All Products
Search
Document Center

Edge Security Acceleration:ListInstanceQuotas

Last Updated:Jun 25, 2026

Queries the quota details of the plan associated with a specific instance or site by quota name.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

esa:ListInstanceQuotas

list

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

InstanceId

string

No

The plan instance ID. You can call the ListSites operation to obtain the ID. You must specify at least one of this parameter and SiteId.

sp-xcdn-96wblslz****

SiteId

integer

No

The site ID. You can call the ListSites operation to obtain the ID. You must specify at least one of this parameter and InstanceId.

2882900****

QuotaNames

string

Yes

The plan quota names, separated by commas (,). Valid values:

  • waf:phase:http_anti_scan:actions: WAF scan protection - action enumeration.

  • waf:phase:http_bot:actions: WAF bot management - all action enumeration.

  • waf:phase:http_bot:http_custom_cc_dev:characteristic:fields: WAF bot management - custom device rate limiting statistical object enumeration.

  • waf:phase:http_bot:http_custom_cc_ip:characteristic:fields: WAF bot management - custom IP rate limiting statistical object enumeration.

  • waf:phase:http_bot:match:symbols: WAF bot management - match operator enumeration.

  • waf:phase:http_bot:http_custom_cc:characteristic:fields: WAF bot management - custom session rate limiting statistical object enumeration.

  • waf:phase:http_bot:match:fields: WAF bot management - match field enumeration.

  • waf:phase:http_whitelist:match:symbols: WAF whitelist - match operator enumeration.

  • waf:phase:http_whitelist:match:fields: WAF whitelist - match field enumeration.

  • waf:phase:http_anti_scan:http_directory_traversal:characteristic:fields: WAF scan protection - folder traverse blocking statistical object enumeration.

  • waf:phase:http_anti_scan:http_high_frequency:characteristic:fields: WAF scan protection - high-frequency scan blocking statistical object enumeration.

  • waf:phase:http_anti_scan:match:symbols: WAF scan protection - match operator enumeration.

  • waf:phase:http_anti_scan:match:fields: WAF scan protection - match field enumeration.

  • waf:phase:http_managed:actions: WAF managed rules - action enumeration.

  • waf:phase:http_managed:group:reference:ids: WAF managed rules - referenced rule group enumeration.

  • waf:phase:http_ratelimit:actions: WAF rate limiting - action enumeration.

  • waf:phase:http_ratelimit:ttls: WAF rate limiting - duration enumeration.

  • waf:phase:http_ratelimit:intervals: WAF rate limiting - statistical period.

  • waf:phase:http_ratelimit:http_ratelimit:characteristic:fields: WAF rate limiting - control type rule match characteristic enumeration.

  • waf:phase:http_ratelimit:match:symbols: WAF rate limiting rule phase match operator enumeration.

  • waf:phase:http_ratelimit:match:fields: WAF rate limiting rule phase match field enumeration.

  • waf:phase:http_custom:actions: WAF custom rule phase action enumeration.

  • waf:phase:http_custom:match:symbols: WAF custom rule phase match operator enumeration.

  • waf:phase:http_custom:match:fields: WAF custom rule phase match field.

  • waiting_room|queuing_method: waiting room - queuing method.

  • origin_rules|origin_scheme: back-to-origin rules - back-to-origin protocol.

  • origin_rules|origin_sni: back-to-origin rules - back-to-origin SNI.

  • origin_rules|origin_host: back-to-origin rules - back-to-origin host.

  • fourlayeracceleration: Layer 4 acceleration.

  • rtlog_service: real-time log feature switch.

  • dashboard_traffic: value-added network traffic analysis capability.

  • custom_name_server: custom NS name.

  • waf:phase:http_bot:enable: WAF bot management switch.

  • waf:phase:http_whitelist:enable: WAF whitelist switch.

  • instantlog: instant log active or not.

  • waf:phase:http_anti_scan:enable: WAF scan protection switch.

  • waf:phase:http_managed:group:reference:enable: WAF managed rules - referenced rule group configuration switch.

  • waf:phase:http_managed:enable: WAF managed rules switch.

  • waf:phase:http_ratelimit:on_hit:enable: WAF rate limiting - apply to cache-hit requests switch.

  • ddos: DDoS instance.

  • waf:phase:http_ratelimit:enable: WAF rate limiting rule phase switch.

  • waf:phase:http_custom:enable: WAF custom rule phase switch.

  • waf:phase:all:page:reference:enable: WAF custom response page switch.

  • rules_support_regex: whether the rule DPI engine supports regular expressions.

  • waiting_room_event: waiting room - scheduled event.

  • waiting_room_rule: waiting room - bypass waiting room.

  • waiting_room|json_response: waiting room - enable JSON response.

  • waiting_room|disable_session_renewal: waiting room - disable session renewal.

  • origin_rules|dns_record: back-to-origin rules - DNS record.

