All Products
Search
Document Center

Web Application Firewall:API overview

Last Updated:Jul 13, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (waf-openapi/2021-10-01) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

Instance information

API

Title

Description

CreatePostpaidInstance CreatePostpaidInstance Creates a pay-as-you-go Web Application Firewall (WAF) 3.0 instance.
DescribeInstance DescribeInstance Retrieves the details of the Web Application Firewall (WAF) instance in your Alibaba Cloud account.

Access configuration

API

Title

Description

Cloud native mode Cloud native mode
DescribeAbnormalCloudResources DescribeAbnormalCloudResources Queries abnormal cloud resources added in cloud native mode.
ReCreateCloudResource Re-register a cloud service with WAF Re-registers a cloud service with WAF. This operation is used only when the cloud native mode status is protection exception.
SyncProductInstance SyncProductInstance Synchronizes Elastic Compute Service (ECS), Classic Load Balancer (CLB), and Network Load Balancer (NLB) instances to Web Application Firewall (WAF).
DescribeCloudResources DescribeCloudResources Queries the list of cloud services added to Web Application Firewall (WAF).
DescribeResourcePort DescribeResourcePort Queries the ports of a cloud service instance that are added to Web Application Firewall (WAF).
DescribeProductInstances Query synchronized cloud service assets Queries the list of synchronized cloud service assets.
DescribeResourceSupportRegions Query supported regions for cloud native mode Queries the list of supported regions for cloud native mode, mainly for CLB and ECS products.
DescribeResourceRegionId DescribeResourceRegionId Queries the region IDs of cloud service resources that can be added to Web Application Firewall (WAF) by using the SDK.
DescribeResourceInstanceCerts DescribeResourceInstanceCerts Queries the certificates of a cloud product instance. This operation is available only in multi-account scenarios and returns the certificates of both the delegated administrator and the member that owns the instance. For example, if user A is a delegated administrator with cert1 and the instance lb-xx-1 belongs to member B who has cert2, a query for the instance lb-xx-1 returns both cert1 and cert2.
ModifyCloudResource Modify cloud service access configuration Modifies the configuration of a cloud service that is connected to Web Application Firewall (WAF).
DescribeCloudResourceAccessedPorts DescribeCloudResourceAccessedPorts Queries the ports of cloud services added to Web Application Firewall (WAF). This operation is supported only for Elastic Compute Service (ECS) and Classic Load Balancer (CLB).
DescribeCloudResourceAccessPortDetails Query the details of cloud service instance ports that are added to WAF Retrieves port details of cloud service instances onboarded to Web Application Firewall (WAF).
ModifyCloudResourceCert ModifyCloudResourceCert Modifies the certificate for a resource managed by WAF in cloud native mode.
DescribeCloudResourceList Query cloud native mode WAF configuration list Queries the list of resources connected to WAF in cloud native mode.
ModifyCloudResourceDefaultCert Modify the default certificate for a cloud service Modifies the default certificate for a cloud native mode resource.
DeleteCloudResourceExtensionCert Delete an extension certificate for a cloud service Deletes an extension certificate for a cloud service connected in cloud native mode.
CreateCloudResourceExtensionCert Add an extension certificate for a cloud native mode resource Adds an extension certificate for a cloud native mode resource.
CNAME access CNAME access
DescribeDomainUsedPorts Query all ports used by user domain names Queries all ports used by domain names of the current user. Only domain names with CNAME access and hybrid cloud CNAME domain names with public network disaster recovery enabled are included.
ModifyDomain ModifyDomain Updates a CNAME-based domain name onboarded to Web Application Firewall (WAF).
DescribeDomains DescribeDomains Queries the domain names that are added to Web Application Firewall (WAF).
DescribePunishedDomains DescribePunishedDomains Queries penalties for domain names added to Web Application Firewall (WAF) without an Internet Content Provider (ICP) filing.
ModifyDomainPunishStatus Re-connect a domain name in ICP filing violation penalty status Re-connects a domain name that is in the ICP filing violation penalty status.
DescribeCertDetail Query certificate details Queries the details of a certificate, such as the certificate name, expiration time, issuance time, and associated domain name.
DescribeCerts DescribeCerts Retrieves the list of certificates for a user.
DescribeDomainDNSRecord Query CNAME DNS resolution status Queries whether the DNS settings of a domain name are correct.
DescribeWafSourceIpSegment Query back-to-origin CIDR blocks of a WAF instance Queries the back-to-origin CIDR blocks of WAF.
CreateSM2Cert Upload SM certificate for cNAME-based WAF access Uploads a China National Cryptographic Algorithm (SM) certificate for a domain that is added to WAF in CNAME mode.
DescribeCnameCount Query the total number of added domain names Queries the total number of domain names that are added to WAF, including domain names added through CNAME and hybrid cloud access.
DescribeDefaultHttps Query default SSL/TLS settings Queries the default SSL/TLS settings.
ModifyDefaultHttps ModifyDefaultHttps Modifies the default SSL/TLS settings.
CreateCerts Upload an international certificate to WAF for cNAME-based access Uploads an international certificate to WAF for CNAME-based access.
VerifyDomainOwner VerifyDomainOwner Verifies that you own the specified domain name. Domain ownership must be verified before you can add a domain name to Web Application Firewall (WAF) by using CNAME access.
DescribeVerifyContent DescribeVerifyContent Queries the domain ownership verification content of a Web Application Firewall (WAF) instance.
ModifyDomainCert ModifyDomainCert Modifies the certificate that is associated with a domain name added to a Web Application Firewall (WAF) instance in CNAME record mode.
Hybrid cloud access Hybrid cloud access
DescribeHybridCloudResources Query hybrid cloud CNAME access list Queries the list of hybrid cloud domain names.
DescribeHybridCloudProtectableCount DescribeHybridCloudProtectableCount Queries the count of protectable nodes that can be added to a hybrid cloud cluster.

