Unit Type | Configuration Example and Description |
Time (seconds) | Set a 30-minute cache: 30 * 60 = 1800 |
Size (bytes) | Set a 10 MB size limit: 10 * 1024 * 1024 = 10485760 |
Name | Type | Required | Description |
Switch | String | No | Switch for Chinese mainland acceleration optimization. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
StatusCode | Integer | No | Status code, value is one of 301, 302, 303, 307, 308. |
Protocol | String | No | Target request protocol, values as follows: http: target request protocol http. https: target request protocol HTTPS. follow: Follow request. |
HostName | No | Target HostName. Note: This field may return null, indicating no valid value. | |
URLPath | No | Target path. Note: This field may return null, indicating no valid value. | |
QueryString | No | Query string. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Action | String | No | Execution action. The values are as follows: full: retain all. ignore: ignore all. |
Name | Type | Required | Description |
Enabled | String | Yes | Whether adaptive frequency control is enabled. Valid values: on: Enable. off: Disable. |
Id | String | No | The rule ID of adaptive frequency control, only returned in output. |
Sensitivity | String | No | The restriction level of adaptive frequency control. This field is required when Enabled is on. Valid values: Loose: Loose. Moderate: Moderate. Strict: Strict. |
Action | No | The handling method of adaptive frequency control. This field is required when Enabled is on. SecurityAction Name supports: Monitor: Monitor. Deny: Block. Challenge: Challenge. For the ChallengeActionParameters.Name parameter, only JSChallenge is supported. |
Name | Type | Required | Description |
Direction | String | Yes | Origin optimization direction. Valid values: MainlandChinaAndGlobalAdaptive: Adaptive. The domain name must have Intelligent Acceleration enabled to take effect. EdgeOne automatically matches the optimal origin optimization direction based on the actual geographical locations of the client and the origin server, without requiring manual specification. For example, if www.example.com has Advanced Origin Optimization enabled, but Intelligent Acceleration is disabled or only partially matched, Advanced Origin Optimization will not take effect. |
Name | Type | Required | Description |
Enabled | String | No | Whether AI crawler detection is enabled. Values are as follows: on: Enable. off: Disable. |
Action | No | The execution action for AI crawler detection. This field is required when Enabled is on. SecurityAction Name supports only the following values: Deny: Block. Monitor: Monitor. Allow: Allow. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports only JSChallenge and ManagedChallenge. |
Name | Type | Required | Description |
MinDelayTime | String | No | Minimum latency response time. When set to 0s, it indicates an immediate response without delay. Supported measurement units: s: seconds, value ranges from 0 to 5. |
MaxDelayTime | String | No | Maximum latency response time. Supported measurement units: s: seconds. s: seconds, value ranges from 5 to 10. |
Name | Type | Required | Description |
AuthType | String | No | Authentication type. Valid values: TypeA: authentication method a type, for specific meaning please refer to Authentication Method A. TypeB: authentication method b type, for specific meaning please refer to, see Authentication Method B. TypeC: authentication method c type, for specific meaning please refer to Authentication Method C. TypeD: Authentication method type D. For specific meaning, see Authentication Method D. TypeVOD: Authentication method type V. For specific meaning, see Authentication Method V. |
SecretKey | String | No | Primary authentication key, consisting of 6–40 uppercase/lowercase letters or numbers, cannot contain " and $. |
Timeout | Integer | No | Valid duration of the authentication URL, in seconds, value: 1–630720000. Used to judge if the client access request is expired. If the current time exceeds "timestamp + validity period", the request is expired, and 403 is returned directly. If the current time does not exceed "timestamp + validity period", the request is not expired, and the md5 string is further validated. Note: when authtype is one of typea, typeb, typec, or typed, this field is required. |
BackupSecretKey | String | No | Backup authentication key, consisting of 6–40 uppercase/lowercase letters or numbers, cannot contain " and $. |
AuthParam | String | No | Authentication parameter name. The node will validate the corresponding value of this parameter name. It consists of 1–100 uppercase/lowercase letters, numbers, or underscores. Note: this field is required when authtype is either typea or typed. |
TimeParam | String | No | Authentication timestamp, which cannot be the same as the field value of AuthParam. Note: this field is required when authtype is typed. |
TimeFormat | String | No | Authentication time format. Valid values: dec: decimal. hex: hexadecimal. Note: this field is required when authtype is typed. the default is hex. |
Name | Type | Required | Description |
Enabled | String | Yes | Whether bandwidth abuse protection (applicable only to Chinese mainland) is enabled. Valid values: on: Enable. off: Disable. |
Id | String | No | The rule ID of traffic anti-fraud, only returned in output. |
Action | No | The handling method of Traffic Anti-Fraud (applicable only to Chinese mainland). This field is required when Enabled is on. SecurityAction Name supports: Monitor: Monitor. Deny: Block. Challenge: Challenge. For the ChallengeActionParameters.Name parameter, only JSChallenge is supported. |
Name | Type | Required | Description |
SourceIDC | No | Configuration for the source IDC of client IPs, used to handle access requests from client IPs in IDCs (data centers). Such source requests are not directly accessed by mobile or browser clients. | |
SearchEngineBots | No | Configuration for search engine bots, used to handle requests from search engine bots. The IP address, User-Agent, or rDNS results of such requests match known search engine bots. | |
KnownBotCategories | No | Configuration for User-Agent characteristics of commercial or open-source tools (formerly UA characteristic rules), used to handle access requests from known commercial or open-source tools. The User-Agent header of such requests matches the characteristics of known commercial or open-source tools. | |
IPReputation | No | Configuration for the IP threat intelligence library (formerly client Profile Analytics), used to handle client IP addresses whose recent access behavior exhibits specific risk characteristics. | |
BotIntelligence | No | Specific configuration for Bot intelligence analysis. |
Name | Type | Required | Description |
Duration | String | Yes | The penalty duration for blocking an IP address. Supported units include: s: seconds, value ranges from 1 to 120. m: minutes, value ranges from 1 to 120. h: hr, value ranges from 1 to 48. |
Name | Type | Required | Description |
Enabled | String | No | The specific configuration switch for Bot intelligence analysis. Valid values are: on: enable; off: disable. |
Id | String | No | The rule ID for Bot intelligence analysis, only returned as an output parameter. |
BotRatings | No | Based on client and request characteristics, classifies request sources into human-originated requests, legitimate Bot requests, suspected Bot requests, and high-risk Bot requests, and provides request handling options. |
Name | Type | Required | Description |
Enabled | String | No | Whether Bot management is enabled. Valid values: on: Enable. off: Disable. |
CustomRules | No | Custom rules for Bot management. They combine various crawler and request behavior characteristics to precisely define bots and configure customized handling methods. | |
BasicBotSettings | No | Basic configuration for Bot management. It takes effect on all domains associated with the policy. You can perform fine-grained customization via CustomRules. | |
ClientAttestationRules | No | Definition list of Client Attestation rules. This feature is in beta. To use it, submit a ticket. | |
BrowserImpersonationDetection | No | Configures browser impersonation detection rules (formerly active feature identification rules). Sets the response page range for JavaScript injection, browser verification options, and handling methods for non-browser clients. |
Name | Type | Required | Description |
Ids | Array of String | No | Specific items under the Bot managed rule group, used to rewrite the configuration content of this single rule. For specific information corresponding to the Ids, see the information returned by the DescribeBotManagedRules API. |
Action | No | Specify the handling action for the Bot rule item in Ids. The Name of SecurityAction supports the following values: Deny: Block. Monitor: Monitor. Disabled: Not enabled, disable specified rule. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. Allow: Pass (only applicable to Bot basic feature management). |
Name | Type | Required | Description |
Id | String | No | Bot custom rule ID. Different rule configurations can be supported through the rule ID: Add new rule: ID is empty or no specified ID parameter. Modify existing rule: specify the rule ID to be updated/modified. Delete existing rules: Existing rules not included in the Rules list of the BotManagementCustomRules parameter will be deleted. |
Name | String | No | Bot custom rule name. |
Enabled | String | No | Whether the Bot custom rule is enabled. Valid values: on: Enable. off: Disable. |
Priority | Integer | No | Priority of Bot custom rules, ranging from 1 to 100. Default is 50. |
Condition | String | No | The content of the Bot custom rule must comply with expression grammar. For detailed specifications, refer to the product documentation. |
Action | Array of SecurityWeightedAction | No | Action for Bot custom rules. Valid values: Monitor: Monitor. Deny: Block. Within DenyActionParameters, the Name parameter supports Deny and ReturnCustomPage. Challenge: Challenge. Within ChallengeActionParameters, the Name parameter supports JSChallenge and ManagedChallenge. Redirect: Redirect to URL. |
Name | Type | Required | Description |
Rules | Array of BotManagementCustomRule | No | List of Bot custom rules. When ModifySecurityPolicy is used to modify the Web protection configuration: If the Rules parameter in SecurityPolicy.BotManagement.CustomRules is not specified or has a length of zero: Clear all Bot custom rule configurations. If the CustomRules parameter value is not specified in the SecurityPolicy.BotManagement parameter: Retain the existing Bot custom rule configurations without modification. |
Name | Type | Required | Description |
CAPTCHAPageChallenge | No | Specific configuration for the CAPTCHA page. | |
AICrawlerDetection | No | Specific configuration for AI crawler detection. |
Name | Type | Required | Description |
HighRiskBotRequestsAction | No | Handling action for malicious Bot requests. The Name of SecurityAction supports the following values: Deny: Block. Monitor: Monitor. Allow: Allow. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. | |
LikelyBotRequestsAction | No | Handling action for suspected Bot requests. The Name of SecurityAction supports the following values: Deny: Block. Monitor: Monitor. Allow: Allow. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. | |
VerifiedBotRequestsAction | No | Handling action for friendly Bot requests. The Name of SecurityAction supports the following values: Deny: Block. Monitor: Monitor. Allow: Allow. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. | |
HumanRequestsAction | No | Handling action for normal Bot requests. The Name of SecurityAction supports the following values: Allow: pass. |
Name | Type | Required | Description |
IssueNewBotSessionCookie | String | No | Whether to update and verify the Cookie. Values are as follows: on: Update and validate the Cookie. off: Validate only. |
MaxNewSessionTriggerConfig | No | The trigger threshold for updating and verifying the Cookie. It takes effect only when IssueNewBotSessionCookie is on. | |
SessionExpiredAction | No | The execution action for requests without a Cookie or with an expired Cookie. Supported Name values for SecurityAction: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. | |
SessionInvalidAction | No | The execution action for invalid Cookies. Supported Name values for SecurityAction: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. | |
SessionRateControl | No | Specific configuration for session rate and periodic characteristic verification. |
