Skip to content
Start here

Get an account or zone ruleset

client.rulesets.get(stringrulesetID, RulesetGetParams { account_id, zone_id } params?, RequestOptionsoptions?): RulesetGetResponse { id, kind, last_updated, 5 more }
GET/{accounts_or_zones}/{account_or_zone_id}/rulesets/{ruleset_id}

Fetches the latest version of an account or zone ruleset.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Mass URL Redirects WriteMass URL Redirects ReadMagic Firewall WriteMagic Firewall ReadL4 DDoS Managed Ruleset WriteL4 DDoS Managed Ruleset ReadTransform Rules WriteTransform Rules ReadSelect Configuration WriteSelect Configuration ReadAccount WAF WriteAccount WAF ReadAccount Rulesets ReadAccount Rulesets WriteLogs WriteLogs Read
ParametersExpand Collapse
rulesetID: string

The unique ID of the ruleset.

params: RulesetGetParams { account_id, zone_id }
account_id?: string

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

zone_id?: string

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

ReturnsExpand Collapse
RulesetGetResponse { id, kind, last_updated, 5 more }

A ruleset object.

id: string

The unique ID of the ruleset.

kind: Kind

The kind of the ruleset.

One of the following:
"managed"
"custom"
"root"
"zone"
last_updated: string

The timestamp of when the ruleset was last modified.

formatdate-time
name: string

The human-readable name of the ruleset.

minLength1
phase: Phase

The phase of the ruleset.

One of the following:
"ddos_l4"
"ddos_l7"
"http_config_settings"
"http_custom_errors"
"http_log_custom_fields"
"http_ratelimit"
"http_request_cache_settings"
"http_request_dynamic_redirect"
"http_request_firewall_custom"
"http_request_firewall_managed"
"http_request_late_transform"
"http_request_origin"
"http_request_redirect"
"http_request_sanitize"
"http_request_sbfm"
"http_request_transform"
"http_response_cache_settings"
"http_response_compression"
"http_response_firewall_managed"
"http_response_headers_transform"
"magic_transit"
"magic_transit_ids_managed"
"magic_transit_managed"
"magic_transit_ratelimit"
rules: Array<BlockRule { id, action, enabled, 2 more } | ChallengeRule { id, action, enabled, 10 more } | ResponseCompressionRule { id, action, enabled, 2 more } | 18 more>

The list of rules in the ruleset.

One of the following:
BlockRule extends BlockRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ChallengeRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "challenge"

The action to perform when the rule matches.

enabled: boolean

Whether the rule should be executed.

expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: unknown

The parameters configuring the rule’s action.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
ResponseCompressionRule extends CompressResponseRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
DDoSDynamicRule extends DDoSDynamicRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ExecuteRule extends ExecuteRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ForceConnectionCloseRule extends ForceConnectionCloseRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
JavaScriptChallengeRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "js_challenge"

The action to perform when the rule matches.

enabled: boolean

Whether the rule should be executed.

expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: unknown

The parameters configuring the rule’s action.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
LogRule extends LogRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
LogCustomFieldRule extends LogCustomFieldRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ManagedChallengeRule extends ManagedChallengeRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
RedirectRule extends RedirectRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
RewriteRule extends RewriteRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
RouteRule extends RouteRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ScoreRule extends ScoreRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ServeErrorRule extends ServeErrorRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
SetCacheControlRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "set_cache_control"

The action to perform when the rule matches.

enabled: boolean
expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: ActionParameters { immutable, max-age, must-revalidate, 10 more }

The parameters configuring the rule’s action.

immutable?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"max-age"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"must-revalidate"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"must-understand"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"no-cache"?: SetDirective { operation, cloudflare_only, qualifiers } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts optional qualifiers (header names).

One of the following:
SetDirective { operation, cloudflare_only, qualifiers }

Set the directive with optional qualifiers.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

qualifiers?: Array<string>

Optional list of header names to qualify the directive (e.g., for “private” or “no-cache” directives).

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"no-store"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"no-transform"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

private?: SetDirective { operation, cloudflare_only, qualifiers } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts optional qualifiers (header names).

One of the following:
SetDirective { operation, cloudflare_only, qualifiers }

Set the directive with optional qualifiers.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

qualifiers?: Array<string>

Optional list of header names to qualify the directive (e.g., for “private” or “no-cache” directives).

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"proxy-revalidate"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

public?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"s-maxage"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"stale-if-error"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"stale-while-revalidate"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
SetCacheSettingsRule extends SetCacheSettingsRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
SetCacheTagsRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "set_cache_tags"

The action to perform when the rule matches.

enabled: boolean
expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: AddCacheTagsValues { operation, values } | AddCacheTagsExpression { expression, operation } | RemoveCacheTagsValues { operation, values } | 3 more

The parameters configuring the rule’s action.