Protection configuration

API

Title

Description

Protected objects Protected objects
CreateDefenseResource CreateDefenseResource Creates a protected object.
DeleteDefenseResource Delete a protected object Deletes a protected object.
CreateDefenseResourceGroup CreateDefenseResourceGroup Creates a protected object group.
ModifyDefenseResourceGroup ModifyDefenseResourceGroup Modifies the configuration of a protected object group.
DeleteDefenseResourceGroup DeleteDefenseResourceGroup Deletes a protected object group.
DescribeDefenseResourceGroup DescribeDefenseResourceGroup Retrieves the details of a protected object group.
DescribeDefenseResourceGroups DescribeDefenseResourceGroups Retrieves information about protected object groups using pagination.
DescribeDefenseResourceGroupNames DescribeDefenseResourceGroupNames Queries the names of protected object groups.
DescribeDefenseResource Query a single protected object Query a single protected object.
DescribeDefenseResources Query protected objects by paging Queries protected objects by paging.
DescribeDefenseResourceNames DescribeDefenseResourceNames Performs a pagination query to retrieve the names of protected objects.
DescribeDefenseResourceOwnerUid DescribeDefenseResourceOwnerUid Queries the asset owner account of protected objects in multi-account management scenarios.
ModifyDefenseResourceXff ModifyDefenseResourceXff Modifies the cookie settings of a protected object and the method to identify the originating IP addresses of clients.
DescribePauseProtectionStatus DescribePauseProtectionStatus Queries the protection pause status of a Web Application Firewall (WAF) instance.
DescribeDefenseGroupValidResources DescribeDefenseGroupValidResources Queries a paginated list of protected objects that can be associated with a defense group.
Protection rules Protection rules
DescribeBaseRuleChangeLog DescribeBaseRuleChangeLog Queries protection rule change logs on a paginated basis.
CreateDefenseTemplate CreateDefenseTemplate Creates a protection template.
ModifyDefenseTemplate ModifyDefenseTemplate Modifies a defense template.
ModifyDefenseTemplateStatus ModifyDefenseTemplateStatus Changes the status of a protection rule template.
CopyDefenseTemplate CopyDefenseTemplate Copies a protection template.
DeleteDefenseTemplate DeleteDefenseTemplate Deletes a protection rule template.
DescribeDefenseTemplate DescribeDefenseTemplate Retrieves the details of a specific protection template.
DescribeDefenseTemplates DescribeDefenseTemplates Retrieves a paginated list of protection templates.
ModifyTemplateResources ModifyTemplateResources Attaches protected objects to or detaches protected objects from a protection template.
DescribeTemplateResources DescribeTemplateResources Queries the resources attached to a protection template.
DescribeTemplateResourceCount DescribeTemplateResourceCount Queries the number of protected resources that are associated with one or more protection templates.
DescribeDefenseTemplateValidResources DescribeDefenseTemplateValidResources Queries a paginated list of protected objects that are valid for a specified protection template.
