List fingerprint rules
const url = 'https://api.nsin.ir/domains/example.com/rules/fingerprint/';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.nsin.ir/domains/example.com/rules/fingerprint/ \ --header 'Authorization: Bearer <token>'Matches requests on their TLS/HTTP fingerprint (JA4, JA4H) and drops, challenges or tags them.
Returned in evaluation order. Requires domain.view.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The domain name (for example example.com) — not a numeric id.
Example
example.comResponses
Section titled “ Responses ”Fingerprint rules.
object
Deprecated single-record scope. Prefer record_ids. Absent for
zone-wide rules.
The proxied DNS records this rule applies to. Empty or absent means zone-wide — every proxied record of the domain.
Evaluation order; lower runs first. Defaults to 100.
Optional hostname filter. Empty means the rule is not host-scoped.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
JA4 TLS fingerprints to match.
JA4H HTTP fingerprints to match.
What to do with a matching request.
Example
[ { "type": "cache", "host_match_type": "", "action_mode": "enforce", "action": "drop" }]Missing, malformed, revoked or expired API key — or the owning account is inactive.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "invalid API key"}No such domain, or your role on it does not permit this operation. The
rules endpoints deliberately answer 404 rather than 403 for an
insufficient role, so they never confirm that a domain exists to someone
who cannot use it.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "not found"}The key exceeded its request budget (300 requests per minute by default).
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "rate limit exceeded"}