Skip to content
AdiosDocumentation
Browse documentation

Gateway security API

Configure HTTPS, CORS, and WAF settings for a hostname your team controls.

Use API authentication for protected requests. Examples use your own resource IDs and a temporary token; saved response examples are synthetic.

MethodPathOperation
GET/v1/gateway_security_profileList gateway security profiles
POST/v1/gateway_security_profileCreate gateway security profile
GET/v1/gateway_security_profile/{id}Get gateway security profile
PUT/v1/gateway_security_profile/{id}Update gateway security profile
DELETE/v1/gateway_security_profile/{id}Delete gateway security profile

List gateway security profiles

GET /v1/gateway_security_profile

Returns a paginated list of GatewaySecurityProfile

Authentication: bearer token and the team header shown below.

Parameters

NameLocationRequiredDescription
X-Tenant-IDheaderyesActive team ID. Must match the tenant bound to a diagnostic token.
pagequerynoPage number
per_pagequerynoItems per page

Request example

Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.

curl --fail-with-body --request GET "$ADIOS_API_URL/v1/gateway_security_profile" \
  -H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
  -H "X-Tenant-ID: $ADIOS_TEAM_ID"

Response: HTTP 200

List of GatewaySecurityProfile

Response fields

FieldTypeDescription
dataarray
data[].cors_enabledboolean
data[].cors_headersstringComma-separated CORS request headers
data[].cors_methodsstringComma-separated HTTP methods
data[].cors_originsstringComma-separated origins or *
data[].created_atinteger(Unix timestamp)
data[].deleted_atinteger(Unix timestamp)
data[].enabledboolean
data[].force_httpsboolean
data[].geo_policyobjectOptional host-level country allow/block policy
data[].hostnamestring
data[].hsts_enabledboolean
data[].max_body_bytesintegerOptional request body size limit. 0 means platform default.
data[].profile_idstring
data[].team_idstring
data[].updated_atinteger(Unix timestamp)
data[].waf_custom_directivesstringRaw Coraza directives used when waf_template=custom
data[].waf_modestringAllowed: off, monitor, block.
data[].waf_overridesobjectStructured template overrides (for example per-path exclusions or rule toggles)
data[].waf_rule_exclusionsobjectOptional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}]
data[].waf_templatestringPreconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom.
paginationobject
pagination.pageintegerCurrent page number
pagination.per_pageintegerNumber of items per page
pagination.totalintegerTotal number of items

Illustrative example; not a live response:

{
  "data": [
    {
      "cors_enabled": true,
      "cors_headers": "example",
      "cors_methods": "example",
      "cors_origins": "example",
      "created_at": 1791072000,
      "deleted_at": 0,
      "enabled": true,
      "force_https": true,
      "geo_policy": {},
      "hostname": "app.example.com",
      "hsts_enabled": true,
      "max_body_bytes": 0,
      "profile_id": "000000000000000000000000001",
      "team_id": "000000000000000000000000001",
      "updated_at": 1791072000,
      "waf_custom_directives": "example",
      "waf_mode": "off",
      "waf_overrides": {},
      "waf_rule_exclusions": {},
      "waf_template": "workload_default"
    }
  ],
  "pagination": {
    "page": 1,
    "per_page": 1,
    "total": 1
  }
}

Create gateway security profile

POST /v1/gateway_security_profile

Creates a new GatewaySecurityProfile

This request changes data or starts an action. Review the target and body before sending it.

Request fields (the body contains an editable example):

FieldTypeRequiredDescription
cors_enabledbooleanyesDefault: true.
cors_headersstringnoComma-separated CORS request headers
cors_methodsstringnoComma-separated HTTP methods
cors_originsstringnoComma-separated origins or *
enabledbooleanyesDefault: true.
force_httpsbooleanyesDefault: true.
geo_policyobjectnoOptional host-level country allow/block policy
hostnamestringyes
hsts_enabledbooleanyesDefault: true.
max_body_bytesintegernoOptional request body size limit. 0 means platform default. Default: 0.
team_idstringyes
waf_custom_directivesstringnoRaw Coraza directives used when waf_template=custom
waf_modestringyesAllowed: off, monitor, block. Default: "off".
waf_overridesobjectnoStructured template overrides (for example per-path exclusions or rule toggles)
waf_rule_exclusionsobjectnoOptional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}]
waf_templatestringyesPreconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. Default: "workload_default".

Authentication: bearer token and the team header shown below.

Parameters

NameLocationRequiredDescription
X-Tenant-IDheaderyesActive team ID. Must match the tenant bound to a diagnostic token.