DescribeDefenseTemplateValidGroups DescribeDefenseTemplateValidGroups Queries the names of protected object groups that can be associated with a specific protection template.
DescribeDefenseResourceTemplates DescribeDefenseResourceTemplates Queries the protection templates associated with a protected object or protected object group.
CreateDefenseRule Create a web core protection rule Creates a Web core protection rule.
ModifyDefenseRule ModifyDefenseRule Modifies the configuration of a protection rule.
ModifyDefenseRuleStatus ModifyDefenseRuleStatus Enables or disables a protection rule.
DeleteDefenseRule DeleteDefenseRule Deletes the specified protection rules.
DescribeDefenseRules DescribeDefenseRules Queries a paginated list of protection rules.
DescribeDefenseRule DescribeDefenseRule Retrieves the details of a specified protection rule.
ModifyDefenseRuleCache ModifyDefenseRuleCache Updates the cache for a web tamper-proofing rule.
DeleteDefenseRuleBlockIp DeleteDefenseRuleBlockIp Unblocks an IP address that is blocked by the scan protection module.
DescribeRelatedDefenseRules Query associated protection rules by page Queries associated protection rules by using paging.
DescribeIpAbroadCountryInfos DescribeIpAbroadCountryInfos Retrieves supported countries and regions outside China for IP-based region blacklist.
DescribeRuleGroups DescribeRuleGroups Queries a paginated list of regular expression rule groups.
ModifyDefenseSceneConfig ModifyDefenseSceneConfig Modifies the mitigation settings for a protection scenario.
DescribeDefenseSceneConfig DescribeDefenseSceneConfig Queries the protection configurations for a specific defense scenario.
DescribeDefenseRuleStatistics Query protection rule statistics Queries statistics of rules under a specified WAF protection module.
DescribeBaseSystemRules DescribeBaseSystemRules Queries the system rules for Web Application Firewall (WAF) protection.
DescribeCustomBaseRuleCompileResult DescribeCustomBaseRuleCompileResult Describes the compilation result of a custom regular expression rule.
DescribeBotRuleLabels DescribeBotRuleLabels Queries the labels of bot management rules.
DescribeBotAppKey DescribeBotAppKey Queries the AppKey for bot management.
Critical event protection Critical event protection
CreateMajorProtectionBlackIp CreateMajorProtectionBlackIp Creates an IP address blacklist for critical event protection.
ModifyMajorProtectionBlackIp ModifyMajorProtectionBlackIp Modifies an IP address blacklist for critical event protection.
DeleteMajorProtectionBlackIp DeleteMajorProtectionBlackIp Deletes an IP address from the blacklist for critical event protection.
ClearMajorProtectionBlackIp ClearMajorProtectionBlackIp Clears the IP blacklist for a critical event protection rule.
DescribeMajorProtectionBlackIps DescribeMajorProtectionBlackIps Queries the IP address blacklist for critical event protection in a paginated format.
Address books Address books
AddAddress Add addresses to an address book Adds addresses to an address book.
DescribeAddresses Query address book addresses by page Queries addresses in an address book by paging.
DeleteAddress Delete addresses from an address book Deletes addresses from an address book.
ClearAddress Clear all addresses from an address book Clears all addresses from an address book.

API security

API

Title

Description

DeleteApisecAbnormals Batch delete API security risks Deletes API security risks in batches.
ModifyApisecAbnormals ModifyApisecAbnormals Modifies the status of API security risks in batches.
DescribeApisecAssetTrend Query API security API asset trends Queries the trend of API security API assets.
DescribeApisecAbnormalDomainStatistic Query API security risk domain name statistics Queries statistics on API security risk domain names.
DescribeApisecEventDomainStatistic Query API security event domain name statistics Queries the domain name statistics of API security events.
DescribeApisecSensitiveDomainStatistic Query API security sensitive data domain name statistics Queries statistics on data endpoints associated with API security sensitive data domains.
ModifyApisecEvents ModifyApisecEvents Modifies the status of a batch of API security events.
DeleteApisecEvents Batch delete API security events Deletes API security events in batches.
ModifyApisecLogDeliveryStatus Modify API security log subscription status Modifies the subscription status of API security logs.
CreateApiExport Create an API security data export task Creates an API security data export task.
DescribeApiExports Query API security export tasks Queries the list of API security export tasks.
DescribeApisecAbnormals Query API security risks Queries the list of API security risks.
DescribeApisecApiResources Query API security assets Queries the list of API security assets.
ModifyApisecStatus Modify API security status Modifies the status of protected objects or protected object groups for API security.
ModifyApisecModuleStatus Modify API security protection module status Modifies the status of protected objects or protected object groups for the API security protection module.
ModifyApisecApiResource ModifyApisecApiResource Modifies the annotation of an API asset in the API security module of Web Application Firewall (WAF).
DescribeUserEventType DescribeUserEventType Queries the types and statistics of user security events.
DescribeUserEventTrend Query API security attack trend Queries the trend of API security attacks.
DescribeUserAsset Query API security user asset statistics Queries API security user asset statistics.
DescribeUserApiRequest DescribeUserApiRequest Queries traffic statistics for an API operation.
DescribeUserAbnormalType DescribeUserAbnormalType Queries user risk types and statistics related to API security in Web Application Firewall (WAF).
DescribeUserAbnormalTrend DescribeUserAbnormalTrend Queries the trend of API security risks for a Web Application Firewall (WAF) instance.
DescribeSensitiveStatistic Query sensitive data statistics for tracing audits Queries sensitive data statistics for tracing audits.
DescribeSensitiveRequests Query sensitive data tracing results Queries the results of sensitive data tracing.
DescribeSensitiveRequestLog Query access logs of sensitive data Queries the access log information of sensitive data.
DescribeSensitiveOutboundTrend Query cross-border transfer trend of personal information Queries the trend of cross-border transfer of personal information data.
DescribeSensitiveOutboundStatistic DescribeSensitiveOutboundStatistic Queries statistics about outbound transfers of personal information.
DescribeSensitiveOutboundDistribution DescribeSensitiveOutboundDistribution Queries the distribution of outbound traffic that contains personal information.
DescribeSensitiveDetectionResult Query API security compliance detection results Queries the detection results of API security compliance requirements.
DescribeSensitiveApiStatistic Query statistics on sites and API operations that involve personal information Queries statistics on sites and API operations that involve personal information.
DescribeFreeUserEvents Query API security basic detection events Queries the list of security events detected by API security basic detection.
DescribeFreeUserEventTypes DescribeFreeUserEventTypes Queries the types of security events for basic API security detection.
DescribeFreeUserEventCount Query security event statistics of API security basic detection Queries the security event statistics of API security basic detection.
DescribeFreeUserAssetCount DescribeFreeUserAssetCount Queries statistics information about assets detected by the basic API security feature.
DescribeApisecUserOperations DescribeApisecUserOperations Queries user operation records for API security of Web Application Firewall (WAF).
DescribeApisecSuggestions Query protection suggestions for API assets Queries protection suggestions for API assets.
DescribeApisecStatistics DescribeApisecStatistics Queries statistics for API security risks or security events.
DescribeApisecRules DescribeApisecRules Queries the rules of an API security policy.
DescribeApisecProtectionResources Query the list of API security protected objects Queries the list of protected objects for which API security protection is enabled.
DescribeApisecProtectionGroups DescribeApisecProtectionGroups Retrieves a list of active API security protection object groups.
DescribeApisecMatchedHosts Query the domain name list for API security detection Queries the list of domain names for API security detection.
DescribeApisecEvents DescribeApisecEvents Queries a list of API security events.
DescribeApisecEventDetail DescribeApisecEventDetail Retrieves the details of an API security event.
DescribeApisecLogDeliveries DescribeApisecLogDeliveries Queries the configurations of API security log subscription.
DescribeApisecSlsLogStores DescribeApisecSlsLogStores Queries the Logstores whose names start with apisec- in Simple Log Service.
DescribeApisecSlsProjects DescribeApisecSlsProjects Queries the projects whose names start with apisec- in Simple Log Service.
ModifyApisecLogDelivery ModifyApisecLogDelivery Updates the API security log subscription settings.
DescribeApisecExamples DescribeApisecExamples Queries the API security examples that are detected by Web Application Firewall (WAF).

Report information

API

Title

Description

DescribeNetworkFlowTimeSeriesMetric DescribeNetworkFlowTimeSeriesMetric Queries the time series statistics of all traffic, including malicious requests and normal service requests.
DescribeSecurityEventTopNMetric Query top attack traffic statistics Queries the top N statistics of attack traffic, which is aggregated by a specified dimension, sorted, and returned.
DescribeSecurityEventTimeSeriesMetric DescribeSecurityEventTimeSeriesMetric Queries the time series data of attack traffic. Attack requests are requests that hit a rule and are identified as a threat.
DescribeSecurityEventLogs DescribeSecurityEventLogs Queries the detailed logs of attack traffic. Each log entry contains the details of a request that matched a protection rule.
DescribeNetworkFlowTopNMetric DescribeNetworkFlowTopNMetric Queries the top N statistics for all traffic that passes through Web Application Firewall (WAF), including malicious and normal service requests. The results are aggregated by different dimensions and sorted in descending order.
DescribeFlowChart DescribeFlowChart Queries the traffic statistics.
DescribePeakTrend DescribePeakTrend Queries the trend of queries per second (QPS).
DescribeResponseCodeTrendGraph View response code trends Queries the trends of abnormal response codes, such as 5XX, 405, 499, 302, and 444, returned by WAF to clients and by origin servers to WAF.
DescribeVisitUas Query top 10 user-Agents by traffic Queries the top 10 User-Agents that initiate the most requests.
DescribeVisitTopIp Query top 10 IP addresses by traffic Queries the top 10 IP addresses that initiate the most requests.
DescribeRuleHitsTopResource DescribeRuleHitsTopResource Queries the top 10 protected objects that triggered protection rules most frequently.
DescribeRuleHitsTopTuleType DescribeRuleHitsTopTuleType Queries the top 10 most frequently triggered protection rule types.
DescribeFlowTopResource DescribeFlowTopResource Queries the top 10 protected objects by request count.
DescribeFlowTopUrl DescribeFlowTopUrl Queries the top 10 most requested URLs.
DescribeThreatEventDetail DescribeThreatEventDetail Retrieves the details of a security event that requires attention.
DescribeThreatEvent DescribeThreatEvent Queries a paginated list of notable security events.
DescribeThreatEventTopMetric Query top statistics of security events Queries the top 5 statistics of security events aggregated by different statistical objects and sorted in descending order.
DescribeAlarmList DescribeAlarmList Queries a list of alerts.
DescribeAlarmBanner DescribeAlarmBanner Queries the alert banner information of a Web Application Firewall (WAF) instance.

Log configuration

API

Title

Description

DescribeUserLogFieldConfig DescribeUserLogFieldConfig Queries the log field configuration of a Web Application Firewall (WAF) instance, including additional fields, removed fields, delivery strategies, and extended settings.
ModifyUserLogFieldConfig ModifyUserLogFieldConfig Modifies the default log field configuration of a Web Application Firewall (WAF) instance for log delivery to Simple Log Service.
DescribeCommonLogFields DescribeCommonLogFields Queries all log fields supported by Simple Log Service for Web Application Firewall (WAF).
ModifyUserWafLogStatus ModifyUserWafLogStatus Enables or disables Simple Log Service for Web Application Firewall (WAF).
DescribeUserWafLogStatus DescribeUserWafLogStatus Queries the status, region ID, and status modification time of Web Application Firewall (WAF) logs.
DescribeUserSlsLogRegions Query available log storage regions Queries the log storage regions available to the user.
DescribeSlsAuthStatus DescribeSlsAuthStatus Queries the Logstore authorization status.
DescribeSlsLogStoreStatus DescribeSlsLogStoreStatus Queries the status of a Simple Log Service Logstore.
DescribeSlsLogStore DescribeSlsLogStore Retrieves Logstore information, including total capacity, storage duration, and used capacity.
ModifyResourceLogStatus Modify the log status of a protected object Modifies the log status of a protected object.
DescribeResourceLogStatus Query log status of protected objects Queries the log status of protected objects.
CreateLogDeliveryConfig CreateLogDeliveryConfig Creates a log delivery configuration for a Web Application Firewall (WAF) instance in a hybrid cloud.
ModifyLogDeliveryConfig ModifyLogDeliveryConfig Modifies a log delivery configuration for a hybrid cloud cluster.
DeleteLogDeliveryConfig DeleteLogDeliveryConfig Deletes a log delivery configuration.
DescribeLogDeliveryConfig DescribeLogDeliveryConfig Queries a single log delivery configuration for a hybrid cloud.
DescribeLogDeliveryConfigs DescribeLogDeliveryConfigs Queries all log delivery configurations of a Web Application Firewall (WAF) instance for hybrid cloud.
ModifyResourceLogFieldConfig ModifyResourceLogFieldConfig Modifies the log field configuration of a protected object.
DescribeResourceLogFieldConfig DescribeResourceLogFieldConfig Queries the log field configuration for a protected object.
ModifyResourceLogDeliveryStatus ModifyResourceLogDeliveryStatus Modifies the log delivery status of a protected object in Web Application Firewall (WAF).
DescribeResourceLogDeliveryStatus DescribeResourceLogDeliveryStatus Queries the log delivery status for protected objects.

Hybrid cloud cluster management

API

Title

Description

DescribeHybridCloudClusterServers DescribeHybridCloudClusterServers Queries the servers in a hybrid cloud Web Application Firewall (WAF) cluster.
DescribeHybridCloudBasicMonitor DescribeHybridCloudBasicMonitor Queries the system status of a node in a hybrid cloud cluster.
CreateHybridCloudCluster CreateHybridCloudCluster Creates a hybrid cloud Web Application Firewall (WAF) cluster.
DescribeHybridCloudServerRegions DescribeHybridCloudServerRegions Queries hybrid cloud server regions, including carriers, continents, and cities.
DescribeHybridCloudUnassignedMachines DescribeHybridCloudUnassignedMachines Queries the list of unassigned servers in a hybrid cloud cluster.
ModifyHybridCloudClusterBypassStatus ModifyHybridCloudClusterBypassStatus Modifies the manual bypass status for a hybrid cloud cluster that is integrated with an SDK.
DescribeHybridCloudUser DescribeHybridCloudUser Queries the available HTTP and HTTPS port ranges for hybrid cloud access.
DescribeHybridCloudGroups DescribeHybridCloudGroups Queries the Hybrid Cloud WAF node groups that are added to Web Application Firewall (WAF).
CreateHybridCloudGroup CreateHybridCloudGroup Creates a node group in a Hybrid Cloud Web Application Firewall (WAF) cluster.
DescribeHybridCloudClusterRule DescribeHybridCloudClusterRule Retrieves a hybrid cloud cluster rule.
DescribeHybridCloudClusters DescribeHybridCloudClusters Queries a list of hybrid cloud clusters.
ModifyHybridCloudClusterRule Modify hybrid cloud cluster rule information Modifies the rule information of a hybrid cloud cluster.
ModifyHybridCloudGroup ModifyHybridCloudGroup Modifies the information of a cluster group.
ModifyHybridCloudGroupExpansionServer ModifyHybridCloudGroupExpansionServer Adds a node to a node group in a hybrid cloud cluster of a Web Application Firewall (WAF) instance.
ModifyHybridCloudGroupShrinkServer Delete nodes from a cluster group Deletes nodes from a cluster group.
ModifyHybridCloudSdkPullinStatus ModifyHybridCloudSdkPullinStatus Modifies the traffic redirection status of a hybrid cloud SDK.
ModifyHybridCloudServer Modify hybrid cloud node information Modifies hybrid cloud node information.
DeleteHybridCloudClusterRule DeleteHybridCloudClusterRule Deletes a hybrid cloud cluster rule from a Web Application Firewall (WAF) instance.
CreateHybridCloudClusterRule CreateHybridCloudClusterRule Creates a Hybrid Cloud Web Application Firewall (WAF) cluster rule.
DescribeHybridCloudClusterRules DescribeHybridCloudClusterRules Cluster rules
DescribeHybridCloudProcessMonitor DescribeHybridCloudProcessMonitor Queries the status of applications on nodes in a hybrid cloud Web Application Firewall (WAF) cluster.
DescribeHybridCloudResourceDetail Query hybrid cloud domain name details Queries the details of a hybrid cloud domain name.
DescribeHybridCloudSdkServers DescribeHybridCloudSdkServers Queries the hybrid cloud SDK servers that are managed by a Web Application Firewall (WAF) instance.
DescribeHybridCloudSupportRegions DescribeHybridCloudSupportRegions Queries the regions that are supported for hybrid cloud access in Web Application Firewall (WAF).
DescribeHybridCloudUnsupportPorts DescribeHybridCloudUnsupportPorts Queries the list of unsupported ports for a hybrid cloud.
DeleteHybridCloudGroup DeleteHybridCloudGroup Deletes a group.
ModifyHybridCloudCluster ModifyHybridCloudCluster Updates hybrid cloud cluster settings, such as the cluster name, ports, and access mode.

Multi-account management

API

Title

Description

CreateMemberAccounts CreateMemberAccounts Adds member accounts to use the multi-account management feature of Web Application Firewall (WAF).
ModifyMemberAccount ModifyMemberAccount Modifies the information of a member account that is managed by the multi-account management feature of Web Application Firewall (WAF).
DeleteMemberAccount DeleteMemberAccount Deletes a Web Application Firewall (WAF) member account.
DescribeAccountDelegatedStatus Query whether a user is a WAF delegated administrator Queries whether the current user is a delegated administrator of WAF in the multi-account management feature.
DescribeMemberAccounts DescribeMemberAccounts Retrieves all member accounts managed by the WAF multi-account management feature.

Pricing inquiry

API

Title

Description

DescribeChargeResult DescribeChargeResult Queries the billing results for Web Application Firewall (WAF).
DescribeChargeModule DescribeChargeModule Retrieves the billing module information of Web Application Firewall (WAF).

Others

API

Title

Description

ModifyPauseProtectionStatus ModifyPauseProtectionStatus Modifies the protection status of Web Application Firewall (WAF).
CreatePocFunction CreatePocFunction Starts a trial for a proof of concept (POC) feature.
DescribePocFunctions DescribePocFunctions Retrieves the enabled proof of concept (POC) feature trials.
DescribeRoleAuthStatus DescribeRoleAuthStatus Queries the authorization status of the service-linked role for Web Application Firewall (WAF).
InitializeWafOperationRole InitializeWafOperationRole Initializes a service-linked role for WAF.
DescribeElasticBills DescribeElasticBills Queries the daily bills for WAF pay-as-you-go instances for the last 7 days.
DescribePrepayDailyBills Query burstable billing details of a subscription WAF instance Queries the burstable pay-as-you-go billing details of a subscription WAF instance, such as burstable QPS.
DescribeUserTraffic Query user traffic Queries the real-time traffic of a user by traffic type.
ChangeResourceGroup Change resource group Modifies the resource group to which a protected object belongs.
CreateCloudResource Connect a cloud service to WAF Connects a cloud service to WAF in cloud native mode. Currently, only ECS and CLB are supported.
CreateDomain Add a CNAME access resource Adds a domain name to a WAF instance by using Website Config for protection.
DeleteCloudResource DeleteCloudResource Removes a cloud service from Web Application Firewall (WAF). This operation currently supports only Elastic Compute Service (ECS) and Classic Load Balancer (CLB).
DeleteDomain Delete a cNAME-connected resource Deletes a CNAME-connected domain name.
DescribeDDoSStatus Query current DDoS attack status Queries whether the current WAF instance is under a DDoS attack.
DescribeDomainDetail Query CNAME access details Queries the Website Config details.
DescribePostpayBills Query pay-as-you-go bills Queries the list of pay-as-you-go bills.
DescribeRuleHitsTopClientIp DescribeRuleHitsTopClientIp Queries the top 10 source IP addresses from which the most attacks originated.
DescribeRuleHitsTopRuleId Query top 10 rule iDs by rule hits Queries the top 10 rule IDs that have triggered mitigation policies the most times.
DescribeRuleHitsTopUa Query top 10 attack user-Agents Queries the top 10 User-Agents that initiated the most attacks.
DescribeRuleHitsTopUrl Query top 10 uRLs with protection rule hits Queries the top 10 URLs that trigger protection rules the most.
ListTagKeys Query tag keys Queries tag keys.
ListTagResources ListTagResources Queries the tags that are added to a resource.
ListTagValues Query tag values of a specified tag key Queries the tag values that correspond to a specified tag key.
ReleaseInstance ReleaseInstance Releases a Web Application Firewall (WAF) 3.0 instance.
TagResources TagResources Adds tags to resources.
UntagResources UntagResources Removes tags from resources and then deletes the tags.