API standards and multilingual preset SDKs
The OpenAPI of this product (waf-openapi/2021-10-01) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.
Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.
Custom signature scenarios
If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.
Account and security preparation
Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.
Instance information
|
API |
Title |
Description |
| CreatePostpaidInstance | CreatePostpaidInstance | Creates a pay-as-you-go Web Application Firewall (WAF) 3.0 instance. |
| DescribeInstance | DescribeInstance | Retrieves the details of the Web Application Firewall (WAF) instance in your Alibaba Cloud account. |
Access configuration
|
API |
Title |
Description |
| Cloud native mode | Cloud native mode | |
| DescribeAbnormalCloudResources | DescribeAbnormalCloudResources | Queries abnormal cloud resources added in cloud native mode. |
| ReCreateCloudResource | Re-register a cloud service with WAF | Re-registers a cloud service with WAF. This operation is used only when the cloud native mode status is protection exception. |
| SyncProductInstance | SyncProductInstance | Synchronizes Elastic Compute Service (ECS), Classic Load Balancer (CLB), and Network Load Balancer (NLB) instances to Web Application Firewall (WAF). |
| DescribeCloudResources | DescribeCloudResources | Queries the list of cloud services added to Web Application Firewall (WAF). |
| DescribeResourcePort | DescribeResourcePort | Queries the ports of a cloud service instance that are added to Web Application Firewall (WAF). |
| DescribeProductInstances | Query synchronized cloud service assets | Queries the list of synchronized cloud service assets. |
| DescribeResourceSupportRegions | Query supported regions for cloud native mode | Queries the list of supported regions for cloud native mode, mainly for CLB and ECS products. |
| DescribeResourceRegionId | DescribeResourceRegionId | Queries the region IDs of cloud service resources that can be added to Web Application Firewall (WAF) by using the SDK. |
| DescribeResourceInstanceCerts | DescribeResourceInstanceCerts | Queries the certificates of a cloud product instance. This operation is available only in multi-account scenarios and returns the certificates of both the delegated administrator and the member that owns the instance. For example, if user A is a delegated administrator with cert1 and the instance lb-xx-1 belongs to member B who has cert2, a query for the instance lb-xx-1 returns both cert1 and cert2. |
| ModifyCloudResource | Modify cloud service access configuration | Modifies the configuration of a cloud service that is connected to Web Application Firewall (WAF). |
| DescribeCloudResourceAccessedPorts | DescribeCloudResourceAccessedPorts | Queries the ports of cloud services added to Web Application Firewall (WAF). This operation is supported only for Elastic Compute Service (ECS) and Classic Load Balancer (CLB). |
| DescribeCloudResourceAccessPortDetails | Query the details of cloud service instance ports that are added to WAF | Retrieves port details of cloud service instances onboarded to Web Application Firewall (WAF). |
| ModifyCloudResourceCert | ModifyCloudResourceCert | Modifies the certificate for a resource managed by WAF in cloud native mode. |
| DescribeCloudResourceList | Query cloud native mode WAF configuration list | Queries the list of resources connected to WAF in cloud native mode. |
| ModifyCloudResourceDefaultCert | Modify the default certificate for a cloud service | Modifies the default certificate for a cloud native mode resource. |
| DeleteCloudResourceExtensionCert | Delete an extension certificate for a cloud service | Deletes an extension certificate for a cloud service connected in cloud native mode. |
| CreateCloudResourceExtensionCert | Add an extension certificate for a cloud native mode resource | Adds an extension certificate for a cloud native mode resource. |
| CNAME access | CNAME access | |
| DescribeDomainUsedPorts | Query all ports used by user domain names | Queries all ports used by domain names of the current user. Only domain names with CNAME access and hybrid cloud CNAME domain names with public network disaster recovery enabled are included. |
