List CDN zones

GET /api/v2/cdn/zones

List registrable CDN zone apexes the caller can manage.

Every manageable entry has a public cdn_... ID, including entries whose CDN setup is not yet provisioned.

Subdomains are excluded because they are DNS records inside a parent CDN zone, not independently configurable Cloudflare zones.

Registrar history in Cancelled, Terminated, or TransferredOut state is excluded unless the account separately owns a DNS-only zone with the same name.

Use this first when you only know the domain name and need the public cdn_... zone ID for detail, settings, or proxy-rule endpoints.

Registrar-backed zones include domainId; DNS-only zones return domainId: null.

Current visitor-filter settings are included as waf.visitorProfileMode and geoRestriction.combinedCountries; these are read from current zone settings, not a cached traffic report.

The canonical setup block describes managed-nameserver or external-DNS onboarding: branch on its status, and copy only returned verification/routing records.

With external nameservers, callers may choose managed nameservers (setup.nameserverManagementUrl when available, otherwise setup.expectedNameservers at the external registrar) or keep external DNS and use POST /api/v2/cdn/zones/{id} with prepare_partial, then check_partial.

A prepared setup or HTTP 200 alone does not mean traffic and HTTPS are ready.

CDN & Edge Other

Authentication

Required API scopes: read:cdnread:domains

Authenticate with an API key in the Authorization: Bearer <token> header.

Context

Query Parameters

limit integer · min: 1 · max: 200 · default: 50 · Example: 50

Maximum number of zones to return. The route accepts 1 through 200.

cursor string · Example: eyJsYXN0SWQiOiJjZG5fMDFoeGEzYjRjNWQ2ZTdmOGc5aDBqMWsybTMifQ

Opaque cursor returned as nextCursor from the previous page.

Headers

Authorization Bearer <token>
Accept application/json

Responses

200 CDN zone list.
data array<object>
data[].setup object required

Canonical CDN setup state for both managed nameservers and external DNS. Read status and reason directly; a prepared partial setup is not active until verification, hostname routing and HTTPS certificate readiness are confirmed. DNS names and targets are returned values to copy, not patterns to reconstruct.

data[].setup.mode string · enum required

full is nameserver-based configuration; partial keeps external authoritative DNS and routes selected hostnames through the CDN. Read currentNameservers for the currently observed delegation.

full
partial
unknown
data[].setup.status string · enum required

Overall readiness. Pending states identify the next setup step. unavailable means the state could not be established; it is not proof that DNS or the certificate is incorrect.

not_configured
pending_verification
pending_routing
pending_certificate
active
unavailable
data[].setup.reason string · nullable required

Explanation of the current setup state, or null when no explanation is needed.

data[].setup.verification object · nullable required

Ownership-verification TXT record to publish at the authoritative DNS provider; null when no record is available or needed. Copy the returned name and value exactly.

data[].setup.routing array<object> required

Selected hostnames with the origin values preserved during preparation and the required external-DNS routing changes. Publish the returned routing record without mixing conflicting record types at that name. An unsupported row cannot be treated as configured.

data[].setup.routing[].hostname string required · Example: www.example.com
data[].setup.routing[].currentOrigin array<object> required
data[].setup.routing[].currentOrigin[].type string · enum required
A
AAAA
CNAME
data[].setup.routing[].currentOrigin[].value string required · Example: 203.0.113.10
data[].setup.routing[].record object · nullable required

Exact routing record to publish at the external DNS provider, or null when unavailable. ALIAS is for an apex-capable flattened alias; only use it when that provider supports it. Do not replace an apex with an ordinary CNAME when that would conflict with its other records.

data[].setup.routing[].status string · enum required
pending
verified
unsupported
unknown
data[].setup.routing[].reason string · nullable required

Nullable: may be null when not applicable.

data[].setup.certificate object required
data[].setup.certificate.status string · enum required
active
pending
error
unknown
data[].setup.certificate.hosts array<string> required

Hostnames reported for the CDN HTTPS certificate.

data[].setup.checkedAt string · nullable required

UTC time of the last setup check, or null when no check time is known.

