All Products
Search
Document Center

Security Center:DescribeVersionConfig

Last Updated:Aug 27, 2026

Queries the version details of a purchased Security Center instance.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeVersionConfig

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

192.0.XX.XX

ResourceDirectoryAccountId

integer

No

The Alibaba Cloud account ID that uses the Security Center service.

Note

Call the GetUser operation to obtain this parameter.

127608589417****

Response elements

Element

Type

Description

Example

object

MVAuthCount

integer

The total number of authorizations when multiple versions are purchased.

5000

SasLog

integer

Indicates whether log analysis is purchased. Valid values:

  • 0: Not purchased.

  • 1: Purchased.

1

SasScreen

integer

Indicates whether the security dashboard is purchased. Valid values:

  • 0: Not purchased.

  • 1: Purchased.

0

HoneypotCapacity

integer

The number of purchased honeypot authorizations.

20

MVUnusedAuthCount

integer

The total number of remaining authorizations when multiple versions are purchased.

40

WebLock

integer

Indicates whether the tamper-proofing service is enabled. Valid values:

  • 0: Not enabled.

  • 1: Enabled.

0

AppWhiteListAuthCount

integer

The number of application whitelist authorizations.

Note

One authorization can apply an application whitelist policy to one server. After the application whitelist feature is enabled, the account has 20 authorizations by default.

20

RequestId

string

The request ID.

C2DC96D2-DD2E-49D9-A28E-85590475DF55

LastTrailEndTime

integer

The end timestamp of the last trial of Security Center. Unit: milliseconds.

1603934844000

Version

integer

The purchased Security Center version. Valid values:

  • 1: Free edition.

  • 3: Enterprise edition.

  • 5: Advanced edition.

  • 6: Anti-virus edition.

  • 7: Ultimate edition.

  • 8: Multi-version edition.

  • 10: Value-added services only.

3

WebLockAuthCount

integer

The number of purchased tamper-proofing authorizations. One authorization can enable tamper-proofing protection for one server. Valid values: 0 to N.

Note

N is the number of servers you own.

0

ReleaseTime

integer

The expiration timestamp of the Security Center instance. Unit: milliseconds.

Note

If you do not renew the service within 7 days after it expires, your paid instance is downgraded to the free edition. You can no longer use the features of the paid edition, and your Security Center configuration data and historical alert data (such as DDoS alerts) become inaccessible. In this case, you must repurchase to enable the paid Security Center service. For more information, see Purchase Security Center.

1625846400000

HighestVersion

integer

The highest purchased Security Center version. Valid values:

  • 1: Free edition.

  • 3: Enterprise edition.

  • 5: Advanced edition.

  • 6: Anti-virus edition.

  • 7: Ultimate edition.

  • 10: Value-added services only.

Note

If a single version is purchased, this value indicates the corresponding version. If multiple versions are purchased, this value indicates the highest version among the purchased Security Center versions.

1

AssetLevel

integer

The number of purchased server authorizations.

30

IsOverBalance

boolean

Indicates whether the current number of servers exceeds the maximum number of purchased authorizations. Valid values:

  • false: Not exceeded.

  • true: Exceeded.

Important This parameter is deprecated. You do not need to pay attention to it.

false

InstanceId

string

The ID of the purchased Security Center instance.

sas-vg6hafdsafs****

SlsCapacity

integer

The purchased log storage capacity. Unit: GB. Valid values: 0 to 200000.

10240

VmCores

integer

The number of purchased authorized cores.

10

AllowPartialBuy

integer

Indicates whether pay-as-you-go purchasing is allowed. Valid values:

  • 0: Not allowed.

  • 1: Allowed.

1

AppWhiteList

integer

Indicates whether the application whitelist is enabled. Valid values:

  • 0: Not enabled.

  • 2: Enabled.

2

ImageScanCapacity

integer

The number of purchased image scan authorizations.

8954

IsTrialVersion

integer

Indicates whether the current Security Center version is a trial version. Valid values:

  • 0: Not a trial version.

  • 1: Trial version.

0

UserDefinedAlarms

integer

Indicates whether the custom alert feature is enabled. Valid values:

  • 0: Not enabled.

