All Products
Search
Document Center

Web Application Firewall:DescribeInstance

Last Updated:Aug 12, 2026

Retrieves the details of a WAF instance in the current Alibaba Cloud account.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-waf:DescribeInstance

get

*All Resource

*

  • acs:ResourceGroupId
None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

No

The region where the WAF instance resides. Valid values:

cn-hangzhou

ResourceManagerResourceGroupId

string

No

The Alibaba Cloud resource group ID.

rg-acfm***q

Response elements

Element

Type

Description

Example

object

Status

integer

The current status of the instance. Valid values:

  • 1: Normal.

  • 2: Expired.

  • 3: Released.

1

Details

object

The instance details.

DefenseObjectInGroupMaxCount

integer

The maximum number of protection objects that a protection group can contain.

100

Tamperproof

boolean

Specifies whether web tamper proofing is supported. Valid values:

true

BotApp

string

Indicates whether scenario-specific protection against app crawlers is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

IpBlacklistRuleInTemplateMaxCount

integer

The maximum number of protection rules that a single blacklist template can contain.

100

WhitelistRuleCondition

string

The match fields for whitelist rules. For more information, refer to the parameter description of whitelist rule (whitelist) conditions in CreateDefenseRule.

URL

CustomRuleCondition

string

The match conditions for custom rules. For more information, refer to the parameter description of custom rule (custom_acl) conditions in CreateDefenseRule.

URL

CustomResponse

boolean

Indicates whether custom responses are supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

HttpPorts

string

The available HTTP port range. For more information, refer to Ports supported by WAF.

80

Gslb

boolean

Specifies whether Global Server Load Balancing (GSLB) is supported. Valid values:

true

Ipv6

boolean

Specifies whether IPv6 is supported. Valid values:

true

Bot

boolean

Specifies whether bot management is supported. Valid values:

true

CustomRule

boolean

Specifies whether custom rules are supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

IpBlacklist

boolean

Indicates whether the IP blacklist is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

CnameResourceMaxCount

integer

The maximum number of CNAMEs that can be added.

1000

BackendMaxCount

integer

The maximum number of back-to-origin IP addresses that can be configured.

20

ExclusiveIp

boolean

Specifies whether exclusive IP addresses are supported. Valid values:

true

CustomResponseRuleInTemplateMaxCount

integer

The maximum number of protection rules that a single custom response template can contain.

100

IpBlacklistIpInRuleMaxCount

integer

The maximum number of IP addresses that can be added to a blacklist rule.

200

AclRuleMaxIpCount

integer

The maximum number of IP addresses that can be added to the match content. For more information about match content, refer to Match condition description.

100

BotTemplateMaxCount

integer

The maximum number of bot management protection templates that can be configured.

50

DefenseGroupMaxCount

integer

The maximum number of protection groups that can be configured.

100

VastIpBlacklistInFileMaxCount

integer

The maximum number of IP addresses that can be imported to the IP blacklist in a single bulk import.

2000

AntiScanTemplateMaxCount

integer

The maximum number of scan protection templates that can be configured.

20

WhitelistLogical

string

The logical operators for whitelist rules. For more information, refer to the parameter description of whitelist rule (whitelist) conditions in CreateDefenseRule.

contain

CustomRuleTemplateMaxCount

integer

The maximum number of custom rule templates that can be configured.

20

TamperproofTemplateMaxCount

integer

The maximum number of web tamper proofing protection templates that can be configured.

50

IpBlacklistTemplateMaxCount

integer

The maximum number of blacklist templates that can be configured.

20

HttpsPorts

string

The available HTTPS port range. For more information, refer to Ports supported by WAF.

443

DlpTemplateMaxCount

integer

The maximum number of information leak prevention templates that can be configured.

50

CustomRuleRatelimitor

string

The rate limiting object for custom rules.

header

DefenseObjectMaxCount

integer

The maximum number of protection objects that can be configured.

20000

Dlp

boolean

Specifies whether data leak prevention is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

DefenseObjectInTemplateMaxCount

integer

The maximum number of protection objects that can be associated with a single template.

100

CustomRuleAction

string

The strings included in custom rules.

block

TamperproofRuleInTemplateMaxCount

integer

The maximum number of protection rules that a single web tamper proofing template can contain.

50

DlpRuleInTemplateMaxCount

integer

The maximum number of protection rules that a single information leak prevention template can contain.

50

WhitelistTemplateMaxCount

integer

The maximum number of whitelist templates that can be configured.

20

MajorProtection

boolean

Specifies whether critical event protection is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

BaseWafGroupRuleTemplateMaxCount

integer

The maximum number of basic protection rule templates that can be configured.

20

BotWeb

string

Specifies whether scenario-specific protection against web crawlers is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

CustomRuleInTemplateMaxCount

integer

The maximum number of protection rules that a single custom rule template can contain.

100

VastIpBlacklistInOperationMaxCount

integer

The maximum number of IP addresses that can be added to the IP blacklist in a single page operation.

500

WhitelistRuleInTemplateMaxCount

integer

The maximum number of protection rules that a single whitelist template can contain.

100

AntiScan

boolean

Specifies whether scan protection is supported. Valid values:

true

CustomResponseTemplateMaxCount

integer

The maximum number of custom response templates that can be configured.

20

BaseWafGroupRuleInTemplateMaxCount

integer

The maximum number of protection rules that can be included in a single basic protection rule template.

100

MajorProtectionTemplateMaxCount

integer

The maximum number of critical event protection templates that can be configured.

20

BaseWafGroup

boolean

Specifies whether basic protection rules are supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

Whitelist

boolean

Specifies whether the IP whitelist is supported. Valid values:

  • true: Supported.

