Get domain CDN settings

GET /api/v2/domains/{id}/cdn

Return CDN state and settings for a domain public ID.

Use this path when you already have dom_...; use GET /api/v2/cdn/zones when you need to discover CDN zones across registrar and DNS-only domains.

The canonical setup block describes managed-nameserver or external-DNS onboarding: branch on its status, and copy only returned verification/routing records.

With external nameservers, callers may choose managed nameservers (setup.nameserverManagementUrl when available, otherwise setup.expectedNameservers at the external registrar) or keep external DNS and use POST /api/v2/cdn/zones/{id} with prepare_partial, then check_partial.

A prepared setup or HTTP 200 alone does not mean traffic and HTTPS are ready.

The setup action uses the cdn_... value returned in this resource's id, not the domain's dom_... ID.

Domains & DNS CDN

Authentication

Required API scopes: read:cdnread:domains

Authenticate with an API key in the Authorization: Bearer <token> header.

Context

Path Parameters

id string required Example: dom_01hxa3b4c5d6e7f8g9h0j1k2m3

Public domain ID. Get it from GET /api/v2/domains data[].id. Do not invent this value; use the exact ID returned by the referenced API response.

Query Parameters

includeRecords boolean · default: false · Example: true

When true, include proxied A, AAAA, and CNAME records in records; otherwise records is null.

Headers

Authorization Bearer <token>
Accept application/json

Responses

200 Domain CDN settings.
setup object

Canonical CDN setup state for both managed nameservers and external DNS. Read status and reason directly; a prepared partial setup is not active until verification, hostname routing and HTTPS certificate readiness are confirmed. DNS names and targets are returned values to copy, not patterns to reconstruct.

setup.mode string · enum required

full is nameserver-based configuration; partial keeps external authoritative DNS and routes selected hostnames through the CDN. Read currentNameservers for the currently observed delegation.

full
partial
unknown
setup.status string · enum required

Overall readiness. Pending states identify the next setup step. unavailable means the state could not be established; it is not proof that DNS or the certificate is incorrect.

not_configured
pending_verification
pending_routing
pending_certificate
active
unavailable
setup.reason string · nullable required

Explanation of the current setup state, or null when no explanation is needed.

setup.verification object · nullable required

Ownership-verification TXT record to publish at the authoritative DNS provider; null when no record is available or needed. Copy the returned name and value exactly.

setup.routing array<object> required

Selected hostnames with the origin values preserved during preparation and the required external-DNS routing changes. Publish the returned routing record without mixing conflicting record types at that name. An unsupported row cannot be treated as configured.

setup.routing[].hostname string required · Example: www.example.com
setup.routing[].currentOrigin array<object> required
setup.routing[].currentOrigin[].type string · enum required
A
AAAA
CNAME
setup.routing[].currentOrigin[].value string required · Example: 203.0.113.10
setup.routing[].record object · nullable required

Exact routing record to publish at the external DNS provider, or null when unavailable. ALIAS is for an apex-capable flattened alias; only use it when that provider supports it. Do not replace an apex with an ordinary CNAME when that would conflict with its other records.

setup.routing[].status string · enum required
pending
verified
unsupported
unknown
setup.routing[].reason string · nullable required

Nullable: may be null when not applicable.

setup.certificate object required
setup.certificate.status string · enum required
active
pending
error
unknown
setup.certificate.hosts array<string> required

Hostnames reported for the CDN HTTPS certificate.

setup.checkedAt string · nullable required

UTC time of the last setup check, or null when no check time is known.

setup.currentNameservers array<string> required
setup.expectedNameservers array<string> required · Example: ["primary.ns.hostup.se","secondary.ns.hostup.se"]

Nameservers for the managed-nameserver alternative. Partial setup does not require switching to these nameservers.

setup.registrarRelation string · enum required

Where the domain's registrar management is available; independent of the selected CDN setup mode.

hostup
external
unknown
setup.nameserverManagementUrl string · nullable required

Customer-facing nameserver-management URL when the domain can be managed here. Otherwise null: publish expectedNameservers through the external registrar if choosing managed nameservers.

id string · Example: cdn_01hxa3b4c5d6e7f8g9h0j1k2m3

Public CDN zone ID. Get it from this endpoint or GET /api/v2/cdn/zones.

