> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a firewall rule

> Project-scoped operation. Successful JSON and status-only responses vary by operation. The service does not declare a stable response schema for this operation; do not assume a collection envelope or undocumented fields.



## OpenAPI

````yaml /openapi-shield.json post /shield/domains/{domain_id}/firewall-rules
openapi: 3.1.0
info:
  title: Aptranet Cloud Shield API
  version: 1.0.0
  description: >-
    Public project-scoped API. Use the access key and secret together.
    Browser-only organization administration is documented separately. Request
    schemas and query parameters follow the service operation allowlist. Plan
    entitlements apply in addition to API permissions. Some analytics and action
    responses have operation-specific JSON shapes; where the implementation
    provides no stable response contract, the reference deliberately does not
    invent one.
servers:
  - url: https://api.aptranet.com
security:
  - bearerAuth: []
    apiSecret: []
paths:
  /shield/domains/{domain_id}/firewall-rules:
    post:
      tags:
        - Cloud Shield Firewall Rules
      summary: Create a firewall rule
      description: >-
        Project-scoped operation. Successful JSON and status-only responses vary
        by operation. The service does not declare a stable response schema for
        this operation; do not assume a collection envelope or undocumented
        fields.
      operationId: POST_shield_domains_domain_id_firewall_rules
      parameters:
        - name: domain_id
          in: path
          required: true
          schema:
            type: integer
            title: Domain Id
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - name
                - enabled
                - action
                - conditions
              title: FirewallRule
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 100
                  example: Block foobar bot
                  title: Name
                description:
                  type: string
                  maxLength: 100
                  title: Description
                enabled:
                  type: boolean
                  title: Enabled
                action:
                  type: object
                  additionalProperties: false
                  title: FirewallRuleAction
                  properties:
                    allow:
                      anyOf:
                        - type: object
                          additionalProperties: true
                          title: RuleAllowAction
                          properties: {}
                        - type: 'null'
                    block:
                      anyOf:
                        - type: object
                          additionalProperties: false
                          title: RuleBlockAction
                          properties:
                            status_code:
                              type: integer
                              enum:
                                - 403
                                - 405
                                - 418
                                - 429
                              title: RuleBlockStatusCode
                            action_duration:
                              type: string
                              minLength: 1
                              maxLength: 10
                              example: 12h
                              title: Action Duration
                        - type: 'null'
                conditions:
                  type: array
                  minItems: 1
                  maxItems: 1
                  title: Conditions
                  items:
                    type: object
                    additionalProperties: false
                    title: FirewallRuleCondition
                    properties:
                      ip:
                        type: object
                        required:
                          - ip_address
                        title: IpCondition
                        properties:
                          negation:
                            type: boolean
                            default: false
                            title: Negation
                          ip_address:
                            type: string
                            format: ipvanyaddress
                            title: Ip Address
                      ip_range:
                        type: object
                        required:
                          - lower_bound
                          - upper_bound
                        title: IpRangeCondition
                        properties:
                          negation:
                            type: boolean
                            default: false
                            title: Negation
                          lower_bound:
                            type: string
                            format: ipvanyaddress
                            title: Lower Bound
                          upper_bound:
                            type: string
                            format: ipvanyaddress
                            title: Upper Bound
      responses:
        2XX:
          description: Successful response.
        default:
          description: >-
            Request rejected or service unavailable. See the error code and
            description; refresh before retrying a mutation whose result is
            uncertain.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
        error_description:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Project API access key.
    apiSecret:
      type: apiKey
      in: header
      name: Aptranet-Secret
      description: Current secret for the access key.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.