| ModifyDomain | ModifyDomain | Updates a CNAME-based domain name onboarded to Web Application Firewall (WAF). |
| DescribeDomains | DescribeDomains | Queries the domain names that are added to Web Application Firewall (WAF). |
| DescribePunishedDomains | DescribePunishedDomains | Queries penalties for domain names added to Web Application Firewall (WAF) without an Internet Content Provider (ICP) filing. |
| ModifyDomainPunishStatus | Re-connect a domain name in ICP filing violation penalty status | Re-connects a domain name that is in the ICP filing violation penalty status. |
| DescribeCertDetail | Query certificate details | Queries the details of a certificate, such as the certificate name, expiration time, issuance time, and associated domain name. |
| DescribeCerts | DescribeCerts | Retrieves the list of certificates for a user. |
| DescribeDomainDNSRecord | Query CNAME DNS resolution status | Queries whether the DNS settings of a domain name are correct. |
| DescribeWafSourceIpSegment | Query back-to-origin CIDR blocks of a WAF instance | Queries the back-to-origin CIDR blocks of WAF. |
| CreateSM2Cert | Upload SM certificate for cNAME-based WAF access | Uploads a China National Cryptographic Algorithm (SM) certificate for a domain that is added to WAF in CNAME mode. |
| DescribeCnameCount | Query the total number of added domain names | Queries the total number of domain names that are added to WAF, including domain names added through CNAME and hybrid cloud access. |
| DescribeDefaultHttps | Query default SSL/TLS settings | Queries the default SSL/TLS settings. |
| ModifyDefaultHttps | ModifyDefaultHttps | Modifies the default SSL/TLS settings. |
| CreateCerts | Upload an international certificate to WAF for cNAME-based access | Uploads an international certificate to WAF for CNAME-based access. |
| VerifyDomainOwner | VerifyDomainOwner | Verifies that you own the specified domain name. Domain ownership must be verified before you can add a domain name to Web Application Firewall (WAF) by using CNAME access. |
| DescribeVerifyContent | DescribeVerifyContent | Queries the domain ownership verification content of a Web Application Firewall (WAF) instance. |
| ModifyDomainCert | ModifyDomainCert | Modifies the certificate that is associated with a domain name added to a Web Application Firewall (WAF) instance in CNAME record mode. |
| Hybrid cloud access | Hybrid cloud access | |
| DescribeHybridCloudResources | Query hybrid cloud CNAME access list | Queries the list of hybrid cloud domain names. |
| DescribeHybridCloudProtectableCount | DescribeHybridCloudProtectableCount | Queries the count of protectable nodes that can be added to a hybrid cloud cluster. |
Protection configuration
|
API |
Title |
Description |
| Protected objects | Protected objects | |
| CreateDefenseResource | CreateDefenseResource | Creates a protected object. |
| DeleteDefenseResource | Delete a protected object | Deletes a protected object. |
| CreateDefenseResourceGroup | CreateDefenseResourceGroup | Creates a protected object group. |
| ModifyDefenseResourceGroup | ModifyDefenseResourceGroup | Modifies the configuration of a protected object group. |
| DeleteDefenseResourceGroup | DeleteDefenseResourceGroup | Deletes a protected object group. |
| DescribeDefenseResourceGroup | DescribeDefenseResourceGroup | Retrieves the details of a protected object group. |
| DescribeDefenseResourceGroups | DescribeDefenseResourceGroups | Retrieves information about protected object groups using pagination. |
| DescribeDefenseResourceGroupNames | DescribeDefenseResourceGroupNames | Queries the names of protected object groups. |
| DescribeDefenseResource | Query a single protected object | Query a single protected object. |
| DescribeDefenseResources | Query protected objects by paging | Queries protected objects by paging. |
| DescribeDefenseResourceNames | DescribeDefenseResourceNames | Performs a pagination query to retrieve the names of protected objects. |
| DescribeDefenseResourceOwnerUid | DescribeDefenseResourceOwnerUid | Queries the asset owner account of protected objects in multi-account management scenarios. |
