/api/v2/domains/{id}/cdn Partially update CDN settings for a domain public ID.
The body uses the same grouped fields returned by the GET endpoint: proxied, security, performance, cache, waf, and geoRestriction.
Send at least one supported setting field; a no-op body returns invalid_request.
To clear the country profile, send geoRestriction.mode: "off".
The canonical setup block describes managed-nameserver or external-DNS onboarding: branch on its status, and copy only returned verification/routing records.
With external nameservers, callers may choose managed nameservers (setup.nameserverManagementUrl when available, otherwise setup.expectedNameservers at the external registrar) or keep external DNS and use POST /api/v2/cdn/zones/{id} with prepare_partial, then check_partial.
A prepared setup or HTTP 200 alone does not mean traffic and HTTPS are ready.
The setup action uses the cdn_... value returned in this resource's id, not the domain's dom_... ID.
setup is response-only; do not send setup actions or DNS-verification records as grouped setting fields.
write:cdnwrite:domains
Authenticate with an API key in the Authorization: Bearer <token> header.
id string required
Example: dom_01hxa3b4c5d6e7f8g9h0j1k2m3 Public domain ID. Get it from GET /api/v2/domains data[].id. Do not invent this value; use the exact ID returned by the referenced API response.
Authorization Bearer <token> Accept application/json Content-Type application/json proxied boolean
· Example: true Turn CDN proxying on or off for this zone.
security object security.level string · enum
· Example: high off low medium high security.sslMode string · enum
· Example: full off flexible full strict security.alwaysUseHttps boolean
· Example: true security.minTlsVersion string · enum
· Example: 1.2 1.0 1.1 1.2 1.3 security.botProtection boolean
· Example: true security.blockBadCrawlers boolean
· Example: true security.blockBadBots boolean
· Example: true security.wpLoginProtection boolean
· Example: true security.wpAdminChallenge boolean
· Example: true performance object performance.earlyHints boolean
· Example: true performance.alwaysOnline boolean
· Example: true cache object cache.purgeCache boolean
· Example: true waf object waf.skipEnabled boolean
· Example: false waf.challengeGeoEnabled boolean
· Example: true waf.visitorProfileMode string · enum
· Example: challenge off challenge block waf.ipAllowlist array<string>
· Example: ["203.0.113.10"] waf.uaAllowlist array<string>
· Example: ["HostUp-Monitor"] waf.pathAllowlist array<string>
· Example: ["/health"] geoRestriction object geoRestriction.mode string · enum
· Example: whitelist off whitelist geoRestriction.additionalCountries array<string>
· Example: ["SE"] Uppercase ISO country codes to allow in addition to any system-required countries.
setup object Canonical CDN setup state for both managed nameservers and external DNS. Read status and reason directly; a prepared partial setup is not active until verification, hostname routing and HTTPS certificate readiness are confirmed. DNS names and targets are returned values to copy, not patterns to reconstruct.
setup.mode string · enum required full is nameserver-based configuration; partial keeps external authoritative DNS and routes selected hostnames through the CDN. Read currentNameservers for the currently observed delegation.
full partial unknown setup.status string · enum required Overall readiness. Pending states identify the next setup step. unavailable means the state could not be established; it is not proof that DNS or the certificate is incorrect.
not_configured pending_verification pending_routing pending_certificate active unavailable setup.reason string · nullable required Explanation of the current setup state, or null when no explanation is needed.
setup.verification object · nullable required Ownership-verification TXT record to publish at the authoritative DNS provider; null when no record is available or needed. Copy the returned name and value exactly.
setup.routing array<object> required Selected hostnames with the origin values preserved during preparation and the required external-DNS routing changes. Publish the returned routing record without mixing conflicting record types at that name. An unsupported row cannot be treated as configured.
setup.routing[].hostname string required
· Example: www.example.com setup.routing[].currentOrigin array<object> required setup.routing[].currentOrigin[].type string · enum required A AAAA CNAME setup.routing[].currentOrigin[].value string required
· Example: 203.0.113.10 setup.routing[].record object · nullable required Exact routing record to publish at the external DNS provider, or null when unavailable. ALIAS is for an apex-capable flattened alias; only use it when that provider supports it. Do not replace an apex with an ordinary CNAME when that would conflict with its other records.
setup.routing[].status string · enum required pending verified unsupported unknown setup.routing[].reason string · nullable required Nullable: may be null when not applicable.
