> ## Documentation Index
> Fetch the complete documentation index at: https://docs.advinservers.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List firewall groups

> ### Overview

Lists firewall groups in the current team, ordered by name. A group can be applied to multiple servers in that team. Each entry includes its rules in evaluation order, assigned servers and assignment status. `applied` is always false in this list because no specific server is selected.

### Permissions

Requires the `firewall.read` (View the firewall) permission for the selected team. Resources outside that team return 404.



## OpenAPI

````yaml https://console.advinservers.com/docs/openapi.json get /firewall-groups
openapi: 3.1.0
info:
  title: API reference
  version: 1.0.0
  description: >-
    Use this API to manage your team's servers, networks, backups, and other
    resources.


    ## Authentication


    Create an API key under **API Keys** and send it as a bearer token with
    every request:


    ```

    Authorization: Bearer {YOUR_API_KEY}

    Accept: application/json

    ```


    Copy the key when you create it. It cannot be shown again. Revoking a key
    takes effect immediately.


    ## Permissions


    Give each key only the permissions it needs. Every endpoint lists the
    required permission.


    Permissions cover servers and other resources in the key's team.


    ## Team scope


    A key can access resources in the team selected when it was created. This
    includes servers,

    snapshots, backups, firewall groups, images, SSH keys, scripts, networks and
    addresses.

    Resources in other teams return `404 Not Found`. Create a separate key for
    each team.


    The key determines the team for every request. Legacy keys that had no team
    are assigned

    to the account's first owned team.


    ## Actions that need the panel


    API keys cannot do the following, even with every permission. Sign in to the
    panel in a

    browser to do them:


    - Create, edit or revoke API keys

    - Edit the IP groups that restrict API keys

    - End signed-in sessions

    - Change two-factor authentication

    - Change the account's email address

    - Accept or decline team invitations

    - Switch or leave a team


    This keeps a leaked key from widening its own access or locking you out of
    your account.


    ## Source IP restrictions


    A key can be restricted to one or more IP groups. Requests from other
    addresses are rejected.


    ## Requests and responses


    Each endpoint lists its path, query, header, and body parameters. Examples
    use fictional data.


    Single records use JSON objects. Collections use JSON arrays unless the
    endpoint supports pagination. Timestamps use ISO 8601 in UTC.


    Error responses include `message`. Validation errors also include an
    `errors` object for each field. Each endpoint lists its status codes.


    ## Audit log


    Every API request, including reads, is recorded in the account audit log
    with the key that made it.
servers:
  - url: https://console.advinservers.com/api/v1/client
security:
  - http: []
tags:
  - name: Account
    description: Billing contact details and account setup progress.
  - name: Account activity
    description: Actions performed in the current team by people and API keys.
  - name: Servers
    description: >-
      Order and list servers, read their state and resource use, open a console,
      and control power.
  - name: Server settings
    description: >-
      Rename a server, rebuild it, and change its hardware, media, resolvers and
      credentials.
  - name: Backups
    description: Scheduled server copies stored separately from the server.
  - name: Snapshots
    description: >-
      Take, restore and move server snapshots. Snapshots are kept in snapshot
      storage that the team buys by the GiB.
  - name: Firewall groups
    description: Reusable sets of firewall rules, and the servers they apply to.
  - name: IP groups
    description: Reusable source address lists for firewall rules.
  - name: Server firewall
    description: >-
      Read default traffic policies and rules managed outside your firewall
      groups.
  - name: IP addresses
    description: Manage floating IPs and server address assignments.
  - name: Private networks
    description: Connect servers over a private network in the same location.
  - name: Reverse DNS
    description: Set the hostnames returned by IP address lookups.
  - name: DDoS protection
    description: Configure attack filtering for server addresses.
  - name: Bandwidth
    description: Buy extra bandwidth and share it between servers or location pools.
  - name: SSH keys
    description: Public keys the account can install on a server when it is built.
  - name: Setup scripts
    description: Scripts the account can run on a server when it is built.
  - name: ISO images
    description: ISO images you have downloaded, and the servers they are mounted on.
  - name: Server upgrades
    description: Change an existing server's plan.
  - name: Checkout
    description: Choose a payment method and pay for a purchase.
  - name: Invoices
    description: View and pay account invoices.
