All Products
Search
Document Center

Security Center:DescribeVersionConfig

Last Updated:Sep 07, 2026

Queries the version details of a purchased Security Center instance.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeVersionConfig

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

192.0.XX.XX

ResourceDirectoryAccountId

integer

No

The Alibaba Cloud account ID that uses the Security Center service.

Note

Invoke the GetUser operation to obtain this parameter.

127608589417****

Response elements

Element

Type

Description

Example

object

MVAuthCount

integer

The total number of authorizations when multiple versions are purchased.

5000

SasLog

integer

Indicates whether log analysis is purchased. Valid values:

  • 0: Not purchased.

  • 1: Purchased.

1

SasScreen

integer

Indicates whether the security dashboard is purchased. Valid values:

  • 0: Not purchased.

  • 1: Purchased.

0

HoneypotCapacity

integer

The number of purchased honeypot authorization licenses.

20

MVUnusedAuthCount

integer

The total number of remaining authorizations when multiple versions are purchased.

40

WebLock

integer

Indicates whether web tamper-proofing is enabled. Valid values:

  • 0: Not enabled.

  • 1: Enabled.

0

AppWhiteListAuthCount

integer

The number of application whitelist authorizations.

Note

One authorization allows you to apply an application whitelist policy to one server. After the application whitelist feature is enabled, the account has 20 authorizations by default.

20

RequestId

string

The unique request ID generated by Alibaba Cloud for this request.

C2DC96D2-DD2E-49D9-A28E-85590475DF55

LastTrailEndTime

integer

The end timestamp of the last trial of Security Center, in milliseconds.

1603934844000

Version

integer

The purchased edition of Security Center. Valid values:

  • 1: Free Edition.

  • 3: Enterprise Edition.

  • 5: Advanced Edition.

  • 6: Anti-virus Edition.

  • 7: Ultimate Edition.

  • 8: Multi-version.

  • 10: Value-added services only.

3

WebLockAuthCount

integer

The number of purchased web tamper-proofing authorizations. One authorization enables web tamper-proofing protection for one server. Valid values: 0 to N.

Note

N is the number of servers that you own.

0

ReleaseTime

integer

The UNIX timestamp when the Security Center instance expires, in milliseconds.

Note

If you do not complete renewal within 7 days after the instance expires, your paid edition instance is downgraded to Free Edition. You can no longer use the features of the paid edition, and your previous Security Center configuration data and historical alerting data (such as DDoS alerts) become inaccessible. In this case, you must repurchase Security Center to enable the paid edition. For more information, see Purchase Security Center.

1625846400000

HighestVersion

integer

The highest purchased edition of Security Center. Valid values:

  • 1: Free Edition.

  • 3: Enterprise Edition.

  • 5: Advanced Edition.

  • 6: Anti-virus Edition.

  • 7: Ultimate Edition.

  • 10: Value-added services only.

Note

If a single version is purchased, this value indicates the corresponding version. If multiple versions are purchased, this value indicates the highest version among the purchased editions of Security Center.

1

AssetLevel

integer

The number of purchased server authorization licenses.

30

IsOverBalance

boolean

Indicates whether the number of existing servers exceeds the maximum number of purchased authorizations. Valid values:

  • false: Not exceeded.

  • true: Exceeded.

Important This parameter is deprecated. You can ignore it.

false

InstanceId

string

The instance ID of the purchased Security Center instance.

sas-vg6hafdsafs****

SlsCapacity

integer

The purchased log storage capacity, in GB. Valid values: 0 to 200000.

10240

VmCores

integer

The number of purchased authorized cores.

10

AllowPartialBuy

integer

Indicates whether pay-as-you-go purchasing is allowed. Valid values:

  • 0: Not allowed.

  • 1: Allowed.

1

AppWhiteList

integer

Indicates whether the application whitelist is enabled. Valid values:

  • 0: Not enabled.

  • 2: Enabled.

2

ImageScanCapacity

integer

The number of purchased image scan authorization licenses.

8954

IsTrialVersion

integer

Indicates whether the current Security Center edition is a trial version. Valid values:

  • 0: Not a trial version.

  • 1: Trial version.

0

UserDefinedAlarms

integer

Indicates whether the custom alerting feature is enabled. Valid values:

  • 0: Not enabled.

  • 2: Enabled.

