API Reference
Fetch your blocklists from your firewall, and automate NxtFireGuard: manage blocklists, whitelists, sensors, aggregators, notification groups and reports, and query threat logs, traffic events and IP threat intelligence.
Getting started
Blocklist delivery
Firewalls poll blocklists from https://limes.nxtfireguard.de. Each blocklist and aggregator has its own URL, shown in the dashboard; it needs no API key. The response is plain text with one IP per line. Use rows to cap the number of entries, for example for firewalls with a small list capacity.
curl "https://limes.nxtfireguard.de/blocklist/<blocklist-name>?rows=500"Management API
All endpoints are relative to https://api.nxtfireguard.nxtgenit.de/v1 and return JSON. Authenticate every request with your API key in the X-API-Key header.
curl https://api.nxtfireguard.nxtgenit.de/v1/blocklists \
-H "X-API-Key: <your-api-key>"Requests without a valid key return 401. Write operations are subject to your plan's limits; see choosing the right product tier.
Blocklist delivery
Blocklists
Serve the merged blocklist of an aggregator as plain text
/aggregator/{name}Retrieves all IP entries across every blocklist belonging to the aggregator (identified by its hashed name), using cached Redis relations when available or falling back to the database, removes whitelisted IPs, and returns the result as a newline-separated plain text list
Path parameters
| name* | string | Hashed blocklist aggregator name |
Query parameters
| rows | integer | Maximum number of entries to return (default: all) |
Returns plain text.
Responses
- 200Newline-separated list of IPs
- 400Bad Request - missing name or invalid rows parameter
- 404Not Found - aggregator not found
- 500Internal Server Error - failed to load blocklists or whitelist
Serve a private blocklist as plain text
/blocklist/{name}Retrieves the IP entries of a private blocklist (identified by its hashed name) from Redis or the database, and returns them as a newline-separated plain text list
Path parameters
| name* | string | Hashed blocklist name |
Query parameters
| rows | integer | Maximum number of entries to return (default: all) |
Returns plain text.
Responses
- 200Newline-separated list of IPs
- 400Bad Request - missing name or invalid rows parameter
- 500Internal Server Error - failed to get IPs
Management API
Blocklist Aggregators
Get all blocklist aggregators
/v1/blocklist-aggregatorsRetrieves all blocklist aggregators for the authenticated user's license, including their connected private and public blocklists, with pagination
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (BlocklistAggregatorGetResponse)
| blocklistAggregators | BlocklistAggregator[] |
Responses
- 200List of blocklist aggregators with pagination
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Create a blocklist aggregator
/v1/blocklist-aggregatorsCreates a blocklist aggregator for the authenticated user's license. Fails if the subscription limit for aggregators is reached, an aggregator with the same name already exists, or the number of attached blocklists exceeds the plan's per-aggregator limit
Request body (BlocklistAggregatorCreateReq)
| id | integer | |
| name | string | |
| privateBlocklists | integer[] | |
| publicBlocklists | integer[] |
Responses
- 200Blocklist aggregator created successfully
- 400Bad Request - invalid input or aggregator already exists
- 401Unauthorized
- 403Forbidden - subscription limit reached
- 500Internal Server Error
Update a blocklist aggregator
/v1/blocklist-aggregators/{id}Updates a specific blocklist aggregator owned by the authenticated user's license. Fails if the aggregator does not exist, is not owned by the license, or the updated blocklist count exceeds the plan's per-aggregator limit
Path parameters
| id* | integer | Blocklist aggregator ID |
Request body (BlocklistAggregatorCreateReq)
| id | integer | |
| name | string | |
| privateBlocklists | integer[] | |
| publicBlocklists | integer[] |
Responses
- 200Blocklist aggregator updated successfully
- 400Bad Request - invalid ID or invalid request body
- 401Unauthorized
- 403Forbidden - not owned by license or limit exceeded
- 404Not Found - blocklist aggregator does not exist
- 500Internal Server Error
Delete a blocklist aggregator
/v1/blocklist-aggregators/{id}Deletes a specific blocklist aggregator owned by the authenticated user's license