Name | Type | Required | Description |
Rules | Array of BrowserImpersonationDetectionRule | No | List of browser impersonation detection rules. Use ModifySecurityPolicy to modify Web protection configuration: If the Rules parameter in SecurityPolicy.BotManagement.BrowserImpersonationDetection is not specified or has a length of zero: Clear all browser spoofing detection rule configurations. If the BrowserImpersonationDetection parameter is not specified within SecurityPolicy.BotManagement: Retain the existing browser spoofing detection rule configurations without modification. |
Name | Type | Required | Description |
BotSessionValidation | No | Cookie validation and session tracking configuration. | |
ClientBehaviorDetection | No | Client behavior validation configuration. |
Name | Type | Required | Description |
Id | String | No | ID of the browser impersonation detection rule. Different rule configurations can be supported through the rule ID: Add new rule: ID is empty or no specified ID parameter. Modify existing rule: specify the rule ID to be updated/modified. Delete existing rules: Existing rules not included in the Rules list of the BrowserImpersonationDetection parameter will be deleted. |
Name | String | No | Name of the browser impersonation detection rule. |
Enabled | String | No | Whether the browser impersonation detection rule is enabled. Valid values are: on: Enable. off: Disable. |
Condition | String | No | Specific content of the browser impersonation detection rule. It only supports the configuration of the request method (Method), request path (Path), and request URL, and must comply with expression syntax. For detailed specifications, refer to the product documentation. |
Action | No | Handling method for the browser impersonation detection rule, including Cookie verification, session tracking configuration, and client behavior verification configuration. |
Name | Type | Required | Description |
Switch | String | No | Custom cache time switch, valid values: on: Enable. off: Disable. |
CacheTime | Integer | No | Custom cache time value, unit: seconds. value range: 0-315360000. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
FollowOrigin | No | Follow the origin site cache config. Only one of FollowOrigin, NoCache, or CustomTime can be configured with Switch set to on. Note: This field may return null, indicating no valid value. | |
NoCache | No | No cache configuration. Only one of FollowOrigin, NoCache, or CustomTime can be configured with Switch set to on. Note: This field may return null, indicating no valid value. | |
CustomTime | No | Custom cache time configuration. Only one of FollowOrigin, NoCache, or CustomTime can be configured with Switch set to on. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
FullURLCache | String | No | Whether to enable full-path caching. Valid values: on: Enable full path cache (ignore parameter disabled). off: Disable full path cache (ignore parameter enabled). |
IgnoreCase | String | No | Whether to ignore case caching. Valid values: on: Ignore. off: Do not ignore. |
QueryString | No | The query string retention config. This field and FullURLCache must be set simultaneously but cannot both be on. |
Name | Type | Required | Description |
Switch | String | No | Feature switch. Valid values: on: Enable. off: Disable. |
Action | String | No | Cache action. The values are as follows: full: Retain all. ignore: Ignore all. includeCustom: Retain specified parameters. excludeCustom: Ignore specified parameters. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Values | Array of String | No | Custom Cache Key Cookie name list. Note: This field is required when Action is includeCustom or excludeCustom. When Action is full or ignore, it is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
Switch | String | No | Feature switch. Valid values: on: Enable. off: Disable. |
Values | Array of String | No | Custom Cache Key HTTP request header list. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
FullURLCache | String | No | Switch to retain the entire query string. Valid values: on: Enable. off: Disable. Note: At least one configuration must be set among FullURLCache, IgnoreCase, Header, Scheme, and Cookie. This field and QueryString.Switch must be set simultaneously but cannot both be on. |
QueryString | No | The query string retention config. This field and FullURLCache must be set simultaneously but cannot both be on. Note: This field may return null, indicating no valid value. | |
IgnoreCase | String | No | Switch to ignore case. Valid values: on: Enable. off: Disable. Note: At least one configuration must be set among FullURLCache, IgnoreCase, Header, Scheme, and Cookie. |
Header | No | HTTP request header configuration parameters. At least one configuration must be set among FullURLCache, IgnoreCase, Header, Scheme, and Cookie. Note: This field may return null, indicating no valid value. | |
Scheme | String | No | Request protocol switch. Valid values: on: Enable. off: Disable. Note: At least one configuration must be set among FullURLCache, IgnoreCase, Header, Scheme, and Cookie. |
Cookie | No | Cookie configuration parameter. At least one configuration must be set among FullURLCache, IgnoreCase, Header, Scheme, and Cookie. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Switch | String | No | Switch to retain/ignore specified parameters in the query string. Valid values: on: Enable. off: Disable. |
Action | String | No | Action to retain/ignore specified parameters in the query string. Valid values: includeCustom: Retain some parameters. excludeCustom: Ignore some parameters. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Values | Array of String | No | List of parameter names to retain/ignore in the query string. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
FollowOrigin | No | Follow the origin site cache. Leave unset means this configuration is unset. Only one of FollowOrigin, NoCache, or CustomTime can be configured with Switch set to on. Note: This field may return null, indicating no valid value. | |
NoCache | No | No cache. Leave unset means this configuration is unset. Only one of FollowOrigin, NoCache, or CustomTime can be configured with Switch set to on. Note: This field may return null, indicating no valid value. | |
CustomTime | No | Custom cache time. Leave unset means this configuration is unset. Only one of FollowOrigin, NoCache, or CustomTime can be configured with Switch set to on. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Switch | String | No | Cache pre-refresh switch, valid values: on: Enable. off: Disable. |
CacheTimePercent | Integer | No | The pre-refresh time is set to a percentage value of the node cache time, values: 1–99. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
Enabled | String | No | Whether the CAPTCHA page is enabled. Valid values are: on: Enable. off: Disable. |
Name | Type | Required | Description |
ChallengeOption | String | Yes | Specific challenge actions for secure execution. Valid values: InterstitialChallenge: Interstitial challenge. InlineChallenge: Embedded challenge. JSChallenge: JavaScript challenge. ManagedChallenge: Managed challenge. |
Interval | String | No | Time interval for repeated challenges. This field is required when Name is InterstitialChallenge/InlineChallenge. The default value is 300s. Supported units include: s: seconds, value ranges from 1 to 60. m: minutes, value ranges from 1 to 60. h: hr, value ranges from 1 to 24. |
AttesterId | String | No | Client authentication method ID. This field is required when Name is InterstitialChallenge/InlineChallenge. |
Name | Type | Required | Description |
Id | String | No | Rule ID of the client authentication rule. Different rule configurations can be supported through the rule ID: Add new rule: ID is empty or no specified ID parameter. Modify existing rule: specify the rule ID to be updated/modified. Delete existing rules: Existing rules not included in the ClientAttestationRule list of BotManagement parameters will be deleted. |
Name | String | No | Name of the client authentication rule. |
Enabled | String | No | Whether to enable the rule. Valid values: on: Enable. off: Disable. |
Priority | Integer | No | Rule priority. A smaller value indicates higher priority execution, ranging from 0 to 100. Default is 0. |
Condition | String | No | The rule content must comply with expression grammar. For details, refer to the product document. |
AttesterId | String | No | Client authentication Option ID. |
DeviceProfiles | Array of DeviceProfile | No | Client device configuration. If the DeviceProfiles parameter value is not specified in ClientAttestationRules: Keep the existing client device configuration and do not modify it. |
InvalidAttestationAction | No | Client authentication failed handling method. SecurityAction Name parameter supports: Deny: Block. Monitor: Monitor. Redirect: Redirect. Challenge: Challenge. Default value: Monitor. |
Name | Type | Required | Description |
Rules | Array of ClientAttestationRule | No | List of client authentication. Use ModifySecurityPolicy to modify Web protection configuration: If the Rules parameter in SecurityPolicy.BotManagement.ClientAttestationRules is not specified or has a length of zero: Clear all client authentication rule configurations. If the ClientAttestationRules parameter value is not specified in SecurityPolicy.BotManagement: Keep the existing client authentication rule configuration and do not modify it. |
Name | Type | Required | Description |
CryptoChallengeIntensity | String | No | Proof-of-work verification intensity. Values: low: Low. medium: Medium. high: High. |
CryptoChallengeDelayBefore | String | No | Execution method for client behavior validation. Values: 0ms: Execute immediately. 100ms: Execute after a delay of 100ms. 200ms: Execute after a delay of 200ms. 300ms: Execute after a delay of IIIms. 400ms: Execute after a delay of 400ms. 500ms: Execute after a delay of 500ms. 600ms: Execute after a delay of 600ms. 700ms: Execute after a delay of 700ms. 800ms: Execute after a delay of 800ms. 900ms: Execute after a delay of 900ms. 1000ms: Execute after a delay of 1000ms. |
MaxChallengeCountInterval | String | No | Time window for threshold-triggered statistics. Valid values: 5s: Within 5 seconds; 10s: Within 10 seconds; 15s: Within 15 seconds; 30s: Within 30 seconds; 60s: Within 60 seconds; 5m: Within 5 minutes; 10m: Within 10 minutes; 30m: Within 30 minutes; 60m: Within 60 minutes. |
MaxChallengeCountThreshold | Integer | No | Cumulative quantity for threshold-triggered statistics. Valid range: 1 to -100000000. |
ChallengeNotFinishedAction | No | Execution action for when the client does not enable JS (detection not completed). Supported Name values for SecurityAction: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. | |
ChallengeTimeoutAction | No | Execution action for when client detection times out. Supported Name values for SecurityAction: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. | |
BotClientAction | No | Handling action for Bot clients. The Name of SecurityAction supports the following values: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. |
Name | Type | Required | Description |
Enabled | String | Yes | Whether to enable intelligent client filtering. Values: on: Enable. off: Disable. |
Id | String | No | The rule ID for intelligent client filtering, only returned as an output parameter. |
Action | No | The handling method of intelligent client filtering. This field is required when Enabled is on. SecurityAction Name supports: Monitor: Monitor. Deny: Block. Challenge: Challenge. For the ChallengeActionParameters.Name parameter, only JSChallenge is supported. |
Name | Type | Required | Description |
Switch | String | No | Configuration switch. Valid values: on: Enable. off: Disable. |
HeaderName | String | No | The request header name for storing regional information of the client IP. Valid when Switch=on. If empty, use the default value: EO-Client-IPCountry. |
Name | Type | Required | Description |
Switch | String | No | Configuration switch. Valid values: on: Enable. off: Disable. |
HeaderName | String | No | The request header name containing client IP during origin pull. When Switch is on, this parameter is required. X-Forwarded-For cannot be filled in. |
Name | Type | Required | Description |
Switch | String | No | Smart compression configuration switch. Valid values: on: Enable. off: Disable. |
Algorithms | Array of String | No | List of supported compression algorithms. When Switch is on, this field is required; otherwise, it does not take effect. Valid values: brotli: the brotli algorithm. gzip: the gzip algorithm. |
