Protect an application
Attach a distribution and verify protection.
Manage protection
Configure managed policies, exceptions, and traffic rules.
Investigate traffic
Review events, attack activity, IP reputation, and insights.
Operate your workspace
Manage response pages, access, audit events, usage, and exports.
Product boundaries
Cloud Shield and Origin Shield are separate features with separate configuration and billing.
Plans and entitlements
The service reports your current limits throughGET /shield/service. Domain and rule limits apply across the organization’s projects. Basic supports managed protection; Advanced and Business also support custom and IP firewall rules. Advanced rules and bot management require eligible add-ons. API security, advanced threat intelligence, SIEM integration, access control, and audit logs require their corresponding Business add-ons.
Review the current plan and available controls in Billing → Subscription. A visible navigation item does not mean its add-on is active. Contact support to enable an eligible add-on.
Automation
The public API prefix is/shield; the Management Console uses /cloud-shield for its pages. Use project-scoped credentials and the Cloud Shield API guide when automating protection.