Path parameters
| id* | integer | Blocklist aggregator ID |
Responses
- 200Blocklist aggregator deleted successfully
- 400Bad Request - invalid ID
- 401Unauthorized
- 403Forbidden - not owned by license
- 404Not Found - blocklist aggregator does not exist
- 500Internal Server Error
Blocklist Changes
Search blocklist change events
/v1/blocklist-changesSearches blocklist change events (e.g. IPs added/removed) for the authenticated license within a time range, using Elasticsearch point-in-time and search_after pagination
Query parameters
| size | integer | Number of results to return. Default: 100 |
| query | string | Elasticsearch query string. Default: * |
| from | string | Start of time range. Default: now-24h |
| to | string | End of time range. Default: now |
| pit_id | string | Elasticsearch point-in-time ID to continue paging from |
| search_after | string | JSON array string of sort values to page from, e.g. [1621234567,\ |
Responses
- 200Matching change events with pagination cursors
- 400Bad Request - invalid from/to timestamp or search_after format
- 401Unauthorized
- 500Internal Server Error
Blocklists
Get all blocklists
/v1/blocklistsRetrieves all blocklists for the authenticated user
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (BlocklistsGetResponse)
| blocklists | Blocklist[] |
Responses
- 200List of blocklists with pagination
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Create a blocklist
/v1/blocklistsCreates a blocklist for the authenticated user. Note: your subscription limits may apply; if the user has reached their allowed number of blocklists, creation will fail with a 403 Forbidden.
Request body (BlocklistCreateRequest)
| checkInterval | integer | |
| contributingNfgTrafficSensors | integer[] | |
| contributingTrafficSensors | integer[] | |
| myTrafficSensorsShouldContribute | boolean | |
| name* | string | |
| nfgScoreThresholdPrivateIPs | integer | |
| nfgScoreThresholdPublicIPs | integer | |
| nfgTrafficSensorsShouldContribute | boolean | |
| shouldIncludePrivateIPs | boolean | |
| shouldIncludePublicIPs | boolean |
Responses
- 200Blocklist created successfully, returns blocklist_id
- 400Bad Request - invalid input or blocklist already exists
- 401Unauthorized - missing or invalid API key
- 403Forbidden - subscription limit reached
- 500Internal Server Error
Update a blocklist
/v1/blocklists/{id}Updates a specific blocklist owned by the authenticated user's license
Path parameters
| id* | integer | Blocklist ID |
Request body (BlocklistCreateRequest)
| checkInterval | integer | |
| contributingNfgTrafficSensors | integer[] | |
| contributingTrafficSensors | integer[] | |
| myTrafficSensorsShouldContribute | boolean | |
| name* | string | |
| nfgScoreThresholdPrivateIPs | integer | |
| nfgScoreThresholdPublicIPs | integer | |
| nfgTrafficSensorsShouldContribute | boolean | |
| shouldIncludePrivateIPs | boolean | |
| shouldIncludePublicIPs | boolean |
Responses
- 200Blocklist updated successfully
- 400Bad Request - invalid ID or invalid request body
- 401Unauthorized
- 403Forbidden - not owned by license
- 404Not Found - blocklist does not exist
- 500Internal Server Error
Delete a blocklist
/v1/blocklists/{id}Deletes a specific blocklist owned by the authenticated user's license
Path parameters
| id* | integer | Blocklist ID |
Responses
- 200Blocklist deleted successfully
- 400Bad Request - invalid ID
- 401Unauthorized
- 403Forbidden - not owned by license
- 404Not Found - blocklist does not exist
- 500Internal Server Error
CTI
Get CTI metadata for an IP address
/v1/cti/{ip}Retrieves cyber threat intelligence metadata for a given IP address, including score components, GeoIP data, and the names of the authenticated license's blocklists that contain the IP
Path parameters
| ip* | string | IP address to look up |
Response 200 (PublicCtiIp)
| blocklists | string[] | |
| ipMetadata | PublicIpMetadata |
Responses
- 200IP metadata and matching blocklist names
- 400Bad Request - IP address is required
- 401Unauthorized
- 500Internal Server Error
Notification Groups
Get all notification groups
/v1/notification-groupsRetrieves all notification groups for the authenticated user's license, including connected emails, traffic sensors, and threat feed aggregators, with pagination
