |
label | string | Ja | Required. An unlabelled range is one nobody dares remove, which is how a list grows until it stops being a control. |
expires_at | string | Nee | null = permanent. An expired entry is NOT deleted - it stays visible and greyed so an operator can see what lapsed and re-add it. |
enabled | boolean | Ja | — |
expired | boolean | Ja | Computed server-side. Two surfaces deriving "is this still in force?" from a raw timestamp is two implementations of one decision, and they disagree on the boundary second. |
in_force | boolean | Ja | enabled AND not expired - the only field that decides anything. |
created_by | string | Ja | Audit ref of whoever added it (`user:<id>` / `apikey:<id>`). |
created_at | string | Ja | — |