Client area

GET · Security

Get a domain's ModSecurity status

Get a domain's ModSecurity status

GET /api/v1/security/modsecurity
R Read
Scope read:hosting

This scope is inferred from the method and the endpoint's group — the OpenAPI document does not carry one per operation. The wire is authoritative; whoami reports what your token actually holds.

Description

Returns modsecurity{enabled, rules[]} — plus the resolved target. supported:false when ModSecurity is not installed on the node. A rules[].id feeds disable_modsecurity_rule.

Query parameters

Name Type Description
input required string A domain, email address, website URL, or Inleed service id — for example example.se, [email protected] or 42976. Resolved to the owning account automatically, and the resolved target is echoed back in the response.

Responses

The specification does not describe this response body; the note in the rail says what to expect. Every non-2xx response is an RFC 7807 problem with a stable code.

Commonly returned errors

The codes this operation reaches on its own path: the auth stack, its own validation and ownership checks, and the transport. Not a closed set — a shared code from the full registry can still surface. Each links to the code’s own page, the same URL its type dereferences to.

401 No token was presented, or the token is revoked, expired or unknown.
403 The token lacks a required scope, or this account does not own the resource.
404 No such resource for this account.
422 Validation error
429 The rate limit for this token is exhausted. See `Retry-After`.
500 Something went wrong on our side. The failure is logged against `requestId`.
Esc
navigate open Esc close