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (NotificationGroupsGetResponse)
| notificationGroups | NotificationGroup[] |
Responses
- 200List of notification groups with pagination
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Create a new notification group
/v1/notification-groupsCreates a notification group with the given emails, and links it to the caller's traffic sensors and threat feed aggregators
Request body (NotificationGroupCreateReq)
| description | string | |
| emails | NotificationEmailReduced[] | |
| name | string | |
| threatFeedAggregators | integer[] | |
| trafficSensors | integer[] |
Responses
- 200Notification Group created successfully
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Update a notification group
/v1/notification-groups/{id}Updates a notification group owned by the caller's license, replacing its emails, traffic sensor links, and threat feed aggregator links
Path parameters
| id* | integer | Notification Group ID |
Request body (NotificationGroupCreateReq)
| description | string | |
| emails | NotificationEmailReduced[] | |
| name | string | |
| threatFeedAggregators | integer[] | |
| trafficSensors | integer[] |
Responses
- 200Notification group updated successfully
- 400Bad Request
- 401Unauthorized
- 403Forbidden
- 500Internal Server Error
Delete a notification group
/v1/notification-groups/{id}Deletes a notification group and its associated emails, owned by the caller's license
Path parameters
| id* | integer | Notification Group ID |
Responses
- 200notification group deleted successfully
- 400Bad Request
- 401Unauthorized
- 403Forbidden
- 500Internal Server Error
Reports
Get all report templates
/v1/reportsRetrieves all report templates for the authenticated user's license, including schedule, sections, and linked notification groups, with pagination
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Responses
- 200List of report templates with pagination
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Create a new report template
/v1/reportsCreates a report template with its sections, optional custom time range, optional schedule, and linked notification groups
Request body (CreateReportRequest)
| customTimeRange | TimeRangeInput | |
| description | string | |
| format | string | |
| name* | string | |
| notificationGroups | integer[] | |
| schedule | ReportScheduleInputFull | |
| sections | ReportSectionInputFull[] | |
| timeRangePreset* | string |
Responses
- 201Report template created successfully
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Get a report template
/v1/reports/{id}Retrieves a single report template owned by the caller's license, including its sections, schedule, and linked notification groups
Path parameters
| id* | string | Report Template ID |
Responses
- 200Report template
- 400Bad Request
- 401Unauthorized
- 404Not Found
- 500Internal Server Error
Update a report template
/v1/reports/{id}Updates a report template owned by the caller's license, replacing its sections, notification group links, and schedule
Path parameters
| id* | string | Report Template ID |
Request body (CreateReportRequest)
| customTimeRange | TimeRangeInput | |
| description | string | |
| format | string | |
| name* | string | |
| notificationGroups | integer[] | |
| schedule | ReportScheduleInputFull | |
| sections | ReportSectionInputFull[] | |
| timeRangePreset* | string |
Responses
- 200Report template updated successfully
- 400Bad Request
- 401Unauthorized
- 404Not Found
- 500Internal Server Error
Delete a report template
/v1/reports/{id}Deletes a report template and its sections, schedules, and notification group associations, owned by the caller's license
Path parameters
| id* | string | Report Template ID |
Responses
- 200Report template deleted successfully
- 400Bad Request
- 401Unauthorized
- 404Not Found
- 500Internal Server Error
Generate a report PDF
/v1/reports/{id}/generateGenerates and streams back the PDF for a report template owned by the caller's license
Path parameters
| id* | string | Report Template ID |
Responses
- 200Generated PDF report
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Threat Feed Aggregators
Get all threat feed aggregators
/v1/threat-feed-aggregatorsRetrieves all threat feed aggregators for the authenticated license, including their connected threat sensors, notification groups, and live healthchecks status.