setup.certificate object required setup.certificate.status string · enum required active pending error unknown setup.certificate.hosts array<string> required Hostnames reported for the CDN HTTPS certificate.
setup.checkedAt string · nullable required UTC time of the last setup check, or null when no check time is known.
setup.currentNameservers array<string> required setup.expectedNameservers array<string> required
· Example: ["primary.ns.hostup.se","secondary.ns.hostup.se"] Nameservers for the managed-nameserver alternative. Partial setup does not require switching to these nameservers.
setup.registrarRelation string · enum required Where the domain's registrar management is available; independent of the selected CDN setup mode.
hostup external unknown setup.nameserverManagementUrl string · nullable required Customer-facing nameserver-management URL when the domain can be managed here. Otherwise null: publish expectedNameservers through the external registrar if choosing managed nameservers.
id string
· Example: cdn_01hxa3b4c5d6e7f8g9h0j1k2m3 Public CDN zone ID. Get it from this endpoint or GET /api/v2/cdn/zones.
domain string
· Example: example.com state object state.exists boolean required
· Example: true state.enabled boolean required
· Example: true state.status string · enum required
· Example: active active inactive disabled not_found state.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
proxied boolean
· Example: true Master CDN proxy switch for the domain.
cdn object cdn.enabled boolean required
· Example: true cdn.proxy boolean required
· Example: true security object security.level string · enum required
· Example: medium Overall CDN security level.
off low medium high security.sslMode string · enum required
· Example: full TLS mode used between visitors, CDN, and origin.
off flexible full strict security.alwaysUseHttps boolean required
· Example: true security.minTlsVersion string · enum required
· Example: 1.2 1.0 1.1 1.2 1.3 security.botProtection boolean required
· Example: true security.blockBadCrawlers boolean required
· Example: true security.blockBadBots boolean required
· Example: true security.wpLoginProtection boolean required
· Example: true Protect WordPress login endpoints.
security.wpAdminChallenge boolean required
· Example: true Challenge requests to WordPress administration paths.
performance object performance.earlyHints boolean required
· Example: true performance.alwaysOnline boolean required
· Example: true cache object cache.purgeCache boolean required
· Example: false Current persisted cache-purge toggle returned by the CDN settings surface.
waf object waf.skipEnabled boolean required
· Example: false Whether custom WAF skip rules are enabled.
waf.challengeGeoEnabled boolean required
· Example: true Whether visitor-profile country challenge logic is enabled.
waf.visitorProfileMode string · enum required
· Example: challenge challenge asks visitors outside the configured country profile to complete a challenge; block blocks them; off disables this profile action.
off challenge block waf.ipAllowlist array<string> required
· Example: ["203.0.113.10"] IP addresses or CIDR ranges allowed through custom WAF checks.
waf.uaAllowlist array<string> required
· Example: ["HostUp-Monitor"] User-agent substrings allowed through custom WAF checks.
waf.pathAllowlist array<string> required
· Example: ["/health"] Path prefixes allowed through custom WAF checks.
geoRestriction object geoRestriction.enabled boolean required
· Example: true geoRestriction.whitelistCountries array<string> required
· Example: ["SE"] Effective uppercase country-code allowlist kept for compatibility. Prefer combinedCountries for new integrations.
geoRestriction.mode string · enum required
· Example: whitelist off disables the allowlist; whitelist allows only combinedCountries.
off whitelist geoRestriction.standardCountries array<string> required
· Example: [] System-required countries that callers cannot remove.
geoRestriction.additionalCountries array<string> required
· Example: ["SE"] Caller-managed country codes layered on top of standardCountries.
geoRestriction.combinedCountries array<string> required
· Example: ["SE"] Effective allowlist: standardCountries plus additionalCountries.
activity object activity.lastChangeDetectedAt string · nullable required
· Example: 2026-04-27T12:00:00.000Z Nullable: may be null when not applicable.
activity.lastCheckedAt string · nullable required
· Example: 2026-04-27T12:00:00.000Z Nullable: may be null when not applicable.
activity.settingsUpdatedAt string · nullable required
· Example: 2026-04-27T12:00:00.000Z Nullable: may be null when not applicable.