  - name: Billing
    description: Manage service renewals, payment methods and account credit.
  - name: Transfers
    description: Move resources between teams or transfer ownership.
  - name: Teams
    description: Manage the team assigned to your API key.
  - name: Team members
    description: Invite people and manage their team access.
  - name: Team roles
    description: Define the permissions granted to team members.
  - name: Team activity
    description: View actions performed in a team.
  - name: Support tickets
    description: >-
      Open, read, reply to and close support tickets. Tickets belong to the
      account holder and are not shared with team members.
paths:
  /firewall-groups:
    get:
      tags:
        - Firewall groups
      summary: List firewall groups
      description: >-
        ### Overview


        Lists firewall groups in the current team, ordered by name. A group can
        be applied to multiple servers in that team. Each entry includes its
        rules in evaluation order, assigned servers and assignment status.
        `applied` is always false in this list because no specific server is
        selected.


        ### Permissions


        Requires the `firewall.read` (View the firewall) permission for the
        selected team. Resources outside that team return 404.
      operationId: firewallGroup.list
      responses:
        '200':
          description: The whole set, as a JSON array. There is no envelope and no paging.
          content:
            application/json:
              schema:
                type: array
                examples:
                  - - id: 72a4a737-236f-456f-827f-6145d9c95727
                      uuid_short: Uuid short
                      name: Lambda Complex ingress
                      applied: false
                      rules:
                        - id: 986f78ba-68f7-4dd3-8f15-1bac745f5ab1
                          position: 0
                          type: in
                          action: ACCEPT
                          macro: Web
                          proto: null
                          sport: null
                          dport: null
                          source: null
                          source_ip_group: null
                          dest: null
                          enabled: true
                        - id: 23f9fb19-d43a-4144-af19-95348d88c247
                          position: 1
                          type: in
                          action: ACCEPT
                          macro: SSH
                          proto: null
                          sport: null
                          dport: null
                          source: null
                          source_ip_group:
                            id: 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
                            name: Sector C lab
                          dest: null
                          enabled: true
                        - id: 97fd3850-8315-4eae-be31-4ef1211f6d76
                          position: 2
                          type: in
                          action: ACCEPT
                          macro: null
                          proto: tcp
                          sport: null
                          dport: '9100'
                          source: 10.24.0.0/24
                          source_ip_group: null
                          dest: null
                          enabled: true
                      servers:
                        - id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
                          uuid_short: ecc6f4f1
                          name: lambda-core
                          hostname: lambda-core.blackmesa.example.com
                          template_name: Ubuntu 24.04
                          template_icon_url: https://img.icons8.com/color/48/ubuntu.png
                          windows: false
                          location: Kansas City, MO
                          address: 203.0.113.24
                          synced_at: '2026-09-14T15:58:21+00:00'
                          sync_state: synced
                          sync_error: null
                          is_current: false
                      created_at: '2026-03-02T19:31:08+00:00'
                items:
                  $ref: '#/components/schemas/FirewallGroupData'
        '401':
          description: >-
            The key was missing, malformed, revoked, or belongs to an account
            that no longer exists.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Unauthenticated.
                required:
                  - message
        '403':
          description: >-
            Access denied. Check the key's team, permissions and allowed IP
            addresses. Some actions, such as managing API keys, require a
            browser session. The response message explains the reason.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - >-
                        This API key is not allowed to do that in this team. It
                        needs the "snapshot.delete" permission.
                required:
                  - message
        '429':
          description: >-
            Too many requests. The `Retry-After` header says how many seconds to
            wait. Limits are per account, so several keys on one account share
            them.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    examples:
                      - Too Many Attempts.
                required:
                  - message
components:
  schemas:
    FirewallGroupData:
      type: object
      description: A reusable set of firewall rules.