data[].setup.currentNameservers array<string> required
data[].setup.expectedNameservers array<string> required · Example: ["primary.ns.hostup.se","secondary.ns.hostup.se"]

Nameservers for the managed-nameserver alternative. Partial setup does not require switching to these nameservers.

data[].setup.registrarRelation string · enum required

Where the domain's registrar management is available; independent of the selected CDN setup mode.

hostup
external
unknown
data[].setup.nameserverManagementUrl string · nullable required

Customer-facing nameserver-management URL when the domain can be managed here. Otherwise null: publish expectedNameservers through the external registrar if choosing managed nameservers.

data[].id string · nullable required · Example: cdn_01hxa3b4c5d6e7f8g9h0j1k2m3

Public CDN zone ID, also returned before setup is provisioned. Null only when no manageable resource identity can be returned.

data[].domain string required · Example: example.com
data[].domainId string · nullable required · Example: dom_01hxa3b4c5d6e7f8g9h0j1k2m3

Public domain ID for registrar-owned domains; null for DNS-only zones.

data[].status string · enum required · Example: active
active
pending
misconfigured
missing
disabled
data[].reason string · nullable required · Example: null

Nullable: may be null when not applicable.

data[].proxied boolean required · Example: true
data[].securityLevel string · enum required · Example: medium
off
low
medium
high
data[].ssl object required
data[].ssl.status string · enum required · Example: active
active
pending
error
data[].ssl.expiresAt string · nullable required · Example: 2026-08-01T00:00:00.000Z

Nullable: may be null when not applicable.

data[].ruleCount integer required · Example: 2
data[].waf object · nullable required

Current saved visitor-profile mode, read with the zone status. Null when settings could not be determined; never sourced from a historical traffic report.

data[].geoRestriction object · nullable required

Current effective audience countries. Having countries configured does not mean visitor verification is enabled; read waf.visitorProfileMode.

hasMore boolean · Example: false
nextCursor string · nullable · Example: null

400 Invalid request. The response body is an RFC 7807 Problem Details document.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
401 Unauthorized. Authentication is required.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
403 Forbidden. The caller lacks a required scope or does not own the resource.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
404 Not found. The resource does not exist or is not owned by the caller.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
429 Rate limited. Retry after the limit resets. 429 responses include Retry-After seconds plus X-RateLimit-* headers.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
500 Internal error. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
502 Upstream failure. A dependent provider request failed; the Problem Details code is upstream_failed. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
GET https://cloud.hostup.se/api/v2/cdn/zones
For AI assistants
View as Markdown
cURL
curl -X GET "https://cloud.hostup.se/api/v2/cdn/zones" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
Response
{
  "data": [
    {
      "id": "cdn_01hxa3b4c5d6e7f8g9h0j1k2m3",
      "domain": "example.com",
      "domainId": "dom_01hxa3b4c5d6e7f8g9h0j1k2m3",
      "status": "active",
      "reason": null,
      "proxied": true,
      "securityLevel": "medium",
      "ssl": {
        "status": "active",
        "expiresAt": "2026-08-01T00:00:00.000Z"
      },
      "ruleCount": 2,
      "waf": {
        "visitorProfileMode": "challenge"
      },
      "geoRestriction": {
        "combinedCountries": [
          "SE"
        ]
      },
      "setup": {
        "mode": "full",
        "status": "active",
        "reason": null,
        "verification": null,
        "routing": [],
        "certificate": {
          "status": "active",
          "hosts": [
            "example.com",
            "www.example.com"
          ]
        },
        "checkedAt": "2026-04-27T12:00:00.000Z",
        "currentNameservers": [
          "primary.ns.hostup.se",
          "secondary.ns.hostup.se"
        ],
        "expectedNameservers": [
          "primary.ns.hostup.se",
          "secondary.ns.hostup.se"
        ],
        "registrarRelation": "hostup",
        "nameserverManagementUrl": "/domains/example.com?tab=nameservers"
      }
    }
  ],
  "hasMore": false,
  "nextCursor": null
}