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (ThreatFeedAggregatorResponse)
| threatFeedAggregators | ThreatFeedAggregator[] |
Responses
- 200List of threat feed aggregators with pagination
- 400Bad Request
- 500Internal Server Error
Create a threat feed aggregator
/v1/threat-feed-aggregatorsCreates a new threat feed aggregator for the authenticated license and generates its auth secret for the threat collector API.
Request body (ThreatFeedAggregatorCreateReq)
| logstashEnabled | boolean | |
| name | string | |
| notificationGroups | integer[] | |
| syslogEnabled | boolean | |
| syslogServices | SyslogServices |
Responses
- 200Threat feed aggregator created successfully
- 400Bad Request - invalid input
- 500Internal Server Error - or threat feed aggregator already exists
Update a threat feed aggregator
/v1/threat-feed-aggregators/{id}Updates a threat feed aggregator owned by the authenticated license, renames its Kong consumer, and notifies it via Kafka to pull the new configuration.
Path parameters
| id* | integer | Threat Feed Aggregator ID |
Request body (ThreatFeedAggregatorCreateReq)
| logstashEnabled | boolean | |
| name | string | |
| notificationGroups | integer[] | |
| syslogEnabled | boolean | |
| syslogServices | SyslogServices |
Responses
- 200Threat feed aggregator updated successfully
- 400Bad Request - invalid ID or invalid input
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Delete a threat feed aggregator
/v1/threat-feed-aggregators/{id}Deletes a threat feed aggregator owned by the authenticated license, along with its Kong consumer and healthchecks check.
Path parameters
| id* | integer | Threat Feed Aggregator ID |
Responses
- 200Threat feed aggregator deleted successfully
- 400Bad Request - invalid ID
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Remove a threat sensor from a threat feed aggregator
/v1/threat-feed-aggregators/{id}/remove-threat-sensor/{sensorId}Deletes the relationship between a threat feed aggregator and a threat sensor, both owned by the authenticated license.
Path parameters
| id* | integer | Threat Feed Aggregator ID |
| sensorId* | integer | Threat Sensor ID |
Responses
- 200Relationship deleted successfully
- 400Bad Request - invalid ID
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Toggle monitoring for a threat feed aggregator
/v1/threat-feed-aggregators/{id}/toggle-monitoringPauses or resumes the healthchecks monitoring check for a threat feed aggregator owned by the authenticated license, based on its current status.
Path parameters
| id* | integer | Threat Feed Aggregator ID |
Responses
- 200Monitoring toggled successfully
- 400Bad Request - invalid aggregator ID
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Threat Logs
Search threat logs
/v1/threat-logsQueries Elasticsearch threat log documents for the authenticated user's license using a query string, time range, and point-in-time/search_after pagination
Query parameters
| size | integer | Number of documents to return. Default: 100 |
| query | string | Elasticsearch query string. Default: * |
| from | string | Range start (Elasticsearch date math). Default: now-24h |
| to | string | Range end (Elasticsearch date math). Default: now |
| pit_id | string | Point-in-time ID to continue a previous search |
| search_after | string | JSON array sort values to page after (search_after) |
Responses
- 200Matching threat log documents with pagination cursors
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Threat Logs Processing
Search processed threat logs
/v1/threat-logs/processingQueries the threat_log_process_index in Elasticsearch for the authenticated license, using point-in-time pagination with search_after.
