Skip to content
Start here

Update an account or zone ruleset rule

client.rulesets.rules.edit(stringruleID, RuleEditParamsparams, RequestOptionsoptions?): RuleEditResponse
PATCH/{accounts_or_zones}/{account_or_zone_id}/rulesets/{ruleset_id}/rules/{rule_id}

Updates an existing rule in an account or zone ruleset.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
Mass URL Redirects WriteMagic Firewall WriteL4 DDoS Managed Ruleset WriteTransform Rules WriteSelect Configuration WriteAccount WAF WriteAccount Rulesets WriteLogs Write
ParametersExpand Collapse
ruleID: string

The unique ID of the rule.

RuleEditParams = BlockRule | ChallengeRule | ResponseCompressionRule | 18 more
RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ruleset_id: string

Path param: The unique ID of the ruleset.

account_id?: string

Path param: The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

zone_id?: string

Path param: The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

dry_run?: boolean

Query param: Validates the request without persisting changes when set to true. Responses that normally return 200 return result: null; endpoints that normally return 204 continue to return 204.

id?: string

Body param: The unique ID of the rule.

action?: "block"

Body param: The action to perform when the rule matches.

action_parameters?: ActionParameters

Body param: The parameters configuring the rule’s action.

response?: Response { content, content_type, status_code }

The response to show when the block is applied.

content: string

The content to return.

minLength1
content_type: string

The type of the content to return.

minLength1
status_code: number

The status code to return.

maximum499
minimum400
description?: string

Body param: An informative description of the rule.

enabled?: boolean

Body param: Whether the rule should be executed.

exposed_credential_check?: ExposedCredentialCheck

Body param: Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
expression?: string

Body param: The expression defining which traffic will match the rule.

minLength1
logging?: Logging { enabled }

Body param: An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

position?: BeforePosition { before } | AfterPosition { after } | IndexPosition { index }

Body param: An object configuring where the rule will be placed.

One of the following:
BeforePosition { before }

An object configuring where the rule will be placed.

before?: string

The ID of another rule to place the rule before. An empty value causes the rule to be placed at the top.

AfterPosition { after }

An object configuring where the rule will be placed.

after?: string

The ID of another rule to place the rule after. An empty value causes the rule to be placed at the bottom.

IndexPosition { index }

An object configuring where the rule will be placed.

index?: number

An index at which to place the rule, where index 1 is the first rule.

minimum1
ratelimit?: Ratelimit

Body param: An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
ref?: string

Body param: The reference of the rule (the rule’s ID by default).

minLength1
BlockRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ChallengeRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ResponseCompressionRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
DDoSDynamicRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ExecuteRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ForceConnectionCloseRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
JavaScriptChallengeRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
LogRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
LogCustomFieldRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ManagedChallengeRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
RedirectRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
RewriteRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
RouteRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ScoreRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ServeErrorRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
SetCacheControlRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
SetCacheSettingsRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
SetCacheTagsRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
SetConfigurationRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
SkipRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
TransformResponseHTMLRule extends RuleEditParamsBase { ruleset_id, account_id, zone_id, 12 more }
ReturnsExpand Collapse
RuleEditResponse = Ruleset { id, kind, last_updated, 5 more } | unknown

A result.

One of the following:
Ruleset { id, kind, last_updated, 5 more }

A ruleset object.

id: string

The unique ID of the ruleset.

kind: Kind

The kind of the ruleset.

One of the following:
"managed"
"custom"
"root"
"zone"
last_updated: string

The timestamp of when the ruleset was last modified.

formatdate-time
name: string

The human-readable name of the ruleset.

minLength1
phase: Phase

The phase of the ruleset.

One of the following:
"ddos_l4"
"ddos_l7"
"http_config_settings"
"http_custom_errors"
"http_log_custom_fields"
"http_ratelimit"
"http_request_cache_settings"
"http_request_dynamic_redirect"
"http_request_firewall_custom"
"http_request_firewall_managed"
"http_request_late_transform"
"http_request_origin"
"http_request_redirect"
"http_request_sanitize"
"http_request_sbfm"
"http_request_transform"
"http_response_cache_settings"
"http_response_compression"
"http_response_firewall_managed"
"http_response_headers_transform"
"magic_transit"
"magic_transit_ids_managed"
"magic_transit_managed"
"magic_transit_ratelimit"
rules: Array<BlockRule { id, action, enabled, 2 more } | ChallengeRule { id, action, enabled, 10 more } | ResponseCompressionRule { id, action, enabled, 2 more } | 18 more>

The list of rules in the ruleset.

