Skip to content
Start here

Update Zone Precursor Config

client.precursor.update(PrecursorUpdateParams { zone_id, default_mode, enforcement_rules } params, RequestOptionsoptions?): PrecursorConfig { default_mode, enforcement_rules }
PUT/zones/{zone_id}/precursor

Updates the Precursor configuration for a zone.

default_mode sets the zone-level enforcement mode. enforcement_rules is the ordered list of rules that override enforcement for matching requests.

This is a partial update: only the fields present in the request body are changed.

  • Sending an empty array ([]) clears all enforcement rules.
  • At least one of default_mode or enforcement_rules must be present; an empty body ({}) is rejected with 400.
  • Rule id is read-only (assigned by Cloudflare) and ignored on input.
  • Rule mode must be min-friction or max-security (off is not a valid rule mode; use default_mode to disable enforcement).
  • Rule expression is limited to 4000 characters. The limit applies to each rule individually, not to the combined size of all rules.
Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
ParametersExpand Collapse
params: PrecursorUpdateParams { zone_id, default_mode, enforcement_rules }
zone_id: string

Path param: Identifier.

maxLength32
Deprecateddefault_mode?: "off" | "min-friction" | "max-security"

Body param: The zone-level Precursor enforcement mode applied to requests that do not match a more specific enforcement rule.

One of the following:
"off"
"min-friction"
"max-security"
Deprecatedenforcement_rules?: Array<EnforcementRule { expression, mode, id, 2 more } >

Body param: The ordered list of enforcement rules for the zone.

expression: string

The filter expression that determines which requests the rule matches.

maxLength4000
mode: "min-friction" | "max-security"

The override mode Precursor applies to requests matching an enforcement rule. Unlike default_mode, this cannot be off.

One of the following:
"min-friction"
"max-security"
id?: string

The read-only identifier that Cloudflare assigns to the rule.

description?: string

An informative description of the rule.

enabled?: boolean

Whether the rule is active.

ReturnsExpand Collapse
PrecursorConfig { default_mode, enforcement_rules }
Deprecateddefault_mode?: "off" | "min-friction" | "max-security"

The zone-level Precursor enforcement mode applied to requests that do not match a more specific enforcement rule.

One of the following:
"off"
"min-friction"
"max-security"
Deprecatedenforcement_rules?: Array<EnforcementRule { expression, mode, id, 2 more } >

The ordered list of enforcement rules for the zone.

expression: string

The filter expression that determines which requests the rule matches.

maxLength4000
mode: "min-friction" | "max-security"

The override mode Precursor applies to requests matching an enforcement rule. Unlike default_mode, this cannot be off.

One of the following:
"min-friction"
"max-security"
id?: string

The read-only identifier that Cloudflare assigns to the rule.

description?: string

An informative description of the rule.

enabled?: boolean

Whether the rule is active.

Update Zone Precursor Config

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const precursorConfig = await client.precursor.update({
  zone_id: '023e105f4ecef8ad9ca31a8372d0c353',
  default_mode: 'min-friction',
});

console.log(precursorConfig.default_mode);
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "default_mode": "min-friction",
    "enforcement_rules": [
      {
        "expression": "http.request.uri.path eq \"/shop\"",
        "mode": "max-security",
        "id": "3a03d665bac043e3a684e0d385a4b1e2",
        "description": "Enforce max-security on the shop page",
        "enabled": true
      }
    ]
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "default_mode": "min-friction",
    "enforcement_rules": [
      {
        "expression": "http.request.uri.path eq \"/shop\"",
        "mode": "max-security",
        "id": "3a03d665bac043e3a684e0d385a4b1e2",
        "description": "Enforce max-security on the shop page",
        "enabled": true
      }
    ]
  }
}