  • false: Not supported.

true

LogService

boolean

Specifies whether the log service is supported. Valid values:

true

VastIpBlacklistMaxCount

integer

The maximum number of IP blacklist entries that a single user can configure.

50000

FreeQps

integer

The free QPS value included in the subscription plan. For more information, see WAF 3.0 editions.

Note

This parameter has no practical meaning for pay-as-you-go instances.

1000

ExtendQps

integer

The extended QPS value of the subscription instance. For more information, see WAF 3.0 editions.

Note

This parameter is not applicable to pay-as-you-go instances.

10000

ElasticQps

integer

The burstable QPS value for the subscription instance with pay-as-you-go billing for burstable capacity. For more information, see WAF 3.0 editions.

Note

This parameter has no practical meaning for pay-as-you-go instances.

2000

QpsBillingCap

integer

The QPS billing protection threshold for the pay-as-you-go edition. For more information, see Traffic billing protection for pay-as-you-go.

Note

This parameter has no practical meaning for subscription instances.

2000

HybridCloud

boolean

Indicates whether hybrid cloud is enabled.

true

HybridCloudNodeExtend

integer

The number of hybrid cloud extended nodes.

3

Apisec

boolean

Indicates whether API security is enabled.

false

AgenticApisec

boolean

Indicates whether Agentic API security is enabled.

true

ResourceDirectory

boolean

Indicates whether the multi-account management feature is supported.

true

RequestId

string

The ID of the request.

66A98669-CC6E-4F3E-80A6-3014697B11AE

EndTime

integer

The time when the instance expires. The value is a UNIX timestamp. Unit: milliseconds. Format: ms.

4809859200000

InstanceId

string

The WAF instance ID.

waf-cn-xxx

InDebt

string

Indicates whether the current instance has an overdue payment. Valid values:

1

StartTime

integer

The purchase time. The value is a UNIX timestamp in milliseconds.

1668496310000

RegionId

string

The region where the WAF instance resides. Valid values:

  • cn-hangzhou: the Chinese mainland.

  • ap-southeast-1: outside the Chinese mainland.

cn-hangzhou

PayType

string

The billing method of the instance. Valid values:

POSTPAY

Edition

string

The WAF edition.

default_version

ProcessStatus

string

The instance execution status. Valid values:

  • commodity_converting: The commodity is being converted.

  • commodity_convert_check_failed: The commodity conversion check failed.

  • commodity_convert_process_failed: The commodity conversion failed.

  • order_create_failed: The order failed to be created.

  • order_pending_payment: The order is pending payment.

order_pending_payment

Examples

Success response

JSON format

{
  "Status": 1,
  "Details": {
    "DefenseObjectInGroupMaxCount": 100,
    "Tamperproof": true,
    "BotApp": "true",
    "IpBlacklistRuleInTemplateMaxCount": 100,
    "WhitelistRuleCondition": "URL",
    "CustomRuleCondition": "URL",
    "CustomResponse": true,
    "HttpPorts": "80",
    "Gslb": true,
    "Ipv6": true,
    "Bot": true,
    "CustomRule": true,
    "IpBlacklist": true,
    "CnameResourceMaxCount": 1000,
    "BackendMaxCount": 20,
    "ExclusiveIp": true,
    "CustomResponseRuleInTemplateMaxCount": 100,
    "IpBlacklistIpInRuleMaxCount": 200,
    "AclRuleMaxIpCount": 100,
    "BotTemplateMaxCount": 50,
    "DefenseGroupMaxCount": 100,
    "VastIpBlacklistInFileMaxCount": 2000,
    "AntiScanTemplateMaxCount": 20,
    "WhitelistLogical": "contain",
    "CustomRuleTemplateMaxCount": 20,
    "TamperproofTemplateMaxCount": 50,
    "IpBlacklistTemplateMaxCount": 20,
    "HttpsPorts": "443",
    "DlpTemplateMaxCount": 50,
    "CustomRuleRatelimitor": "header",
    "DefenseObjectMaxCount": 20000,
    "Dlp": true,
    "DefenseObjectInTemplateMaxCount": 100,
    "CustomRuleAction": "block",
    "TamperproofRuleInTemplateMaxCount": 50,
    "DlpRuleInTemplateMaxCount": 50,
    "WhitelistTemplateMaxCount": 20,
    "MajorProtection": true,
    "BaseWafGroupRuleTemplateMaxCount": 20,
    "BotWeb": "true",
    "CustomRuleInTemplateMaxCount": 100,
    "VastIpBlacklistInOperationMaxCount": 500,
    "WhitelistRuleInTemplateMaxCount": 100,
    "AntiScan": true,
    "CustomResponseTemplateMaxCount": 20,
    "BaseWafGroupRuleInTemplateMaxCount": 100,
    "MajorProtectionTemplateMaxCount": 20,
    "BaseWafGroup": true,
    "Whitelist": true,
    "LogService": true,
    "VastIpBlacklistMaxCount": 50000,
    "FreeQps": 1000,
    "ExtendQps": 10000,
    "ElasticQps": 2000,
    "QpsBillingCap": 2000,
    "HybridCloud": true,
    "HybridCloudNodeExtend": 3,
    "Apisec": false,
    "AgenticApisec": true,
    "ResourceDirectory": true
  },
  "RequestId": "66A98669-CC6E-4F3E-80A6-3014697B11AE",
  "EndTime": 4809859200000,
  "InstanceId": "waf-cn-xxx",
  "InDebt": "1",
  "StartTime": 1668496310000,
  "RegionId": "cn-hangzhou",
  "PayType": "POSTPAY",
  "Edition": "default_version",
  "ProcessStatus": "order_pending_payment"
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.