Request example

Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.

curl --fail-with-body --request POST "$ADIOS_API_URL/v1/gateway_security_profile" \
  -H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
  -H "X-Tenant-ID: $ADIOS_TEAM_ID" \
  -H "Content-Type: application/json" \
  --data-binary @- <<'JSON'
{
  "cors_enabled": true,
  "enabled": true,
  "force_https": true,
  "hostname": "YOUR_HOSTNAME",
  "hsts_enabled": true,
  "max_body_bytes": 0,
  "team_id": "YOUR_TEAM_ID",
  "waf_mode": "off",
  "waf_template": "workload_default"
}
JSON

Replace YOUR_* body placeholders before sending. The quoted heredoc keeps the JSON literal.

Response: HTTP 201

GatewaySecurityProfile created

Response fields

FieldTypeDescription
cors_enabledboolean
cors_headersstringComma-separated CORS request headers
cors_methodsstringComma-separated HTTP methods
cors_originsstringComma-separated origins or *
created_atinteger(Unix timestamp)
deleted_atinteger(Unix timestamp)
enabledboolean
force_httpsboolean
geo_policyobjectOptional host-level country allow/block policy
hostnamestring
hsts_enabledboolean
max_body_bytesintegerOptional request body size limit. 0 means platform default.
profile_idstring
team_idstring
updated_atinteger(Unix timestamp)
waf_custom_directivesstringRaw Coraza directives used when waf_template=custom
waf_modestringAllowed: off, monitor, block.
waf_overridesobjectStructured template overrides (for example per-path exclusions or rule toggles)
waf_rule_exclusionsobjectOptional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}]
waf_templatestringPreconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom.

Illustrative example; not a live response:

{
  "cors_enabled": true,
  "cors_headers": "example",
  "cors_methods": "example",
  "cors_origins": "example",
  "created_at": 1791072000,
  "deleted_at": 0,
  "enabled": true,
  "force_https": true,
  "geo_policy": {},
  "hostname": "app.example.com",
  "hsts_enabled": true,
  "max_body_bytes": 0,
  "profile_id": "000000000000000000000000001",
  "team_id": "000000000000000000000000001",
  "updated_at": 1791072000,
  "waf_custom_directives": "example",
  "waf_mode": "off",
  "waf_overrides": {},
  "waf_rule_exclusions": {},
  "waf_template": "workload_default"
}

Get gateway security profile

GET /v1/gateway_security_profile/{id}

Returns a single GatewaySecurityProfile

Set gateway_security_profile_id using IDs from your own API responses.

Authentication: bearer token and the team header shown below.

Parameters

NameLocationRequiredDescription
idpathyesResource identifier from your team's API results.
X-Tenant-IDheaderyesActive team ID. Must match the tenant bound to a diagnostic token.

Request example

Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.

curl --fail-with-body --request GET "$ADIOS_API_URL/v1/gateway_security_profile/${ADIOS_GATEWAY_SECURITY_PROFILE_ID}" \
  -H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
  -H "X-Tenant-ID: $ADIOS_TEAM_ID"

Response: HTTP 200

GatewaySecurityProfile

Response fields

FieldTypeDescription
cors_enabledboolean
cors_headersstringComma-separated CORS request headers
cors_methodsstringComma-separated HTTP methods
cors_originsstringComma-separated origins or *
created_atinteger(Unix timestamp)
deleted_atinteger(Unix timestamp)
enabledboolean
force_httpsboolean
geo_policyobjectOptional host-level country allow/block policy
hostnamestring
hsts_enabledboolean
max_body_bytesintegerOptional request body size limit. 0 means platform default.
profile_idstring
team_idstring
updated_atinteger(Unix timestamp)
waf_custom_directivesstringRaw Coraza directives used when waf_template=custom
waf_modestringAllowed: off, monitor, block.
waf_overridesobjectStructured template overrides (for example per-path exclusions or rule toggles)
waf_rule_exclusionsobjectOptional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}]
waf_templatestringPreconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom.

Illustrative example; not a live response:

{
  "cors_enabled": true,
  "cors_headers": "example",
  "cors_methods": "example",
  "cors_origins": "example",
  "created_at": 1791072000,
  "deleted_at": 0,
  "enabled": true,
  "force_https": true,
  "geo_policy": {},
  "hostname": "app.example.com",
  "hsts_enabled": true,
  "max_body_bytes": 0,
  "profile_id": "000000000000000000000000001",
  "team_id": "000000000000000000000000001",
  "updated_at": 1791072000,
  "waf_custom_directives": "example",
  "waf_mode": "off",
  "waf_overrides": {},
  "waf_rule_exclusions": {},
  "waf_template": "workload_default"
}

Update gateway security profile

PUT /v1/gateway_security_profile/{id}

Updates an existing GatewaySecurityProfile

Set gateway_security_profile_id using IDs from your own API responses.