Name | Type | Required | Description |
Function | String | Yes | Specifies the function to be executed, with the value being the unique identifier of the function within the site. Takes effect when TriggerType is direct. |
Regions | Array of String | Yes | List of countries/regions. Example values: CN: China, CN.GD: Guangdong, China. For valid values, see Country/Region and Corresponding Code Enums. |
Name | Type | Required | Description |
Condition | String | Yes | Matching condition. |
TriggerType | String | No | Function selection configuration type: Enum values: direct: Directly specify the execution function. weight: Select a function based on the weight ratio. region: Select a function based on the country/region of the client IP address. |
Function | String | No | Specifies the function to be executed, with the value being the unique identifier of the function within the site. Takes effect when TriggerType is direct. |
RegionMappingSelections | Array of ConfigGroupFunctionRegionSelection | No | Function selection configuration based on client IP address country/region. |
WeightedSelections | Array of ConfigGroupFunctionWeightedSelection | No | Function selection configuration based on weight. |
Remark | String | No | Rule description. |
Name | Type | Required | Description |
Function | String | Yes | Specifies the function to be executed, with the value being the unique identifier of the function within the site. Takes effect when TriggerType is direct. |
Weight | Integer | Yes | Selection weight. Valid values range from 0 to 100, and the sum of all weights must be 100. The selection probability is calculated as follows: weight/100. For example, if two functions A and B are configured, and the weight of A is 30, then the weight of B must be 70. In this case, the probability of selecting A is 30%, and the probability of selecting B is 70%. |
Name | Type | Required | Description |
RuleName | String | No | Rule name. The name length limit is no more than 255 characters. |
Description | Array of String | No | Rule annotation. Multiple annotations can be filled. |
Branches | Array of RuleBranch | No | Sub-rule branch. This list currently only supports filling in one rule. Multiple entries are invalid. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Switch | String | Yes | Content compression configuration switch. Valid values: on: Enable. off: Disable. When the Switch is on, it simultaneously supports the brotli and gzip compression algorithms. |
Name | Type | Required | Description |
ActionId | String | Yes | Id of the custom configuration item. You can obtain it from the CustomActionSet[].ActionId value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
Parameters | Array of CustomActionParameter | Yes | Values of the parameter fields under this custom configuration item. You can obtain it from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
Name | Type | Required | Description |
Name | String | Yes | Name of each parameter field under the custom configuration item. You can obtain it from the CustomActionSet[].Parameters[].Name value returned by the DescribeAvailableCustomActionsForRuleEngine API, such as "Seconds", "Ports", and "StatusCode". |
ValueType | String | Yes | Type of each parameter field value under the custom configuration item. Enum values: String: String type. Integer: Integer type. Float: Float type. Boolean: Boolean type. ArrayOfString: String array type. ArrayOfInteger: Integer array type. ArrayOfFloat: Float array type. You can obtain it from the CustomActionSet[].Parameters[].Type value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
StringValue | String | No | A string type parameter value. This parameter is required when ValueType is String. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
IntegerValue | Integer | No | An integer type parameter value. This parameter is required when ValueType is Integer. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
FloatValue | Float | No | A float type parameter value. This parameter is required when ValueType is Float. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
BooleanValue | Boolean | No | Boolean parameter value. This parameter is required when ValueType is Boolean. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
StringArrayValue | Array of String | No | A string array type parameter value. This parameter is required when ValueType is ArrayOfString. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
IntegerArrayValue | Array of Integer | No | An integer array type parameter value. This parameter is required when ValueType is ArrayOfInteger. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
FloatArrayValue | Array of Float | No | A float array type parameter value. This parameter is required when ValueType is ArrayOfFloat. You can obtain the default values, units, limits, and other descriptions of parameter values from the CustomActionSet[].Parameters value returned by the DescribeAvailableCustomActionsForRuleEngine API. |
Name | Type | Required | Description |
CustomActions | Array of CustomAction | Yes | List of custom configurations to be configured. |
Name | Type | Required | Description |
Name | String | Yes | Custom rule name. |
Condition | String | Yes | The content of the custom rule must comply with expression grammar. For detailed specifications, refer to the product documentation. |
Action | Yes | Handling action of the custom rule. Supported SecurityAction.Name values: Deny: Block. Monitor: Monitor. ReturnCustomPage: Use the specified page to block. Redirect: Redirect to URL. BlockIP: IP block JSChallenge: JavaScript challenge. ManagedChallenge: Managed challenge. Allow: pass. | |
Enabled | String | Yes | Whether to enable the custom rule. Valid values: on: Enable. off: Disable. |
Id | String | No | Custom rule ID. Different rule configurations can be supported through the rule ID: Add new rule: ID is empty or no specified ID parameter. Modify existing rule: specify the rule ID to be updated/modified. Delete existing rules: Existing rules not included in the Rules list of CustomRules parameters will be deleted. |
RuleType | String | No | Type of custom rule. Values include: BasicAccessRule: basic access control PreciseMatchRule: precise matching rule. ManagedAccessRule: Expert-customized rule, supporting only output parameters. Description: When RuleType is not specified, it defaults to PreciseMatchRule. |
Priority | Integer | No | Priority of custom rules, ranging from 0 to 100. Default is 0. Only supports exact matching rules (PreciseMatchRule). |
Name | Type | Required | Description |
Rules | Array of CustomRule | No | Custom rule definition list. Use ModifySecurityPolicy to modify Web protection configuration: If the Rules parameter is not specified or has a length of zero: Clear all custom rule configurations. If the CustomRules parameter value is not specified in SecurityPolicy: Keep the existing custom rule configuration and do not modify it. |
Name | Type | Required | Description |
Switch | String | No | Custom cache time switch, valid values: on: Enable. off: Disable. |
IgnoreCacheControl | String | No | Switch for ignoring origin CacheControl, valid values: on: Enable. off: Disable. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
CacheTime | Integer | No | Custom cache time value in seconds, range: 0–315360000. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
ManagedRules | No | Configuration for the default blocking and handling action of managed rules. Supported configuration parameters for DenyActionParameters: ReturnCustomPage: Whether to use a custom page. ResponseCode: The status code for a custom page. ErrorPageId: The PageId for a custom page. | |
OtherModules | No | Configuration for the default blocking and handling action of security rules other than managed rules (including custom rules, rate limiting, and Bot Management features). Supported configuration parameters for DenyActionParameters: ReturnCustomPage: Whether to use a custom page. ResponseCode: The status code for a custom page. ErrorPageId: The PageId for a custom page. |
Name | Type | Required | Description |
BlockIp | String | No | Whether to extend the ban on the source IP address. Valid values: on: Enable. off: Disable. After this option is enabled, the client IPs that trigger the rule are continuously blocked. When this option is enabled, you must also specify the BlockIpDuration parameter. Note: This option cannot be enabled together with the ReturnCustomPage or Stall option. |
BlockIpDuration | String | No | IP address ban duration when BlockIP is on. |
ReturnCustomPage | String | No | Whether to use a custom page. Valid values: on: Enable. off: Disable. After this option is enabled, the custom page content is used to intercept (respond to) requests. When this option is enabled, you must also specify the ResponseCode and ErrorPageId parameters. Note: This option cannot be enabled together with the BlockIp or Stall option. |
ResponseCode | String | No | Status code of the custom page. |
ErrorPageId | String | No | PageId of the custom page. |
Stall | String | No | Whether to suspend requests from the source without processing them. Valid values: on: Enable. off: Disable. After this option is enabled, the system no longer responds to requests within the current connection session and does not actively disconnect the connection. When this option is used for crawler defense, it consumes client connection resources. Note: This option cannot be enabled together with the BlockIp or ReturnCustomPage option. |
Name | Type | Required | Description |
ClientType | String | Yes | Client device type. Values as follows: iOS; Android; WebView; WeChatMiniProgram. |
HighRiskMinScore | Integer | No | The minimum value to determine a request as high-risk ranges from 1–99. The larger the value, the higher the request risk, resembling a request initiated by a Bot client. The default value is 50, corresponding to 51–100 as high-risk. |
HighRiskRequestAction | No | Handling method for high-risk requests. SecurityAction Name parameter supports: Deny: Block. Monitor: Monitor. Redirect: Redirect. Challenge: Challenge. Default value: Monitor. | |
MediumRiskMinScore | Integer | No | The minimum value to determine a request as medium-risk ranges from 1–99. The larger the value, the higher the request risk, resembling a request initiated by a Bot client. The default value is 15, corresponding to 16–50 as medium-risk. |
MediumRiskRequestAction | No | Handling method for medium-risk requests. SecurityAction Name parameter supports: Deny: Block. Monitor: Monitor. Redirect: Redirect. Challenge: Challenge. Default value: Monitor. |
Name | Type | Required | Description |
StatusCode | Integer | Yes | Status code. Support scope: 400, 403, 404, 405, 414, 416, 451, 500, 501, 502, 503, 504. |
RedirectURL | String | Yes | Redirect URL. Must be a complete redirect path, for example, https://www.test.com/error.html. |
Name | Type | Required | Description |
ErrorPageParams | Array of ErrorPage | No | Custom error page configuration list. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Id | String | No | Exception rule ID. Different rule configurations can be supported through the rule ID: Add new rule: ID is empty or no specified ID parameter. Modify existing rule: specify the rule ID to be updated/modified. Delete existing rules: Existing rules not included in the Rules list of ExceptionRules parameters will be deleted. |
Name | String | No | Exception rule name. |
Condition | String | No | The exception rule content must comply with expression grammar. For details, refer to the product document. |
SkipScope | String | No | Execution options for the exception rule. Valid values: WebSecurityModules: The security protection module for which exception rules are specified. It must be used in conjunction with WebSecurityModulesForException. WebSecuritySubmodules: The security protection submodule for which exception rules are specified. It must be used in conjunction with WebSecuritySubmodulesForException. ManagedRules: The specific managed rule for which exception rules are specified. It must be used in conjunction with ManagedRulesForException. ManagedRuleGroups: The managed rule group for which exception rules are specified. It must be used in conjunction with ManagedRuleGroupsForException. |
SkipOption | String | No | Specific request type to skip. Valid values: SkipOnAllRequestFields: Skip all requests; SkipOnSpecifiedRequestFields: Skip specified request fields. Valid only when SkipScope is ManagedRules or ManagedRuleGroups. |
