Gateway security API
Configure HTTPS, CORS, and WAF settings for a hostname your team controls.
Use API authentication for protected requests. Examples use your own resource IDs and a temporary token; saved response examples are synthetic.
| Method | Path | Operation |
|---|---|---|
GET | /v1/gateway_security_profile | List gateway security profiles |
POST | /v1/gateway_security_profile | Create gateway security profile |
GET | /v1/gateway_security_profile/{id} | Get gateway security profile |
PUT | /v1/gateway_security_profile/{id} | Update gateway security profile |
DELETE | /v1/gateway_security_profile/{id} | Delete gateway security profile |
List gateway security profiles
GET /v1/gateway_security_profile
Returns a paginated list of GatewaySecurityProfile
Authentication: bearer token and the team header shown below.
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
X-Tenant-ID | header | yes | Active team ID. Must match the tenant bound to a diagnostic token. |
page | query | no | Page number |
per_page | query | no | Items per page |
Request example
Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.
curl --fail-with-body --request GET "$ADIOS_API_URL/v1/gateway_security_profile" \
-H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
-H "X-Tenant-ID: $ADIOS_TEAM_ID"
Response: HTTP 200
List of GatewaySecurityProfile
Response fields
| Field | Type | Description |
|---|---|---|
data | array | |
data[].cors_enabled | boolean | |
data[].cors_headers | string | Comma-separated CORS request headers |
data[].cors_methods | string | Comma-separated HTTP methods |
data[].cors_origins | string | Comma-separated origins or * |
data[].created_at | integer | (Unix timestamp) |
data[].deleted_at | integer | (Unix timestamp) |
data[].enabled | boolean | |
data[].force_https | boolean | |
data[].geo_policy | object | Optional host-level country allow/block policy |
data[].hostname | string | |
data[].hsts_enabled | boolean | |
data[].max_body_bytes | integer | Optional request body size limit. 0 means platform default. |
data[].profile_id | string | |
data[].team_id | string | |
data[].updated_at | integer | (Unix timestamp) |
data[].waf_custom_directives | string | Raw Coraza directives used when waf_template=custom |
data[].waf_mode | string | Allowed: off, monitor, block. |
data[].waf_overrides | object | Structured template overrides (for example per-path exclusions or rule toggles) |
data[].waf_rule_exclusions | object | Optional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}] |
data[].waf_template | string | Preconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. |
pagination | object | |
pagination.page | integer | Current page number |
pagination.per_page | integer | Number of items per page |
pagination.total | integer | Total number of items |
Illustrative example; not a live response:
{
"data": [
{
"cors_enabled": true,
"cors_headers": "example",
"cors_methods": "example",
"cors_origins": "example",
"created_at": 1791072000,
"deleted_at": 0,
"enabled": true,
"force_https": true,
"geo_policy": {},
"hostname": "app.example.com",
"hsts_enabled": true,
"max_body_bytes": 0,
"profile_id": "000000000000000000000000001",
"team_id": "000000000000000000000000001",
"updated_at": 1791072000,
"waf_custom_directives": "example",
"waf_mode": "off",
"waf_overrides": {},
"waf_rule_exclusions": {},
"waf_template": "workload_default"
}
],
"pagination": {
"page": 1,
"per_page": 1,
"total": 1
}
}
Create gateway security profile
POST /v1/gateway_security_profile
Creates a new GatewaySecurityProfile
This request changes data or starts an action. Review the target and body before sending it.
Request fields (the body contains an editable example):
| Field | Type | Required | Description |
|---|---|---|---|
cors_enabled | boolean | yes | Default: true. |
cors_headers | string | no | Comma-separated CORS request headers |
cors_methods | string | no | Comma-separated HTTP methods |
cors_origins | string | no | Comma-separated origins or * |
enabled | boolean | yes | Default: true. |
force_https | boolean | yes | Default: true. |
geo_policy | object | no | Optional host-level country allow/block policy |
hostname | string | yes | |
hsts_enabled | boolean | yes | Default: true. |
max_body_bytes | integer | no | Optional request body size limit. 0 means platform default. Default: 0. |
team_id | string | yes | |
waf_custom_directives | string | no | Raw Coraza directives used when waf_template=custom |
waf_mode | string | yes | Allowed: off, monitor, block. Default: "off". |
waf_overrides | object | no | Structured template overrides (for example per-path exclusions or rule toggles) |
waf_rule_exclusions | object | no | Optional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}] |
waf_template | string | yes | Preconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. Default: "workload_default". |
Authentication: bearer token and the team header shown below.
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
X-Tenant-ID | header | yes | Active team ID. Must match the tenant bound to a diagnostic token. |
Request example
Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.
curl --fail-with-body --request POST "$ADIOS_API_URL/v1/gateway_security_profile" \
-H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
-H "X-Tenant-ID: $ADIOS_TEAM_ID" \
-H "Content-Type: application/json" \
--data-binary @- <<'JSON'
{
"cors_enabled": true,
"enabled": true,
"force_https": true,
"hostname": "YOUR_HOSTNAME",
"hsts_enabled": true,
"max_body_bytes": 0,
"team_id": "YOUR_TEAM_ID",
"waf_mode": "off",
"waf_template": "workload_default"
}
JSON
Replace YOUR_* body placeholders before sending. The quoted heredoc keeps the JSON literal.
