Get DDoS scrubbing status

GET /api/v2/vps/{id}/ddos-scrubbing

Get the on-demand DDoS scrubbing state for the VPS primary IP.

If available is false, reason explains why scrubbing cannot be used.

When a session is active, durationSeconds and expiresAt describe how long it runs.

networkMitigation reports any network-level mitigation currently applied to the IP — including automatic attack responses.

networkMitigation.action "blackhole" means all internet traffic to the IP is temporarily dropped (the VPS is unreachable from outside until expiresAt); "scrub" means traffic is filtered but services keep working.

networkMitigation.status "unknown" means the mitigation state could not be verified right now — do not treat it as "no mitigation".

Use POST /api/v2/vps/{id}/ddos-scrubbing to enable a session and DELETE /api/v2/vps/{id}/ddos-scrubbing to end it early.

VPS Services VM

Authentication

Required API scope: read:vm

Authenticate with an API key in the Authorization: Bearer <token> header.

Context

Path Parameters

id string required Example: vps_01hxa3b4c5d6e7f8g9h0j1k2m3

Public VPS ID. Get it from GET /api/v2/vps data[].id. Do not invent this value; use the exact ID returned by the referenced API response.

Headers

Authorization Bearer <token>
Accept application/json

Responses

200 The current DDoS scrubbing state.
available boolean required

Whether on-demand DDoS scrubbing can be used on this VPS.

reason string · nullable required

Why scrubbing is unavailable, or null when it is available.

ip string · nullable required

IP address the scrubbing state applies to.

active boolean required

Whether an on-demand scrubbing session is currently active.

durationSeconds integer · nullable required

Duration of the active session in seconds, or null when no session is active.

createdAt string · nullable required

When the active session started, or null.

expiresAt string · nullable required

When the active session ends, or null.

networkMitigation object required

Any network-level DDoS mitigation currently applied to the VPS IP, including automatic attack responses that are not part of an on-demand session.

networkMitigation.status string · enum required

"active" when a mitigation is applied, "none" when verified clear, "unknown" when the state could not be verified right now (never assume "unknown" means clear).

active
none
unknown
networkMitigation.action string · nullable · enum required

"blackhole": all internet traffic to the IP is dropped until the mitigation ends — the VPS appears offline from outside. "scrub": traffic is filtered; services keep working. Null when status is not "active".

blackhole
scrub
networkMitigation.automatic boolean · nullable required

True when the mitigation was applied automatically in response to an attack; false when it is the customer's own on-demand scrubbing session. Null when unknown.

networkMitigation.createdAt string · nullable required

When the mitigation started, or null.

networkMitigation.expiresAt string · nullable required

When the mitigation automatically ends, or null.

400 Invalid request. The response body is an RFC 7807 Problem Details document.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
401 Unauthorized. Authentication is required.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
403 Forbidden. The caller lacks a required scope or does not own the resource.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
404 Not found. The resource does not exist or is not owned by the caller.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
429 Rate limited. Retry after the limit resets. 429 responses include Retry-After seconds plus X-RateLimit-* headers.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
500 Internal error. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
GET https://cloud.hostup.se/api/v2/vps/{id}/ddos-scrubbing
For AI assistants
View as Markdown
cURL
curl -X GET "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/ddos-scrubbing" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
Response
{
  "available": true,
  "reason": null,
  "ip": "192.0.2.10",
  "active": false,
  "durationSeconds": null,
  "createdAt": null,
  "expiresAt": null,
  "networkMitigation": {
    "status": "active",
    "action": "blackhole",
    "automatic": true,
    "createdAt": "2026-08-07T11:15:20.000Z",
    "expiresAt": "2026-08-07T12:15:20.000Z"
  }
}