WebSecurityModulesForException | Array of String | No | Security protection module with specified exception rules. Valid when SkipScope is WebSecurityModules. Valid values: websec-mod-managed-rules: managed rules; websec-mod-rate-limiting: rate limit; websec-mod-custom-rules: custom rule; websec-mod-adaptive-control: adaptive frequency control, intelligent client filter, slow attack protection, traffic theft protection; websec-mod-bot: Bot management. |
WebSecuritySubmodulesForException | Array of String | No | Security protection submodules with specified exception rules. Valid when SkipScope is WebSecuritySubmodules. Valid values: Managed Rules (ManagedRules) module features: websec-mod-managed-rules/managed-rule-groups: rule set; websec-mod-managed-rules/frequent-scanning-protection: high-frequency scanning protection; Rate Limit (RateLimitingRules) module features: websec-mod-rate-limiting-rules: rate limiting rules; Custom Rules (CustomRules) module features: websec-mod-custom-rules: custom rule; HTTP Anti-DDoS (HttpDDoSProtection) module features: websec-mod-http-ddos-protection/adaptive-frequency-control: adaptive frequency control; websec-mod-http-ddos-protection/client-filtering: intelligent client filtering; websec-mod-http-ddos-protection/bandwidth-abuse-defense: bandwidth abuse defense; Advanced Bot Management (BotManagement) module features: websec-mod-bot-management/basic-feature: basic feature management; websec-mod-bot-management/ip-reputation: client profile analytics; websec-mod-Bot-management/Bot-intelligence: intelligent Bot analysis; websec-mod-bot-management/custom-rules: custom rule; websec-mod-bot-management/browser-impersonation-detection: active feature identification; websec-mod-bot-management/client-attestation-rules: client attestation; Basic Bot Management (BotManagementLite) module features: websec-mod-bot-management-lite/ai-crawler-detection: AI crawler handling; websec-mod-bot-management-lite/captcha-page-challenge: CAPTCHA page; |
ManagedRulesForException | Array of String | No | Specific managed rules for the exception rule. Valid only when SkipScope is ManagedRules. |
ManagedRuleGroupsForException | Array of String | No | Managed rule groups for the exception rule. Valid only when SkipScope is ManagedRuleGroups. |
RequestFieldsForException | Array of RequestFieldsForException | No | Specific configuration for the exception rule to skip specified request fields. Valid only when SkipScope is ManagedRules or ManagedRuleGroups and SkipOption is SkipOnSpecifiedRequestFields. |
Enabled | String | No | Whether to enable the exception rule. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Rules | Array of ExceptionRule | No | Definition list of exception rules. Use ModifySecurityPolicy to modify the Web protection configuration: If the Rules parameter is not specified or has a length of zero: Clear all exception rule configurations. If the ExceptionRules parameter value is not specified in SecurityPolicy: Keep the existing exception rule configuration and do not modify it. |
Name | Type | Required | Description |
Switch | String | Yes | Switch that determines whether to follow the origin server configuration. Valid values: on: Enable. off: Disable. |
DefaultCache | String | No | Switch that determines whether to cache or not cache content when the origin server does not return a Cache-Control header. When Switch is on, this field is required. When Switch is off, this field is not required and will not take effect if filled. Valid values: on: Cache. off: Do not cache. |
DefaultCacheStrategy | String | No | Switch that determines whether to use/not use the default cache policy when the origin server does not return a Cache-Control header. When DefaultCache is on, this field is required. Otherwise, this field does not take effect. When DefaultCacheTime is not 0, this field must be off. Valid values: on: Use the default cache policy. off: Do not use default caching policy. |
DefaultCacheTime | Integer | No | Default cache time in seconds when the origin server does not return a Cache-Control header. Value range: 0-315360000. When DefaultCache is on, this field is required, otherwise it is ineffective. When DefaultCacheStrategy is on, this field must be 0. |
Name | Type | Required | Description |
Switch | String | No | Switch for forced redirect configuration. Valid values: on: Enable. off: Disable. |
RedirectStatusCode | Integer | No | Redirect status code. When Switch is on, this field is required; otherwise, it does not take effect. Valid values: 301: 301 redirect. 302: 302 redirect. |
Name | Type | Required | Description |
Enabled | String | No | Whether to enable the high-frequency scan protection rule. Valid values: on: Enable high frequency scan protection rule to take effect. off: Disable high frequency scan protection rule. |
Id | String | No | The rule ID of high-frequency scan protection, only returned in output. |
Action | No | Handling action for high-frequency scan protection. This field is required when Enabled is on. SecurityAction Name supports: Deny: Block and respond with an interception page. Monitor: Observe without processing requests, record security events in logs. JSChallenge: JavaScript challenge, respond with a JavaScript challenge page. | |
CountBy | String | No | Request statistics matching method. This field is required when Enabled is on. Valid values: http.request.xff_header_ip: client ip (priority match xff header); http.request.ip: client IP. |
BlockThreshold | Integer | No | This parameter specifies the threshold for high-frequency scan protection, which is the cumulative number of interceptions when managed rules configured as blocklist are hit within the time range set by CountingPeriod. The value ranges from 1 to 4294967294, such as 100. When exceeding this statistical value, subsequent requests will trigger the handling action set by Action. This field is required when Enabled is on. |
CountingPeriod | String | No | This parameter specifies the statistical time window for high-frequency scan protection, which is the time window for counting requests that hit managed rules configured as blocklist. The value ranges from 5 to 1800, and the measurement unit is only supported in seconds (s), such as 5s. This field is required when Enabled is on. |
ActionDuration | String | No | This parameter specifies the duration of the handling Action set by the Action parameter for high-frequency scan protection. The value ranges from 60 to 86400, and the unit is only supported in seconds (s), such as 60s. This field is required when Enabled is on. |
Name | Type | Required | Description |
Switch | String | No | gRPC configuration switch. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Action | String | Yes | HTTP header setting method. Valid values: set: Set. Change the value of the specified header parameter to the set value. del: Delete. Delete the specified header parameter. add: Add. Add the specified header parameter. |
Name | String | Yes | HTTP header name. |
Value | String | No | HTTP header value. This parameter is required when Action is set or add; not required when Action is del. |
Name | Type | Required | Description |
Action | String | No | Execution action. The values are as follows: followOrigin: Follow origin domain. custom: Custom. Customize. |
ServerName | String | No | Host Header rewrite, need to fill in complete domain name. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
Action | String | No | Target HostName configuration. Valid values: follow: Follow request. custom: Custom. Customize. |
Value | String | No | Target HostName custom value, maximum length 1024. Note: This field is required when Action is custom. When Action is follow, it is ineffective. |
Configuration Field | Type | Required | Description |
Host | String | No | Site-level policy. A policy that takes effect for all domains under the site. For details, see Site-level Policy. |
PolicyType | String | No | The policy type used by the current domain. Valid values: ZoneDefault: Use site-level policy, that is, the policy configuration defined in ZoneDefaultPolicy. Custom: Use domain-level policy. When using this option, you must also configure the Policy field to specify detailed policy configuration. Template: Use policy template. When using this option, you must also configure the TemplateId field to specify the policy template for the current domain. |
Policy | No | Optional. When PolicyType is Custom, this field specifies the detailed policy configuration for the current domain and takes effect for the current domain. | |
TemplateId | String | No | Optional. When PolicyType is Template, this field specifies the Id of the policy template used by the current domain. |
Name | Type | Required | Description |
Switch | String | No | HSTS configuration switch. Valid values: on: Enable. off: Disable. |
Timeout | Integer | No | Cache HSTS header time in seconds, range: 1-31536000. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
IncludeSubDomains | String | No | Whether to allow other subdomains to inherit the same HSTS header. Valid values: on: Allow other subdomains to inherit the same HSTS header. off: Do not allow other subdomains to inherit the same HSTS header. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Preload | String | No | Whether to allow browsers to preload the HSTS header. Valid values: on: Allow the browser to preload HSTS header. off: Do not allow the browser to preload HSTS header. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
Switch | String | No | HTTP2 access configuration switch. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
AdaptiveFrequencyControl | No | Specific configuration of adaptive frequency control. | |
ClientFiltering | No | Specific configuration of intelligent client filter. | |
BandwidthAbuseDefense | No | Specific configuration of bandwidth abuse protection. | |
SlowAttackDefense | No | Specific configuration of slow attack protection. |
Name | Type | Required | Description |
StatusCode | Integer | No | Response status code. Support 2XX, 4XX, 5XX, excluding 499, 514, 101, 301, 302, 303, 509, 520-599. |
ResponsePage | String | No | Response page ID. |
Name | Type | Required | Description |
ResponseTimeout | Integer | No | HTTP response timeout, in seconds, value: 5–600. |
Name | Type | Required | Description |
Enabled | String | No | IP threat intelligence library (formerly client Profile Analytics). Valid values are: on: Enable. off: Disable. |
IPReputationGroup | No | Specific configuration content of the IP threat intelligence library (formerly client Profile Analytics). |
Name | Type | Required | Description |
BaseAction | No | The execution action for the IP threat intelligence library (formerly client Profile Analytics). The Name field of SecurityAction supports the following values: Deny: Block. Monitor: Monitor. Disabled: Not enabled, disable specified rule. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. | |
BotManagementActionOverrides | Array of BotManagementActionOverrides | No | The specific configuration of the IP threat intelligence library (formerly client Profile Analytics), used to override the default configuration in BaseAction. The Ids field of BotManagementActionOverrides can be filled with the following values: IPREP_WEB_AND_DDOS_ATTACKERS_LOW: Network Attack - General Confidence. IPREP_WEB_AND_DDOS_ATTACKERS_MID: Network Attack - Medium Confidence. IPREP_WEB_AND_DDOS_ATTACKERS_HIGH: Network Attack - High Confidence. IPREP_PROXIES_AND_ANONYMIZERS_LOW: Network Proxy - General Confidence. IPREP_PROXIES_AND_ANONYMIZERS_MID: Network Proxy - Medium Confidence. IPREP_PROXIES_AND_ANONYMIZERS_HIGH: Network Proxy - High Confidence. IPREP_SCANNING_TOOLS_LOW: Scanner - General Confidence. IPREP_SCANNING_TOOLS_MID: Scanner - Medium Confidence. IPREP_SCANNING_TOOLS_HIGH: Scanner - High Confidence. IPREP_ATO_ATTACKERS_LOW: Account Takeover Attack - General Confidence. IPREP_ATO_ATTACKERS_MID: Account Takeover Attack - Medium Confidence. IPREP_ATO_ATTACKERS_HIGH: Account Takeover Attack - High Confidence. IPREP_WEB_SCRAPERS_AND_TRAFFIC_BOTS_LOW: Malicious BOT - General Confidence. IPREP_WEB_SCRAPERS_AND_TRAFFIC_BOTS_MID: Malicious BOT - Medium Confidence. IPREP_WEB_SCRAPERS_AND_TRAFFIC_BOTS_HIGH: Malicious BOT - High Confidence. |
Name | Type | Required | Description |
Switch | String | No | IPv6 access feature configuration. Valid values: on: Enable IPv6 access feature. off: Disable IPv6 access feature. |
Name | Type | Required | Description |
