/api/v2/vps/{id}/ddos-scrubbing Get the on-demand DDoS scrubbing state for the VPS primary IP.
If available is false, reason explains why scrubbing cannot be used.
When a session is active, durationSeconds and expiresAt describe how long it runs.
networkMitigation reports any network-level mitigation currently applied to the IP — including automatic attack responses.
networkMitigation.action "blackhole" means all internet traffic to the IP is temporarily dropped (the VPS is unreachable from outside until expiresAt); "scrub" means traffic is filtered but services keep working.
networkMitigation.status "unknown" means the mitigation state could not be verified right now — do not treat it as "no mitigation".
Use POST /api/v2/vps/{id}/ddos-scrubbing to enable a session and DELETE /api/v2/vps/{id}/ddos-scrubbing to end it early.
read:vm
Authenticate with an API key in the Authorization: Bearer <token> header.
id string required
Example: vps_01hxa3b4c5d6e7f8g9h0j1k2m3 Public VPS ID. Get it from GET /api/v2/vps data[].id. Do not invent this value; use the exact ID returned by the referenced API response.
Authorization Bearer <token> Accept application/json available boolean required Whether on-demand DDoS scrubbing can be used on this VPS.
reason string · nullable required Why scrubbing is unavailable, or null when it is available.
ip string · nullable required IP address the scrubbing state applies to.
active boolean required Whether an on-demand scrubbing session is currently active.
durationSeconds integer · nullable required Duration of the active session in seconds, or null when no session is active.
createdAt string · nullable required When the active session started, or null.
expiresAt string · nullable required When the active session ends, or null.
networkMitigation object required Any network-level DDoS mitigation currently applied to the VPS IP, including automatic attack responses that are not part of an on-demand session.
networkMitigation.status string · enum required "active" when a mitigation is applied, "none" when verified clear, "unknown" when the state could not be verified right now (never assume "unknown" means clear).
active none unknown networkMitigation.action string · nullable · enum required "blackhole": all internet traffic to the IP is dropped until the mitigation ends — the VPS appears offline from outside. "scrub": traffic is filtered; services keep working. Null when status is not "active".
blackhole scrub networkMitigation.automatic boolean · nullable required True when the mitigation was applied automatically in response to an attack; false when it is the customer's own on-demand scrubbing session. Null when unknown.
networkMitigation.createdAt string · nullable required When the mitigation started, or null.
networkMitigation.expiresAt string · nullable required When the mitigation automatically ends, or null.
type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object Retry-After seconds plus X-RateLimit-* headers. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object https://cloud.hostup.se/api/v2/vps/{id}/ddos-scrubbing curl -X GET "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/ddos-scrubbing" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Accept: application/json" {
"available": true,
"reason": null,
"ip": "192.0.2.10",
"active": false,
"durationSeconds": null,
"createdAt": null,
"expiresAt": null,
"networkMitigation": {
"status": "active",
"action": "blackhole",
"automatic": true,
"createdAt": "2026-08-07T11:15:20.000Z",
"expiresAt": "2026-08-07T12:15:20.000Z"
}
}