Update a bot route rule
const url = 'https://api.nsin.cloud/domains/example.com/rules/bot-route/1';const options = { method: 'PUT', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"record_id":1,"record_ids":[1],"enabled":true,"priority":100,"host_pattern":"example","host_match_type":"","action_mode":"enforce","bot_kinds":["*"],"require_verified":true,"action":"block","status":200,"body":"example","alt_dest":"example","alt_port":1,"alt_scheme":"http"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PUT \ --url https://api.nsin.cloud/domains/example.com/rules/bot-route/1 \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "record_id": 1, "record_ids": [ 1 ], "enabled": true, "priority": 100, "host_pattern": "example", "host_match_type": "", "action_mode": "enforce", "bot_kinds": [ "*" ], "require_verified": true, "action": "block", "status": 200, "body": "example", "alt_dest": "example", "alt_port": 1, "alt_scheme": "http" }'Partial update — omitted fields keep their current value. Requires
rules.edit.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The domain name (for example example.com) — not a numeric id.
Example
example.comNumeric id of the rule.
Request Body required
Section titled “Request Body required ”object
Deprecated single-record scope. Prefer record_ids.
Scope the rule to these proxied records. Omit or send an empty array for a zone-wide rule. Every id must belong to this domain.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
Which bots this rule matches. Must not be empty.
Only match bots whose identity was verified (by reverse DNS or published IP ranges), not merely self-declared in the user agent.
block— refuse the request.alt_content— servebodywithstatusinstead of the origin.alt_origin— proxy toalt_dest:alt_portoveralt_scheme.tag— let it through, but tag it in telemetry.
Status code for alt_content.
Response body for alt_content.
Origin address for alt_origin.
Origin port for alt_origin.
Scheme used to reach alt_dest.
Responses
Section titled “ Responses ”The updated rule.
object
Deprecated single-record scope. Prefer record_ids. Absent for
zone-wide rules.
The proxied DNS records this rule applies to. Empty or absent means zone-wide — every proxied record of the domain.
Evaluation order; lower runs first. Defaults to 100.
Optional hostname filter. Empty means the rule is not host-scoped.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
Which bots this rule matches. Must not be empty.
Only match bots whose identity was verified (by reverse DNS or published IP ranges), not merely self-declared in the user agent.
block— refuse the request.alt_content— servebodywithstatusinstead of the origin.alt_origin— proxy toalt_dest:alt_portoveralt_scheme.tag— let it through, but tag it in telemetry.
Status code for alt_content.
Response body for alt_content.
Origin address for alt_origin.
Origin port for alt_origin.
Scheme used to reach alt_dest.
Example
{ "type": "cache", "host_match_type": "", "action_mode": "enforce", "bot_kinds": [ "*" ], "action": "block", "status": 200, "alt_scheme": "http"}Malformed body, an invalid field value, or record_ids containing a
record that does not belong to this domain.
The error shape used by every endpoint. error is always present. code
is present only on the failures that have one — do not require it, and do
not parse error to recover it.
object
Human-readable description of what went wrong.
Stable machine-readable reason. Present on some failures only; the
wording of error may change, this will not.
account_suspended—403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.domain_disabled—409, not403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.managed_by_reseller—403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.invite_email_mismatch—403fromPOST /invites/{token}/accept. The invitation was addressed to a different email; the body also carriesinvited_email, masked.
A panel session — not an API key — can additionally see
session_check_failed on a 503, which means the session could not
be verified, not that it is invalid. Retry it; do not discard the
token.
Examples
{ "error": "record_ids do not belong to this domain"}Missing, malformed, revoked or expired API key, or a key whose owning
user row is gone. A key whose owning account has merely been deactivated
is not this: that is 403 with code: account_suspended, because the
credential itself is intact and re-issuing it changes nothing.
The error shape used by every endpoint. error is always present. code
is present only on the failures that have one — do not require it, and do
not parse error to recover it.
object
Human-readable description of what went wrong.
Stable machine-readable reason. Present on some failures only; the
wording of error may change, this will not.
account_suspended—403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.domain_disabled—409, not403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.managed_by_reseller—403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.invite_email_mismatch—403fromPOST /invites/{token}/accept. The invitation was addressed to a different email; the body also carriesinvited_email, masked.
A panel session — not an API key — can additionally see
session_check_failed on a 503, which means the session could not
be verified, not that it is invalid. Retry it; do not discard the
token.
Examples
{ "error": "invalid API key"}The rule does not exist, or it belongs to another domain or another rule type — a rule id is always checked against both the domain in the path and the type of the endpoint. It also covers a domain that does not exist or that you hold no role on.
It no longer means “your role is too low”. A caller who may read the
domain but not write its rules is refused before the rule is even looked
up, with 403; a write against a disabled domain is refused with 409
and code: domain_disabled.
The error shape used by every endpoint. error is always present. code
is present only on the failures that have one — do not require it, and do
not parse error to recover it.
object
Human-readable description of what went wrong.
Stable machine-readable reason. Present on some failures only; the
wording of error may change, this will not.
account_suspended—403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.domain_disabled—409, not403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.managed_by_reseller—403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.invite_email_mismatch—403fromPOST /invites/{token}/accept. The invitation was addressed to a different email; the body also carriesinvited_email, masked.
A panel session — not an API key — can additionally see
session_check_failed on a 503, which means the session could not
be verified, not that it is invalid. Retry it; do not discard the
token.
Example
{ "error": "read-only API key"}The key exceeded its request budget (300 requests per minute by default).
The error shape used by every endpoint. error is always present. code
is present only on the failures that have one — do not require it, and do
not parse error to recover it.
object
Human-readable description of what went wrong.
Stable machine-readable reason. Present on some failures only; the
wording of error may change, this will not.
account_suspended—403. The account behind the credential has been switched off, by an admin or by its provider. Every authenticated route answers this, so treat it as terminal rather than retrying.domain_disabled—409, not403. You have every right to the operation; the domain is simply switched off and is not being served, so its configuration cannot change. It stays readable, and writes work again once it is enabled.managed_by_reseller—403. The account is a reseller’s client and this surface belongs to its provider. See If your account is managed by a reseller.invite_email_mismatch—403fromPOST /invites/{token}/accept. The invitation was addressed to a different email; the body also carriesinvited_email, masked.
A panel session — not an API key — can additionally see
session_check_failed on a 503, which means the session could not
be verified, not that it is invalid. Retry it; do not discard the
token.
Examples
{ "error": "rate limit exceeded"}