0

OpenTime

integer

The timestamp when the service was activated, in milliseconds.

1657244824669

IsNewContainerVersion

boolean

Indicates whether the instance is the new Ultimate Edition. Valid values:

  • true: The instance is the latest version.

  • false: The instance is not the latest version.

true

IsNewMultiVersion

boolean

Indicates whether the instance is the new multi-version. Valid values:

  • true: The instance is the latest multi-version.

  • false: The instance is not the latest multi-version.

true

ThreatAnalysisCapacity

integer

The purchased threat analysis capacity, in GB.

25

CspmCapacity

integer

The number of purchased Cloud Security Posture Management (CSPM) scans, in scans per month.

10

VulFixCapacity

integer

The number of purchased vulnerability fixes, in fixes per month.

10

RaspCapacity

integer

The number of purchased application protection licenses, in licenses per month.

10

AgentlessCapacity

integer

The number of agentless detection licenses.

Note

Agentless detection is not available for purchase. You can ignore this field.

10

IsPostpay

boolean

Indicates whether pay-as-you-go billing is enabled. Valid values:

  • false: Not enabled.

  • true: Enabled.

true

PostPayInstanceId

string

The instance ID of the pay-as-you-go instance.

postpay-sas-**

PostPayModuleSwitch

string

The status of pay-as-you-go module switches, in JSON string format. Valid values:

  • Key:
    • VUL: Vulnerability fix module.

    • CSPM: Cloud Security Posture Management (CSPM) module.

    • AGENTLESS: Agentless detection module.

    • SERVERLESS: Serverless security module.

    • CTDR: Cloud Threat Detection and Response (CTDR) module.

    • POST_HOST: Host and container security module.

    • SDK: Malicious file detection SDK module.

    • RASP: Runtime application self-protection (RASP) module.

  • Value: 0 indicates disabled, and 1 indicates enabled.

{"VUL":1}

PostPayStatus

integer

The instance status of the pay-as-you-go instance. Valid values:

  • 1: Normal.

  • 2: Suspended due to overdue payment.

1

PostPayOpenTime

integer

The time when pay-as-you-go billing was activated. The value is a UNIX timestamp, in milliseconds.

1698915219000

SdkCapacity

integer

The number of malicious file detection SDK authorization licenses.

10

AntiRansomwareCapacity

integer

The anti-ransomware backup capacity, in GB.

160

NewThreatAnalysis

integer

Indicates whether the new version of Cloud Threat Detection and Response (CTDR) is enabled. The new version of CTDR supports purchasing traffic ingestion and log storage capacity. Valid values:

  • 0: No.

  • 1: Yes.

1

ThreatAnalysisFlow

integer

The purchased log ingestion traffic for Cloud Threat Detection and Response (CTDR), in GB per day.

10

MergedVersion

integer

The higher protection edition when both host protection and container protection are activated with subscription and pay-as-you-go billing methods in Security Center. Valid values:

  • 1: Basic Edition.

  • 6: Anti-virus Edition.

  • 5: Advanced Edition.

  • 3: Enterprise Edition.

  • 7: Ultimate Edition.

7

PostPayHostVersion

integer

The highest protection edition bound to assets when the pay-as-you-go host and container security service is activated. Valid values:

  • 1: Free Edition.

  • 3: Enterprise Edition.

  • 5: Advanced Edition.

  • 6: Anti-virus Edition.

  • 7: Ultimate Edition.

7

AntiRansomwareService

integer

The status of the anti-ransomware managed service. Valid values:

  • 0: Not activated.

  • 1: Activated.

1

MultiVersion

string

The multi-version number and authorization usage information.

null

CanTryPostPaidPackage

integer

Indicates whether the pay-as-you-go trial plan can be activated. Valid values:

  • 0: Not supported.

  • 1: Supported.

1

TrialVersion

integer

The trial version.

1

InstanceBuyType

integer

The instance purchase type. Valid values:

  • 0: Self-purchased.

  • 1: Allocated from a multi-account setup.

0

OnboardedAssets

integer

The AI digital human managed instances.

10

IntelligentAnalysisFlow

integer

The AI digital human analysis traffic.

100

CspmInstanceCapacity

integer

The AI digital human analysis traffic.

100

HybridSwitch

integer

The AI digital human analysis traffic.