| ModifyDefenseResourceXff | ModifyDefenseResourceXff | Modifies the cookie settings of a protected object and the method to identify the originating IP addresses of clients. |
| DescribePauseProtectionStatus | DescribePauseProtectionStatus | Queries the protection pause status of a Web Application Firewall (WAF) instance. |
| DescribeDefenseGroupValidResources | DescribeDefenseGroupValidResources | Queries a paginated list of protected objects that can be associated with a defense group. |
| Protection rules | Protection rules | |
| DescribeBaseRuleChangeLog | DescribeBaseRuleChangeLog | Queries protection rule change logs on a paginated basis. |
| CreateDefenseTemplate | CreateDefenseTemplate | Creates a protection template. |
| ModifyDefenseTemplate | ModifyDefenseTemplate | Modifies a defense template. |
| ModifyDefenseTemplateStatus | ModifyDefenseTemplateStatus | Changes the status of a protection rule template. |
| CopyDefenseTemplate | CopyDefenseTemplate | Copies a protection template. |
| DeleteDefenseTemplate | DeleteDefenseTemplate | Deletes a protection rule template. |
| DescribeDefenseTemplate | DescribeDefenseTemplate | Retrieves the details of a specific protection template. |
| DescribeDefenseTemplates | DescribeDefenseTemplates | Retrieves a paginated list of protection templates. |
| ModifyTemplateResources | ModifyTemplateResources | Attaches protected objects to or detaches protected objects from a protection template. |
| DescribeTemplateResources | DescribeTemplateResources | Queries the resources attached to a protection template. |
| DescribeTemplateResourceCount | DescribeTemplateResourceCount | Queries the number of protected resources that are associated with one or more protection templates. |
| DescribeDefenseTemplateValidResources | DescribeDefenseTemplateValidResources | Queries a paginated list of protected objects that are valid for a specified protection template. |
| DescribeDefenseTemplateValidGroups | DescribeDefenseTemplateValidGroups | Queries the names of protected object groups that can be associated with a specific protection template. |
| DescribeDefenseResourceTemplates | DescribeDefenseResourceTemplates | Queries the protection templates associated with a protected object or protected object group. |
| CreateDefenseRule | Create a web core protection rule | Creates a Web core protection rule. |
| ModifyDefenseRule | ModifyDefenseRule | Modifies the configuration of a protection rule. |
| ModifyDefenseRuleStatus | ModifyDefenseRuleStatus | Enables or disables a protection rule. |
| DeleteDefenseRule | DeleteDefenseRule | Deletes the specified protection rules. |
| DescribeDefenseRules | DescribeDefenseRules | Queries a paginated list of protection rules. |
| DescribeDefenseRule | DescribeDefenseRule | Retrieves the details of a specified protection rule. |
| ModifyDefenseRuleCache | ModifyDefenseRuleCache | Updates the cache for a web tamper-proofing rule. |
| DeleteDefenseRuleBlockIp | DeleteDefenseRuleBlockIp | Unblocks an IP address that is blocked by the scan protection module. |
| DescribeRelatedDefenseRules | Query associated protection rules by page | Queries associated protection rules by using paging. |
| DescribeIpAbroadCountryInfos | DescribeIpAbroadCountryInfos | Retrieves supported countries and regions outside China for IP-based region blacklist. |
| DescribeRuleGroups | DescribeRuleGroups | Queries a paginated list of regular expression rule groups. |
| ModifyDefenseSceneConfig | ModifyDefenseSceneConfig | Modifies the mitigation settings for a protection scenario. |
| DescribeDefenseSceneConfig | DescribeDefenseSceneConfig | Queries the protection configurations for a specific defense scenario. |
| DescribeDefenseRuleStatistics | Query protection rule statistics | Queries statistics of rules under a specified WAF protection module. |
| DescribeBaseSystemRules | DescribeBaseSystemRules | Queries the system rules for Web Application Firewall (WAF) protection. |
| DescribeCustomBaseRuleCompileResult | DescribeCustomBaseRuleCompileResult | Describes the compilation result of a custom regular expression rule. |
| DescribeBotRuleLabels | DescribeBotRuleLabels | Queries the labels of bot management rules. |
| DescribeBotAppKey | DescribeBotAppKey | Queries the AppKey for bot management. |