  • managed_transforms|add_client_geolocation_headers: whether the real client IP header is active in transform rules.

  • tiered_cache|regional_enable: area cache.

  • real_client_ip_header: client IP header.

  • data_timerange: data query time range in minutes.

  • cache_rules|edge_cache_ttl: cache - node TTL.

  • cache_rules|browser_cache_ttl: cache - browser TTL.

  • fourLayerRecordCount: record count limit for Layer 4 acceleration.

  • waitingroomRuleCount: maximum number of rules per waiting room ID.

  • waitingroomEventCount: maximum number of events per waiting room ID.

  • waitingroom_custom_pathhost: waiting room - hostname and path.

  • er_routers: function routing.

  • cache_rules|rule_quota: cache rules.

  • configuration_rules|rule_quota: configuration rules.

  • redirect_rules|rule_quota: redirect rules.

  • compression_rules|rule_quota: compression rules.

  • origin_rules|rule_quota: back-to-origin rules.

  • waf:phase:http_bot:rulesets_per_instance:less_than_or_equal: WAF bot management - maximum number of rule groups per instance.

  • waf:phase:http_whitelist:rules_per_instance:less_than_or_equal: WAF whitelist - maximum number of rules per instance.

  • rtlog_quota: quota for real-time log push node count.

  • waf:phase:http_anti_scan:rulesets_per_instance:less_than_or_equal: WAF scan protection - maximum number of rule groups per instance.

  • ddos_instance: number of DDoS instances.

  • waf:phase:http_ratelimit:rules_per_instance:less_than_or_equal: maximum number of WAF rate limiting rules.

  • waf:phase:http_custom:rules_per_instance:less_than_or_equal: maximum number of WAF custom rules per instance.

  • ruleNestedConditionalCount: number of nesting levels for rules.

  • waiting_room: waiting room.

  • transition_rule: transform rules.

  • customHttpCert: number of custom certificates.

  • free_cert: number of free certificates.

  • preload: resource prefetch.

  • refresh_cache_tag: refresh - cache tag.

  • refresh_ignore_param: refresh - purge without parameters.

  • refresh_directory: refresh - purge by folder.

  • refresh_hostname: refresh - purge by hostname.

  • refresh_all: refresh - purge all cache.

  • refresh_file: URL refresh.

  • wildcard: number of wildcard domain names.

  • recordCount: number of Layer 7 records.

  • siteCount: number of sites.

  • https|rule_quota: number of SSL/TLS rules.

waf:phase:http_anti_scan:actions, waf:phase:http_bot:actions, siteCount

Response elements

Element

Type

Description

Example

object

Schema of Response

RequestId

string

The request ID.

15C66C7B-671A-4297-9187-2C4477247B78

InstanceId

string

The plan instance ID.

sp-xcdn-96wblslz****

Status

string

The plan instance status. Valid values:

  • online: The instance is in normal service.

  • offline: The instance has expired but has not exceeded the grace period and is unavailable.

  • disable: The instance has been released.

online

Quotas

array<object>

The list of plan instance quotas.

object

The plan instance quota details.

QuotaName

string

The quota name.

customHttpCert

QuotaValue

string

The quota value.

10

QuotaValueType

string

The threshold type of the quota. Valid values:

  • value: enumeration type. The enumeration range of quota values.

  • bool: Boolean type. Indicates whether the quota is available.

  • num: numeric type. The maximum usage of the quota.

  • range: range type. The value range of the quota.

  • custom: custom type. Other types that do not fall into the preceding four threshold types.

bool

Examples

Success response

JSON format

{
  "RequestId": "15C66C7B-671A-4297-9187-2C4477247B78",
  "InstanceId": "sp-xcdn-96wblslz****",
  "Status": "online",
  "Quotas": [
    {
      "QuotaName": "customHttpCert",
      "QuotaValue": "10",
      "QuotaValueType": "bool"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidParameter The specified parameter is invalid. The specified parameter is invalid.
400 QuotaNotExist The quota item does not exist or the purchased plan has not taken effect. Confirm and try again. The quota item does not exist or the purchased plan has not taken effect. Confirm and try again.
400 InstanceNotExist The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account. The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account.
400 ErService.HasOpened You have already activated Edge Routine. You have already activated Edge Routine.
403 Site.NotExist The specified website does not exist or is not recognized by the system.Check whether the specified website identifier is valid and matches a website that is active, defined, and recognized by the system.If you want to add a new website, make sure that the creation and registration process is complete to integrate the website to the system. The specified website does not exist or is not recognized by the system.Check whether the specified website identifier is valid and matches a website that is active, defined, and recognized by the system.If you want to add a new website, make sure that the creation and registration process is complete to integrate the website to the system.
404 SiteNotFound The website does not exist or does not belong to you. The website does not exist or does not belong to you.
404 UnsupportQuota Unsupported quota is specified. Check and try again. Unsupported quota is specified. Check and try again.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.