List cache rules
const url = 'https://api.nsin.ir/domains/example.com/rules/cache/';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.nsin.ir/domains/example.com/rules/cache/ \ --header 'Authorization: Bearer <token>'Decides what the edge caches, for how long, and which safety bypasses apply. A domain may hold several cache rules with different tradeoffs; each is self-contained.
Returned in evaluation order. Requires domain.view.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The domain name (for example example.com) — not a numeric id.
Example
example.comResponses
Section titled “ Responses ”Cache rules.
object
Deprecated single-record scope. Prefer record_ids. Absent for
zone-wide rules.
The proxied DNS records this rule applies to. Empty or absent means zone-wide — every proxied record of the domain.
Evaluation order; lower runs first. Defaults to 100.
Optional hostname filter. Empty means the rule is not host-scoped.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
How path_includes and path_excludes are interpreted.
Paths the rule applies to. Defaults to ["/*"] — everything.
Paths carved back out of path_includes.
How long an entry stays fresh, in seconds. 0 uses the default.
Background refresh interval in seconds — the entry is re-fetched
this often while still being served. 0 disables it.
Include the query string in the cache key. Off means ?a=1 and ?a=2 share one entry.
What the rule caches among the paths it already matches.
default— static assets only, chosen by file extension.everything— every cacheable response, HTML included.
There is no “custom” scope: narrow what you cache by scoping
path_includes instead.
Skip caching requests that carry an Authorization header. Leave on
unless you are certain the response is not user-specific.
Skip caching responses that set a cookie. Turning this off can serve one visitor’s session to another — only do it for responses you know are anonymous.
Honour Cache-Control: no-store from the client.
Honour the origin’s Cache-Control directives.
Use the origin’s max-age instead of ttl_sec.
Never cache WordPress admin and login paths.
Example
[ { "type": "cache", "host_match_type": "", "action_mode": "enforce", "path_match_type": "wildcard", "scope": "default", "bypass_authorization": true, "bypass_set_cookie": true, "respect_client_no_store": true, "respect_origin_cache_control": true, "respect_origin_max_age": true, "bypass_wp_admin": true }]Missing, malformed, revoked or expired API key — or the owning account is inactive.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "invalid API key"}No such domain, or your role on it does not permit this operation. The
rules endpoints deliberately answer 404 rather than 403 for an
insufficient role, so they never confirm that a domain exists to someone
who cannot use it.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "not found"}The key exceeded its request budget (300 requests per minute by default).
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "rate limit exceeded"}