One of the following:
AddCacheTagsValues { operation, values }

Add cache tags using a list of values.

operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
values: Array<string>

A list of cache tag values.

AddCacheTagsExpression { expression, operation }

Add cache tags using an expression.

expression: string

An expression that evaluates to an array of cache tag values.

minLength1
operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
RemoveCacheTagsValues { operation, values }

Remove cache tags using a list of values.

operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
values: Array<string>

A list of cache tag values.

RemoveCacheTagsExpression { expression, operation }

Remove cache tags using an expression.

expression: string

An expression that evaluates to an array of cache tag values.

minLength1
operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
SetCacheTagsValues { operation, values }

Set cache tags using a list of values.

operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
values: Array<string>

A list of cache tag values.

SetCacheTagsExpression { expression, operation }

Set cache tags using an expression.

expression: string

An expression that evaluates to an array of cache tag values.

minLength1
operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
SetConfigurationRule extends SetConfigRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
SkipRule extends SkipRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
TransformResponseHTMLRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "transform_response_html"

The action to perform when the rule matches.

enabled: boolean
expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: ActionParameters { link_maze }

The parameters configuring the rule’s action.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
version: string

The version of the ruleset.

description?: string

An informative description of the ruleset.

Get an account or zone ruleset

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const ruleset = await client.rulesets.get('2f2feab2026849078ba485f918791bdc', {
  account_id: 'account_id',
});

console.log(ruleset.id);
{
  "errors": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "messages": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "result": {
    "id": "2f2feab2026849078ba485f918791bdc",
    "kind": "root",
    "last_updated": "2000-01-01T00:00:00Z",
    "name": "My ruleset",
    "phase": "http_request_firewall_custom",
    "rules": [
      {
        "last_updated": "2000-01-01T00:00:00Z",
        "version": "1",
        "id": "id",
        "action": "action",
        "action_parameters": {
          "response": {
            "content": "{\n  \"success\": false,\n  \"error\": \"you have been blocked\"\n}",
            "content_type": "application/json",
            "status_code": 400
          }
        },
        "categories": [
          "directory-traversal"
        ],
        "description": "Block the request.",
        "enabled": true,
        "exposed_credential_check": {
          "password_expression": "url_decode(http.request.body.form[\\\"password\\\"][0])",
          "username_expression": "url_decode(http.request.body.form[\\\"username\\\"][0])"
        },
        "expression": "expression",
        "logging": {
          "enabled": true
        },
        "ratelimit": {
          "characteristics": [
            "cf.colo.id"
          ],
          "period": 60,
          "counting_expression": "http.request.body.raw eq \"abcd\"",
          "mitigation_timeout": 600,
          "requests_per_period": 1000,
          "requests_to_origin": true,
          "score_per_period": 400,
          "score_response_header_name": "my-score"
        },
        "ref": "ref"
      }
    ],
    "version": "1",
    "description": "A description for my ruleset."
  },
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "messages": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "result": {
    "id": "2f2feab2026849078ba485f918791bdc",
    "kind": "root",
    "last_updated": "2000-01-01T00:00:00Z",
    "name": "My ruleset",
    "phase": "http_request_firewall_custom",
    "rules": [
      {
        "last_updated": "2000-01-01T00:00:00Z",
        "version": "1",
        "id": "id",
        "action": "action",
        "action_parameters": {
          "response": {
            "content": "{\n  \"success\": false,\n  \"error\": \"you have been blocked\"\n}",
            "content_type": "application/json",
            "status_code": 400
          }
        },
        "categories": [
          "directory-traversal"
        ],
        "description": "Block the request.",
        "enabled": true,
        "exposed_credential_check": {
          "password_expression": "url_decode(http.request.body.form[\\\"password\\\"][0])",
          "username_expression": "url_decode(http.request.body.form[\\\"username\\\"][0])"
        },
        "expression": "expression",
        "logging": {
          "enabled": true
        },
        "ratelimit": {
          "characteristics": [
            "cf.colo.id"
          ],
          "period": 60,
          "counting_expression": "http.request.body.raw eq \"abcd\"",
          "mitigation_timeout": 600,
          "requests_per_period": 1000,
          "requests_to_origin": true,
          "score_per_period": 400,
          "score_response_header_name": "my-score"
        },
        "ref": "ref"
      }
    ],
    "version": "1",
    "description": "A description for my ruleset."
  },
  "success": true
}