Get a basic auth rule
const url = 'https://api.nsin.ir/domains/example.com/rules/basic_auth/1';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.nsin.ir/domains/example.com/rules/basic_auth/1 \ --header 'Authorization: Bearer <token>'Requires domain.view.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The domain name (for example example.com) — not a numeric id.
Example
example.comNumeric id of the rule.
Responses
Section titled “ Responses ”The rule.
object
Deprecated single-record scope. Prefer record_ids. Absent for
zone-wide rules.
The proxied DNS records this rule applies to. Empty or absent means zone-wide — every proxied record of the domain.
Evaluation order; lower runs first. Defaults to 100.
Legacy single-hostname filter, kept for rules written before
host_includes existed. It is evaluated as one more entry of
host_includes; prefer the lists.
How the host filter — host_pattern, host_includes and
host_excludes — is matched. One strategy covers all three, exactly as
one path_match_type covers both path lists.
The empty string means “no host filter”, and is the only valid value
when the pattern and both lists are empty. Set a list without a match
type and the API defaults it to wildcard.
A wildcard entry matches subdomains, not the label itself:
*.example.com covers shop.example.com but not example.com — the
same reading as the DNS wildcard. Add the bare name as its own entry to
include it.
Hostnames the rule applies to. Empty or absent means every host the
scoped record(s) serve — which on a wildcard-proxied zone
(*.example.com) is every subdomain.
Hostnames carved back out of host_includes. An exclude always
wins over an include, so “everything except staging” is an empty
include list plus one exclude.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
How path_includes and path_excludes are interpreted.
Paths the rule applies to. Defaults to ["/*"] — everything.
Paths carved back out of path_includes.
Shown in the browser’s sign-in prompt. Must not contain ", \, or
control characters.
IPs or CIDRs whose requests skip the prompt entirely — an office
network, an uptime monitor. Bare IPs are stored as a full-length
prefix (203.0.113.7 → 203.0.113.7/32).
A credential as it is returned — username only.
object
Always true for a usable credential. Passwords are never returned.
Example
{ "type": "cache", "host_match_type": "", "action_mode": "enforce", "path_match_type": "wildcard", "realm": "Restricted"}Missing, malformed, revoked or expired API key — or the owning account is inactive.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "invalid API key"}The domain or the rule does not exist, the rule belongs to another domain or another rule type, or your role does not permit this operation.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Example
{ "error": "read-only API key"}The key exceeded its request budget (300 requests per minute by default).
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "rate limit exceeded"}