curl --request POST \
--url https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "udp",
"sport": null,
"dport": "27015",
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
}
'import requests
url = "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules"
payload = {
"type": "in",
"action": "ACCEPT",
"macro": None,
"proto": "udp",
"sport": None,
"dport": "27015",
"source": None,
"source_ip_group": None,
"dest": None,
"enabled": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
type: 'in',
action: 'ACCEPT',
macro: null,
proto: 'udp',
sport: null,
dport: '27015',
source: null,
source_ip_group: null,
dest: null,
enabled: true
})
};
fetch('https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'type' => 'in',
'action' => 'ACCEPT',
'macro' => null,
'proto' => 'udp',
'sport' => null,
'dport' => '27015',
'source' => null,
'source_ip_group' => null,
'dest' => null,
'enabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules"
payload := strings.NewReader("{\n \"type\": \"in\",\n \"action\": \"ACCEPT\",\n \"macro\": null,\n \"proto\": \"udp\",\n \"sport\": null,\n \"dport\": \"27015\",\n \"source\": null,\n \"source_ip_group\": null,\n \"dest\": null,\n \"enabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"type\": \"in\",\n \"action\": \"ACCEPT\",\n \"macro\": null,\n \"proto\": \"udp\",\n \"sport\": null,\n \"dport\": \"27015\",\n \"source\": null,\n \"source_ip_group\": null,\n \"dest\": null,\n \"enabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"type\": \"in\",\n \"action\": \"ACCEPT\",\n \"macro\": null,\n \"proto\": \"udp\",\n \"sport\": null,\n \"dport\": \"27015\",\n \"source\": null,\n \"source_ip_group\": null,\n \"dest\": null,\n \"enabled\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": false,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "c54fb379-1b07-45d2-8229-9c69dcecb4a5",
"position": 3,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "udp",
"sport": null,
"dport": "27015",
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": false
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Add a firewall rule
Overview
Adds a rule to the end of the group. Rules are evaluated from top to bottom. Use either source or source_ip_group, not both. A macro defines its own protocol and ports, so proto, sport and dport are ignored when a macro is selected. Without a macro or protocol, a source or destination is required. Returns the updated group. Assigned servers remain pending until the rules are applied in the background.
Permissions
Requires the firewall.update (Change the firewall) permission for the selected team. Resources outside that team return 404.
curl --request POST \
--url https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "udp",
"sport": null,
"dport": "27015",
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
}
'import requests
url = "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules"
payload = {
"type": "in",
"action": "ACCEPT",
"macro": None,
"proto": "udp",
"sport": None,
"dport": "27015",
"source": None,
"source_ip_group": None,
"dest": None,
"enabled": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
type: 'in',
action: 'ACCEPT',
macro: null,
proto: 'udp',
sport: null,
dport: '27015',
source: null,
source_ip_group: null,
dest: null,
enabled: true
})
};
fetch('https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'type' => 'in',
'action' => 'ACCEPT',
'macro' => null,
'proto' => 'udp',
'sport' => null,
'dport' => '27015',
'source' => null,
'source_ip_group' => null,
'dest' => null,
'enabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules"
payload := strings.NewReader("{\n \"type\": \"in\",\n \"action\": \"ACCEPT\",\n \"macro\": null,\n \"proto\": \"udp\",\n \"sport\": null,\n \"dport\": \"27015\",\n \"source\": null,\n \"source_ip_group\": null,\n \"dest\": null,\n \"enabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"type\": \"in\",\n \"action\": \"ACCEPT\",\n \"macro\": null,\n \"proto\": \"udp\",\n \"sport\": null,\n \"dport\": \"27015\",\n \"source\": null,\n \"source_ip_group\": null,\n \"dest\": null,\n \"enabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/rules")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"type\": \"in\",\n \"action\": \"ACCEPT\",\n \"macro\": null,\n \"proto\": \"udp\",\n \"sport\": null,\n \"dport\": \"27015\",\n \"source\": null,\n \"source_ip_group\": null,\n \"dest\": null,\n \"enabled\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": false,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "c54fb379-1b07-45d2-8229-9c69dcecb4a5",
"position": 3,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "udp",
"sport": null,
"dport": "27015",
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": false
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Authorizations
Your API key, sent as a bearer token. Create one in the control panel under API Keys, give it only the permissions the integration needs, and copy it when it is created. It cannot be shown again. Each key is restricted to one owned team. The key determines the team for every request.
Path Parameters
The firewall group uuid short
"72a4a737-236f-456f-827f-6145d9c95727"
Body
Send a JSON object containing the fields below. Required fields are marked in the schema.
The type of operation or resource.
in, out The value of action.
ACCEPT, DROP The value of macro.
50The value of proto.
tcp, udp, icmp, gre, null The source port or port range this rule matches.
20^\d{1,5}(:\d{1,5})?(,\d{1,5}(:\d{1,5})?)*$The destination port or port range this rule matches.
20^\d{1,5}(:\d{1,5})?(,\d{1,5}(:\d{1,5})?)*$The source address or network this rule matches.
100The value of source_ip_group.
36The value of dest.
100The value of enabled.
Response
The record, as a JSON object. There is no envelope.
A reusable set of firewall rules.
The id ID.
"72a4a737-236f-456f-827f-6145d9c95727"
The first eight characters of the UUID. Either form can identify the group.
"Uuid short"
The name shown to customers.
"Lambda Complex ingress"
Whether the group is applied to the requested server. Always false when no server was requested.
false
The value of rules.
Show child attributes
Show child attributes
[
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
]
The value of servers.
Show child attributes
Show child attributes
[
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "synced",
"sync_error": null,
"is_current": false
}
]
The date and time for created at, in UTC.
"2026-03-02T19:31:08+00:00"