Enable or disable a cache rule
const url = 'https://api.nsin.ir/domains/example.com/rules/cache/1/toggle';const options = {method: 'PATCH', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://api.nsin.ir/domains/example.com/rules/cache/1/toggle \ --header 'Authorization: Bearer <token>'Flips the rule’s enabled flag. Takes no request body — the new state
is always the opposite of the current one, and is returned. Requires
rules.edit.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The domain name (for example example.com) — not a numeric id.
Example
example.comNumeric id of the rule.
Responses
Section titled “ Responses ”The rule in its new state.
object
Deprecated single-record scope. Prefer record_ids. Absent for
zone-wide rules.
The proxied DNS records this rule applies to. Empty or absent means zone-wide — every proxied record of the domain.
Evaluation order; lower runs first. Defaults to 100.
Optional hostname filter. Empty means the rule is not host-scoped.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
How path_includes and path_excludes are interpreted.
Paths the rule applies to. Defaults to ["/*"] — everything.
Paths carved back out of path_includes.
How long an entry stays fresh, in seconds. 0 uses the default.
Background refresh interval in seconds — the entry is re-fetched
this often while still being served. 0 disables it.
Include the query string in the cache key. Off means ?a=1 and ?a=2 share one entry.
What the rule caches among the paths it already matches.
default— static assets only, chosen by file extension.everything— every cacheable response, HTML included.
There is no “custom” scope: narrow what you cache by scoping
path_includes instead.
Skip caching requests that carry an Authorization header. Leave on
unless you are certain the response is not user-specific.
Skip caching responses that set a cookie. Turning this off can serve one visitor’s session to another — only do it for responses you know are anonymous.
Honour Cache-Control: no-store from the client.
Honour the origin’s Cache-Control directives.
Use the origin’s max-age instead of ttl_sec.
Never cache WordPress admin and login paths.
Example
{ "type": "cache", "host_match_type": "", "action_mode": "enforce", "path_match_type": "wildcard", "scope": "default", "bypass_authorization": true, "bypass_set_cookie": true, "respect_client_no_store": true, "respect_origin_cache_control": true, "respect_origin_max_age": true, "bypass_wp_admin": true}Missing, malformed, revoked or expired API key — or the owning account is inactive.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "invalid API key"}The domain or the rule does not exist, the rule belongs to another domain or another rule type, or your role does not permit this operation.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Example
{ "error": "read-only API key"}The key exceeded its request budget (300 requests per minute by default).
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "rate limit exceeded"}