/api/v2/cdn/zones List registrable CDN zone apexes the caller can manage.
Every manageable entry has a public cdn_... ID, including entries whose CDN setup is not yet provisioned.
Subdomains are excluded because they are DNS records inside a parent CDN zone, not independently configurable Cloudflare zones.
Registrar history in Cancelled, Terminated, or TransferredOut state is excluded unless the account separately owns a DNS-only zone with the same name.
Use this first when you only know the domain name and need the public cdn_... zone ID for detail, settings, or proxy-rule endpoints.
Registrar-backed zones include domainId; DNS-only zones return domainId: null.
Current visitor-filter settings are included as waf.visitorProfileMode and geoRestriction.combinedCountries; these are read from current zone settings, not a cached traffic report.
The canonical setup block describes managed-nameserver or external-DNS onboarding: branch on its status, and copy only returned verification/routing records.
With external nameservers, callers may choose managed nameservers (setup.nameserverManagementUrl when available, otherwise setup.expectedNameservers at the external registrar) or keep external DNS and use POST /api/v2/cdn/zones/{id} with prepare_partial, then check_partial.
A prepared setup or HTTP 200 alone does not mean traffic and HTTPS are ready.
read:cdnread:domains
Authenticate with an API key in the Authorization: Bearer <token> header.
limit integer · min: 1 · max: 200 · default: 50
· Example: 50 Maximum number of zones to return. The route accepts 1 through 200.
cursor string
· Example: eyJsYXN0SWQiOiJjZG5fMDFoeGEzYjRjNWQ2ZTdmOGc5aDBqMWsybTMifQ Opaque cursor returned as nextCursor from the previous page.
Authorization Bearer <token> Accept application/json data array<object> data[].setup object required Canonical CDN setup state for both managed nameservers and external DNS. Read status and reason directly; a prepared partial setup is not active until verification, hostname routing and HTTPS certificate readiness are confirmed. DNS names and targets are returned values to copy, not patterns to reconstruct.
data[].setup.mode string · enum required full is nameserver-based configuration; partial keeps external authoritative DNS and routes selected hostnames through the CDN. Read currentNameservers for the currently observed delegation.
full partial unknown data[].setup.status string · enum required Overall readiness. Pending states identify the next setup step. unavailable means the state could not be established; it is not proof that DNS or the certificate is incorrect.
not_configured pending_verification pending_routing pending_certificate active unavailable data[].setup.reason string · nullable required Explanation of the current setup state, or null when no explanation is needed.
data[].setup.verification object · nullable required Ownership-verification TXT record to publish at the authoritative DNS provider; null when no record is available or needed. Copy the returned name and value exactly.
data[].setup.routing array<object> required Selected hostnames with the origin values preserved during preparation and the required external-DNS routing changes. Publish the returned routing record without mixing conflicting record types at that name. An unsupported row cannot be treated as configured.
data[].setup.routing[].hostname string required
· Example: www.example.com data[].setup.routing[].currentOrigin array<object> required data[].setup.routing[].currentOrigin[].type string · enum required A AAAA CNAME data[].setup.routing[].currentOrigin[].value string required
· Example: 203.0.113.10 data[].setup.routing[].record object · nullable required Exact routing record to publish at the external DNS provider, or null when unavailable. ALIAS is for an apex-capable flattened alias; only use it when that provider supports it. Do not replace an apex with an ordinary CNAME when that would conflict with its other records.
data[].setup.routing[].status string · enum required pending verified unsupported unknown data[].setup.routing[].reason string · nullable required Nullable: may be null when not applicable.
data[].setup.certificate object required data[].setup.certificate.status string · enum required active pending error unknown data[].setup.certificate.hosts array<string> required Hostnames reported for the CDN HTTPS certificate.
data[].setup.checkedAt string · nullable required UTC time of the last setup check, or null when no check time is known.
data[].setup.currentNameservers array<string> required data[].setup.expectedNameservers array<string> required
· Example: ["primary.ns.hostup.se","secondary.ns.hostup.se"] Nameservers for the managed-nameserver alternative. Partial setup does not require switching to these nameservers.
data[].setup.registrarRelation string · enum required Where the domain's registrar management is available; independent of the selected CDN setup mode.
hostup external unknown data[].setup.nameserverManagementUrl string · nullable required Customer-facing nameserver-management URL when the domain can be managed here. Otherwise null: publish expectedNameservers through the external registrar if choosing managed nameservers.
data[].id string · nullable required
· Example: cdn_01hxa3b4c5d6e7f8g9h0j1k2m3 Public CDN zone ID, also returned before setup is provisioned. Null only when no manageable resource identity can be returned.
data[].domain string required
· Example: example.com data[].domainId string · nullable required
· Example: dom_01hxa3b4c5d6e7f8g9h0j1k2m3 Public domain ID for registrar-owned domains; null for DNS-only zones.
data[].status string · enum required
· Example: active active pending misconfigured missing disabled data[].reason string · nullable required
· Example: null Nullable: may be null when not applicable.
data[].proxied boolean required
· Example: true data[].securityLevel string · enum required
· Example: medium off low medium high data[].ssl object required data[].ssl.status string · enum required
· Example: active active pending error data[].ssl.expiresAt string · nullable required
· Example: 2026-08-01T00:00:00.000Z Nullable: may be null when not applicable.
data[].ruleCount integer required
· Example: 2 data[].waf object · nullable required Current saved visitor-profile mode, read with the zone status. Null when settings could not be determined; never sourced from a historical traffic report.
data[].geoRestriction object · nullable required Current effective audience countries. Having countries configured does not mean visitor verification is enabled; read waf.visitorProfileMode.
hasMore boolean
· Example: false nextCursor string · nullable
· Example: null type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object Retry-After seconds plus X-RateLimit-* headers. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object code is upstream_failed. Retry later or contact support if the issue persists. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object https://cloud.hostup.se/api/v2/cdn/zones curl -X GET "https://cloud.hostup.se/api/v2/cdn/zones" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Accept: application/json" {
"data": [
{
"id": "cdn_01hxa3b4c5d6e7f8g9h0j1k2m3",
"domain": "example.com",
"domainId": "dom_01hxa3b4c5d6e7f8g9h0j1k2m3",
"status": "active",
"reason": null,
"proxied": true,
"securityLevel": "medium",
"ssl": {
"status": "active",
"expiresAt": "2026-08-01T00:00:00.000Z"
},
"ruleCount": 2,
"waf": {
"visitorProfileMode": "challenge"
},
"geoRestriction": {
"combinedCountries": [
"SE"
]
},
"setup": {
"mode": "full",
"status": "active",
"reason": null,
"verification": null,
"routing": [],
"certificate": {
"status": "active",
"hosts": [
"example.com",
"www.example.com"
]
},
"checkedAt": "2026-04-27T12:00:00.000Z",
"currentNameservers": [
"primary.ns.hostup.se",
"secondary.ns.hostup.se"
],
"expectedNameservers": [
"primary.ns.hostup.se",
"secondary.ns.hostup.se"
],
"registrarRelation": "hostup",
"nameserverManagementUrl": "/domains/example.com?tab=nameservers"
}
}
],
"hasMore": false,
"nextCursor": null
}