domain string · Example: example.com
state object
state.exists boolean required · Example: true
state.enabled boolean required · Example: true
state.status string · enum required · Example: active
active
inactive
disabled
not_found
state.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

proxied boolean · Example: true

Master CDN proxy switch for the domain.

cdn object
cdn.enabled boolean required · Example: true
cdn.proxy boolean required · Example: true
security object
security.level string · enum required · Example: medium

Overall CDN security level.

off
low
medium
high
security.sslMode string · enum required · Example: full

TLS mode used between visitors, CDN, and origin.

off
flexible
full
strict
security.alwaysUseHttps boolean required · Example: true
security.minTlsVersion string · enum required · Example: 1.2
1.0
1.1
1.2
1.3
security.botProtection boolean required · Example: true
security.blockBadCrawlers boolean required · Example: true
security.blockBadBots boolean required · Example: true
security.wpLoginProtection boolean required · Example: true

Protect WordPress login endpoints.

security.wpAdminChallenge boolean required · Example: true

Challenge requests to WordPress administration paths.

performance object
performance.earlyHints boolean required · Example: true
performance.alwaysOnline boolean required · Example: true
cache object
cache.purgeCache boolean required · Example: false

Current persisted cache-purge toggle returned by the CDN settings surface.

waf object
waf.skipEnabled boolean required · Example: false

Whether custom WAF skip rules are enabled.

waf.challengeGeoEnabled boolean required · Example: true

Whether visitor-profile country challenge logic is enabled.

waf.visitorProfileMode string · enum required · Example: challenge

challenge asks visitors outside the configured country profile to complete a challenge; block blocks them; off disables this profile action.

off
challenge
block
waf.ipAllowlist array<string> required · Example: ["203.0.113.10"]

IP addresses or CIDR ranges allowed through custom WAF checks.

waf.uaAllowlist array<string> required · Example: ["HostUp-Monitor"]

User-agent substrings allowed through custom WAF checks.

waf.pathAllowlist array<string> required · Example: ["/health"]

Path prefixes allowed through custom WAF checks.

geoRestriction object
geoRestriction.enabled boolean required · Example: true
geoRestriction.whitelistCountries array<string> required · Example: ["SE"]

Effective uppercase country-code allowlist kept for compatibility. Prefer combinedCountries for new integrations.

geoRestriction.mode string · enum required · Example: whitelist

off disables the allowlist; whitelist allows only combinedCountries.

off
whitelist
geoRestriction.standardCountries array<string> required · Example: []

System-required countries that callers cannot remove.

geoRestriction.additionalCountries array<string> required · Example: ["SE"]

Caller-managed country codes layered on top of standardCountries.

geoRestriction.combinedCountries array<string> required · Example: ["SE"]

Effective allowlist: standardCountries plus additionalCountries.

activity object
activity.lastChangeDetectedAt string · nullable required · Example: 2026-04-27T12:00:00.000Z

Nullable: may be null when not applicable.

activity.lastCheckedAt string · nullable required · Example: 2026-04-27T12:00:00.000Z

Nullable: may be null when not applicable.

activity.settingsUpdatedAt string · nullable required · Example: 2026-04-27T12:00:00.000Z

Nullable: may be null when not applicable.

actions object
actions.canEnableProxy object required
actions.canEnableProxy.allowed boolean required · Example: true
actions.canEnableProxy.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canEnableProxy.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canIssueCertificate object required
actions.canIssueCertificate.allowed boolean required · Example: true
actions.canIssueCertificate.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canIssueCertificate.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canChangeMode object required
actions.canChangeMode.allowed boolean required · Example: true
actions.canChangeMode.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canChangeMode.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canActivate object required
actions.canActivate.allowed boolean required · Example: true
actions.canActivate.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canActivate.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canDeactivate object required
actions.canDeactivate.allowed boolean required · Example: true
actions.canDeactivate.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canDeactivate.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canPreparePartial object required

Whether external-DNS preparation may be requested. The request also verifies current authoritative delegation; a currently delegated full setup cannot be converted through this action.

actions.canPreparePartial.allowed boolean required · Example: true
actions.canPreparePartial.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canPreparePartial.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

actions.canCheckPartial object required

Whether an existing partial setup can be checked now.

actions.canCheckPartial.allowed boolean required · Example: true
actions.canCheckPartial.reason string · nullable required · Example: null

Nullable: may be null when not applicable.

actions.canCheckPartial.code string · nullable · Example: pending_order

Machine-readable reason code when an action is blocked.

records array<any> · nullable

null unless includeRecords=true; then contains proxied A, AAAA, and CNAME records.

