Skip to main content

Headers

Send Accept: application/json. For requests with a JSON body, send Content-Type: application/json. Authentication headers are required for every public product endpoint.

Project scope

An API key is already bound to a project. The Management Console uses a project query parameter for its session-authenticated requests, but API clients should omit it.

Resource identifiers

Cloud CDN, Cloud DNS, and TLS Manager use query parameters for resource identifiers: Cloud Shield uses path identifiers, for example /shield/domains/{domain_id}/custom-rules/{rule_id}. Use the ID returned by the same project’s API. Its collection queries usually use limit and offset, with endpoint-specific maxima. Array filters use repeated query keys.

Updates

CDN configuration and DNS record-set update bodies represent the complete intended state for that configuration. Read the current value, modify it, and send the full document. Do not omit a field with the expectation that it will remain unchanged unless the endpoint schema explicitly makes it optional.

Empty responses

The API can return 204 No Content for a successful operation or an empty collection. Clients should accept both an empty JSON array and 204 where the endpoint documents it.

Retries

Retry transient 429, 502, 503, and 504 responses with exponential backoff and jitter. Honor Retry-After when present. Do not automatically retry a mutation unless you know whether the first request took effect; the current API does not document general idempotency-key support.

Dates and time

Timestamp formats are endpoint-specific. ISO 8601 strings preserve their timezone offset; CDN request logs and some security analytics expose numeric timestamps. Read the endpoint schema before converting values. Pre-billing filters use calendar dates.