Endpoint referenceRules
Create a rule
POST
bearerAuthheader
AuthorizationBearer <token>API token created in Settings → API. Scopes are attached to the token; each operation lists its required scope in x-scope.
org_id?stringPartners only (orgs:manage): act on this child organization. May also be sent as org_id in JSON bodies.
Format
uuidIdempotency-Key?stringReplays the original response for 24 h
Length
1 <= length <= 255application/json- body
store_id*stringFormat
uuidtype*stringValue in
"block""allow"target*stringValue in
"domain""src""hash"value*stringLength
length <= 512label?|Length
length <= 120Rule
application/json- response
id?stringFormat
uuidstore_id?stringFormat
uuidtype?stringValue in
"block""allow"target?stringValue in
"domain""src""hash"value?stringlabel?string|nullactive?booleancreated_at?stringFormat
date-timecurl -X POST "https://example.com/rules" \ -H "Content-Type: application/json" \ -d '{ "store_id": "0c1d2e3f-1111-4222-8333-444455556666", "type": "block", "target": "domain", "value": "evil-cdn.example", "label": "Known skimmer host" }'{ "id": "c9d8e7f6-6666-4777-8888-999900001111", "store_id": "0c1d2e3f-1111-4222-8333-444455556666", "type": "block", "target": "domain", "value": "evil-cdn.example", "label": "Known skimmer host", "active": true, "created_at": "2026-09-27T10:10:00.000Z"}