Shield API reference

Shield API.

20 endpoints, 9 of them read-only. Every one is also a command in the orbit CLI, a method in the SDKs and a tool on the MCP server.

01

sites

EndpointScopeParametersCLI · MCP tool
GET /cdn/sites/{id}/threats
Threat intelligence for a site: share of traffic by risk band, top ASNs / countries / reasons, timeline (aggregates only)
readid integer
?range 24h | 7d
orbit shield sites threats <id>
shield_sites_threats
GET /cdn/sites
List Shield sites (proxied hostnames)
read?limit integer
?offset integer
orbit shield sites list
shield_sites_list
POST /cdn/sites
Onboard a hostname by CNAME (DNS stays at your provider)
writebody: hostname* string, origin* string, origin_scheme http | https | strict, origin_host_header boolean, service_id integerorbit shield sites create
shield_sites_create
GET /cdn/sites/{id}
Get a site
readid integerorbit shield sites get <id>
shield_sites_get
PATCH /cdn/sites/{id}
Update site settings (partial)
writeid integer
body: waf object, cache_ttl integer, cache_mode all | static | origin, cache_html_ttl integer, force_https boolean, rate_limit integer, origin_scheme http | https | strict, origin_host_header boolean, cert_pem string, key_pem string, waiting_room object, under_attack boolean, bot_fight boolean, sense object
orbit shield sites patch <id>
shield_sites_patch
DELETE /cdn/sites/{id}
Remove a CNAME-mode site (zone-hosted sites are removed by un-proxying their record)
writeid integerorbit shield sites delete <id>
shield_sites_delete
PUT /cdn/sites/{id}/origin
Point a hostname at a Pages project, an Orbit Link tunnel, or back at its own origin
writeid integer
body: pages_project_id integer, link_tunnel_id integer
orbit shield sites origin <id>
shield_sites_origin
POST /cdn/sites/{id}/verify
Check the CNAMEs in public DNS; request the certificate once seen
writeid integerorbit shield sites verify <id>
shield_sites_verify
POST /cdn/sites/{id}/purge
Purge cache (everything, or given paths)
writeid integer
body: urls string[]
orbit shield sites purge <id>
shield_sites_purge
POST /cdn/sites/{id}/origin-certificate
Issue an Orbit Origin CA certificate for the origin
writeid integerorbit shield sites origincert <id>
shield_sites_origincert
POST /cdn/sites/{id}/acme
Start automated Let's Encrypt issuance (dns-01)
writeid integerorbit shield sites acme <id>
shield_sites_acme
GET /cdn/sites/{id}/analytics
Traffic analytics: exact per-minute counters plus top lists and latency from the sampled logs
readid integer
?range 1h | 24h | 7d
orbit shield sites analytics <id>
shield_sites_analytics
GET /cdn/sites/{id}/waf/hits
Which firewall rules have been matching, with one example path each
readid integer
?range 15m | 1h | 24h | 7d
orbit shield sites wafhits <id>
shield_sites_wafhits
02

onboard

EndpointScopeParametersCLI · MCP tool
GET /onboard/recommend
Which onboarding modes fit a hostname, best first
read?hostname stringorbit shield onboard recommend
shield_onboard_recommend
03

logs

EndpointScopeParametersCLI · MCP tool
GET /cdn/sites/{id}/logs
Request logs (sampled), newest first, cursor-paged; format=csv exports up to 10 000 rows
readid integer
?since string
?until string
?ray string
?ip string
?path string
?status string
?action pass | netrule_block | waf | challenge | ratelimit | waiting | origin_error | redirect
?cc string
?limit integer
?cursor string
?format json | csv
orbit shield logs list <id>
shield_logs_list
GET /cdn/sites/{id}/logs/{ray}
One request by Ray ID, with every header
readid integer
ray string
orbit shield logs get <id> <ray>
shield_logs_get
04

rules

EndpointScopeParametersCLI · MCP tool
GET /security/rules
List security rules
read?limit integer
?offset integer
?site_id integer
?zone_id integer
orbit shield rules list
shield_rules_list
POST /security/rules
Add a rule for a site or a whole zone
writebody: site_id integer, zone_id integer, field* country | asn | ip | isp, op* in | not_in, value* string, action* block | allow | challenge | ratelimit, seq integer, note stringorbit shield rules create
shield_rules_create
PATCH /security/rules/{id}
Enable/disable a rule
writeid integer
body: enabled* boolean
orbit shield rules patch <id>
shield_rules_patch
DELETE /security/rules/{id}
Delete a rule
writeid integerorbit shield rules delete <id>
shield_rules_delete
Next

Related

Account API reference

Every Account endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.

Organization API reference

Every Organization endpoint in the Orbit API (10): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.

Services API reference

Every Services endpoint in the Orbit API (15): method and path, the token scope it needs, its parameters, and the matching CLI command and MCP tool.

← All documentation