| Critical event protection | Critical event protection | |
| CreateMajorProtectionBlackIp | CreateMajorProtectionBlackIp | Creates an IP address blacklist for critical event protection. |
| ModifyMajorProtectionBlackIp | ModifyMajorProtectionBlackIp | Modifies an IP address blacklist for critical event protection. |
| DeleteMajorProtectionBlackIp | DeleteMajorProtectionBlackIp | Deletes an IP address from the blacklist for critical event protection. |
| ClearMajorProtectionBlackIp | ClearMajorProtectionBlackIp | Clears the IP blacklist for a critical event protection rule. |
| DescribeMajorProtectionBlackIps | DescribeMajorProtectionBlackIps | Queries the IP address blacklist for critical event protection in a paginated format. |
| Address books | Address books | |
| AddAddress | Add addresses to an address book | Adds addresses to an address book. |
| DescribeAddresses | Query address book addresses by page | Queries addresses in an address book by paging. |
| DeleteAddress | Delete addresses from an address book | Deletes addresses from an address book. |
| ClearAddress | Clear all addresses from an address book | Clears all addresses from an address book. |
API security
|
API |
Title |
Description |
| DeleteApisecAbnormals | Batch delete API security risks | Deletes API security risks in batches. |
| ModifyApisecAbnormals | ModifyApisecAbnormals | Modifies the status of API security risks in batches. |
| DescribeApisecAssetTrend | Query API security API asset trends | Queries the trend of API security API assets. |
| DescribeApisecAbnormalDomainStatistic | Query API security risk domain name statistics | Queries statistics on API security risk domain names. |
| DescribeApisecEventDomainStatistic | Query API security event domain name statistics | Queries the domain name statistics of API security events. |
| DescribeApisecSensitiveDomainStatistic | Query API security sensitive data domain name statistics | Queries statistics on data endpoints associated with API security sensitive data domains. |
| ModifyApisecEvents | ModifyApisecEvents | Modifies the status of a batch of API security events. |
| DeleteApisecEvents | Batch delete API security events | Deletes API security events in batches. |
| ModifyApisecLogDeliveryStatus | Modify API security log subscription status | Modifies the subscription status of API security logs. |
| CreateApiExport | Create an API security data export task | Creates an API security data export task. |
| DescribeApiExports | Query API security export tasks | Queries the list of API security export tasks. |
| DescribeApisecAbnormals | Query API security risks | Queries the list of API security risks. |
| DescribeApisecApiResources | Query API security assets | Queries the list of API security assets. |
| ModifyApisecStatus | Modify API security status | Modifies the status of protected objects or protected object groups for API security. |
| ModifyApisecModuleStatus | Modify API security protection module status | Modifies the status of protected objects or protected object groups for the API security protection module. |
| ModifyApisecApiResource | ModifyApisecApiResource | Modifies the annotation of an API asset in the API security module of Web Application Firewall (WAF). |
| DescribeUserEventType | DescribeUserEventType | Queries the types and statistics of user security events. |
| DescribeUserEventTrend | Query API security attack trend | Queries the trend of API security attacks. |
| DescribeUserAsset | Query API security user asset statistics | Queries API security user asset statistics. |
| DescribeUserApiRequest | DescribeUserApiRequest | Queries traffic statistics for an API operation. |
| DescribeUserAbnormalType | DescribeUserAbnormalType | Queries user risk types and statistics related to API security in Web Application Firewall (WAF). |
| DescribeUserAbnormalTrend | DescribeUserAbnormalTrend | Queries the trend of API security risks for a Web Application Firewall (WAF) instance. |
| DescribeSensitiveStatistic | Query sensitive data statistics for tracing audits | Queries sensitive data statistics for tracing audits. |
| DescribeSensitiveRequests | Query sensitive data tracing results | Queries the results of sensitive data tracing. |