      examples:
        - id: 72a4a737-236f-456f-827f-6145d9c95727
          uuid_short: Uuid short
          name: Lambda Complex ingress
          applied: false
          rules:
            - id: 986f78ba-68f7-4dd3-8f15-1bac745f5ab1
              position: 0
              type: in
              action: ACCEPT
              macro: Web
              proto: null
              sport: null
              dport: null
              source: null
              source_ip_group: null
              dest: null
              enabled: true
            - id: 23f9fb19-d43a-4144-af19-95348d88c247
              position: 1
              type: in
              action: ACCEPT
              macro: SSH
              proto: null
              sport: null
              dport: null
              source: null
              source_ip_group:
                id: 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
                name: Sector C lab
              dest: null
              enabled: true
            - id: 97fd3850-8315-4eae-be31-4ef1211f6d76
              position: 2
              type: in
              action: ACCEPT
              macro: null
              proto: tcp
              sport: null
              dport: '9100'
              source: 10.24.0.0/24
              source_ip_group: null
              dest: null
              enabled: true
          servers:
            - id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
              uuid_short: ecc6f4f1
              name: lambda-core
              hostname: lambda-core.blackmesa.example.com
              template_name: Ubuntu 24.04
              template_icon_url: https://img.icons8.com/color/48/ubuntu.png
              windows: false
              location: Kansas City, MO
              address: 203.0.113.24
              synced_at: '2026-09-14T15:58:21+00:00'
              sync_state: synced
              sync_error: null
              is_current: false
          created_at: '2026-03-02T19:31:08+00:00'
      properties:
        id:
          type: string
          description: The id ID.
          examples:
            - 72a4a737-236f-456f-827f-6145d9c95727
        uuid_short:
          type: string
          description: >-
            The first eight characters of the UUID. Either form can identify the
            group.
          examples:
            - Uuid short
        name:
          type: string
          description: The name shown to customers.
          examples:
            - Lambda Complex ingress
        applied:
          type: boolean
          description: >-
            Whether the group is applied to the requested server. Always false
            when no server was requested.
          examples:
            - false
        rules:
          type: array
          description: The value of `rules`.
          examples:
            - - id: 986f78ba-68f7-4dd3-8f15-1bac745f5ab1
                position: 0
                type: in
                action: ACCEPT
                macro: Web
                proto: null
                sport: null
                dport: null
                source: null
                source_ip_group: null
                dest: null
                enabled: true
              - id: 23f9fb19-d43a-4144-af19-95348d88c247
                position: 1
                type: in
                action: ACCEPT
                macro: SSH
                proto: null
                sport: null
                dport: null
                source: null
                source_ip_group:
                  id: 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
                  name: Sector C lab
                dest: null
                enabled: true
              - id: 97fd3850-8315-4eae-be31-4ef1211f6d76
                position: 2
                type: in
                action: ACCEPT
                macro: null
                proto: tcp
                sport: null
                dport: '9100'
                source: 10.24.0.0/24
                source_ip_group: null
                dest: null
                enabled: true
          items:
            $ref: '#/components/schemas/FirewallGroupRuleData'
        servers:
          type: array
          description: The value of `servers`.
          examples:
            - - id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
                uuid_short: ecc6f4f1
                name: lambda-core
                hostname: lambda-core.blackmesa.example.com
                template_name: Ubuntu 24.04
                template_icon_url: https://img.icons8.com/color/48/ubuntu.png
                windows: false
                location: Kansas City, MO
                address: 203.0.113.24
                synced_at: '2026-09-14T15:58:21+00:00'
                sync_state: synced
                sync_error: null
                is_current: false
          items:
            $ref: '#/components/schemas/FirewallGroupServerData'
        created_at:
          type:
            - string
            - 'null'
          description: The date and time for created at, in UTC.
          examples:
            - '2026-03-02T19:31:08+00:00'
      required:
        - id
        - uuid_short
        - name
        - applied
        - rules
        - servers
        - created_at
      title: FirewallGroupData
    FirewallGroupRuleData:
      type: object
      description: One rule in a firewall group.
      examples:
        - id: 23f9fb19-d43a-4144-af19-95348d88c247
          uuid_short: Uuid short
          position: 1
          type: in
          action: ACCEPT
          macro: SSH
          proto: null
          sport: null
          dport: null
          source: null
          source_ip_group:
            id: 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
            name: Sector C lab
          dest: null
          enabled: true
      properties:
        id:
          type: string
          description: The id ID.
          examples:
            - 23f9fb19-d43a-4144-af19-95348d88c247
        uuid_short:
          type: string
          description: >-
            The first eight characters of the UUID. Either form can identify the
            rule.
          examples:
            - Uuid short
        position:
          type: integer
          description: Where the rule sits in its group's top-down evaluation order.
          examples:
            - 1
        type:
          type: string
          description: The type of operation or resource.
          enum:
            - in
            - out
          examples:
            - in
        action:
          type: string
          description: The value of `action`.
          enum:
            - ACCEPT
            - DROP
          examples:
            - ACCEPT
        macro:
          type:
            - string
            - 'null'
          description: The value of `macro`.
