## POST /api/v2/vps/{id}/ddos-scrubbing

**Enable DDoS scrubbing**

Enable on-demand DDoS scrubbing for the VPS primary IP — either for a fixed `duration`, or always-on with `permanent: true` (no expiry; stays active until disabled with `DELETE /api/v2/vps/{id}/ddos-scrubbing`). Successful responses are wrapperless; validation, ownership, permission, and state failures use Problem Details with JSON pointers where applicable.

### Related Endpoints

- `GET /api/v2/vps/{id}/ddos-scrubbing`: Get DDoS scrubbing status
- `DELETE /api/v2/vps/{id}/ddos-scrubbing`: Disable DDoS scrubbing
- `GET /api/v2/vps/{id}`: Get VPS details

### Headers

- `Accept`: application/json
- `Authorization`: Bearer YOUR_API_KEY
- Required API scope: `write:vm`
- `Content-Type`: application/json

### Parameters

- `id` (path, string, required): Public VPS ID. Get it from `GET /api/v2/vps` `data[].id`. Do not invent this value; use the exact ID returned by the referenced API response. Example: `vps_01hxa3b4c5d6e7f8g9h0j1k2m3`

### Request Body

- `duration` (integer, optional): Requested scrubbing duration in seconds. Mutually exclusive with `permanent`.
  Allowed values: 3600, 10800, 21600, 43200, 86400
- `permanent` (boolean, optional): Enable always-on scrubbing with no expiry — protection stays active until it is disabled with DELETE. Mutually exclusive with `duration`; pass exactly one of the two.
  Allowed values: true

### Request Examples

#### Enable for one hour

```bash
curl -X POST "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/ddos-scrubbing" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "duration": 3600
  }'
```

```json
{
  "duration": 3600
}
```

#### Enable always-on scrubbing

```bash
curl -X POST "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/ddos-scrubbing" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "permanent": true
  }'
```

```json
{
  "permanent": true
}
```

### Response Schema

- `available` (boolean, required)
- `reason` (string, required, nullable): Nullable (may be null when not applicable).
- `ip` (string, required, nullable): Nullable (may be null when not applicable).
- `active` (boolean, required)
- `durationSeconds` (integer, required, nullable): Nullable (may be null when not applicable).
- `createdAt` (string, required, nullable): Nullable (may be null when not applicable).
- `expiresAt` (string, required, nullable): Nullable (may be null when not applicable).
- `networkMitigation` (object, required): Network-level mitigation state for the VPS IP. Action responses do not re-verify the platform-wide mitigation state, so this is typically "unknown" here — read GET /api/v2/vps/{id}/ddos-scrubbing for the verified state.
- `networkMitigation.status` (string, required): "active" when a mitigation is applied, "none" when verified clear, "unknown" when the state was not verified in this response.
  Allowed values: active, none, unknown
- `networkMitigation.action` (string, required, nullable): "blackhole": all internet traffic to the IP is dropped. "scrub": traffic is filtered; services keep working. Null when status is not "active".
  Allowed values: blackhole, scrub
- `networkMitigation.automatic` (boolean, required, nullable): True for automatic attack responses, false for the customer's own on-demand session, null when unknown.
- `networkMitigation.createdAt` (string, required, nullable): When the mitigation started, or null.
- `networkMitigation.expiresAt` (string, required, nullable): When the mitigation automatically ends, or null.

### Responses

#### 200 - DDoS scrubbing status after the enable attempt.
```json
{
  "available": true,
  "reason": null,
  "ip": "192.0.2.10",
  "active": true,
  "durationSeconds": 3600,
  "createdAt": null,
  "expiresAt": "2026-06-22T13:07:03.000Z",
  "networkMitigation": {
    "status": "unknown",
    "action": null,
    "automatic": null,
    "createdAt": null,
    "expiresAt": null
  }
}
```

#### 400 - Invalid request. The response body is an RFC 7807 Problem Details document.
```json
{
  "type": "https://developer.hostup.se/errors/invalid_request",
  "title": "Invalid request",
  "status": 400,
  "detail": "The request body failed validation.",
  "code": "invalid_request",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z",
  "errors": [
    {
      "pointer": "/items/0/domainName",
      "detail": "`domainName` is required.",
      "code": "invalid_request"
    }
  ]
}
```

#### 401 - Unauthorized. Authentication is required.
```json
{
  "type": "https://developer.hostup.se/errors/unauthorized",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Authentication is required.",
  "code": "unauthorized",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 403 - Forbidden. The caller lacks a required scope or does not own the resource.
```json
{
  "type": "https://developer.hostup.se/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "The caller lacks a required scope or does not own the resource.",
  "code": "forbidden",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 404 - Not found. The resource does not exist or is not owned by the caller.
```json
{
  "type": "https://developer.hostup.se/errors/not_found",
  "title": "Not found",
  "status": 404,
  "detail": "The requested resource could not be found.",
  "code": "not_found",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 409 - DDoS mitigation is already active for this IP address.
```json
{
  "type": "https://developer.hostup.se/errors/ddos_mitigation_active",
  "title": "DDoS mitigation already active",
  "status": 409,
  "detail": "DDoS mitigation is already active for this IP address.",
  "instance": "/api/v2/vps/vps_06ew6449dmcp69wfm2x20hrv1w/ddos-scrubbing",
  "code": "ddos_mitigation_active",
  "requestId": "00000000-0000-4000-8000-000000000000",
  "timestamp": "2026-06-22T12:07:03.000Z"
}
```

#### 429 - Rate limited. Retry after the limit resets. 429 responses include `Retry-After` seconds plus `X-RateLimit-*` headers.
```json
{
  "type": "https://developer.hostup.se/errors/rate_limit_exceeded",
  "title": "Too many requests",
  "status": 429,
  "detail": "Too many requests. Retry after the limit resets.",
  "code": "rate_limit_exceeded",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 500 - Internal error. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/internal_error",
  "title": "Internal server error",
  "status": 500,
  "detail": "An unexpected error occurred. Retry later or contact support if the issue persists.",
  "code": "internal_error",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```