| DescribeSensitiveRequestLog | Query access logs of sensitive data | Queries the access log information of sensitive data. |
| DescribeSensitiveOutboundTrend | Query cross-border transfer trend of personal information | Queries the trend of cross-border transfer of personal information data. |
| DescribeSensitiveOutboundStatistic | DescribeSensitiveOutboundStatistic | Queries statistics about outbound transfers of personal information. |
| DescribeSensitiveOutboundDistribution | DescribeSensitiveOutboundDistribution | Queries the distribution of outbound traffic that contains personal information. |
| DescribeSensitiveDetectionResult | Query API security compliance detection results | Queries the detection results of API security compliance requirements. |
| DescribeSensitiveApiStatistic | Query statistics on sites and API operations that involve personal information | Queries statistics on sites and API operations that involve personal information. |
| DescribeFreeUserEvents | Query API security basic detection events | Queries the list of security events detected by API security basic detection. |
| DescribeFreeUserEventTypes | DescribeFreeUserEventTypes | Queries the types of security events for basic API security detection. |
| DescribeFreeUserEventCount | Query security event statistics of API security basic detection | Queries the security event statistics of API security basic detection. |
| DescribeFreeUserAssetCount | DescribeFreeUserAssetCount | Queries statistics information about assets detected by the basic API security feature. |
| DescribeApisecUserOperations | DescribeApisecUserOperations | Queries user operation records for API security of Web Application Firewall (WAF). |
| DescribeApisecSuggestions | Query protection suggestions for API assets | Queries protection suggestions for API assets. |
| DescribeApisecStatistics | DescribeApisecStatistics | Queries statistics for API security risks or security events. |
| DescribeApisecRules | DescribeApisecRules | Queries the rules of an API security policy. |
| DescribeApisecProtectionResources | Query the list of API security protected objects | Queries the list of protected objects for which API security protection is enabled. |
| DescribeApisecProtectionGroups | DescribeApisecProtectionGroups | Retrieves a list of active API security protection object groups. |
| DescribeApisecMatchedHosts | Query the domain name list for API security detection | Queries the list of domain names for API security detection. |
| DescribeApisecEvents | DescribeApisecEvents | Queries a list of API security events. |
| DescribeApisecEventDetail | DescribeApisecEventDetail | Retrieves the details of an API security event. |
| DescribeApisecLogDeliveries | DescribeApisecLogDeliveries | Queries the configurations of API security log subscription. |
| DescribeApisecSlsLogStores | DescribeApisecSlsLogStores | Queries the Logstores whose names start with apisec- in Simple Log Service. |
| DescribeApisecSlsProjects | DescribeApisecSlsProjects | Queries the projects whose names start with apisec- in Simple Log Service. |
| ModifyApisecLogDelivery | ModifyApisecLogDelivery | Updates the API security log subscription settings. |
| DescribeApisecExamples | DescribeApisecExamples | Queries the API security examples that are detected by Web Application Firewall (WAF). |
Report information
|
API |
Title |
Description |
| DescribeNetworkFlowTimeSeriesMetric | DescribeNetworkFlowTimeSeriesMetric | Queries the time series statistics of all traffic, including malicious requests and normal service requests. |
| DescribeSecurityEventTopNMetric | Query top attack traffic statistics | Queries the top N statistics of attack traffic, which is aggregated by a specified dimension, sorted, and returned. |
| DescribeSecurityEventTimeSeriesMetric | DescribeSecurityEventTimeSeriesMetric | Queries the time series data of attack traffic. Attack requests are requests that hit a rule and are identified as a threat. |
| DescribeSecurityEventLogs | DescribeSecurityEventLogs | Queries the detailed logs of attack traffic. Each log entry contains the details of a request that matched a protection rule. |