          examples:
            - SSH
        proto:
          type:
            - string
            - 'null'
          description: The value of `proto`.
          examples:
            - null
        sport:
          type:
            - string
            - 'null'
          description: The source port or port range this rule matches.
          examples:
            - null
        dport:
          type:
            - string
            - 'null'
          description: The destination port or port range this rule matches.
          examples:
            - null
        source:
          type:
            - string
            - 'null'
          description: The source address or network this rule matches.
          examples:
            - null
        source_ip_group:
          description: The value of `source_ip_group`.
          examples:
            - id: 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
              name: Sector C lab
          anyOf:
            - $ref: '#/components/schemas/FirewallRuleSourceIpGroupData'
            - type: 'null'
        dest:
          type:
            - string
            - 'null'
          description: The value of `dest`.
          examples:
            - null
        enabled:
          type: boolean
          description: The value of `enabled`.
          examples:
            - true
      required:
        - id
        - uuid_short
        - position
        - type
        - action
        - macro
        - proto
        - sport
        - dport
        - source
        - source_ip_group
        - dest
        - enabled
      title: FirewallGroupRuleData
    FirewallGroupServerData:
      type: object
      description: >-
        One server a group is applied to, carrying enough of the server to be
        listed the same way the dashboard lists it - icon, name, where it is and
        how to reach it - alongside how far the assignment has got.
      examples:
        - id: ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
          uuid_short: ecc6f4f1
          name: lambda-core
          hostname: lambda-core.blackmesa.example.com
          template_name: Ubuntu 24.04
          template_icon_url: https://img.icons8.com/color/48/ubuntu.png
          windows: false
          location: Kansas City, MO
          address: 203.0.113.24
          synced_at: '2026-09-14T15:58:21+00:00'
          sync_state: synced
          sync_error: null
          is_current: false
      properties:
        id:
          type: string
          description: The id ID.
          examples:
            - ecc6f4f1-c89b-4dce-a20b-a330641c5b0b
        uuid_short:
          type: string
          description: The value of `uuid_short`.
          examples:
            - ecc6f4f1
        name:
          type: string
          description: The name shown to customers.
          examples:
            - lambda-core
        hostname:
          type: string
          description: The fully qualified hostname.
          examples:
            - lambda-core.blackmesa.example.com
        template_name:
          type:
            - string
            - 'null'
          description: The value of `template_name`.
          examples:
            - Ubuntu 24.04
        template_icon_url:
          type:
            - string
            - 'null'
          description: The value of `template_icon_url`.
          examples:
            - https://img.icons8.com/color/48/ubuntu.png
        windows:
          type: boolean
          description: The value of `windows`.
          examples:
            - false
        location:
          type:
            - string
            - 'null'
          description: The value of `location`.
          examples:
            - Kansas City, MO
        address:
          type:
            - string
            - 'null'
          description: The IP address assigned to the resource.
          examples:
            - 203.0.113.24
        synced_at:
          type:
            - string
            - 'null'
          description: The date and time for synced at, in UTC.
          examples:
            - '2026-09-14T15:58:21+00:00'
        sync_state:
          type: string
          description: The value of `sync_state`.
          enum:
            - pending
            - synced
            - failed
          examples:
            - synced
        sync_error:
          type:
            - string
            - 'null'
          description: The value of `sync_error`.
          examples:
            - null
        is_current:
          type: boolean
          description: Whether this is the requested server.
          examples:
            - false
      required:
        - id
        - uuid_short
        - name
        - hostname
        - template_name
        - template_icon_url
        - windows
        - location
        - address
        - synced_at
        - sync_state
        - sync_error
        - is_current
      title: FirewallGroupServerData
    FirewallRuleSourceIpGroupData:
      type: object
      description: The IP group a rule draws its source from, named rather than referenced.
      examples:
        - id: 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
          name: Sector C lab
      properties:
        id:
          type: string
          description: The id ID.
          examples:
            - 145e6e6f-a6b0-4b9e-9060-2d4f017baff8
        name:
          type: string
          description: The name shown to customers.
          examples:
            - Sector C lab
      required:
        - id
        - name
      title: FirewallRuleSourceIpGroupData
  securitySchemes:
    http:
      type: http
      description: >-
        Your API key, sent as a bearer token. Create one in the control panel
        under API Keys, give it only the permissions the integration needs, and
        copy it when it is created. It cannot be shown again. Each key is
        restricted to one owned team. The key determines the team for every
        request.
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.