BaseAction | No | Handling method for access requests from known commercial tools or open-source tools. The Name parameter of SecurityAction supports: Deny: Block. Monitor: Monitor. Disabled: Not enabled, disable specified rule. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. Allow: Pass (to be deprecated). | |
BotManagementActionOverrides | Array of BotManagementActionOverrides | No | Specifies the handling method for access requests from known commercial tools or open-source tools. |
Name | Type | Required | Description |
RuleId | String | Yes | Specific items under the managed rule group, used to rewrite the configuration content of this single rule. Refer to product documentation. |
Action | Yes | Specify the handling action for the managed rule item in RuleId. Supported Name values for SecurityAction: Deny: Block and respond with an interception page. Monitor: Observe without processing requests, record security events in logs. Disabled: Not activated, skip scan requests, skip the rule. |
Name | Type | Required | Description |
AutoUpdateToLatestVersion | String | Yes | Whether to enable automatic updates to the latest version. Valid values: on: Enable. off: Disable. |
RulesetVersion | String | No | The version currently in use. Its format complies with the ISO 8601 standard, for example, 2023-12-21T12:00:32Z. It is empty by default and is an output-only parameter. |
Name | Type | Required | Description |
RuleId | String | No | Managed rule Id. |
RiskLevel | String | No | Protection level of the managed rule. Valid values: low: Low risk, this rule poses lower risk and is suitable for access scenarios under strict control. This severity rule may cause considerable false alarms. medium: Medium-risk, means this rule poses normal risk and applies to strict protection scenarios. high: High-risk, means this rule poses relatively high risk and will not generate false alarms in most scenarios. extreme: Ultra-high risk, means this rule poses extremely high risk and rarely generates false alarms. |
Description | String | No | Rule description. |
Tags | Array of String | No | Rule tag. Some types of rules do not have tags. |
RuleVersion | String | No | Rule ownership version. |
Name | Type | Required | Description |
GroupId | String | Yes | The group name of the managed rule. Unspecified configuration rules will be processed based on the default configuration. Refer to product documentation for the specific value of GroupId. |
SensitivityLevel | String | Yes | Protection level of the managed rule group. Valid values: loose: Loose, includes only ultra-high risk rules. In this mode, you must configure Action, and RuleActions configuration is invalid. normal: Normal, includes ultra-high risk and high-risk rules. In this mode, you must configure Action, and RuleActions configuration is invalid. strict: Strict, includes ultra-high risk, high-risk, and medium-risk rules. In this mode, you must configure Action, and RuleActions configuration is invalid. extreme: Ultra-strict, includes ultra-high risk, high-risk, medium-risk, and low-risk rules. In this mode, you must configure Action, and RuleActions configuration is invalid. custom: Custom, a granular policy. Configure handling methods per rule. In this mode, the Action field is invalid. Use RuleActions to configure the granular policy for individual rules. |
Action | Yes | Handling actions for the managed rule group. Supported Name values for SecurityAction: Deny: Block and respond with an interception page. Monitor: Observe without processing requests, record security events in logs. Disabled: Not activated, skip scan requests and the rule. | |
RuleActions | Array of ManagedRuleAction | No | Configuration of rule items under the managed rule group takes effect only when SensitivityLevel is set to custom. |
MetaData | No | Information of the managed rule group, only returned in output. |
Name | Type | Required | Description |
GroupDetail | String | No | Managed rule group description, only returned in output. |
GroupName | String | No | Managed rule group name, only returned in output. |
RuleDetails | Array of ManagedRuleDetail | No | Information of all sub-rules under the current managed rule group, only returned in output. |
Name | Type | Required | Description |
Enabled | String | Yes | Whether to enable managed rules. Valid values: on: turn on, all managed rules take effect as configured. off: turn off, all managed rules are disabled. |
DetectionOnly | String | Yes | Whether to enable evaluation mode. This parameter takes effect only when Enabled is on. Valid values: on: enable, indicating all managed rules take effect in observation mode. off: turn off, indicating all managed rules take effect with actual configuration. |
SemanticAnalysis | String | No | Whether to enable the semantic analysis option for managed rules. This option takes effect only when the Enabled parameter is on. Valid values: on: enable, perform semantic analysis on the request and process it. off: turn off, skip semantic analysis and process the request directly. Default off. |
AutoUpdate | No | Managed rule automatic update option. | |
ManagedRuleGroups | Array of ManagedRuleGroup | No | Configuration of managed rule groups. If this structure passes an empty array or GroupId is not included in the list, it will be handled based on the default method. |
FrequentScanningProtection | No | High-frequency scan protection configuration options. When a visitor's frequent requests hit a managed rule configured for interception, all requests from that visitor will be blocked within a period of time. |
Name | Type | Required | Description |
FollowOrigin | String | No | Switch for following origin server Cache-Control. Valid values: on: follow the origin site, ignore CacheTime time setting; off: do not follow the origin site, use CacheTime time setting. |
CacheTime | Integer | No | Custom cache time value in seconds, range: 0–315360000. Note: When FollowOrigin is off, it means not following the origin server and using CacheTime to set the cache time, otherwise it is ineffective. |
Name | Type | Required | Description |
MaxNewSessionCountInterval | String | No | Time window for threshold-triggered statistics. Valid values: 5s: Within 5 seconds; 10s: Within 10 seconds; 15s: Within 15 seconds; 30s: Within 30 seconds; 60s: Within 60 seconds; 5m: Within 5 minutes; 10m: Within 10 minutes; 30m: Within 30 minutes; 60m: Within 60 minutes. |
MaxNewSessionCountThreshold | Integer | No | Cumulative quantity for threshold-triggered statistics. Valid range: 1 to -100000000. |
Name | Type | Required | Description |
MinimalAvgTransferRateThreshold | String | Yes | Minimum Body Transfer Rate threshold. Only bps is supported as the unit. |
CountingPeriod | String | Yes | Statistical time range for the minimum body transfer rate. Valid values: 10s: 10 seconds; 30s: 30 seconds; 60s: 60 seconds; 120s: 120 seconds. |
Enabled | String | Yes | Whether to enable the minimum body transfer rate threshold. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
OriginType | String | No | Origin server type. Valid values: IPDomain: IPV4, IPV6, or domain name type origin server; OriginGroup: Origin server group type origin server; LoadBalance: CLB. This feature is in beta testing. To use it, submit a ticket. Tencent Cloud COS: Cloud Object Storage origin server; AWSS3: Supports ALL object storage origin servers with AWS S3 protocol. |
Origin | String | No | Origin server address is divided into following scenarios based on OriginType value. When OriginType = IPDomain, specify this parameter as an IPV4 address, IPV6 address, or domain name; When OriginType = COS, specify this parameter as the cos bucket access domain; When OriginType = AWSS3, specify this parameter as the S3 bucket access domain; When OriginType = OriginGroup, specify this parameter as the origin server group ID. When this parameter is used as an output parameter, if an origin server group from another site is referenced, use the format {origin server group ID}@{ZoneID}. For example: og-testorigin@zone-38moq1z10wwwy. When OriginType = LoadBalance, specify this parameter as the CLB instance ID. This feature is currently available only to allowlisted users. When this parameter is used as an output parameter, if a CLB instance from another site is referenced, use the format {CLB ID}@{ZoneID}. For example: lb-2rxpamcyqfzg@zone-38moq1z10wwwy. |
OriginProtocol | String | No | Protocol configuration for origin request. This parameter is required when OriginType value is IPDomain, OriginGroup, or LoadBalance. Valid values: http: use HTTP protocol; https: use HTTPS protocol; follow: follow protocol. |
HTTPOriginPort | Integer | No | HTTP origin port, value ranges from 1 to 65535. This parameter must be filled in when the origin-pull protocol OriginProtocol is http or follow. |
HTTPSOriginPort | Integer | No | HTTPS origin port, value ranges from 1 to 65535. This parameter must be filled in when the origin-pull protocol OriginProtocol is https or follow. |
PrivateAccess | String | No | Whether access to the private Cloud Object Storage origin server is allowed. This parameter is required when the origin server type OriginType = COS or AWSS3. Valid values: on: enable private authentication; off: Do not use private authentication. |
PrivateParameters | No | Private authentication parameter. This parameter is valid only when OriginType = AWSS3 and PrivateAccess = on. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
HeaderActions | Array of HeaderAction | No | HTTP header setting rule list. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
HeaderActions | Array of HeaderAction | No | HTTP origin-pull header rule list. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Switch | String | No | Network error log configuration switch, values are as follows: on: Enable. off: Disable. |
Name | Type | Required | Description |
Switch | String | Yes | Switch for disabling cache. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Switch | String | No | OCSP stapling configuration switch. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Switch | String | No | Offline cache switch, valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
RequestProperties | Yes | Origin authentication request properties. |
Name | Type | Required | Description |
Type | String | Yes | Authentication parameter type for origin authentication. Valid values: QueryString: Indicates that the origin authentication parameter type is set to query string. Header: Indicates that the origin authentication parameter type is set to request header. |
Name | String | Yes | Parameter name for the origin authentication type. |
Value | String | Yes | Parameter value for the origin authentication type. |
Name | Type | Required | Description |
AccessKeyId | String | Yes | Access Key ID. |
SecretAccessKey | String | Yes | Secret Access Key. |
SignatureVersion | String | Yes | Authentication version. Valid values: v2: v2 version. v4: v4 version. |
Region | String | No | bucket region |
Name | Type | Required | Description |
Protocol | String | No | Origin-pull protocol configuration. Valid values: http: use HTTP protocol for origin retrieval. https: use HTTPS protocol for origin retrieval. follow: follow protocol. |
Name | Type | Required | Description |
Switch | String | No | Whether to enable POST request upload file limits. Unit: Byte. The platform default limit is 32 * 220 Byte. Valid values: on: Enable limitation. off: Disable limit. |
MaxSize | Integer | No | Maximum limit for file streaming transmission in POST requests. This field is valid only when Switch is on, with a value between 1MB and 800MB in bytes. |
Name | Type | Required | Description |
Switch | String | No | QUIC configuration switch. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Switch | String | No | Switch for fragment-based origin-pull. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Id | String | No | Precise rate limit ID. Different rule configurations can be supported through the rule ID: Add new rule: ID is empty or no specified ID parameter. Modify existing rule: specify the rule ID to be updated/modified. Delete existing rules: Existing rules not included in the Rules list of RateLimitingRules parameters will be deleted. |
Name | String | No | Name of the precise rate limit. |
Condition | String | No | The specific content of precision rate limiting must comply with expression grammar. For detailed specifications, see Product Documentation. |