One of the following:
BlockRule extends BlockRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ChallengeRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "challenge"

The action to perform when the rule matches.

enabled: boolean

Whether the rule should be executed.

expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: unknown

The parameters configuring the rule’s action.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
ResponseCompressionRule extends CompressResponseRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
DDoSDynamicRule extends DDoSDynamicRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ExecuteRule extends ExecuteRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ForceConnectionCloseRule extends ForceConnectionCloseRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
JavaScriptChallengeRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "js_challenge"

The action to perform when the rule matches.

enabled: boolean

Whether the rule should be executed.

expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: unknown

The parameters configuring the rule’s action.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
LogRule extends LogRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
LogCustomFieldRule extends LogCustomFieldRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ManagedChallengeRule extends ManagedChallengeRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
RedirectRule extends RedirectRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
RewriteRule extends RewriteRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
RouteRule extends RouteRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ScoreRule extends ScoreRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
ServeErrorRule extends ServeErrorRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
SetCacheControlRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "set_cache_control"

The action to perform when the rule matches.

enabled: boolean
expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: ActionParameters { immutable, max-age, must-revalidate, 10 more }

The parameters configuring the rule’s action.

immutable?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"max-age"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"must-revalidate"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"must-understand"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"no-cache"?: SetDirective { operation, cloudflare_only, qualifiers } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts optional qualifiers (header names).

One of the following:
SetDirective { operation, cloudflare_only, qualifiers }

Set the directive with optional qualifiers.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

qualifiers?: Array<string>

Optional list of header names to qualify the directive (e.g., for “private” or “no-cache” directives).

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"no-store"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"no-transform"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

private?: SetDirective { operation, cloudflare_only, qualifiers } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts optional qualifiers (header names).

One of the following:
SetDirective { operation, cloudflare_only, qualifiers }

Set the directive with optional qualifiers.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

qualifiers?: Array<string>

Optional list of header names to qualify the directive (e.g., for “private” or “no-cache” directives).

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"proxy-revalidate"?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

public?: SetDirective { operation, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration.

One of the following:
SetDirective { operation, cloudflare_only }

Set the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"s-maxage"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"stale-if-error"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

"stale-while-revalidate"?: SetDirective { operation, value, cloudflare_only } | RemoveDirective { operation, cloudflare_only }

A cache-control directive configuration that accepts a duration value in seconds.

One of the following:
SetDirective { operation, value, cloudflare_only }

Set the directive with a duration value in seconds.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
value: number

The duration value in seconds for the directive.

minimum0
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

RemoveDirective { operation, cloudflare_only }

Remove the directive.

operation: "set" | "remove"

The operation to perform on the cache-control directive.

One of the following:
"set"
"remove"
cloudflare_only?: boolean

Whether the directive should only be applied to the Cloudflare CDN cache.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
SetCacheSettingsRule extends SetCacheSettingsRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
SetCacheTagsRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "set_cache_tags"

The action to perform when the rule matches.

enabled: boolean
expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: AddCacheTagsValues { operation, values } | AddCacheTagsExpression { expression, operation } | RemoveCacheTagsValues { operation, values } | 3 more

The parameters configuring the rule’s action.

One of the following:
AddCacheTagsValues { operation, values }

Add cache tags using a list of values.

operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
values: Array<string>

A list of cache tag values.

AddCacheTagsExpression { expression, operation }

Add cache tags using an expression.

expression: string

An expression that evaluates to an array of cache tag values.

minLength1
operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
RemoveCacheTagsValues { operation, values }

Remove cache tags using a list of values.

operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
values: Array<string>

A list of cache tag values.

RemoveCacheTagsExpression { expression, operation }

Remove cache tags using an expression.

expression: string

An expression that evaluates to an array of cache tag values.

minLength1
operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
SetCacheTagsValues { operation, values }

Set cache tags using a list of values.

operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
values: Array<string>

A list of cache tag values.

SetCacheTagsExpression { expression, operation }

Set cache tags using an expression.

expression: string

An expression that evaluates to an array of cache tag values.

minLength1
operation: "add" | "remove" | "set"

The operation to perform on the cache tags.

One of the following:
"add"
"remove"
"set"
categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
SetConfigurationRule extends SetConfigRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
SkipRule extends SkipRule { last_updated, version, id, 10 more } { id, action, enabled, 2 more }
id: string
action: string
enabled: boolean
expression: string
ref: string
TransformResponseHTMLRule { id, action, enabled, 10 more }
id: string

The unique ID of the rule.

action: "transform_response_html"

The action to perform when the rule matches.

enabled: boolean
expression: string

The expression defining which traffic will match the rule.

minLength1
last_updated: string

The timestamp of when the rule was last modified.

formatdate-time
ref: string

The reference of the rule (the rule’s ID by default).

minLength1
version: string

The version of the rule.

action_parameters?: ActionParameters { link_maze }

The parameters configuring the rule’s action.