400 Invalid request. The response body is an RFC 7807 Problem Details document.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
401 Unauthorized. Authentication is required.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
403 Forbidden. The caller lacks a required scope or does not own the resource.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
404 Not found. The resource does not exist or is not owned by the caller; code is domain_not_found.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
409 Conflict. code is account_suspended.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
429 Rate limited. Retry after the limit resets. 429 responses include Retry-After seconds plus X-RateLimit-* headers.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
500 Internal error. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
502 Upstream failure. A dependent provider request failed; the Problem Details code is upstream_failed. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
GET https://cloud.hostup.se/api/v2/domains/{id}/cdn
For AI assistants
View as Markdown
cURL
curl -X GET "https://cloud.hostup.se/api/v2/domains/dom_01hxa3b4c5d6e7f8g9h0j1k2m3/cdn" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
Response
{
  "id": "cdn_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "domain": "example.com",
  "state": {
    "exists": true,
    "enabled": true,
    "status": "active",
    "reason": null
  },
  "proxied": true,
  "cdn": {
    "enabled": true,
    "proxy": true
  },
  "security": {
    "level": "medium",
    "sslMode": "full",
    "alwaysUseHttps": true,
    "minTlsVersion": "1.2",
    "botProtection": true,
    "blockBadCrawlers": true,
    "blockBadBots": true,
    "wpLoginProtection": true,
    "wpAdminChallenge": true
  },
  "performance": {
    "earlyHints": true,
    "alwaysOnline": true
  },
  "cache": {
    "purgeCache": false
  },
  "waf": {
    "skipEnabled": false,
    "challengeGeoEnabled": true,
    "visitorProfileMode": "challenge",
    "ipAllowlist": [
      "203.0.113.10"
    ],
    "uaAllowlist": [
      "HostUp-Monitor"
    ],
    "pathAllowlist": [
      "/health"
    ]
  },
  "geoRestriction": {
    "enabled": true,
    "whitelistCountries": [
      "SE"
    ],
    "mode": "whitelist",
    "standardCountries": [],
    "additionalCountries": [
      "SE"
    ],
    "combinedCountries": [
      "SE"
    ]
  },
  "activity": {
    "lastChangeDetectedAt": "2026-04-27T12:00:00.000Z",
    "lastCheckedAt": "2026-04-27T12:00:00.000Z",
    "settingsUpdatedAt": "2026-04-27T12:00:00.000Z"
  },
  "actions": {
    "canEnableProxy": {
      "allowed": true,
      "reason": null
    },
    "canIssueCertificate": {
      "allowed": true,
      "reason": null
    },
    "canChangeMode": {
      "allowed": true,
      "reason": null
    },
    "canActivate": {
      "allowed": false,
      "reason": "CDN is already active for this domain."
    },
    "canDeactivate": {
      "allowed": true,
      "reason": null
    },
    "canPreparePartial": {
      "allowed": true,
      "reason": null
    },
    "canCheckPartial": {
      "allowed": false,
      "reason": "Prepare external DNS setup first."
    }
  },
  "records": [
    {
      "id": "drr_01hxa3b4c5d6e7f8g9h0j1k2m3",
      "fqdn": "example.com",
      "type": "A",
      "value": "203.0.113.10",
      "proxied": true,
      "ttl": 300,
      "proxyRule": {
        "enabled": true,
        "mode": "always"
      }
    }
  ],
  "setup": {
    "mode": "full",
    "status": "active",
    "reason": null,
    "verification": null,
    "routing": [],
    "certificate": {
      "status": "active",
      "hosts": [
        "example.com",
        "www.example.com"
      ]
    },
    "checkedAt": "2026-04-27T12:00:00.000Z",
    "currentNameservers": [
      "primary.ns.hostup.se",
      "secondary.ns.hostup.se"
    ],
    "expectedNameservers": [
      "primary.ns.hostup.se",
      "secondary.ns.hostup.se"
    ],
    "registrarRelation": "hostup",
    "nameserverManagementUrl": "/domains/example.com?tab=nameservers"
  }
}