  • 2: Enabled.

0

OpenTime

integer

The timestamp when the service was activated. Unit: milliseconds.

1657244824669

IsNewContainerVersion

boolean

Indicates whether this is the new Ultimate edition. Valid values:

  • true: The latest version.

  • false: Not the latest version.

true

IsNewMultiVersion

boolean

Indicates whether this is the new multi-version edition. Valid values:

  • true: The latest multi-version edition.

  • false: Not the latest multi-version edition.

true

ThreatAnalysisCapacity

integer

The purchased threat analysis capacity. Unit: GB.

25

CspmCapacity

integer

The number of purchased cloud platform configuration check scans. Unit: times/month.

10

VulFixCapacity

integer

The number of purchased vulnerability fixes. Unit: times/month.

10

RaspCapacity

integer

The number of purchased application protection instances. Unit: instances/month.

10

AgentlessCapacity

integer

The number of agentless detections.

Note

Agentless detection is not currently available for purchase. You do not need to pay attention to this field.

10

IsPostpay

boolean

Indicates whether pay-as-you-go billing is enabled. Valid values:

  • false: Not enabled.

  • true: Enabled.

true

PostPayInstanceId

string

The ID of the pay-as-you-go instance.

postpay-sas-**

PostPayModuleSwitch

string

The switch status of pay-as-you-go modules in JSON string format. Valid values:

  • Key:
    • VUL: Vulnerability fix module.

    • CSPM: Cloud security posture management module.

    • AGENTLESS: Agentless detection module.

    • SERVERLESS: Serverless security module.

    • CTDR: Threat analysis and response module.

    • POST_HOST: Host and container security module.

    • SDK: Malicious file detection SDK module.

    • RASP: Application protection module.

  • Value: 0 indicates disabled, and 1 indicates enabled.

{"VUL":1}

PostPayStatus

integer

The status of the pay-as-you-go instance. Valid values:

  • 1: Normal.

  • 2: Suspended due to overdue payment.

1

PostPayOpenTime

integer

The time when pay-as-you-go billing was activated.

1698915219000

SdkCapacity

integer

The number of malicious file detection SDK authorizations.

10

AntiRansomwareCapacity

integer

The anti-ransomware backup capacity. Unit: GB.

160

NewThreatAnalysis

integer

Indicates whether the new threat analysis and response service is enabled. The new threat analysis and response service supports purchasing ingestion traffic and log storage capacity. Valid values:

  • 0: No.

  • 1: Yes.

1

ThreatAnalysisFlow

integer

The purchased threat analysis and response log ingestion traffic. Unit: GB/day.

10

MergedVersion

integer

The higher protection version between the subscription and pay-as-you-go Security Center host and container security services when both are enabled. Valid values:

  • 1: Free edition.

  • 6: Anti-virus edition.

  • 5: Advanced edition.

  • 3: Enterprise edition.

  • 7: Ultimate edition.

7

PostPayHostVersion

integer

The highest protection version bound to assets when the host and container security pay-as-you-go service is enabled. Valid values:

  • 1: Free edition.

  • 3: Enterprise edition.

  • 5: Advanced edition.

  • 6: Anti-virus edition.

  • 7: Ultimate edition.

7

AntiRansomwareService

integer

The anti-ransomware managed service. Valid values:

  • 0: Not enabled.

  • 1: Enabled.

1

MultiVersion

string

The multi-version number and authorization usage information.

null

CanTryPostPaidPackage

integer

Indicates whether the post-paid trial package can be activated. Valid values:

  • 0: Not supported.

  • 1: Supported.

1

TrialVersion

integer

The trial version.

1

InstanceBuyType

integer

The instance purchase type. Valid values:

  • 0: Self-purchased.

  • 1: Allocated by multi-account management.

0

OnboardedAssets

integer

The AI digital human managed instances.

10

IntelligentAnalysisFlow

integer

The AI digital human analysis traffic.

100

CspmInstanceCapacity

integer

The AI digital human analysis traffic.

100

HybridSwitch

integer

The AI digital human analysis traffic.