| DescribeNetworkFlowTopNMetric | DescribeNetworkFlowTopNMetric | Queries the top N statistics for all traffic that passes through Web Application Firewall (WAF), including malicious and normal service requests. The results are aggregated by different dimensions and sorted in descending order. |
| DescribeFlowChart | DescribeFlowChart | Queries the traffic statistics. |
| DescribePeakTrend | DescribePeakTrend | Queries the trend of queries per second (QPS). |
| DescribeResponseCodeTrendGraph | View response code trends | Queries the trends of abnormal response codes, such as 5XX, 405, 499, 302, and 444, returned by WAF to clients and by origin servers to WAF. |
| DescribeVisitUas | Query top 10 user-Agents by traffic | Queries the top 10 User-Agents that initiate the most requests. |
| DescribeVisitTopIp | Query top 10 IP addresses by traffic | Queries the top 10 IP addresses that initiate the most requests. |
| DescribeRuleHitsTopResource | DescribeRuleHitsTopResource | Queries the top 10 protected objects that triggered protection rules most frequently. |
| DescribeRuleHitsTopTuleType | DescribeRuleHitsTopTuleType | Queries the top 10 most frequently triggered protection rule types. |
| DescribeFlowTopResource | DescribeFlowTopResource | Queries the top 10 protected objects by request count. |
| DescribeFlowTopUrl | DescribeFlowTopUrl | Queries the top 10 most requested URLs. |
| DescribeThreatEventDetail | DescribeThreatEventDetail | Retrieves the details of a security event that requires attention. |
| DescribeThreatEvent | DescribeThreatEvent | Queries a paginated list of notable security events. |
| DescribeThreatEventTopMetric | Query top statistics of security events | Queries the top 5 statistics of security events aggregated by different statistical objects and sorted in descending order. |
| DescribeAlarmList | DescribeAlarmList | Queries a list of alerts. |
| DescribeAlarmBanner | DescribeAlarmBanner | Queries the alert banner information of a Web Application Firewall (WAF) instance. |
Log configuration
|
API |
Title |
Description |
| DescribeUserLogFieldConfig | DescribeUserLogFieldConfig | Queries the log field configuration of a Web Application Firewall (WAF) instance, including additional fields, removed fields, delivery strategies, and extended settings. |
| ModifyUserLogFieldConfig | ModifyUserLogFieldConfig | Modifies the default log field configuration of a Web Application Firewall (WAF) instance for log delivery to Simple Log Service. |
| DescribeCommonLogFields | DescribeCommonLogFields | Queries all log fields supported by Simple Log Service for Web Application Firewall (WAF). |
| ModifyUserWafLogStatus | ModifyUserWafLogStatus | Enables or disables Simple Log Service for Web Application Firewall (WAF). |
| DescribeUserWafLogStatus | DescribeUserWafLogStatus | Queries the status, region ID, and status modification time of Web Application Firewall (WAF) logs. |
| DescribeUserSlsLogRegions | Query available log storage regions | Queries the log storage regions available to the user. |
| DescribeSlsAuthStatus | DescribeSlsAuthStatus | Queries the Logstore authorization status. |
| DescribeSlsLogStoreStatus | DescribeSlsLogStoreStatus | Queries the status of a Simple Log Service Logstore. |
| DescribeSlsLogStore | DescribeSlsLogStore | Retrieves Logstore information, including total capacity, storage duration, and used capacity. |
| ModifyResourceLogStatus | Modify the log status of a protected object | Modifies the log status of a protected object. |
| DescribeResourceLogStatus | Query log status of protected objects | Queries the log status of protected objects. |
| CreateLogDeliveryConfig | CreateLogDeliveryConfig | Creates a log delivery configuration for a Web Application Firewall (WAF) instance in a hybrid cloud. |
| ModifyLogDeliveryConfig | ModifyLogDeliveryConfig | Modifies a log delivery configuration for a hybrid cloud cluster. |
| DeleteLogDeliveryConfig | DeleteLogDeliveryConfig | Deletes a log delivery configuration. |
| DescribeLogDeliveryConfig | DescribeLogDeliveryConfig | Queries a single log delivery configuration for a hybrid cloud. |
| DescribeLogDeliveryConfigs | DescribeLogDeliveryConfigs | Queries all log delivery configurations of a Web Application Firewall (WAF) instance for hybrid cloud. |