Mode | String | No | Rate limiting method. Within the statistical time window CountingPeriod, the following rate limiting methods can be configured for requests that meet the CountBy feature: Block: Block the access source. When the count exceeds the threshold MaxRequestThreshold, the system performs the Action on all subsequent requests that meet the criteria for the duration of ActionDuration. Throttle: Only handle excess requests. When the number of requests exceeds the threshold MaxRequestThreshold, the system performs the Action only on requests that exceed the threshold and stops handling them after the window ends. In this case, the ActionDuration parameter is ignored. Default value: Block. |
CountBy | Array of String | No | Matching method of rate threshold request features. This field is required when Enabled is on. When there are multiple conditions, they will be combined for statistical calculation, and the maximum number of conditions is 5. Valid values: http.request.ip: client IP; http.request.xff_header_ip: client ip (priority match xff header); http.request.uri.path: request access path; http.request.cookies['session']: Cookie named 'session', where 'session' can be replaced with a user-specified parameter; http.request.headers['user-agent']: HTTP header named 'user-agent', where 'user-agent' can be replaced with a user-specified parameter; http.request.ja3: JA3 fingerprint of the request; http.request.ja4: JA4 fingerprint of the request; http.request.uri.query['test']: URL query parameter named 'test', where 'test' can be replaced with a user-specified parameter. |
MaxRequestThreshold | Integer | No | Precise rate limiting intercept count within the specified time range. The value ranges from 1 to 100000. |
CountingPeriod | String | No | Statistical time window. Valid values: 1s: 1 second 5s: 5 seconds; 10s: 10 seconds; 20s: 20 seconds; 30s: 30 seconds; 40s: 40 seconds; 50s: 50 seconds; 1m: 1 minute; 2m: 2 minutes; 5m: 5 minutes; 10m: 10 minutes; 1h: 1 hour. |
ActionDuration | String | No | Duration of Action. Supported measurement units: s: seconds, value ranges from 1 to 120. m: minutes, value ranges from 1 to 120. h: hr, value ranges from 1 to 48. d: days, value ranges from 1 to 30. When Mode is Throttle, this parameter is ignored and does not take effect. |
Action | No | Precision rate limiting handling method. Valid values: Monitor: Monitor. Deny: Block. Within DenyActionParameters, the Name parameter supports Deny and ReturnCustomPage. Challenge: Challenge. Within ChallengeActionParameters, the Name parameter supports JSChallenge and ManagedChallenge. Redirect: Redirect to URL. | |
Priority | Integer | No | Priority of precision rate limiting, ranging from 0 to 100. Default is 0. |
Enabled | String | No | Precision rate limiting rule is enabled or not. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Rules | Array of RateLimitingRule | No | Definition list for precise rate limiting. When ModifySecurityPolicy is used to modify Web protection configuration: If the Rules parameter is not specified or has a length of zero: Clear all precision rate limiting configurations. If the RateLimitingRules parameter value is not specified in SecurityPolicy: Keep the existing custom rule configuration and do not modify it. |
Name | Type | Required | Description |
URL | String | Yes | The URL for redirection. |
Name | Type | Required | Description |
IdleTimeout | String | Yes | Body transfer timeout duration takes value from 5 to 120, and the measurement unit is only supported in seconds (s). |
Enabled | String | Yes | Whether body transfer timeout is enabled. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Scope | String | Yes | Skip specific field. Supported values: body.json: JSON request body. In this case, Condition supports key and value, and TargetField supports key and value. For example, { "Scope":"body.json", "Condition":"", "TargetField":"key" } indicates that all parameters in the JSON request body skip WAF scanning. cookie: Cookie; in this case, Condition supports key and value, and TargetField supports key and value. For example, { "Scope": "cookie", "Condition": "${key} in ['account-id'] and ${value} like ['prefix-']", "TargetField": "value" } indicates that the Cookie parameter name equals account-id and the parameter value matches prefix- by wildcard, skipping WAF scan; header: HTTP header parameter; in this case, Condition supports key and value, and TargetField supports key and value. For example, { "Scope": "header", "Condition": "${key} like ['x-auth-']", "TargetField": "value" } indicates that the header parameter name matches x-auth- by wildcard, skipping WAF scan; uri.query: URL encoded content/query parameter; in this case, Condition supports key and value, and TargetField supports key and value. For example, { "Scope": "uri.query", "Condition": "${key} in ['action'] and ${value} in ['upload', 'delete']", "TargetField": "value" } indicates that the parameter name of the URL encoded content/query parameter equals action and the parameter value equals upload or delete, skipping WAF scan; uri: request path URI; in this case, Condition must be empty, and TargetField supports query, path, and fullpath. For example, { "Scope": "uri", "Condition": "", "TargetField": "query" } indicates that only the query parameter of the request path URI skips WAF scan; body: request body content. In this case, Condition must be empty, and TargetField supports fullbody and multipart. For example, { "Scope": "body", "Condition": "", "TargetField": "fullbody" } indicates that the request body content as the full request body skips WAF scan. |
Condition | String | Yes | Expression of the specific field to skip, which must comply with the expression syntax. Condition supports the expression configuration syntax: Written according to the rule's matching condition expression syntax, supporting references to key and value. Supports the in and like operators, as well as the and logical combination. For example: ${key} in ['x-trace-id']: parameter name equals x-trace-id; ${key} in ['x-trace-id'] and ${value} like ['Bearer *']: parameter name equals x-trace-id and parameter value wildcard matches Bearer *. |
TargetField | String | Yes | When the Scope parameter takes different values, the supported values in the TargetField expression are as follows: body.json: supports key, value cookie: supports key, value header: supports key, value uri.query: supports key, value uri: supports path, query, fullpath body: supports fullbody, multipart |
Name | Type | Required | Description |
Mode | String | Yes | Download speed limit mode. Valid values: LimitUponDownload: download speed limit for the entire process LimitAfterSpecificBytesDownloaded: starts rate limiting after downloading specific bytes at full speed LimitAfterSpecificSecondsDownloaded: starts rate limiting after downloading for a specified time at full speed. |
MaxSpeed | String | Yes | Speed limit, specify the speed limit size, fill in the value or variable with unit. Currently supported units: KB/s. |
StartAt | String | No | Speed limit start value can be download size or specified duration. Fill in the value or variable with unit, assign download size or specify duration. When the Mode is set to LimitAfterSpecificBytesDownloaded, the unit is: KB. When the Mode is set to LimitAfterSpecificSecondsDownloaded, the unit is: s. |
Name | Type | Required | Description |
ResponseCode | String | Yes | Response status code. |
ErrorPageId | String | Yes | Custom error page ID for the response. |
Name | Type | Required | Description |
Condition | String | No | |
Actions | Array of RuleEngineAction | No | Operation. Note: Actions and SubRules cannot be empty at the same time. Note: This field may return null, indicating that no valid value can be obtained. |
SubRules | Array of RuleEngineSubRule | No | Sub-rule list. Multiple rules can exist in this list and are executed sequentially from top to bottom. Note: SubRules and Actions cannot be empty at the same time. Currently, only one level of SubRules is supported. Note: This field may return null, indicating that no valid value can be obtained. |
Name | Type | Required | Description |
Name | String | Yes | Operation name. The name must correspond to the parameter structure, for example, if Name=Cache, then CacheParameters is required. Cache: node cache TTL; CacheKey: custom Cache Key; CachePrefresh: cache pre-refresh AccessURLRedirect: URL redirection; UpstreamURLRewrite: origin-pull URL rewrite; QUIC:QUIC; WebSocket:WebSocket; Authentication: Token authentication; MaxAge: browser cache TTL; StatusCodeCache: status code cache TTL; OfflineCache: Offline cache; SmartRouting: Smart acceleration; AdvancedOriginRouting: advanced origin optimization; RangeOriginPull: range-based origin pull; UpstreamHTTP2: HTTP2 origin pull; HostHeader: host header rewrite; ForceRedirectHTTPS: access protocol forced HTTPS redirect configuration; OriginPullProtocol: HTTPS origin pull; Compression: intelligent compression configuration; HSTS:HSTS; ClientIPHeader: Storage of client request IP header information configuration; OCSPStapling: OCSP stapling; HTTP2: HTTP2 integration; PostMaxSize: Maximum limit configuration for POST request upload file streaming transmission; ClientIPCountry: Carry client IP region information during origin pull; UpstreamFollowRedirect: Parameter configuration for upstream follow redirect; UpstreamRequest: Origin-pull request parameter; Shield: Origin server offload configuration; TLSConfig: SSL/TLS security ModifyOrigin: Modify origin server; SiteFailover: origin server failover; HTTPUpstreamTimeout: Layer 7 origin pull timeout configuration; HttpResponse: HTTP response; ErrorPage: Custom error page; ModifyResponseHeader: Modify HTTP node response header; ModifyRequestHeader: Modify HTTP node request header; ResponseSpeedLimit: Download speed limit for a single connection; SetContentIdentifier: Set content identifier; Vary: Vary feature configuration; ContentCompression: Content compression configuration; OriginAuthentication: Origin authentication configuration; CustomAction: Custom configuration. |
CacheParameters | No | Node cache TTL config. When Name value is Cache, this parameter is required. Note: This field may return null, indicating no valid value. | |
CacheKeyParameters | No | Custom Cache Key config. When Name value is CacheKey, this parameter is required. Note: This field may return null, indicating no valid value. | |
CachePrefreshParameters | No | Cache pre-refresh config. When Name value is CachePrefresh, this parameter is required. Note: This field may return null, indicating no valid value. | |
AccessURLRedirectParameters | No | Access URL redirection configuration parameter. When Name value is AccessURLRedirect, this parameter is required. Note: This field may return null, indicating no valid value. | |
UpstreamURLRewriteParameters | No | Origin-pull URL rewrite configuration parameter. When Name value is UpstreamURLRewrite, this parameter is required. Note: This field may return null, indicating no valid value. | |
QUICParameters | No | QUIC configuration parameter. When Name value is QUIC, this parameter is required. Note: This field may return null, indicating no valid value. | |
WebSocketParameters | No | WebSocket configuration parameter. When Name value is WebSocket, this parameter is required. Note: This field may return null, indicating no valid value. | |
AuthenticationParameters | No | Token authentication configuration parameter. When Name value is Authentication, this parameter is required. Note: This field may return null, indicating no valid value. | |
MaxAgeParameters | No | Browser cache TTL config. When Name value is MaxAge, this parameter is required. Note: This field may return null, indicating no valid value. | |
StatusCodeCacheParameters | No | Status code cache TTL config. When Name value is StatusCodeCache, this parameter is required. Note: This field may return null, indicating no valid value. | |
OfflineCacheParameters | No | Offline cache config. When Name value is OfflineCache, this parameter is required. Note: This field may return null, indicating no valid value. | |
SmartRoutingParameters | No | Smart acceleration config. When Name value is SmartRouting, this parameter is required. Note: This field may return null, indicating no valid value. | |
AdvancedOriginRoutingParameters | No | Advanced origin-pull optimization config. When Name value is AdvancedOriginRouting, this parameter is required. Note: This field may return null, indicating no valid value. | |
RangeOriginPullParameters | No | Fragment-based origin pull configuration parameters. When Name value is RangeOriginPull, this parameter is required. Note: This field may return null, indicating no valid value. | |
UpstreamHTTP2Parameters | No | HTTP2 origin-pull configuration parameter. When Name value is UpstreamHTTP2, this parameter is required. Note: This field may return null, indicating no valid value. | |
