Endpoint referenceScripts
Block a script (creates a block rule)
POST
Sets status = blocked, records a review and upserts a block rule (inline script → content hash; external → domain).
bearerAuthheader
AuthorizationBearer <token>API token created in Settings → API. Scopes are attached to the token; each operation lists its required scope in x-scope.
id*stringFormat
uuidorg_id?stringPartners only (orgs:manage): act on this child organization. May also be sent as org_id in JSON bodies.
Format
uuidIdempotency-Key?stringReplays the original response for 24 h
Length
1 <= length <= 255application/json- body
justification?stringLength
length <= 2000Blocked script + rule
application/json- response
id?stringFormat
uuidstore_id?stringFormat
uuidsrc?stringtype?|Value in
"first_party""known_third""unknown"nullcategory?string|nullstatus?stringValue in
"trusted""needs_review""suspicious""malicious""authorized""blocked"integrity_status?|Value in
"match""mismatch""pending""monitored""blocked"nullcurrent_hash?string|nullauthorized_hash?string|nullhash_source?string|nullsri_hash?string|nullintegrity_attr?boolean|nullsize_bytes?integer|nullvendor_id?string|nullgtm_container?string|nullauthorization_method?|Value in
"manual""auto""policy""ai_assisted""import""api""expiry""integrity""system"nullauthorized_by?string|nulljustification?string|nullpolicy_id?|Format
uuidpolicy_version?integer|nullreviewed_at?|Format
date-timeexpires_at?|Format
date-timereview_due_at?|Format
date-timefirst_seen_at?stringFormat
date-timelast_seen_at?stringFormat
date-timelast_verified_at?|Format
date-timelast_hash_change_at?|Format
date-timerule?|nullcurl -X POST "https://example.com/scripts/497f6eca-6276-4993-bfeb-53cbbbba6f08/block" \ -H "Content-Type: application/json" \ -d '{ "justification": "Unknown script exfiltrating card data." }'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "store_id": "7fe87115-950c-4ae8-bd7e-970406bc9ac0", "src": "string", "type": "first_party", "category": "string", "status": "trusted", "integrity_status": "match", "current_hash": "string", "authorized_hash": "string", "hash_source": "string", "sri_hash": "string", "integrity_attr": true, "size_bytes": 0, "vendor_id": "string", "gtm_container": "string", "authorization_method": "manual", "authorized_by": "string", "justification": "string", "policy_id": "ee9b03e0-6495-427a-85a5-34444d24ae04", "policy_version": 0, "reviewed_at": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z", "review_due_at": "2019-08-24T14:15:22Z", "first_seen_at": "2019-08-24T14:15:22Z", "last_seen_at": "2019-08-24T14:15:22Z", "last_verified_at": "2019-08-24T14:15:22Z", "last_hash_change_at": "2019-08-24T14:15:22Z", "rule": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "store_id": "7fe87115-950c-4ae8-bd7e-970406bc9ac0", "type": "block", "target": "domain", "value": "string", "label": "string", "active": true, "created_at": "2019-08-24T14:15:22Z" }}