Response: HTTP 201
GatewaySecurityProfile created
Response fields
| Field | Type | Description |
|---|---|---|
cors_enabled | boolean | |
cors_headers | string | Comma-separated CORS request headers |
cors_methods | string | Comma-separated HTTP methods |
cors_origins | string | Comma-separated origins or * |
created_at | integer | (Unix timestamp) |
deleted_at | integer | (Unix timestamp) |
enabled | boolean | |
force_https | boolean | |
geo_policy | object | Optional host-level country allow/block policy |
hostname | string | |
hsts_enabled | boolean | |
max_body_bytes | integer | Optional request body size limit. 0 means platform default. |
profile_id | string | |
team_id | string | |
updated_at | integer | (Unix timestamp) |
waf_custom_directives | string | Raw Coraza directives used when waf_template=custom |
waf_mode | string | Allowed: off, monitor, block. |
waf_overrides | object | Structured template overrides (for example per-path exclusions or rule toggles) |
waf_rule_exclusions | object | Optional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}] |
waf_template | string | Preconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. |
Illustrative example; not a live response:
{
"cors_enabled": true,
"cors_headers": "example",
"cors_methods": "example",
"cors_origins": "example",
"created_at": 1791072000,
"deleted_at": 0,
"enabled": true,
"force_https": true,
"geo_policy": {},
"hostname": "app.example.com",
"hsts_enabled": true,
"max_body_bytes": 0,
"profile_id": "000000000000000000000000001",
"team_id": "000000000000000000000000001",
"updated_at": 1791072000,
"waf_custom_directives": "example",
"waf_mode": "off",
"waf_overrides": {},
"waf_rule_exclusions": {},
"waf_template": "workload_default"
}
Get gateway security profile
GET /v1/gateway_security_profile/{id}
Returns a single GatewaySecurityProfile
Set gateway_security_profile_id using IDs from your own API responses.
Authentication: bearer token and the team header shown below.
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
id | path | yes | Resource identifier from your team's API results. |
X-Tenant-ID | header | yes | Active team ID. Must match the tenant bound to a diagnostic token. |
Request example
Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.
curl --fail-with-body --request GET "$ADIOS_API_URL/v1/gateway_security_profile/${ADIOS_GATEWAY_SECURITY_PROFILE_ID}" \
-H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
-H "X-Tenant-ID: $ADIOS_TEAM_ID"
Response: HTTP 200
GatewaySecurityProfile
Response fields
| Field | Type | Description |
|---|---|---|
cors_enabled | boolean | |
cors_headers | string | Comma-separated CORS request headers |
cors_methods | string | Comma-separated HTTP methods |
cors_origins | string | Comma-separated origins or * |
created_at | integer | (Unix timestamp) |
deleted_at | integer | (Unix timestamp) |
enabled | boolean | |
force_https | boolean | |
geo_policy | object | Optional host-level country allow/block policy |
hostname | string | |
hsts_enabled | boolean | |
max_body_bytes | integer | Optional request body size limit. 0 means platform default. |
profile_id | string | |
team_id | string | |
updated_at | integer | (Unix timestamp) |
waf_custom_directives | string | Raw Coraza directives used when waf_template=custom |
waf_mode | string | Allowed: off, monitor, block. |
waf_overrides | object | Structured template overrides (for example per-path exclusions or rule toggles) |
waf_rule_exclusions | object | Optional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}] |
waf_template | string | Preconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. |
Illustrative example; not a live response:
{
"cors_enabled": true,
"cors_headers": "example",
"cors_methods": "example",
"cors_origins": "example",
"created_at": 1791072000,
"deleted_at": 0,
"enabled": true,
"force_https": true,
"geo_policy": {},
"hostname": "app.example.com",
"hsts_enabled": true,
"max_body_bytes": 0,
"profile_id": "000000000000000000000000001",
"team_id": "000000000000000000000000001",
"updated_at": 1791072000,
"waf_custom_directives": "example",
"waf_mode": "off",
"waf_overrides": {},
"waf_rule_exclusions": {},
"waf_template": "workload_default"
}
Update gateway security profile
PUT /v1/gateway_security_profile/{id}
Updates an existing GatewaySecurityProfile
Set gateway_security_profile_id using IDs from your own API responses.
This request changes data or starts an action. Review the target and body before sending it.