This request changes data or starts an action. Review the target and body before sending it.

Request fields (the body contains an editable example):

FieldTypeRequiredDescription
cors_enabledbooleanyesDefault: true.
cors_headersstringnoComma-separated CORS request headers
cors_methodsstringnoComma-separated HTTP methods
cors_originsstringnoComma-separated origins or *
enabledbooleanyesDefault: true.
force_httpsbooleanyesDefault: true.
geo_policyobjectnoOptional host-level country allow/block policy
hostnamestringyes
hsts_enabledbooleanyesDefault: true.
max_body_bytesintegernoOptional request body size limit. 0 means platform default. Default: 0.
team_idstringyes
waf_custom_directivesstringnoRaw Coraza directives used when waf_template=custom
waf_modestringyesAllowed: off, monitor, block. Default: "off".
waf_overridesobjectnoStructured template overrides (for example per-path exclusions or rule toggles)
waf_rule_exclusionsobjectnoOptional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}]
waf_templatestringyesPreconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. Default: "workload_default".

Authentication: bearer token and the team header shown below.

Parameters

NameLocationRequiredDescription
idpathyesResource identifier from your team's API results.
X-Tenant-IDheaderyesActive team ID. Must match the tenant bound to a diagnostic token.

Request example

Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.

curl --fail-with-body --request PUT "$ADIOS_API_URL/v1/gateway_security_profile/${ADIOS_GATEWAY_SECURITY_PROFILE_ID}" \
  -H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
  -H "X-Tenant-ID: $ADIOS_TEAM_ID" \
  -H "Content-Type: application/json" \
  --data-binary @- <<'JSON'
{
  "cors_enabled": true,
  "enabled": true,
  "force_https": true,
  "hostname": "YOUR_HOSTNAME",
  "hsts_enabled": true,
  "max_body_bytes": 0,
  "team_id": "YOUR_TEAM_ID",
  "waf_mode": "off",
  "waf_template": "workload_default"
}
JSON

Replace YOUR_* body placeholders before sending. The quoted heredoc keeps the JSON literal.

Response: HTTP 200

GatewaySecurityProfile updated

Response fields

FieldTypeDescription
cors_enabledboolean
cors_headersstringComma-separated CORS request headers
cors_methodsstringComma-separated HTTP methods
cors_originsstringComma-separated origins or *
created_atinteger(Unix timestamp)
deleted_atinteger(Unix timestamp)
enabledboolean
force_httpsboolean
geo_policyobjectOptional host-level country allow/block policy
hostnamestring
hsts_enabledboolean
max_body_bytesintegerOptional request body size limit. 0 means platform default.
profile_idstring
team_idstring
updated_atinteger(Unix timestamp)
waf_custom_directivesstringRaw Coraza directives used when waf_template=custom
waf_modestringAllowed: off, monitor, block.
waf_overridesobjectStructured template overrides (for example per-path exclusions or rule toggles)
waf_rule_exclusionsobjectOptional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}]
waf_templatestringPreconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom.

Illustrative example; not a live response:

{
  "cors_enabled": true,
  "cors_headers": "example",
  "cors_methods": "example",
  "cors_origins": "example",
  "created_at": 1791072000,
  "deleted_at": 0,
  "enabled": true,
  "force_https": true,
  "geo_policy": {},
  "hostname": "app.example.com",
  "hsts_enabled": true,
  "max_body_bytes": 0,
  "profile_id": "000000000000000000000000001",
  "team_id": "000000000000000000000000001",
  "updated_at": 1791072000,
  "waf_custom_directives": "example",
  "waf_mode": "off",
  "waf_overrides": {},
  "waf_rule_exclusions": {},
  "waf_template": "workload_default"
}

Delete gateway security profile

DELETE /v1/gateway_security_profile/{id}

Deletes a GatewaySecurityProfile

Set gateway_security_profile_id using IDs from your own API responses.

This request changes data or starts an action. Review the target and body before sending it.

Authentication: bearer token and the team header shown below.

Parameters

NameLocationRequiredDescription
idpathyesResource identifier from your team's API results.
X-Tenant-IDheaderyesActive team ID. Must match the tenant bound to a diagnostic token.

Request example

Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.

curl --fail-with-body --request DELETE "$ADIOS_API_URL/v1/gateway_security_profile/${ADIOS_GATEWAY_SECURITY_PROFILE_ID}" \
  -H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
  -H "X-Tenant-ID: $ADIOS_TEAM_ID"

Response: HTTP 200

Resource deleted.

Response fields

FieldTypeDescription
messagestring

Illustrative example; not a live response:

{
  "message": "Deleted successfully"
}