Query parameters
| size | integer | Number of documents to return. Default: 100 |
| query | string | Elasticsearch query_string. Default: * |
| from | string | Range start (date math or timestamp). Default: now-24h |
| to | string | Range end (date math or timestamp). Default: now |
| pit_id | string | Point-in-time ID to continue an existing search |
| search_after | string | JSON array string used for search_after pagination, e.g. [1621234567, \ |
Responses
- 200Matching documents with pagination cursors
- 400Bad Request - invalid search_after format
- 500Internal Server Error
Threat Sensors
Get all threat sensors
/v1/threat-sensorsRetrieves all threat sensors for the authenticated user's license, including last-active timestamp and contributions in the last 24 hours, with pagination
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (ThreatSensorsGetResponse)
| threatSensors | ThreatSensor[] |
Responses
- 200List of threat sensors with pagination
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Create a new threat sensor
/v1/threat-sensorsCreates a threat sensor for the authenticated user's license and generates its auth secret
Request body (ThreatSensorCreateRequset)
| contributePrivate | boolean | |
| contributePublic | boolean | |
| hostname | string | |
| id | integer | |
| name | string | |
| sensorLabel | string | |
| sensorType | string |
Responses
- 200Threat Sensor created successfully
- 400Bad Request
- 401Unauthorized
- 500Internal Server Error
Update a threat sensor
/v1/threat-sensors/{id}Updates a threat sensor owned by the caller's license
Path parameters
| id* | integer | Threat Sensor ID |
Request body (ThreatSensorCreateRequset)
| contributePrivate | boolean | |
| contributePublic | boolean | |
| hostname | string | |
| id | integer | |
| name | string | |
| sensorLabel | string | |
| sensorType | string |
Responses
- 200Threat Sensor updated successfully
- 400Bad Request
- 401Unauthorized
- 403Forbidden
- 404Not Found
- 500Internal Server Error
Delete a threat sensor
/v1/threat-sensors/{id}Deletes a threat sensor owned by the caller's license
Path parameters
| id* | integer | Threat Sensor ID |
Responses
- 200Threat Sensor deleted successfully
- 400Bad Request
- 401Unauthorized
- 403Forbidden
- 404Not Found
- 500Internal Server Error
Traffic Events
Search traffic events
/v1/traffic-eventsQueries the nfg-ip-alerts index in Elasticsearch for the authenticated license, using point-in-time pagination with search_after.
Query parameters
| size | integer | Number of documents to return. Default: 100 |
| query | string | Elasticsearch query_string. Default: * |
| from | string | Range start (date math or timestamp). Default: now-24h |
| to | string | Range end (date math or timestamp). Default: now |
| pit_id | string | Point-in-time ID to continue an existing search |
| search_after | string | JSON array string used for search_after pagination, e.g. [1621234567, \ |
Responses
- 200Matching documents with pagination cursors
- 400Bad Request - invalid search_after format
- 500Internal Server Error
Traffic Sensors
Get all traffic sensors
/v1/traffic-sensorsRetrieves all traffic sensors for the authenticated license, including their applied whitelists, contributing blocklists, notification groups, live healthchecks status, and recent contribution stats.
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (TrafficSensorsGetResponse)
| trafficSensors | TrafficSensor[] |
Responses
- 200List of traffic sensors with pagination
- 400Bad Request
- 500Internal Server Error
Create a traffic sensor
/v1/traffic-sensorsCreates a new traffic sensor for the authenticated license, attaches its blocklists/whitelists/notification groups, and provisions its Kong consumer and healthchecks check. Note: your subscription limits may apply; if the license has reached its allowed number of traffic sensors, creation will fail with a 403 Forbidden.
Request body (TrafficSensorCreateRequest)
| alertNotificationGroupIds | integer[] | |
| alertThreshold | integer | |
| blocklistIds | integer[] | |
| id | integer | |
| name | string | |
| notificationGroupIds | integer[] | |
| runSyslog | boolean | |
| sniffTraffic | boolean | |
| whitelistIds | integer[] |
Responses
- 200Traffic sensor created successfully
- 400Bad Request - invalid input or traffic sensor already exists
- 403Forbidden - subscription limit reached
- 500Internal Server Error
Update a traffic sensor
/v1/traffic-sensors/{id}Updates a traffic sensor owned by the authenticated license, renames its Kong consumer, and notifies it via Kafka to pull down its updated blocklists, whitelists, and alert threshold.
Path parameters
| id* | integer | Traffic Sensor ID |
Request body (TrafficSensorCreateRequest)
| alertNotificationGroupIds | integer[] | |
| alertThreshold | integer | |
| blocklistIds | integer[] | |
| id | integer | |
| name | string | |
| notificationGroupIds | integer[] | |
| runSyslog | boolean | |
| sniffTraffic | boolean | |
| whitelistIds | integer[] |
Responses
- 200Traffic sensor updated successfully
- 400Bad Request - invalid ID or invalid input
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Delete a traffic sensor
/v1/traffic-sensors/{id}Deletes a traffic sensor owned by the authenticated license, along with its blocklist/whitelist/notification group relationships, Kong consumer, and healthchecks check.
Path parameters
| id* | integer | Traffic Sensor ID |
Responses
- 200Traffic sensor deleted successfully
- 400Bad Request - invalid ID
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Toggle monitoring for a traffic sensor
/v1/traffic-sensors/{id}/toggle-monitoringPauses or resumes the healthchecks monitoring check for a traffic sensor owned by the authenticated license, based on its current status.
Path parameters
| id* | integer | Traffic Sensor ID |
Responses
- 200Monitoring toggled successfully
- 400Bad Request - invalid sensor ID
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Whitelists
Get all whitelists
/v1/whitelistsRetrieves all whitelists for the authenticated license, including their entries and associated blocklists, blocklist aggregators, and traffic sensors.
Query parameters
| page | integer | Page number. Default: 1 |
| limit | integer | Items per page. Default: 10 |
| sort | string | Sort by field. Default: name |
| direction | string | Sort direction. Default: asc |
| query | string | Search query. Default: |
Response 200 (WhitelistsGetResponse)
| whitelists | Whitelist[] |
Responses
- 200List of whitelists with pagination
- 400Bad Request
- 500Internal Server Error
Create a whitelist
/v1/whitelistsCreates a whitelist for the authenticated license and, if traffic sensors are attached, notifies them via Kafka to pull down the update.
Request body (WhitelistCreateReq)
| blocklistAggregators | integer[] | |
| blocklists | integer[] | |
| entries | IpWhitelistCreateReq[] | |
| name | string | |
| trafficSensors | integer[] |
Responses
- 200Whitelist created successfully, returns whitelist_id
- 400Bad Request - invalid input or whitelist already exists
- 500Internal Server Error
Check whitelist status for an IP
/v1/whitelists/ip/{ip}Checks a given IP address against the authenticated license's whitelists and returns which of the supplied blocklist IDs the IP is NOT whitelisted against.
Path parameters
| ip* | string | IP address to check |
Query parameters
| blocklistIds | string | Comma-separated list of blocklist IDs to check, e.g. [1,2,3] |
Responses
- 200Blocklist IDs where the IP is not whitelisted
- 400Bad Request - invalid IP address
- 500Internal Server Error
Update a whitelist
/v1/whitelists/{id}Updates a whitelist owned by the authenticated license and notifies both previously and newly attached traffic sensors via Kafka to pull down the update.
Path parameters
| id* | integer | Whitelist ID |
Request body (WhitelistCreateReq)
| blocklistAggregators | integer[] | |
| blocklists | integer[] | |
| entries | IpWhitelistCreateReq[] | |
| name | string | |
| trafficSensors | integer[] |
Responses
- 200Whitelist updated successfully
- 400Bad Request - invalid ID or invalid input
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error
Delete a whitelist
/v1/whitelists/{id}Deletes a whitelist owned by the authenticated license and notifies its previously attached traffic sensors via Kafka to pull down the update.
Path parameters
| id* | integer | Whitelist ID |
Responses
- 200Whitelist deleted successfully
- 400Bad Request - invalid ID
- 403Forbidden - not owned by this license
- 404Not Found
- 500Internal Server Error