> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an advanced rule

> Project-scoped operation. Requires the advanced_rules add-on. Successful JSON and status-only responses vary by operation. The service does not declare a stable response schema for this operation; do not assume a collection envelope or undocumented fields.



## OpenAPI

````yaml /openapi-shield.json post /shield/domains/{domain_id}/advanced-rules
openapi: 3.1.0
info:
  title: Aptranet Cloud Shield API
  version: 1.0.0
  description: >-
    Public project-scoped API. Use the access key and secret together.
    Browser-only organization administration is documented separately. Request
    schemas and query parameters follow the service operation allowlist. Plan
    entitlements apply in addition to API permissions. Some analytics and action
    responses have operation-specific JSON shapes; where the implementation
    provides no stable response contract, the reference deliberately does not
    invent one.
servers:
  - url: https://api.aptranet.com
security:
  - bearerAuth: []
    apiSecret: []
paths:
  /shield/domains/{domain_id}/advanced-rules:
    post:
      tags:
        - Cloud Shield Advanced Rules
      summary: Create an advanced rule
      description: >-
        Project-scoped operation. Requires the advanced_rules add-on. Successful
        JSON and status-only responses vary by operation. The service does not
        declare a stable response schema for this operation; do not assume a
        collection envelope or undocumented fields.
      operationId: POST_shield_domains_domain_id_advanced_rules
      parameters:
        - name: domain_id
          in: path
          required: true
          schema:
            type: integer
            title: Domain Id
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - name
                - enabled
                - action
                - source
              title: AdvancedRule
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 100
                  example: Block foobar bot
                  title: Name
                description:
                  type: string
                  maxLength: 100
                  title: Description
                enabled:
                  type: boolean
                  title: Enabled
                action:
                  type: object
                  additionalProperties: false
                  title: CustomerRuleAction
                  properties:
                    allow:
                      type: object
                      additionalProperties: true
                      title: RuleAllowAction
                      properties: {}
                    block:
                      type: object
                      additionalProperties: false
                      title: RuleBlockAction
                      properties:
                        status_code:
                          type: integer
                          enum:
                            - 403
                            - 405
                            - 418
                            - 429
                          title: RuleBlockStatusCode
                        action_duration:
                          type: string
                          minLength: 1
                          maxLength: 10
                          example: 12h
                          title: Action Duration
                    captcha:
                      type: object
                      additionalProperties: true
                      title: RuleCaptchaAction
                      properties: {}
                    handshake:
                      type: object
                      additionalProperties: true
                      title: RuleHandshakeAction
                      properties: {}
                    monitor:
                      type: object
                      additionalProperties: true
                      title: RuleMonitorAction
                      properties: {}
                    tag:
                      type: object
                      required:
                        - tags
                      title: RuleTagAction
                      properties:
                        tags:
                          type: array
                          minItems: 1
                          maxItems: 5
                          title: Tags
                          items:
                            type: string
                source:
                  type: string
                  minLength: 1
                  example: >-
                    request.rate_limit([], '.*events', 5, 200, [], [], '', 'ip')
                    and not ('mb-web-ui' in request.headers['Cookie'] or
                    'mb-mobile-ios' in request.headers['Cookie'] or
                    'session-token' in request.headers['Cookie']) and not
                    request.headers['session']
                  title: Source
                phase:
                  default: access
                  title: Phase
                  anyOf:
                    - type: string
                      enum:
                        - access
                        - header_filter
                        - body_filter
                    - type: 'null'
      responses:
        2XX:
          description: Successful response.
        default:
          description: >-
            Request rejected or service unavailable. See the error code and
            description; refresh before retrying a mutation whose result is
            uncertain.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
        error_description:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Project API access key.
    apiSecret:
      type: apiKey
      in: header
      name: Aptranet-Secret
      description: Current secret for the access key.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.