| ModifyResourceLogFieldConfig | ModifyResourceLogFieldConfig | Modifies the log field configuration of a protected object. |
| DescribeResourceLogFieldConfig | DescribeResourceLogFieldConfig | Queries the log field configuration for a protected object. |
| ModifyResourceLogDeliveryStatus | ModifyResourceLogDeliveryStatus | Modifies the log delivery status of a protected object in Web Application Firewall (WAF). |
| DescribeResourceLogDeliveryStatus | DescribeResourceLogDeliveryStatus | Queries the log delivery status for protected objects. |
Hybrid cloud cluster management
|
API |
Title |
Description |
| DescribeHybridCloudClusterServers | DescribeHybridCloudClusterServers | Queries the servers in a hybrid cloud Web Application Firewall (WAF) cluster. |
| DescribeHybridCloudBasicMonitor | DescribeHybridCloudBasicMonitor | Queries the system status of a node in a hybrid cloud cluster. |
| CreateHybridCloudCluster | CreateHybridCloudCluster | Creates a hybrid cloud Web Application Firewall (WAF) cluster. |
| DescribeHybridCloudServerRegions | DescribeHybridCloudServerRegions | Queries hybrid cloud server regions, including carriers, continents, and cities. |
| DescribeHybridCloudUnassignedMachines | DescribeHybridCloudUnassignedMachines | Queries the list of unassigned servers in a hybrid cloud cluster. |
| ModifyHybridCloudClusterBypassStatus | ModifyHybridCloudClusterBypassStatus | Modifies the manual bypass status for a hybrid cloud cluster that is integrated with an SDK. |
| DescribeHybridCloudUser | DescribeHybridCloudUser | Queries the available HTTP and HTTPS port ranges for hybrid cloud access. |
| DescribeHybridCloudGroups | DescribeHybridCloudGroups | Queries the Hybrid Cloud WAF node groups that are added to Web Application Firewall (WAF). |
| CreateHybridCloudGroup | CreateHybridCloudGroup | Creates a node group in a Hybrid Cloud Web Application Firewall (WAF) cluster. |
| DescribeHybridCloudClusterRule | DescribeHybridCloudClusterRule | Retrieves a hybrid cloud cluster rule. |
| DescribeHybridCloudClusters | DescribeHybridCloudClusters | Queries a list of hybrid cloud clusters. |
| ModifyHybridCloudClusterRule | Modify hybrid cloud cluster rule information | Modifies the rule information of a hybrid cloud cluster. |
| ModifyHybridCloudGroup | ModifyHybridCloudGroup | Modifies the information of a cluster group. |
| ModifyHybridCloudGroupExpansionServer | ModifyHybridCloudGroupExpansionServer | Adds a node to a node group in a hybrid cloud cluster of a Web Application Firewall (WAF) instance. |
| ModifyHybridCloudGroupShrinkServer | Delete nodes from a cluster group | Deletes nodes from a cluster group. |
| ModifyHybridCloudSdkPullinStatus | ModifyHybridCloudSdkPullinStatus | Modifies the traffic redirection status of a hybrid cloud SDK. |
| ModifyHybridCloudServer | Modify hybrid cloud node information | Modifies hybrid cloud node information. |
| DeleteHybridCloudClusterRule | DeleteHybridCloudClusterRule | Deletes a hybrid cloud cluster rule from a Web Application Firewall (WAF) instance. |
| CreateHybridCloudClusterRule | CreateHybridCloudClusterRule | Creates a Hybrid Cloud Web Application Firewall (WAF) cluster rule. |
| DescribeHybridCloudClusterRules | DescribeHybridCloudClusterRules | Cluster rules |
| DescribeHybridCloudProcessMonitor | DescribeHybridCloudProcessMonitor | Queries the status of applications on nodes in a hybrid cloud Web Application Firewall (WAF) cluster. |
| DescribeHybridCloudResourceDetail | Query hybrid cloud domain name details | Queries the details of a hybrid cloud domain name. |
| DescribeHybridCloudSdkServers | DescribeHybridCloudSdkServers | Queries the hybrid cloud SDK servers that are managed by a Web Application Firewall (WAF) instance. |
| DescribeHybridCloudSupportRegions | DescribeHybridCloudSupportRegions | Queries the regions that are supported for hybrid cloud access in Web Application Firewall (WAF). |
| DescribeHybridCloudUnsupportPorts | DescribeHybridCloudUnsupportPorts | Queries the list of unsupported ports for a hybrid cloud. |
| DeleteHybridCloudGroup | DeleteHybridCloudGroup | Deletes a group. |
| ModifyHybridCloudCluster | ModifyHybridCloudCluster | Updates hybrid cloud cluster settings, such as the cluster name, ports, and access mode. |
Multi-account management
