https://api.aptranet.com/shield with the access-key and secret headers. The key determines the project. Resource IDs returned by this API belong to that project; never derive or reuse IDs from another account.
Start with service and distributions
- Read
GET /shield/servicefor readiness, plan code, limits, and active add-ons. - Read
GET /shield/distributionsfor eligible CDN distributions and existing attachments. - Attach a distribution with
POST /shield/domainsand{"distribution_id": 42}. - Wait until the returned domain ID is available before changing domain policies or rules.
Request conventions
Most collections uselimit and offset; inspect each endpoint’s maximum. Array query parameters use repeated keys, such as ids=12&ids=15. Send ISO 8601 timestamps when a filter requires a time; use YYYY-MM-DD for pre-billing dates. Unknown query filters are rejected.
Read the endpoint reference for the required fields of each action. PATCH routes accept the fields described by their schema. Bulk rule deletion uses POST with delete permission. Response-page preview uses POST with list permission. Clearing local reputation tags uses modify permission.
Readiness and errors
Collection responses can include a
results array and count, while some analytics return arrays directly. Responses vary by operation. Handle an empty body separately from an empty collection and preserve the data-freshness headers described in investigations.
Legacy /shield/domains/{domain_id}/tls operations return 409 managed_by_cdn. Use the linked distribution’s TLS configuration instead.