Msingi wa maarifa

Protect your sites with your own Gcore WAAP

Connect a Gcore API token from an account with WAAP enabled, then see your protected domains and switch each one's firewall mode from your dashboard.

What connecting it does for you

Connecting Gcore WAAP (Gcore's web application and API protection) lets you see the domains your own Gcore WAAP protects, and switch each domain's firewall mode, from your Zinn® dashboard.

Before you start

A Gcore account of your own, with WAAP enabled on it. This is bring-your-own only: we do not resell WAAP, so the product, the contract and the bill are between you and Gcore, and what you run there is charged to your Gcore account, not to your Zinn® plan.

1. Create the key at Gcore

In the Gcore Customer Portal, open your avatar at the top right, then Profile → API tokens → Create token. Name it, choose Never expire or an expiry date, and give it a role for each product it needs. Gcore shows the token once; copy it then.

The same token works for every Gcore product you connect, so if you have already connected one Gcore product you can paste the same token again — provided its roles cover this product too. A token cannot be given a higher role than your own login has.

2. Connect it here

Open Integrations in your dashboard and choose Connect an account. Pick Web app firewall as the group and Gcore WAAP as the account, fill in API token, and press Connect account.

We test what you paste before anything is saved. A key that does not work is never stored, and the answer says what was wrong with it. A key that works is kept encrypted in our secrets vault — never in our database — and is never shown again, not even to you.

What happens next

  • Your protected domains, and the mode each one is in, are listed under **Your own
  • services, reached from the connection's Open your own services button on Integrations**.

  • You can switch a domain between block (matching requests are refused), monitor
  • (matches are only logged and traffic still gets through) and off. What we show and record is the mode Gcore reports after the change, not the one requested.

  • ⚠️ Monitor is not protection. It is useful while you check a rule would not refuse real
  • visitors, and nothing is blocked while a domain is in it.

If it does not connect

It says the product is not enabled. The token is valid, but WAAP is not switched on for that Gcore account — Gcore then refuses every read. Enable it in the Gcore Customer Portal (or ask Gcore to), then connect again. A token whose role does not include WAAP produces the same refusal; create one that does.

A domain says locked. Gcore locks a domain's mode itself, usually for an account or billing reason, and a locked mode cannot be changed from here. Resolve it in Gcore's own control panel.

It says the key was rejected. Almost always one of three things: a space or a line break copied with it, a key that has expired, or a key that was revoked or regenerated after you copied it. Create a fresh one and paste it again.

It connects, but something later fails. The key authenticates but lacks a permission the action needs. Create a new key with the permissions listed above, then disconnect the old connection and connect the new key.

Disconnecting

Open Integrations, find the account and press Disconnect. That deletes the stored key at once. Anything that was using it stops at its next action, and the screens that depended on it say so rather than failing quietly.

Disconnecting does not undo what was already done — records, deployments or settings we changed on your account stay as they are. If you think the key itself may have leaked, also revoke it at the vendor; disconnecting removes our copy, not theirs.

Makala hii bado haijatafsiriwa katika lugha yako, kwa hivyo unasoma toleo la Kiingereza.

Hivi karibuni kutoka kwenye blogu

Mambo ambayo tumekuwa tukiandika kuyahusu upangishaji, SEO na kuendesha tovuti kwa kiwango kikubwa.

SEO na Kujenga Viungo kutoka kwa Tabaka la Uhifadhi: Mtazamo wa Operator wa 2026

Jinsi hosting inavyoathiri uwekaji faharasa na usawa wa viungo mwaka 2026: kuweka kurasa kwenye faharasa, kukagua vikoa vya zamani kabla ya kuvijenga, ujenzi wa viungo bila alama, na mtazamo wa ukweli kuhusu kile ambacho miundombinu inaweza na haiwezi kufanya kwa ajili ya SEO.

Soma chapisho

Kufanya WordPress Iwe Kasi na Salama: Orodha ya Uhakiki ya Utendaji na Programu-jalizi

Orodha ya vitendo vya kuaminika kwa ajili ya WordPress ya haraka na salama: kache ya kiwango cha seva, kache ya vitu kwa kila tovuti, idadi ndogo ya programu-jalizi zinazofaa kutumika, kuweka mfumo wa sasa, na kurasa za WooCommerce ambazo hupaswi kuzifanyia kache kamwe.

Soma chapisho

Jinsi ya Kuchagua Huduma ya Kuegesha Tovuti Inayosimamiwa mnamo 2026: Mwongozo wa Mnunuzi

Kile kinachotofautisha mwenyeji unaosimamiwa vizuri na seva ya bei rahisi yenye paneli ya udhibiti — wahamiaji, nakala rudufu, utengaji, akiba halisi na upanuzi wa kweli — na jinsi ya kukitathmini kabla ya kujitolea.

Soma chapisho

Soma blogu

Bado umekwama?

Usaidizi umejumuishwa kwenye kila mpango, huduma ya msaada iko wazi saa 24 kwa siku, na unaweza kutuandikia kwa lugha yoyote kati ya lugha zetu 58 — tunakujibu kwa lugha yako.

Wasiliana na usaidizi Makala zote