categories?: Array<string>

The categories of the rule.

description?: string

An informative description of the rule.

exposed_credential_check?: ExposedCredentialCheck { password_expression, username_expression }

Configuration for exposed credential checking.

password_expression: string

An expression that selects the password used in the credentials check.

minLength1
username_expression: string

An expression that selects the user ID used in the credentials check.

minLength1
logging?: Logging { enabled }

An object configuring the rule’s logging behavior.

enabled: boolean

Whether to generate a log when the rule matches.

ratelimit?: Ratelimit { characteristics, period, counting_expression, 5 more }

An object configuring the rule’s rate limit behavior.

characteristics: Array<string>

Characteristics of the request on which the rate limit counter will be incremented.

period: number

Period in seconds over which the counter is being incremented.

minimum0
counting_expression?: string

An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule’s expression.

minLength1
mitigation_timeout?: number

Period of time in seconds after which the action will be disabled following its first execution.

requests_per_period?: number

The threshold of requests per period after which the action will be executed for the first time.

minimum1
requests_to_origin?: boolean

Whether counting is only performed when an origin is reached.

score_per_period?: number

The score threshold per period for which the action will be executed the first time.

score_response_header_name?: string

A response header name provided by the origin, which contains the score to increment rate limit counter with.

minLength1
version: string

The version of the ruleset.

description?: string

An informative description of the ruleset.

unknown

Update an account or zone ruleset rule

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const response = await client.rulesets.rules.edit('3a03d665bac047339bb530ecb439a90d', {
  ruleset_id: '2f2feab2026849078ba485f918791bdc',
  account_id: 'account_id',
});

console.log(response);
{
  "errors": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "messages": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "result": {
    "id": "2f2feab2026849078ba485f918791bdc",
    "kind": "root",
    "last_updated": "2000-01-01T00:00:00Z",
    "name": "My ruleset",
    "phase": "http_request_firewall_custom",
    "rules": [
      {
        "last_updated": "2000-01-01T00:00:00Z",
        "version": "1",
        "id": "id",
        "action": "action",
        "action_parameters": {
          "response": {
            "content": "{\n  \"success\": false,\n  \"error\": \"you have been blocked\"\n}",
            "content_type": "application/json",
            "status_code": 400
          }
        },
        "categories": [
          "directory-traversal"
        ],
        "description": "Block the request.",
        "enabled": true,
        "exposed_credential_check": {
          "password_expression": "url_decode(http.request.body.form[\\\"password\\\"][0])",
          "username_expression": "url_decode(http.request.body.form[\\\"username\\\"][0])"
        },
        "expression": "expression",
        "logging": {
          "enabled": true
        },
        "ratelimit": {
          "characteristics": [
            "cf.colo.id"
          ],
          "period": 60,
          "counting_expression": "http.request.body.raw eq \"abcd\"",
          "mitigation_timeout": 600,
          "requests_per_period": 1000,
          "requests_to_origin": true,
          "score_per_period": 400,
          "score_response_header_name": "my-score"
        },
        "ref": "ref"
      }
    ],
    "version": "1",
    "description": "A description for my ruleset."
  },
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "messages": [
    {
      "message": "something bad happened",
      "code": 10000,
      "source": {
        "pointer": "/rules/0/action"
      }
    }
  ],
  "result": {
    "id": "2f2feab2026849078ba485f918791bdc",
    "kind": "root",
    "last_updated": "2000-01-01T00:00:00Z",
    "name": "My ruleset",
    "phase": "http_request_firewall_custom",
    "rules": [
      {
        "last_updated": "2000-01-01T00:00:00Z",
        "version": "1",
        "id": "id",
        "action": "action",
        "action_parameters": {
          "response": {
            "content": "{\n  \"success\": false,\n  \"error\": \"you have been blocked\"\n}",
            "content_type": "application/json",
            "status_code": 400
          }
        },
        "categories": [
          "directory-traversal"
        ],
        "description": "Block the request.",
        "enabled": true,
        "exposed_credential_check": {
          "password_expression": "url_decode(http.request.body.form[\\\"password\\\"][0])",
          "username_expression": "url_decode(http.request.body.form[\\\"username\\\"][0])"
        },
        "expression": "expression",
        "logging": {
          "enabled": true
        },
        "ratelimit": {
          "characteristics": [
            "cf.colo.id"
          ],
          "period": 60,
          "counting_expression": "http.request.body.raw eq \"abcd\"",
          "mitigation_timeout": 600,
          "requests_per_period": 1000,
          "requests_to_origin": true,
          "score_per_period": 400,
          "score_response_header_name": "my-score"
        },
        "ref": "ref"
      }
    ],
    "version": "1",
    "description": "A description for my ruleset."
  },
  "success": true
}