|
API |
Title |
Description |
| CreateMemberAccounts | CreateMemberAccounts | Adds member accounts to use the multi-account management feature of Web Application Firewall (WAF). |
| ModifyMemberAccount | ModifyMemberAccount | Modifies the information of a member account that is managed by the multi-account management feature of Web Application Firewall (WAF). |
| DeleteMemberAccount | DeleteMemberAccount | Deletes a Web Application Firewall (WAF) member account. |
| DescribeAccountDelegatedStatus | Query whether a user is a WAF delegated administrator | Queries whether the current user is a delegated administrator of WAF in the multi-account management feature. |
| DescribeMemberAccounts | DescribeMemberAccounts | Retrieves all member accounts managed by the WAF multi-account management feature. |
Pricing inquiry
|
API |
Title |
Description |
| DescribeChargeResult | DescribeChargeResult | Queries the billing results for Web Application Firewall (WAF). |
| DescribeChargeModule | DescribeChargeModule | Retrieves the billing module information of Web Application Firewall (WAF). |
Others
|
API |
Title |
Description |
| ModifyPauseProtectionStatus | ModifyPauseProtectionStatus | Modifies the protection status of Web Application Firewall (WAF). |
| CreatePocFunction | CreatePocFunction | Starts a trial for a proof of concept (POC) feature. |
| DescribePocFunctions | DescribePocFunctions | Retrieves the enabled proof of concept (POC) feature trials. |
| DescribeRoleAuthStatus | DescribeRoleAuthStatus | Queries the authorization status of the service-linked role for Web Application Firewall (WAF). |
| InitializeWafOperationRole | InitializeWafOperationRole | Initializes a service-linked role for WAF. |
| DescribeElasticBills | DescribeElasticBills | Queries the daily bills for WAF pay-as-you-go instances for the last 7 days. |
| DescribePrepayDailyBills | Query burstable billing details of a subscription WAF instance | Queries the burstable pay-as-you-go billing details of a subscription WAF instance, such as burstable QPS. |
| DescribeUserTraffic | Query user traffic | Queries the real-time traffic of a user by traffic type. |
| ChangeResourceGroup | Change resource group | Modifies the resource group to which a protected object belongs. |
| CreateCloudResource | Connect a cloud service to WAF | Connects a cloud service to WAF in cloud native mode. Currently, only ECS and CLB are supported. |
| CreateDomain | Add a CNAME access resource | Adds a domain name to a WAF instance by using Website Config for protection. |
| DeleteCloudResource | DeleteCloudResource | Removes a cloud service from Web Application Firewall (WAF). This operation currently supports only Elastic Compute Service (ECS) and Classic Load Balancer (CLB). |
| DeleteDomain | Delete a cNAME-connected resource | Deletes a CNAME-connected domain name. |
| DescribeDDoSStatus | Query current DDoS attack status | Queries whether the current WAF instance is under a DDoS attack. |
| DescribeDomainDetail | Query CNAME access details | Queries the Website Config details. |
| DescribePostpayBills | Query pay-as-you-go bills | Queries the list of pay-as-you-go bills. |
| DescribeRuleHitsTopClientIp | DescribeRuleHitsTopClientIp | Queries the top 10 source IP addresses from which the most attacks originated. |
| DescribeRuleHitsTopRuleId | Query top 10 rule iDs by rule hits | Queries the top 10 rule IDs that have triggered mitigation policies the most times. |
| DescribeRuleHitsTopUa | Query top 10 attack user-Agents | Queries the top 10 User-Agents that initiated the most attacks. |
| DescribeRuleHitsTopUrl | Query top 10 uRLs with protection rule hits | Queries the top 10 URLs that trigger protection rules the most. |
| ListTagKeys | Query tag keys | Queries tag keys. |
| ListTagResources | ListTagResources | Queries the tags that are added to a resource. |
| ListTagValues | Query tag values of a specified tag key | Queries the tag values that correspond to a specified tag key. |
| ReleaseInstance | ReleaseInstance | Releases a Web Application Firewall (WAF) 3.0 instance. |
| TagResources | TagResources | Adds tags to resources. |
| UntagResources | UntagResources | Removes tags from resources and then deletes the tags. |