actions object actions.canEnableProxy object required actions.canEnableProxy.allowed boolean required
· Example: true actions.canEnableProxy.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canEnableProxy.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
actions.canIssueCertificate object required actions.canIssueCertificate.allowed boolean required
· Example: true actions.canIssueCertificate.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canIssueCertificate.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
actions.canChangeMode object required actions.canChangeMode.allowed boolean required
· Example: true actions.canChangeMode.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canChangeMode.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
actions.canActivate object required actions.canActivate.allowed boolean required
· Example: true actions.canActivate.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canActivate.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
actions.canDeactivate object required actions.canDeactivate.allowed boolean required
· Example: true actions.canDeactivate.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canDeactivate.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
actions.canPreparePartial object required Whether external-DNS preparation may be requested. The request also verifies current authoritative delegation; a currently delegated full setup cannot be converted through this action.
actions.canPreparePartial.allowed boolean required
· Example: true actions.canPreparePartial.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canPreparePartial.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
actions.canCheckPartial object required Whether an existing partial setup can be checked now.
actions.canCheckPartial.allowed boolean required
· Example: true actions.canCheckPartial.reason string · nullable required
· Example: null Nullable: may be null when not applicable.
actions.canCheckPartial.code string · nullable
· Example: pending_order Machine-readable reason code when an action is blocked.
records array<any> · nullable null unless includeRecords=true; then contains proxied A, AAAA, and CNAME records.
type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object code is domain_not_found. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object code is account_suspended, or a route-specific blocker with its own recovery fields. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object Retry-After seconds plus X-RateLimit-* headers. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object code is upstream_failed. Retry later or contact support if the issue persists. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object https://cloud.hostup.se/api/v2/domains/{id}/cdn curl -X PATCH "https://cloud.hostup.se/api/v2/domains/dom_01hxa3b4c5d6e7f8g9h0j1k2m3/cdn" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{
"proxied": true,
"security": {
"sslMode": "full",
"alwaysUseHttps": true,
"minTlsVersion": "1.2"
}
}' {
"id": "cdn_01hxa3b4c5d6e7f8g9h0j1k2m3",
"domain": "example.com",
"state": {
"exists": true,
"enabled": true,
"status": "active",
"reason": null
},
"proxied": true,
"cdn": {
"enabled": true,
"proxy": true
},
"security": {
"level": "medium",
"sslMode": "full",
"alwaysUseHttps": true,
"minTlsVersion": "1.2",
"botProtection": true,
"blockBadCrawlers": true,
"blockBadBots": true,
"wpLoginProtection": true,
"wpAdminChallenge": true
},
"performance": {
"earlyHints": true,
"alwaysOnline": true
},
"cache": {
"purgeCache": false
},
"waf": {
"skipEnabled": false,
"challengeGeoEnabled": true,
"visitorProfileMode": "challenge",
"ipAllowlist": [
"203.0.113.10"
],
"uaAllowlist": [
"HostUp-Monitor"
],
"pathAllowlist": [
"/health"
]
},
"geoRestriction": {
"enabled": true,
"whitelistCountries": [
"SE"
],
"mode": "whitelist",
"standardCountries": [],
"additionalCountries": [
"SE"
],
"combinedCountries": [
"SE"
]
},
"activity": {
"lastChangeDetectedAt": "2026-04-27T12:00:00.000Z",
"lastCheckedAt": "2026-04-27T12:00:00.000Z",
"settingsUpdatedAt": "2026-04-27T12:00:00.000Z"
},
"actions": {
"canEnableProxy": {
"allowed": true,
"reason": null
},
"canIssueCertificate": {
"allowed": true,
"reason": null
},
"canChangeMode": {
"allowed": true,
"reason": null
},
"canActivate": {
"allowed": false,
"reason": "CDN is already active for this domain."
},
"canDeactivate": {
"allowed": true,
"reason": null
},
"canPreparePartial": {
"allowed": true,
"reason": null
},
"canCheckPartial": {
"allowed": false,
"reason": "Prepare external DNS setup first."
}
},
"records": null,
"setup": {
"mode": "full",
"status": "active",
"reason": null,
"verification": null,
"routing": [],
"certificate": {
"status": "active",
"hosts": [
"example.com",
"www.example.com"
]
},
"checkedAt": "2026-04-27T12:00:00.000Z",
"currentNameservers": [
"primary.ns.hostup.se",
"secondary.ns.hostup.se"
],
"expectedNameservers": [
"primary.ns.hostup.se",
"secondary.ns.hostup.se"
],
"registrarRelation": "hostup",
"nameserverManagementUrl": "/domains/example.com?tab=nameservers"
}
} {
"proxied": true,
"security": {
"sslMode": "full",
"alwaysUseHttps": true,
"minTlsVersion": "1.2"
}
}