HostHeaderParameters | No | Host Header rewrite config. When Name value is HostHeader, this parameter is required. Note: This field may return null, indicating no valid value. | |
ForceRedirectHTTPSParameters | No | Access protocol forced HTTPS redirect configuration. When Name value is ForceRedirectHTTPS, this parameter is required. Note: This field may return null, indicating no valid value. | |
OriginPullProtocolParameters | No | HTTPS back-to-origin configuration parameters. When Name value is OriginPullProtocol, this parameter is required. Note: This field may return null, indicating no valid value. | |
CompressionParameters | No | Intelligent compression configuration. When Name value is Compression, this parameter is required. Note: This field may return null, indicating no valid value. | |
HSTSParameters | No | HSTS configuration parameters. When Name value is HSTS, this parameter is required. Note: This field may return null, indicating no valid value. | |
ClientIPHeaderParameters | No | Storage of client request IP header information configuration. When Name value is ClientIPHeader, this parameter is required. Note: This field may return null, indicating no valid value. | |
OCSPStaplingParameters | No | OCSP stapling configuration parameters. When Name value is OCSPStapling, this parameter is required. Note: This field may return null, indicating no valid value. | |
HTTP2Parameters | No | HTTP2 access configuration parameter. When Name value is HTTP2, this parameter is required. Note: This field may return null, indicating no valid value. | |
PostMaxSizeParameters | No | POST request upload file streaming transmission maximum limit configuration. When Name value is PostMaxSize, this parameter is required. Note: This field may return null, indicating no valid value. | |
ClientIPCountryParameters | No | Back-to-origin configuration parameter carrying client IP address regional information. When Name value is ClientIPCountry, this parameter is required. Note: This field may return null, indicating no valid value. | |
UpstreamFollowRedirectParameters | No | Upstream Follow Redirect parameter configuration. When Name value is UpstreamFollowRedirect, this parameter is required. Note: This field may return null, indicating no valid value. | |
UpstreamRequestParameters | No | Upstream Request parameter configuration. When Name value is UpstreamRequest, this parameter is required. Note: This field may return null, indicating no valid value. | |
ShieldParameters | No | Origin site offload configuration parameter. When Name value is Shield, this parameter is required. Note: This field may return null, indicating no valid value. | |
TLSConfigParameters | No | SSL/TLS security configuration parameters. When Name value is TLSConfig, this parameter is required. Note: This field may return null, indicating no valid value. | |
ModifyOriginParameters | No | Modify origin server configuration parameters. When Name value is ModifyOrigin, this parameter is required. Note: This field may return null, indicating no valid value. | |
SiteFailoverParameters | No | Origin site failover configuration parameter. When Name value is SiteFailover, this parameter is required. Note: This field may return null, indicating no valid value. | |
HTTPUpstreamTimeoutParameters | No | Layer-7 origin-pull timeout. When Name value is HTTPUpstreamTimeout, this parameter is required. Note: This field may return null, indicating no valid value. | |
ErrorPageParameters | No | Custom error page configuration parameter. When Name value is ErrorPage, this parameter is required. Note: This field may return null, indicating no valid value. | |
ModifyResponseHeaderParameters | No | Modify HTTP node response header configuration. When Name value is ModifyResponseHeader, this parameter is required. Note: This field may return null, indicating no valid value. | |
ModifyRequestHeaderParameters | No | Modify HTTP node request header configuration. When Name value is ModifyRequestHeader, this parameter is required. Note: This field may return null, indicating no valid value. | |
ResponseSpeedLimitParameters | No | Download speed limit configuration parameter for single connection. When Name value is ResponseSpeedLimit, this parameter is required. Note: This field may return null, indicating no valid value. | |
SetContentIdentifierParameters | No | Content identification configuration parameter. When Name value is SetContentIdentifier, this parameter is required. Note: This field may return null, indicating no valid value. | |
VaryParameters | No | Vary feature configuration parameter. When Name value is Vary, this parameter is required. | |
ContentCompressionParameters | No | Content compression configuration parameter. When Name value is ContentCompression, this parameter is required. This parameter is an allowlist feature. If needed, contact Tencent Cloud Engineers. | |
OriginAuthenticationParameters | No | Origin authentication configuration parameter. When Name value is OriginAuthentication, this parameter is required. This parameter is an allowlist feature. If needed, contact Tencent Cloud Engineers. | |
CustomActionParameters | No | Custom action configuration parameter. When Name value is CustomAction, this parameter is required. You can obtain the list of currently supported custom configuration items from the CustomActionSet value returned by the DescribeAvailableCustomActionsForRuleEngine API. | |
HttpResponseParameters | No | HTTP response configuration parameter. When Name value is HttpResponse, this parameter is required. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Branches | Array of RuleBranch | No | Sub-rule branch Note: This field may return null, indicating no valid value. |
Description | Array of String | No | Rule annotation. |
Name | Type | Required | Description |
BaseAction | No | Execution action for requests from search engine crawlers. Supported Name values for SecurityAction: Deny: Block. Monitor: Monitor. Disabled: Not enabled, disable specified rule. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. Allow: Pass (to be deprecated). | |
BotManagementActionOverrides | Array of BotManagementActionOverrides | No | Specifies the handling method for requests from search engine crawlers. |
Name | Type | Required | Description |
Name | String | Yes | Safe execution actions. Valid values: Deny: Block and block request access to site resources. Monitor: Monitor, only record logs. Redirect: Redirect to URL. Disabled: Not enabled, disable specified rule. Allow: Allow access, but delay processing requests. Challenge: Challenge, respond to challenge content. Trans: Allow. Permit requests to access site resources directly. BlockIP: To be deprecated, IP block. ReturnCustomPage: To be deprecated, use the specified page to block. JSChallenge: To be deprecated, JavaScript challenge. ManagedChallenge: To be deprecated, managed challenge. |
DenyActionParameters | No | Additional parameters when Name is Deny. | |
RedirectActionParameters | No | Additional parameters when Name is Redirect. | |
AllowActionParameters | No | Additional parameters when Name is Allow. | |
ChallengeActionParameters | No | Additional parameters when Name is Challenge. | |
BlockIPActionParameters | No | To be deprecated, additional parameters when Name is BlockIP. | |
ReturnCustomPageActionParameters | No | To be deprecated, additional parameters when Name is ReturnCustomPage. |
Name | Type | Required | Description |
CustomRules | No | Custom rule configuration. | |
ManagedRules | No | Managed rule configuration. | |
HttpDDoSProtection | No | HTTP Anti-DDoS configuration. | |
RateLimitingRules | No | Rate limiting rule configuration. | |
ExceptionRules | No | Exception rule configuration. | |
BotManagement | No | Bot management configuration. | |
BotManagementLite | No | Basic Bot management configuration. | |
DefaultDenySecurityActionParameters | No | Default blocking action configuration. |
Name | Type | Required | Description |
SecurityAction | No | Action for Bot custom rules. Valid values: Allow: Allow access. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters are supported. Deny: Block. Within DenyActionParameters, the BlockIp, ReturnCustomPage, and Stall configurations are supported. Monitor: Monitor. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. Redirect: Redirect to URL. | |
Weight | Integer | No | The weight of the current SecurityAction. It supports only values from 10 to 100, which must be multiples of 10. The sum of all Weight parameters must equal 100. |
Name | Type | Required | Description |
Enabled | String | No | Whether the session rate and periodic characteristic verification configuration is enabled. Valid values are: on: Enable off: Disable |
HighRateSessionAction | No | The execution action for high-risk session rate and periodic characteristic verification. SecurityAction Name parameter supports: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. | |
MidRateSessionAction | No | The execution action for medium-risk session rate and periodic characteristic verification. SecurityAction Name parameter supports: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. | |
LowRateSessionAction | No | The execution action for low-risk session rate and periodic characteristic verification. SecurityAction Name parameter supports: Deny: Block. Within DenyActionParameters, the Stall configuration is supported. Monitor: Monitor. Allow: Respond after a delay. Within AllowActionParameters, the MinDelayTime and MaxDelayTime parameters must be configured. |
Name | Type | Required | Description |
ContentIdentifier | String | No | Content identifier id. |
Name | Type | Required | Description |
ShieldSpaceId | String | Yes | Origin site offload space ID. |
Name | Type | Required | Description |
Mode | String | Yes | Origin failover type. Values as follows: FailoverToHost: fall back to the specified IP address/domain; FailoverToCOS: fall back to Tencent Cloud COS; FailoverToS3CompatibleObjectStorage: fall back to S3-compatible object storage; FailoverRedirectToURL: Redirect to the specified URL. FailoverCustomResponsePage: Uses a custom response page. |
Origin | String | No | Origin server address is divided into following scenarios based on Mode value: When Mode = FailoverToHost, specify this parameter as an IPV4 address, IPV6 address, or domain name. When Mode = FailoverToCOS, specify this parameter as the access domain of the COS bucket. When Mode = FailoverToS3CompatibleObjectStorage, specify this parameter as the access domain for the S3 bucket. |
OriginProtocol | String | No | Origin protocol configuration. This parameter is required when Mode value is FailoverToHost. Valid values: http: use HTTP protocol; https: use HTTPS protocol; follow: follow protocol. |
HTTPOriginPort | Integer | No | HTTP origin port, value ranges from 1 to 65535. This parameter must be filled in when the origin-pull protocol OriginProtocol is http or follow. |
HTTPSOriginPort | Integer | No | HTTPS origin port, value ranges from 1 to 65535. This parameter must be filled in when the origin-pull protocol OriginProtocol is https or follow. |
UpstreamHostHeader | No | Origin-pull Host Header rewrite configuration | |
UpstreamURLRewrite | No | Origin-pull URL rewrite configuration. | |
UpstreamRequestParameters | No | Origin-pull request parameters configuration. | |
UpstreamHTTP2Parameters | No | HTTP2 origin-pull configuration parameters. | |
PrivateAccess | String | No | Specifies whether access to the private Cloud Object Storage origin server is allowed. This parameter is required when the origin server type Mode = FailoverToCOS or FailoverToS3CompatibleObjectStorage. Valid values: on: enable private authentication; off: Do not use private authentication. |
PrivateParameters | No | Private authentication parameter. This parameter takes effect only when Mode = FailoverToS3CompatibleObjectStorage and PrivateAccess = on. | |
RedirectURL | String | No | Redirect target URL. This parameter is required when Mode value is FailoverRedirectToURL. |
ResponsePageId | String | No | Response page ID. This parameter is required when Mode value is FailoverCustomResponsePage. |
StatusCode | Integer | No | Response status code. This parameter is required when Mode value is FailoverRedirectToURL or FailoverCustomResponsePage. Valid values: When Mode = FailoverRedirectToURL, this parameter must be set to one of the following values: 301, 302, 303, 307, or 308. When Mode = FailoverCustomResponsePage, this parameter must be set to one of the following values: 400, 403, 404, 405, 414, 416, 451, 500, 501, 502, 503, or 504. |