Request fields (the body contains an editable example):
| Field | Type | Required | Description |
|---|---|---|---|
cors_enabled | boolean | yes | Default: true. |
cors_headers | string | no | Comma-separated CORS request headers |
cors_methods | string | no | Comma-separated HTTP methods |
cors_origins | string | no | Comma-separated origins or * |
enabled | boolean | yes | Default: true. |
force_https | boolean | yes | Default: true. |
geo_policy | object | no | Optional host-level country allow/block policy |
hostname | string | yes | |
hsts_enabled | boolean | yes | Default: true. |
max_body_bytes | integer | no | Optional request body size limit. 0 means platform default. Default: 0. |
team_id | string | yes | |
waf_custom_directives | string | no | Raw Coraza directives used when waf_template=custom |
waf_mode | string | yes | Allowed: off, monitor, block. Default: "off". |
waf_overrides | object | no | Structured template overrides (for example per-path exclusions or rule toggles) |
waf_rule_exclusions | object | no | Optional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}] |
waf_template | string | yes | Preconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. Default: "workload_default". |
Authentication: bearer token and the team header shown below.
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
id | path | yes | Resource identifier from your team's API results. |
X-Tenant-ID | header | yes | Active team ID. Must match the tenant bound to a diagnostic token. |
Request example
Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.
curl --fail-with-body --request PUT "$ADIOS_API_URL/v1/gateway_security_profile/${ADIOS_GATEWAY_SECURITY_PROFILE_ID}" \
-H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
-H "X-Tenant-ID: $ADIOS_TEAM_ID" \
-H "Content-Type: application/json" \
--data-binary @- <<'JSON'
{
"cors_enabled": true,
"enabled": true,
"force_https": true,
"hostname": "YOUR_HOSTNAME",
"hsts_enabled": true,
"max_body_bytes": 0,
"team_id": "YOUR_TEAM_ID",
"waf_mode": "off",
"waf_template": "workload_default"
}
JSON
Replace YOUR_* body placeholders before sending. The quoted heredoc keeps the JSON literal.
Response: HTTP 200
GatewaySecurityProfile updated
Response fields
| Field | Type | Description |
|---|---|---|
cors_enabled | boolean | |
cors_headers | string | Comma-separated CORS request headers |
cors_methods | string | Comma-separated HTTP methods |
cors_origins | string | Comma-separated origins or * |
created_at | integer | (Unix timestamp) |
deleted_at | integer | (Unix timestamp) |
enabled | boolean | |
force_https | boolean | |
geo_policy | object | Optional host-level country allow/block policy |
hostname | string | |
hsts_enabled | boolean | |
max_body_bytes | integer | Optional request body size limit. 0 means platform default. |
profile_id | string | |
team_id | string | |
updated_at | integer | (Unix timestamp) |
waf_custom_directives | string | Raw Coraza directives used when waf_template=custom |
waf_mode | string | Allowed: off, monitor, block. |
waf_overrides | object | Structured template overrides (for example per-path exclusions or rule toggles) |
waf_rule_exclusions | object | Optional managed exclusion list. Example: [{"path_prefix":"/api/monitoring","remove_rule_ids":[920420]}] |
waf_template | string | Preconfigured WAF ruleset template to apply for this host Allowed: platform_default, workload_default, api_strict, nextjs, django, wordpress, custom. |
Illustrative example; not a live response:
{
"cors_enabled": true,
"cors_headers": "example",
"cors_methods": "example",
"cors_origins": "example",
"created_at": 1791072000,
"deleted_at": 0,
"enabled": true,
"force_https": true,
"geo_policy": {},
"hostname": "app.example.com",
"hsts_enabled": true,
"max_body_bytes": 0,
"profile_id": "000000000000000000000000001",
"team_id": "000000000000000000000000001",
"updated_at": 1791072000,
"waf_custom_directives": "example",
"waf_mode": "off",
"waf_overrides": {},
"waf_rule_exclusions": {},
"waf_template": "workload_default"
}
Delete gateway security profile
DELETE /v1/gateway_security_profile/{id}
Deletes a GatewaySecurityProfile
Set gateway_security_profile_id using IDs from your own API responses.
This request changes data or starts an action. Review the target and body before sending it.
Authentication: bearer token and the team header shown below.
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
id | path | yes | Resource identifier from your team's API results. |
X-Tenant-ID | header | yes | Active team ID. Must match the tenant bound to a diagnostic token. |
Request example
Set ADIOS_API_URL=https://api.adios.dev. For protected requests, set ADIOS_ACCESS_TOKEN and ADIOS_TEAM_ID as in the quickstart. Set any additional ADIOS_* variables from your own resource results.
curl --fail-with-body --request DELETE "$ADIOS_API_URL/v1/gateway_security_profile/${ADIOS_GATEWAY_SECURITY_PROFILE_ID}" \
-H "Authorization: Bearer $ADIOS_ACCESS_TOKEN" \
-H "X-Tenant-ID: $ADIOS_TEAM_ID"
Response: HTTP 200
Resource deleted.
Response fields
| Field | Type | Description |
|---|---|---|
message | string |
Illustrative example; not a live response:
{
"message": "Deleted successfully"
}