Skip to content

Create a waf-rule

POST
/waf-rules
object
data
object
name
required
string
description
string
rule_type
string
Allowed values: rate_limit ip_block geo_block header_check sql_injection xss_protection custom
rule_config
required

Provider-agnostic rule configuration. Shape depends on rule_type: rate_limit={requests_per_minute,action}, ip_block={ip_addresses[]}, geo_block={countries[],action}, header_check={header,required,pattern}.

provider
string
Allowed values: aws azure gcp cloudflare manual
provider_rule_id

Provider-side rule/resource identifier returned after sync.

string
enabled
boolean
priority
integer
last_synced_at
string format: date-time
sync_status
string
Allowed values: pending synced error manual
organisation
One of:

DocumentId reference to api::organisation.organisation

string

Created

object
data
object
name
required
string
description
string
rule_type
string
Allowed values: rate_limit ip_block geo_block header_check sql_injection xss_protection custom
rule_config
required

Provider-agnostic rule configuration. Shape depends on rule_type: rate_limit={requests_per_minute,action}, ip_block={ip_addresses[]}, geo_block={countries[],action}, header_check={header,required,pattern}.

provider
string
Allowed values: aws azure gcp cloudflare manual
provider_rule_id

Provider-side rule/resource identifier returned after sync.

string
enabled
boolean
priority
integer
last_synced_at
string format: date-time
sync_status
string
Allowed values: pending synced error manual
organisation
One of:

DocumentId reference to api::organisation.organisation

string
documentId
string
id
integer
createdAt
string format: date-time
updatedAt
string format: date-time
publishedAt
string format: date-time
nullable

Validation error

Missing or invalid authentication

Not authorized (tenant scope or capability)