Name | Type | Required | Description |
SiteFailoverStatusCodes | Array of Integer | Yes | Status codes for origin site failover conditions. Origin site failover is triggered only when the response status code returned by the origin site matches a value in this field, and is executed according to SiteFailoverParams. The value of this parameter is either 4xx or 5xx. |
SiteFailoverParams | Array of SiteFailover | Yes | List of origin failover configuration parameters. The minimum length is 1, and the maximum length is 2. |
Name | Type | Required | Description |
Enabled | String | Yes | Slow attack protection is enabled. Valid values: on: Enable. off: Disable. |
Id | String | No | The rule ID of slow attack protection, only returned in output. |
Action | No | The handling method of slow attack protection. This field is required when Enabled is on. SecurityAction Name supports: Monitor: Monitor. Deny: Block. | |
MinimalRequestBodyTransferRate | No | Minimum Body Transfer Rate threshold configuration. This field is required when Enabled is on. | |
RequestBodyTransferTimeout | No | Body transfer timeout duration configuration. This field is required when Enabled is on. |
Name | Type | Required | Description |
Switch | String | No | Smart acceleration configuration switch. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
BaseAction | No | Handling method for access requests from a specified IDC. The Name parameter of SecurityAction supports: Deny: Block. Monitor: Monitor. Disabled: Not enabled, disable specified rule. Challenge: Challenge. Within ChallengeActionParameters, the ChallengeOption parameter supports JSChallenge and ManagedChallenge. Allow: Pass (to be deprecated). | |
BotManagementActionOverrides | Array of BotManagementActionOverrides | No | Specifies the handling method for requests from a specified IDC. |
Name | Type | Required | Description |
Switch | String | No | Debug feature switch, valid values: on: Enable. off: Disable. |
AllowClientIPList | Array of String | No | Allowed client source. Supports filling in IPv4 and IPv6 IP ranges. 0.0.0.0/0 indicates that all IPv4 clients are allowed for debugging; ::/0 indicates that all IPv6 clients are allowed for debugging. 127.0.0.1 cannot be filled in. Note: When the Switch field is on, this field is required and the number of writes must be 1–100. When Switch is off, this field is not required. If filled, it does not take effect. |
Expires | Timestamp ISO8601 | No | Debug feature expiry time. If the set time is exceeded, the feature will be disabled. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
StatusCode | Integer | No | Status code, value is one of 400, 401, 403, 404, 405, 407, 414, 500, 501, 502, 503, 504, 509, 514. |
CacheTime | Integer | No | Cache time value in seconds, range: 0–31536000. |
Name | Type | Required | Description |
StatusCodeCacheParams | Array of StatusCodeCacheParam | No | Status code cache TTL. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Version | Array of String | No | TLS version. At least one must be filled in. If multiple, they need to be consecutive version numbers, for example: enable TLS 1, 1.1, 1.2, and 1.3. You cannot only enable 1 and 1.2 while disabling 1.1. Valid values: TLSv1: TLSv1 version. TLSv1.1: TLSv1.1 version. TLSv1.2: TLSv1.2 version. TLSv1.3: TLSv1.3 version. |
CipherSuite | String | No | Valid values: loose-v2023: loose-v2023 cipher suite. general-v2023: general-v2023 cipher suite. strict-v2023: strict-v2023 cipher suite. |
Name | Type | Required | Description |
Switch | String | No | Switch that determines whether to follow redirects to the origin server. Valid values: on: Enable. off: Disable. |
MaxTimes | Integer | No | Maximum number of redirects. Value is 1-5. Note: When Switch is on, this field is required. When Switch is off, this field is not required. If filled, it does not take effect. |
Name | Type | Required | Description |
Switch | String | No | HTTP2 origin-pull configuration switch. Valid values: on: Enable. off: Disable. |
Name | Type | Required | Description |
Switch | String | No | Cookie configuration switch for origin-pull request parameters. Valid values: on: Enable. off: Disable. |
Action | String | No | Origin-pull request parameter Cookie mode. When Switch is on, this parameter is required. Valid values: full: Retain all. ignore: Ignore all. includeCustom: Retain some parameters. excludeCustom: Ignore some parameters. |
Values | Array of String | No | Specify parameter values. This parameter takes effect only when the query string mode Action is includeCustom or excludeCustom, used to specify parameters to keep or ignore. Supports a maximum of 10 parameters. |
Name | Type | Required | Description |
QueryString | No | Query string configuration. Optional configuration. Leave blank for no configuration. Note: This field may return null, indicating no valid value. | |
Cookie | No | Cookie configuration. Optional configuration. Leave blank for no configuration. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
Switch | String | No | Query string configuration switch for origin-pull request parameters. Valid values: on: Enable. off: Disable. |
Action | String | No | Query string mode. When Switch is on, this parameter is required. Valid values: full: Retain all. ignore: Ignore all. includeCustom: Retain some parameters. excludeCustom: Ignore some parameters. |
Values | Array of String | No | Specify parameter values. This parameter takes effect only when the query string mode Action is includeCustom or excludeCustom, used to specify parameters to keep or ignore. Supports a maximum of 10 parameters. |
Name | Type | Required | Description |
Type | String | No | Origin-pull URL rewrite type. Only supports filling in Path. |
Action | String | No | Origin-pull URL rewrite action. Valid values: replace: Replaces the complete path. It is used to replace the full request URL path with the specified path. addPrefix: Adds a path prefix. It is used to add the specified path prefix to the request URL path. rmvPrefix: Removes a path prefix. It is used to remove the specified path prefix from the request URL path. regexReplace: Replaces the complete path using a regular expression. It is used to match and replace the complete path with a Google RE2 regular expression. |
Value | String | No | Origin-pull URL rewrite value. Should meet URL Path standard and ensure the rewritten Path starts with / to prevent modification of the origin-pull URL Host, length range 1–1024. When Action is addPrefix, it cannot end with /; when Action is rmvPrefix, * cannot exist; when Action is regexReplace, $NUM can be used to refer to a regular expression capture group, where NUM represents the group number, such as $1, supporting up to $9. |
Regex | String | No | Origin-pull URL rewrite is used for regex replacement to match the full path regular expression. Should meet Google RE2 specification, length range 1–1024. When Action is regexReplace, this field is required, otherwise not required. |
Name | Type | Required | Description |
Action | String | No | Execution action. The values are as follows: follow: Follow request. custom: Custom. Customize. regex: Regular expression matching. |
Regex | String | No | Regular expression matching, length range 1–1024. Note: This field is required when Action is regex. When Action is follow or custom, no need to specify this field. If filled, it does not take effect. |
Value | String | No | The target URL for redirection, length range 1–1024. Note: This field is required when Action is regex or custom. When Action is follow, no need to specify this field. If filled, it does not take effect. |
Name | Type | Required | Description |
Switch | String | Yes | Switch for the Vary feature configuration. Valid values: on: Enable. off: Disable. |
Configuration Field | Type | Required | Description |
ZoneDefaultPolicy | No | Configuration details of the site-level policy. | |
HostPolicy | No | Configuration details of the domain-level policy. | |
Templates | No | Configuration details of policy templates. |
Name | Type | Required | Description |
TemplateId | String | No | Policy template ID |
TemplateName | String | No | Policy template name. It consists of Chinese characters, letters, digits, and underscores. It cannot start with an underscore and cannot exceed 32 characters in length. |
Policy | No | Policy configuration of the policy template. The configuration takes effect for all domains associated with the policy template. |
Name | Type | Required | Description |
Switch | String | No | Switch for WebSocket timeout configuration. Valid values: on: Use Timeout as the WebSocket timeout period. off: The platform still supports WebSocket connections, using the system default 15-second timeout period. |
Timeout | Integer | No | Timeout period in seconds, maximum timeout time 120 seconds. Note: When Switch is on, this field is required, otherwise it is ineffective. |
Name | Type | Required | Description |
SmartRouting | No | Intelligent acceleration configuration. Note: This field may return null, indicating no valid value. | |
Cache | No | Cache expiration time configuration. Note: This field may return null, indicating no valid value. | |
MaxAge | No | Browser cache configuration. Note: This field may return null, indicating no valid value. | |
CacheKey | No | Node cache key configuration. Note: This field may return null, indicating no valid value. | |
CachePrefresh | No | Cache pre-refresh configuration. Note: This field may return null, indicating no valid value. | |
OfflineCache | No | Offline cache configuration. Note: This field may return null, indicating no valid value. | |
Compression | No | Intelligent compression configuration. Note: This field may return null, indicating no valid value. | |
ForceRedirectHTTPS | No | Access protocol forced HTTPS redirect configuration. Note: This field may return null, indicating no valid value. | |
HSTS | No | HSTS configuration. Note: This field may return null, indicating no valid value. | |
TLSConfig | No | TLS configuration. Note: This field may return null, indicating no valid value. | |
OCSPStapling | No | OCSP stapling configuration. Note: This field may return null, indicating no valid value. | |
HTTP2 | No | HTTP2 configuration. Note: This field may return null, indicating no valid value. | |
QUIC | No | QUIC access configuration. Note: This field may return null, indicating no valid value. | |
UpstreamHTTP2 | No | HTTP2 origin-pull configuration. Note: This field may return null, indicating no valid value. | |
IPv6 | No | IPv6 access configuration. Note: This field may return null, indicating no valid value. | |
WebSocket | No | WebSocket configuration. Note: This field may return null, indicating no valid value. | |
PostMaxSize | No | POST request transmission configuration. Note: This field may return null, indicating no valid value. | |
ClientIPHeader | No | Client IP HTTP Request Headers configuration. Note: This field may return null, indicating no valid value. | |
ClientIPCountry | No | Configuration for whether to carry client IP address regional information during back-to-origin. Note: This field may return null, indicating no valid value. | |
Grpc | No | The gRPC protocol supports configuration. Note: This field may return null, indicating no valid value. | |
NetworkErrorLogging | No | Network error logging configuration. Note: This field may return null, indicating no valid value. | |
AccelerateMainland | No | Accelerate and optimize configurations in the Chinese mainland. Note: This field may return null, indicating no valid value. | |
StandardDebug | No | Standard Debug configuration. Note: This field may return null, indicating no valid value. |
Name | Type | Required | Description |
FormatVersion | String | Yes | Syntax version, defaults to 1.0. Input other value error will be reported. |
ZoneConfig | No | Site-level configuration includes all configuration items in Site Acceleration, and all are required unless the configuration is invalid. | |
Rules | Array of ConfigGroupRuleEngineItem | No | Rule-level configuration includes all rules in the rule engine, and the array can be empty, indicating no rules are enabled. |
WebSecurity | No | Web security protection configuration, corresponding to the features supported in Security Protection - Web Protection in the console. | |
FunctionTriggers | Array of ConfigGroupFunctionTrigger | No | Edge function trigger rule configuration, includes all rules for triggering edge functions, and the array can be empty, indicating that no rules are enabled. |
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback