All Products
Search
Document Center

Web Application Firewall:API overview

Last Updated:Aug 14, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (waf-openapi/2021-10-01) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

Instance information

API

Title

Description

CreatePostpaidInstance Create a WAF 3.0 pay-as-you-go instance Creates a Web Application Firewall (WAF) 3.0 pay-as-you-go instance.
DescribeInstance Retrieve WAF instance details Retrieves the details of a WAF instance in the current Alibaba Cloud account.
ReleaseInstance ReleaseInstance Releases a Web Application Firewall (WAF) 3.0 instance.

Access configuration

API

Title

Description

Cloud native mode Cloud native mode
DescribeAbnormalCloudResources DescribeAbnormalCloudResources Queries abnormal cloud resources added in cloud native mode.
ReCreateCloudResource Re-connect a cloud service to WAF Re-connects a cloud service to WAF. This operation is used only when the cloud native mode connection status is protection exception.
SyncProductInstance SyncProductInstance Synchronizes Elastic Compute Service (ECS), Classic Load Balancer (CLB), and Network Load Balancer (NLB) instances to Web Application Firewall (WAF).
DescribeCloudResources DescribeCloudResources Queries the list of cloud services added to Web Application Firewall (WAF).
DescribeResourcePort DescribeResourcePort Queries the ports of a cloud service instance that are added to Web Application Firewall (WAF).
DescribeProductInstances Query synchronized cloud service assets Queries the list of synchronized cloud service assets.
DescribeResourceSupportRegions Query supported regions for cloud native mode Queries the list of supported regions for cloud native mode, mainly for CLB and ECS products.
DescribeResourceRegionId DescribeResourceRegionId Queries the region IDs of cloud service resources that can be added to Web Application Firewall (WAF) by using the SDK.
DescribeResourceInstanceCerts Query the certificate list of a cloud service instance Queries the certificate list of a cloud service instance. This operation returns the certificate list of the current delegated administrator and the user who owns the instance. This operation is used only in multi-account scenarios. For example, if user A is the delegated administrator and has certificate cert1, and cloud service instance lb-xx-1 belongs to member user B and has certificate cert2, when you query instance lb-xx-1, the operation returns both cert1 and cert2.
CreateCloudResource Connect a cloud service to WAF Connects a cloud service to WAF in cloud native mode. Supported cloud services include ECS, CLB, NLB, and DDoS.
ModifyCloudResource Modify cloud native mode configuration Modifies the configuration of a cloud service that is connected to WAF.
DeleteCloudResource DeleteCloudResource Removes a cloud service from Web Application Firewall (WAF). This operation currently supports only Elastic Compute Service (ECS) and Classic Load Balancer (CLB).
DescribeCloudResourceAccessedPorts DescribeCloudResourceAccessedPorts Queries the ports of cloud services added to Web Application Firewall (WAF). This operation is supported only for Elastic Compute Service (ECS) and Classic Load Balancer (CLB).
DescribeCloudResourceAccessPortDetails Query port details of cloud service instances connected to WAF Queries the port details of cloud service instances that are connected to WAF.
ModifyCloudResourceCert Modify the certificate for a cloud native mode resource Modifies the certificate for a cloud native mode resource.
DescribeCloudResourceList Query cloud native mode WAF configuration list Queries the list of resources connected to WAF in cloud native mode.
ModifyCloudResourceDefaultCert Modify the default certificate for a cloud service Modifies the default certificate for a cloud native mode resource.
DeleteCloudResourceExtensionCert Delete an extension certificate for a cloud service Deletes an extension certificate for a cloud service connected in cloud native mode.
CreateCloudResourceExtensionCert Add an extension certificate for a cloud native mode resource Adds an extension certificate for a cloud native mode resource.
CNAME access CNAME access
DescribeDomainUsedPorts Query all ports used by user domain names Queries all ports used by domain names of the current user. Only domain names with CNAME access and hybrid cloud CNAME domain names with public network disaster recovery enabled are included.
CreateDomain Add a cNAME-based access resource Adds a domain name to a WAF instance for Website Config.
ModifyDomain Modify CNAME access resource Modifies a CNAME-based domain name.
DeleteDomain Delete a cNAME-connected resource Deletes a CNAME-connected domain name.
DescribeDomains DescribeDomains Queries the domain names that are added to Web Application Firewall (WAF).
DescribeDomainDetail Query CNAME access details Queries the details of a Website Config.
DescribePunishedDomains DescribePunishedDomains Queries penalties for domain names added to Web Application Firewall (WAF) without an Internet Content Provider (ICP) filing.
ModifyDomainPunishStatus Re-connect a domain name in ICP filing violation penalty status Re-connects a domain name that is in the ICP filing violation penalty status.
DescribeCertDetail Query certificate details Queries the details of a certificate, such as the certificate name, expiration time, issuance time, and associated domain name.
DescribeCerts Query available certificates for a user Queries the certificate list of a user.
DescribeDomainDNSRecord Query CNAME DNS resolution status Queries whether the DNS settings of a domain name are correct.
DescribeWafSourceIpSegment Query back-to-origin CIDR blocks of a WAF instance Queries the back-to-origin CIDR blocks of WAF.
DescribeDDoSStatus Query current DDoS attack status Queries whether the current WAF instance is under a DDoS attack.
CreateSM2Cert Upload SM certificate for cNAME-based WAF access Uploads a China National Cryptographic Algorithm (SM) certificate for a domain that is added to WAF in CNAME mode.
DescribeCnameCount Query the total number of added domain names Queries the total number of domain names that are added to WAF, including domain names added through CNAME and hybrid cloud access.
DescribeDefaultHttps Query default SSL/TLS settings Queries the default SSL/TLS settings.
ModifyDefaultHttps Modify default SSL/TLS settings Modifies the default SSL/TLS settings.
CreateCerts Upload an international certificate to WAF for cNAME-based access Uploads an international certificate to WAF for CNAME-based access.
VerifyDomainOwner VerifyDomainOwner Verifies that you own the specified domain name. Domain ownership must be verified before you can add a domain name to Web Application Firewall (WAF) by using CNAME access.
DescribeVerifyContent DescribeVerifyContent Queries the domain ownership verification content of a Web Application Firewall (WAF) instance.
ModifyDomainCert Modify the certificate of a domain name Modifies the certificate of a domain name.
Hybrid cloud access Hybrid cloud access
DescribeHybridCloudResources Query hybrid cloud CNAME access list Queries the list of hybrid cloud domain names.
DescribeHybridCloudProtectableCount DescribeHybridCloudProtectableCount Queries the count of protectable nodes that can be added to a hybrid cloud cluster.

Protection configuration

API

Title

Description

Protected objects Protected objects
CreateDefenseResource Create a protected object Creates a protected object.
DeleteDefenseResource Delete a protected object Deletes a protected object.
CreateDefenseResourceGroup CreateDefenseResourceGroup Creates a protected object group.
ModifyDefenseResourceGroup ModifyDefenseResourceGroup Modifies the configuration of a protected object group.
DeleteDefenseResourceGroup DeleteDefenseResourceGroup Deletes a protected object group.
DescribeDefenseResourceGroup DescribeDefenseResourceGroup Retrieves the details of a protected object group.
DescribeDefenseResourceGroups DescribeDefenseResourceGroups Retrieves information about protected object groups using pagination.
DescribeDefenseResourceGroupNames DescribeDefenseResourceGroupNames Queries the names of protected object groups.
DescribeDefenseResource Query a single protected object Query a single protected object.
DescribeDefenseResources Query protected objects by paging Queries protected objects by paging.
DescribeDefenseResourceNames DescribeDefenseResourceNames Performs a pagination query to retrieve the names of protected objects.
DescribeDefenseResourceOwnerUid Query asset owner account of a protected object Queries the asset owner account of a protected object in a multi-account management feature scenario.
ModifyDefenseResourceXff ModifyDefenseResourceXff Modifies the cookie settings of a protected object and the method to identify the originating IP addresses of clients.
DescribePauseProtectionStatus DescribePauseProtectionStatus Queries the protection pause status of a Web Application Firewall (WAF) instance.
DescribeDefenseGroupValidResources DescribeDefenseGroupValidResources Queries a paginated list of protected objects that can be associated with a defense group.
Protection rules Protection rules
DescribeBaseRuleChangeLog Query rule group rule update history Queries the change records of rule group rules by paging.
CreateDefenseTemplate Create a protection template Creates a protection template.
ModifyDefenseTemplate ModifyDefenseTemplate Modifies a defense template.
ModifyDefenseTemplateStatus ModifyDefenseTemplateStatus Changes the status of a protection rule template.
CopyDefenseTemplate CopyDefenseTemplate Copies a protection template.
DeleteDefenseTemplate DeleteDefenseTemplate Deletes a protection rule template.
DescribeDefenseTemplate DescribeDefenseTemplate Retrieves the details of a specific protection template.
DescribeDefenseTemplates Query protection templates by paging Queries a list of protection templates by paging.
ModifyTemplateResources ModifyTemplateResources Attaches protected objects to or detaches protected objects from a protection template.
DescribeTemplateResources Query resources bound to a protection template Queries the resources bound to a protection template.
DescribeTemplateResourceCount DescribeTemplateResourceCount Queries the number of protected resources that are associated with one or more protection templates.
DescribeDefenseTemplateValidResources DescribeDefenseTemplateValidResources Queries a paginated list of protected objects that are valid for a specified protection template.
DescribeDefenseTemplateValidGroups DescribeDefenseTemplateValidGroups Queries the names of protected object groups that can be associated with a specific protection template.
DescribeDefenseResourceTemplates Query protection templates of a protected object or protected object group Queries the protection templates of a protected object or a protected object group.
CreateDefenseRule Create a web core protection rule Creates a web core protection rule.
ModifyDefenseRule Modify a protection rule Modifies the configuration of a protection rule.
ModifyDefenseRuleStatus Modify protection rule status Modifies the status of a protection rule.
DeleteDefenseRule Delete a protection rule Deletes a protection rule.
DescribeDefenseRules DescribeDefenseRules Queries a paginated list of protection rules.
DescribeDefenseRule Query a single protection rule Queries a single protection rule.
ModifyDefenseRuleCache ModifyDefenseRuleCache Updates the cache for a web tamper-proofing rule.
DeleteDefenseRuleBlockIp DeleteDefenseRuleBlockIp Unblocks an IP address that is blocked by the scan protection module.
DescribeRelatedDefenseRules Query associated protection rules by paging Queries associated protection rules by using paging.
DescribeIpAbroadCountryInfos DescribeIpAbroadCountryInfos Retrieves supported countries and regions outside China for IP-based region blacklist.
DescribeRuleGroups DescribeRuleGroups Queries a paginated list of regular expression rule groups.
ModifyDefenseSceneConfig ModifyDefenseSceneConfig Modifies the mitigation settings for a protection scenario.
DescribeDefenseSceneConfig DescribeDefenseSceneConfig Queries the protection configurations for a specific defense scenario.
DescribeDefenseRuleStatistics Query protection rule statistics Queries statistics of rules under a specified WAF protection module.
DescribeBaseSystemRules Query web core protection system rules Queries the system rules of Web core protection.
DescribeCustomBaseRuleCompileResult DescribeCustomBaseRuleCompileResult Describes the compilation result of a custom regular expression rule.
DescribeBotRuleLabels Query bot management rule tags Queries the tag information of bot management rules.
DescribeBotAppKey DescribeBotAppKey Queries the AppKey for bot management.
Critical event protection Critical event protection
CreateMajorProtectionBlackIp Add IP blacklist for critical event protection Adds IP addresses to the IP blacklist for critical event protection in WAF.
ModifyMajorProtectionBlackIp Modify IP blacklist for critical event protection scenario Modifies the IP blacklist for a critical event protection scenario.
DeleteMajorProtectionBlackIp Delete blacklisted iPs from a critical event protection scenario Deletes blacklisted IPs from a critical event protection scenario.
ClearMajorProtectionBlackIp Clear the IP blacklist for a critical event protection scenario Clears the IP blacklist for a critical event protection scenario.
DescribeMajorProtectionBlackIps Query critical event protection IP blacklist by page Queries blacklisted IPs for critical event protection by paged query.
Address books Address books
AddAddress Add addresses to an address book Adds addresses to an address book.
DescribeAddresses Query address book addresses by page Queries addresses in an address book by paging.
DeleteAddress Delete addresses from an address book Deletes addresses from an address book.
ClearAddress Clear all addresses from an address book Clears all addresses from an address book.

API security

API

Title

Description

DeleteApisecAbnormals Batch delete API security risks Deletes API security risks in batches.
ModifyApisecAbnormals ModifyApisecAbnormals Modifies the status of API security risks in batches.
DescribeApisecAssetTrend Query API security API asset trends Queries the trend of API security API assets.
DescribeApisecAbnormalDomainStatistic Query API security risk domain name statistics Queries statistics on API security risk domain names.
DescribeApisecEventDomainStatistic Query API security event domain name statistics Queries the domain name statistics of API security events.
DescribeApisecSensitiveDomainStatistic Query API security sensitive data domain name statistics Queries statistics on data endpoints associated with API security sensitive data domains.
ModifyApisecEvents Batch modify API security event statuses Modifies the statuses of multiple API security events in a batch.
DeleteApisecEvents Batch delete API security events Deletes API security events in batches.
ModifyApisecLogDeliveryStatus Modify API security log subscription status Modifies the subscription status of API security logs.
CreateApiExport Create an API security data export task Creates an API security data export task.
DescribeApiExports Query API security export tasks Queries the list of API security export tasks.
DescribeApisecAbnormals Query API security risks Queries the list of API security risks.
DescribeApisecApiResources Query API security assets Queries the list of API security assets.
ModifyApisecStatus Modify API security status Modifies the status of protected objects or protected object groups for API security.
ModifyApisecModuleStatus Modify API security protection module status Modifies the status of protected objects or protected object groups for the API security protection module.
ModifyApisecApiResource ModifyApisecApiResource Modifies the annotation of an API asset in the API security module of Web Application Firewall (WAF).
DescribeUserEventType Query API security event types and statistics Queries the security event types and statistics for API security users.
DescribeUserEventTrend Query API security attack trend Queries the attack trend of API security.
DescribeUserAsset Query API security user asset statistics Queries API security user asset statistics.
DescribeUserApiRequest DescribeUserApiRequest Queries traffic statistics for an API operation.
DescribeUserAbnormalType DescribeUserAbnormalType Queries user risk types and statistics related to API security in Web Application Firewall (WAF).
DescribeUserAbnormalTrend DescribeUserAbnormalTrend Queries the trend of API security risks for a Web Application Firewall (WAF) instance.
DescribeSensitiveStatistic Query sensitive data statistics of tracing watermark audits Queries the sensitive data statistics of tracing watermark audits.
DescribeSensitiveRequests Query sensitive data tracing results Queries the results of sensitive data tracing.
DescribeSensitiveRequestLog Query access logs of sensitive data Queries the access log information of sensitive data.
DescribeSensitiveOutboundTrend Query cross-border transfer trend of personal information Queries the trend of cross-border transfer of personal information data.
DescribeSensitiveOutboundStatistic DescribeSensitiveOutboundStatistic Queries statistics about outbound transfers of personal information.
DescribeSensitiveOutboundDistribution Query cross-border personal information traffic distribution Queries the distribution of cross-border traffic that contains personal information.
DescribeSensitiveDetectionResult Query API security compliance detection results Queries the detection results of API security compliance requirements.
DescribeSensitiveApiStatistic Query statistics on sites and API operations that involve personal information Queries statistics on sites and API operations that involve personal information.
DescribeFreeUserEvents Query API security basic detection events Queries the list of security events detected by API security basic detection.
DescribeFreeUserEventTypes DescribeFreeUserEventTypes Queries the types of security events for basic API security detection.
DescribeFreeUserEventCount Query security event statistics of API security basic detection Queries the security event statistics of API security basic detection.
DescribeFreeUserAssetCount DescribeFreeUserAssetCount Queries statistics information about assets detected by the basic API security feature.
DescribeApisecUserOperations DescribeApisecUserOperations Queries user operation records for API security of Web Application Firewall (WAF).
DescribeApisecSuggestions Query protection suggestions for API assets Queries protection suggestions for API assets.
DescribeApisecStatistics DescribeApisecStatistics Queries statistics for API security risks or security events.
DescribeApisecRules DescribeApisecRules Queries the rules of an API security policy.
DescribeApisecProtectionResources Query the list of API security protected objects Queries the list of protected objects for which API security protection is enabled.
DescribeApisecProtectionGroups DescribeApisecProtectionGroups Retrieves a list of active API security protection object groups.
DescribeApisecMatchedHosts Query the domain name list for API security detection Queries the list of domain names for API security detection.
DescribeApisecEvents Query API security events Queries the list of API security events.
DescribeApisecEventDetail Query API security event details Queries the details of an API security event.
DescribeApisecLogDeliveries DescribeApisecLogDeliveries Queries the configurations of API security log subscription.
DescribeApisecSlsLogStores Query logstores in simple log service Queries the list of Logstores in Simple Log Service.
DescribeApisecSlsProjects Query simple log service projects Queries the list of Simple Log Service projects.
ModifyApisecLogDelivery Modify API security log subscription Modifies the API security log subscription.
DescribeApisecExamples Query API security sample information Queries API security sample information.

Report information

API

Title

Description

DescribeNetworkFlowTimeSeriesMetric DescribeNetworkFlowTimeSeriesMetric Queries the time series statistics of all traffic, including malicious requests and normal service requests.
DescribeSecurityEventTopNMetric Query top attack traffic statistics Queries the top N statistics of attack traffic, which is aggregated by a specified dimension, sorted, and returned.
DescribeSecurityEventTimeSeriesMetric DescribeSecurityEventTimeSeriesMetric Queries the time series data of attack traffic. Attack requests are requests that hit a rule and are identified as a threat.
DescribeSecurityEventLogs DescribeSecurityEventLogs Queries the detailed logs of attack traffic. Each log entry contains the details of a request that matched a protection rule.
DescribeNetworkFlowTopNMetric DescribeNetworkFlowTopNMetric Queries the top N statistics for all traffic that passes through Web Application Firewall (WAF), including malicious and normal service requests. The results are aggregated by different dimensions and sorted in descending order.
DescribeFlowChart DescribeFlowChart Queries the traffic statistics.
DescribePeakTrend DescribePeakTrend Queries the trend of queries per second (QPS).
DescribeResponseCodeTrendGraph View response code trends Queries the trends of abnormal response codes, such as 5XX, 405, 499, 302, and 444, returned by WAF to clients and by origin servers to WAF.
DescribeVisitUas Query top 10 user-Agents by traffic Queries the top 10 User-Agents that initiate the most requests.
DescribeVisitTopIp Query top 10 IP addresses by traffic Queries the top 10 IP addresses that initiate the most requests.
DescribeRuleHitsTopResource DescribeRuleHitsTopResource Queries the top 10 protected objects that triggered protection rules most frequently.
DescribeRuleHitsTopRuleId Query top 10 rule iDs by rule hits Queries the top 10 rule IDs that have triggered mitigation policies the most times.
DescribeRuleHitsTopTuleType DescribeRuleHitsTopTuleType Queries the top 10 most frequently triggered protection rule types.
DescribeRuleHitsTopUrl Query top 10 uRLs with protection rule hits Queries the top 10 URLs that trigger protection rules the most.
DescribeRuleHitsTopClientIp DescribeRuleHitsTopClientIp Queries the top 10 source IP addresses from which the most attacks originated.
DescribeFlowTopResource DescribeFlowTopResource Queries the top 10 protected objects by request count.
DescribeRuleHitsTopUa Query top 10 attack user-Agents Queries the top 10 User-Agents that initiated the most attacks.
DescribeFlowTopUrl DescribeFlowTopUrl Queries the top 10 most requested URLs.
DescribeThreatEventDetail DescribeThreatEventDetail Retrieves the details of a security event that requires attention.
DescribeThreatEvent DescribeThreatEvent Queries a paginated list of notable security events.
DescribeThreatEventTopMetric Query top statistics of security events Queries the top 5 statistics of security events aggregated by different statistical objects and sorted in descending order.
DescribeAlarmList DescribeAlarmList Queries a list of alerts.
DescribeAlarmBanner DescribeAlarmBanner Queries the alert banner information of a Web Application Firewall (WAF) instance.

Log configuration

API

Title

Description

DescribeUserLogFieldConfig Query default log field configuration Queries the default log field configuration of a user.
ModifyUserLogFieldConfig Modify default log field configuration for a user Modifies the default field configuration of the log service for a user.
DescribeCommonLogFields DescribeCommonLogFields Queries all log fields supported by Simple Log Service for Web Application Firewall (WAF).
ModifyUserWafLogStatus ModifyUserWafLogStatus Enables or disables Simple Log Service for Web Application Firewall (WAF).
DescribeUserWafLogStatus DescribeUserWafLogStatus Queries the status, region ID, and status modification time of Web Application Firewall (WAF) logs.
DescribeUserSlsLogRegions Query available log storage regions Queries the log storage regions available to the user.
DescribeSlsAuthStatus DescribeSlsAuthStatus Queries the Logstore authorization status.
DescribeSlsLogStoreStatus DescribeSlsLogStoreStatus Queries the status of a Simple Log Service Logstore.
DescribeSlsLogStore DescribeSlsLogStore Retrieves Logstore information, including total capacity, storage duration, and used capacity.
ModifyResourceLogStatus Modify the log status of a protected object Modifies the log status of a protected object.
DescribeResourceLogStatus Query log status of protected objects Queries the log status of protected objects.
CreateLogDeliveryConfig Create a hybrid cloud log delivery configuration Creates a log delivery configuration for hybrid cloud environments.
ModifyLogDeliveryConfig Modify hybrid cloud log delivery configuration Modifies the log delivery configuration for hybrid cloud.
DeleteLogDeliveryConfig Delete hybrid cloud log forwarding delivery configuration Deletes a hybrid cloud log forwarding delivery configuration.
DescribeLogDeliveryConfig DescribeLogDeliveryConfig Queries a single log delivery configuration for a hybrid cloud.
DescribeLogDeliveryConfigs DescribeLogDeliveryConfigs Queries all log delivery configurations of a Web Application Firewall (WAF) instance for hybrid cloud.
ModifyResourceLogFieldConfig Modify the log field configuration of a protected object Modifies the log field configuration of a protected object.
DescribeResourceLogFieldConfig DescribeResourceLogFieldConfig Queries the log field configuration for a protected object.
ModifyResourceLogDeliveryStatus ModifyResourceLogDeliveryStatus Modifies the log delivery status of a protected object in Web Application Firewall (WAF).
DescribeResourceLogDeliveryStatus Query log delivery status of protected objects Queries the log delivery status of protected objects.

Hybrid cloud cluster management

API

Title

Description

DescribeHybridCloudClusterServers List cluster machines Queries the list of machines in a cluster.
DescribeHybridCloudBasicMonitor Query hybrid cloud cluster node system status Queries the system status of hybrid cloud cluster nodes.
CreateHybridCloudCluster CreateHybridCloudCluster Creates a hybrid cloud Web Application Firewall (WAF) cluster.
DescribeHybridCloudServerRegions Query regions supported by hybrid cloud Queries the dictionary of region information supported by hybrid cloud, including ISPs, continents, and cities.
DescribeHybridCloudUnassignedMachines Query unassigned servers in a hybrid cloud cluster Queries the list of unassigned servers in a hybrid cloud cluster.
ModifyHybridCloudClusterBypassStatus Modify manual bypass switch for hybrid cloud SDK integration cluster Modifies the manual bypass switch for a hybrid cloud SDK integration cluster.
DescribeHybridCloudUser Query hybrid cloud customer ports Queries the port ranges that a customer is allowed to use for hybrid cloud access. The response includes both HTTP and HTTPS ports.
DescribeHybridCloudGroups Query hybrid cloud node groups in a cluster Queries the list of hybrid cloud node groups added to Web Application Firewall (WAF).
CreateHybridCloudGroup CreateHybridCloudGroup Creates a node group in a Hybrid Cloud Web Application Firewall (WAF) cluster.
DescribeHybridCloudClusterRule Retrieve hybrid cloud cluster rule information Retrieves the rule information of a hybrid cloud cluster.
DescribeHybridCloudClusters DescribeHybridCloudClusters Queries a list of hybrid cloud clusters.
ModifyHybridCloudClusterRule Modify hybrid cloud cluster rule information Modifies the rule information of a hybrid cloud cluster.
ModifyHybridCloudGroup Modify cluster group information Modifies cluster group information.
ModifyHybridCloudGroupExpansionServer ModifyHybridCloudGroupExpansionServer Adds a node to a node group in a hybrid cloud cluster of a Web Application Firewall (WAF) instance.
ModifyHybridCloudGroupShrinkServer Delete nodes from a cluster group Deletes nodes from a cluster group.
ModifyHybridCloudSdkPullinStatus Modify hybrid cloud SDK traffic redirection status Modifies the traffic redirection status of the hybrid cloud SDK.
ModifyHybridCloudServer Modify hybrid cloud node information Modifies hybrid cloud node information.
DeleteHybridCloudClusterRule Delete a hybrid cloud cluster rule Deletes cluster rule information.
CreateHybridCloudClusterRule Create cluster rule information Creates cluster rule information.
DescribeHybridCloudClusterRules DescribeHybridCloudClusterRules Cluster rules
DescribeHybridCloudProcessMonitor Query hybrid cloud cluster node application status Queries the application status of hybrid cloud cluster nodes.
DescribeHybridCloudResourceDetail Query hybrid cloud domain name details Queries the details of a hybrid cloud domain name.
DescribeHybridCloudSdkServers Query hybrid cloud SDK list Queries the list of hybrid cloud SDKs.
DescribeHybridCloudSupportRegions Query access regions Queries the access regions.
DescribeHybridCloudUnsupportPorts DescribeHybridCloudUnsupportPorts Queries the list of unsupported ports for a hybrid cloud.
DeleteHybridCloudGroup DeleteHybridCloudGroup Deletes a group.
ModifyHybridCloudCluster Modify cluster information Modifies cluster information.

Multi-account management

API

Title

Description

CreateMemberAccounts Add member accounts Adds WAF member accounts in the multi-account management feature.
ModifyMemberAccount Modify a member account Modifies the information of member accounts in the multi-account management feature.
DeleteMemberAccount Delete a member account Deletes a WAF member account from the multi-account management feature.
DescribeAccountDelegatedStatus Query whether a user is a WAF delegated administrator Queries whether the current user is a delegated administrator of WAF in the multi-account management feature.
DescribeMemberAccounts Query all member accounts Queries the information about all member accounts in the WAF multi-account management feature.

Resource group management

API

Title

Description

ChangeResourceGroup Change resource group Modifies the resource group to which a protected object belongs.

Tag management

API

Title

Description

ListTagKeys Query tag keys Queries tag keys.
UntagResources UntagResources Removes tags from resources and then deletes the tags.
ListTagResources Query tags attached to a resource Queries the tags that are attached to a resource.
ListTagValues Query tag values of a specified tag key Queries the tag values that correspond to a specified tag key.
TagResources TagResources Adds tags to resources.

Pricing inquiry

API

Title

Description

DescribeChargeResult Query WAF pricing module results Queries the pricing results of WAF pricing modules.
DescribeChargeModule DescribeChargeModule Retrieves the billing module information of Web Application Firewall (WAF).

Others

API

Title

Description

ModifyPauseProtectionStatus ModifyPauseProtectionStatus Modifies the protection status of Web Application Firewall (WAF).
CreatePocFunction CreatePocFunction Starts a trial for a proof of concept (POC) feature.
DescribePocFunctions DescribePocFunctions Retrieves the enabled proof of concept (POC) feature trials.
DescribeRoleAuthStatus DescribeRoleAuthStatus Queries the authorization status of the service-linked role for Web Application Firewall (WAF).
InitializeWafOperationRole InitializeWafOperationRole Initializes a service-linked role for WAF.
DescribeElasticBills Query bills of a pay-as-you-go instance Queries the daily bills of a pay-as-you-go WAF instance for the last 7 days.
DescribePrepayDailyBills Query burstable billing details of a subscription WAF instance Queries the burstable pay-as-you-go billing details of a subscription WAF instance, such as burstable QPS.
DescribeUserTraffic Query user traffic Queries the real-time traffic of a user by traffic type.
DescribePostpayBills Query pay-as-you-go bills Queries the list of pay-as-you-go bills.