100

HybridPaidModuleSwitchMap

integer

The AI digital human analysis traffic.

100

NewPostPaidCspm

integer

The AI digital human analysis traffic.

100

HybridPaidStatus

integer

The status of the elastic billing switch.

1

BuySasEdr

string

Indicates whether EDR is purchased.

true

SasEdrClientAuthCount

string

The number of servers purchased for EDR.

10

SasEdrPrePaidInstanceId

string

The subscription instance ID of EDR.

sas-edr-sfkhakhk

SasEdrPostPaidInstanceId

string

The pay-as-you-go instance ID of EDR.

sas-edr-postpaid-fadaf

SasEdrVersion

string

The purchased edition of EDR.

1

HybridPaidGrayStatus

string

The canary release module for elastic billing.

{"CSPM_INSTANCE":1}

SasEdrPrePaidInstanceStatus

string

The instance status of the EDR upfront instance.

RELEASED

TrialModuleList

array<object>

The list of trial sub-modules.

object

Name

string

The name of the trial sub-module.

EDR

SdkAiPostPaidGray

integer

The canary release status of the pay-as-you-go SDK.

1

In actual calls, the following parameters are also returned in addition to the response parameters listed in the preceding table.

  • AvdsFlag

  • FLag

  • CreateTime

  • IsSasOpening

  • Log

  • AgentlessCapacity

Note

The parameters in the preceding list are deprecated. You can ignore them.

Examples

Success response

JSON format

{
  "MVAuthCount": 5000,
  "SasLog": 1,
  "SasScreen": 0,
  "HoneypotCapacity": 20,
  "MVUnusedAuthCount": 40,
  "WebLock": 0,
  "AppWhiteListAuthCount": 20,
  "RequestId": "C2DC96D2-DD2E-49D9-A28E-85590475DF55",
  "LastTrailEndTime": 1603934844000,
  "Version": 3,
  "WebLockAuthCount": 0,
  "ReleaseTime": 1625846400000,
  "HighestVersion": 1,
  "AssetLevel": 30,
  "IsOverBalance": false,
  "InstanceId": "sas-vg6hafdsafs****",
  "SlsCapacity": 10240,
  "VmCores": 10,
  "AllowPartialBuy": 1,
  "AppWhiteList": 2,
  "ImageScanCapacity": 8954,
  "IsTrialVersion": 0,
  "UserDefinedAlarms": 0,
  "OpenTime": 1657244824669,
  "IsNewContainerVersion": true,
  "IsNewMultiVersion": true,
  "ThreatAnalysisCapacity": 25,
  "CspmCapacity": 10,
  "VulFixCapacity": 10,
  "RaspCapacity": 10,
  "AgentlessCapacity": 10,
  "IsPostpay": true,
  "PostPayInstanceId": "postpay-sas-**",
  "PostPayModuleSwitch": "{\"VUL\":1}",
  "PostPayStatus": 1,
  "PostPayOpenTime": 1698915219000,
  "SdkCapacity": 10,
  "AntiRansomwareCapacity": 160,
  "NewThreatAnalysis": 1,
  "ThreatAnalysisFlow": 10,
  "MergedVersion": 7,
  "PostPayHostVersion": 7,
  "AntiRansomwareService": 1,
  "MultiVersion": "null",
  "CanTryPostPaidPackage": 1,
  "TrialVersion": 1,
  "InstanceBuyType": 0,
  "OnboardedAssets": 10,
  "IntelligentAnalysisFlow": 100,
  "CspmInstanceCapacity": 100,
  "HybridSwitch": 100,
  "HybridPaidModuleSwitchMap": 100,
  "NewPostPaidCspm": 100,
  "HybridPaidStatus": 1,
  "BuySasEdr": "true",
  "SasEdrClientAuthCount": "10",
  "SasEdrPrePaidInstanceId": "sas-edr-sfkhakhk",
  "SasEdrPostPaidInstanceId": "sas-edr-postpaid-fadaf",
  "SasEdrVersion": "1",
  "HybridPaidGrayStatus": "{\"CSPM_INSTANCE\":1}",
  "SasEdrPrePaidInstanceStatus": "RELEASED",
  "TrialModuleList": [
    {
      "Name": "EDR"
    }
  ],
  "SdkAiPostPaidGray": 1
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.