100

HybridPaidModuleSwitchMap

integer

The AI digital human analysis traffic.

100

NewPostPaidCspm

integer

The AI digital human analysis traffic.

100

HybridPaidStatus

integer

The elastic billing switch status.

1

BuySasEdr

string

Indicates whether EDR is purchased.

true

SasEdrClientAuthCount

string

The number of machines purchased for EDR.

10

SasEdrPrePaidInstanceId

string

The subscription instance ID of EDR.

sas-edr-sfkhakhk

SasEdrPostPaidInstanceId

string

The pay-as-you-go instance ID of EDR.

sas-edr-postpaid-fadaf

SasEdrVersion

string

The purchased EDR version.

1

HybridPaidGrayStatus

string

The grayscale module for elastic billing.

{"CSPM_INSTANCE":1}

SasEdrPrePaidInstanceStatus

string

The EDR subscription instance status.

RELEASED

TrialModuleList

array<object>

The list of trial sub-modules.

object

Name

string

The name of the trial sub-module.

EDR

In addition to the response parameters listed in the preceding table, the following parameters are also returned when you call this operation.

  • AvdsFlag

  • FLag

  • CreateTime

  • IsSasOpening

  • Log

  • AgentlessCapacity

Note

The parameters listed above are deprecated. You can ignore them.

Examples

Success response

JSON format

{
  "MVAuthCount": 5000,
  "SasLog": 1,
  "SasScreen": 0,
  "HoneypotCapacity": 20,
  "MVUnusedAuthCount": 40,
  "WebLock": 0,
  "AppWhiteListAuthCount": 20,
  "RequestId": "C2DC96D2-DD2E-49D9-A28E-85590475DF55",
  "LastTrailEndTime": 1603934844000,
  "Version": 3,
  "WebLockAuthCount": 0,
  "ReleaseTime": 1625846400000,
  "HighestVersion": 1,
  "AssetLevel": 30,
  "IsOverBalance": false,
  "InstanceId": "sas-vg6hafdsafs****",
  "SlsCapacity": 10240,
  "VmCores": 10,
  "AllowPartialBuy": 1,
  "AppWhiteList": 2,
  "ImageScanCapacity": 8954,
  "IsTrialVersion": 0,
  "UserDefinedAlarms": 0,
  "OpenTime": 1657244824669,
  "IsNewContainerVersion": true,
  "IsNewMultiVersion": true,
  "ThreatAnalysisCapacity": 25,
  "CspmCapacity": 10,
  "VulFixCapacity": 10,
  "RaspCapacity": 10,
  "AgentlessCapacity": 10,
  "IsPostpay": true,
  "PostPayInstanceId": "postpay-sas-**",
  "PostPayModuleSwitch": "{\"VUL\":1}",
  "PostPayStatus": 1,
  "PostPayOpenTime": 1698915219000,
  "SdkCapacity": 10,
  "AntiRansomwareCapacity": 160,
  "NewThreatAnalysis": 1,
  "ThreatAnalysisFlow": 10,
  "MergedVersion": 7,
  "PostPayHostVersion": 7,
  "AntiRansomwareService": 1,
  "MultiVersion": "null",
  "CanTryPostPaidPackage": 1,
  "TrialVersion": 1,
  "InstanceBuyType": 0,
  "OnboardedAssets": 10,
  "IntelligentAnalysisFlow": 100,
  "CspmInstanceCapacity": 100,
  "HybridSwitch": 100,
  "HybridPaidModuleSwitchMap": 100,
  "NewPostPaidCspm": 100,
  "HybridPaidStatus": 1,
  "BuySasEdr": "true",
  "SasEdrClientAuthCount": "10",
  "SasEdrPrePaidInstanceId": "sas-edr-sfkhakhk",
  "SasEdrPostPaidInstanceId": "sas-edr-postpaid-fadaf",
  "SasEdrVersion": "1",
  "HybridPaidGrayStatus": "{\"CSPM_INSTANCE\":1}",
  "SasEdrPrePaidInstanceStatus": "RELEASED",
  "TrialModuleList": [
    {
      "Name": "EDR"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.