curl --request PUT \
--url https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"groups": [
"72a4a737-236f-456f-827f-6145d9c95727",
"437b596c-78c9-47e4-abc9-94bc0eab1598"
]
}
'import requests
url = "https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder"
payload = { "groups": ["72a4a737-236f-456f-827f-6145d9c95727", "437b596c-78c9-47e4-abc9-94bc0eab1598"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
groups: ['72a4a737-236f-456f-827f-6145d9c95727', '437b596c-78c9-47e4-abc9-94bc0eab1598']
})
};
fetch('https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'groups' => [
'72a4a737-236f-456f-827f-6145d9c95727',
'437b596c-78c9-47e4-abc9-94bc0eab1598'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder"
payload := strings.NewReader("{\n \"groups\": [\n \"72a4a737-236f-456f-827f-6145d9c95727\",\n \"437b596c-78c9-47e4-abc9-94bc0eab1598\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"groups\": [\n \"72a4a737-236f-456f-827f-6145d9c95727\",\n \"437b596c-78c9-47e4-abc9-94bc0eab1598\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"groups\": [\n \"72a4a737-236f-456f-827f-6145d9c95727\",\n \"437b596c-78c9-47e4-abc9-94bc0eab1598\"\n ]\n}"
response = http.request(request)
puts response.read_body[
{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": true,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": true
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}
]{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Reorder a server's firewall groups
Overview
Changes the order in which the server’s firewall groups are evaluated. Send groups with every assigned group ID exactly once, from first to last. Invalid lists return 422 without changing the order. The new order is applied in the background.
Permissions
Requires the firewall.update (Change the firewall) permission for the selected team. Resources outside that team return 404.
curl --request PUT \
--url https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"groups": [
"72a4a737-236f-456f-827f-6145d9c95727",
"437b596c-78c9-47e4-abc9-94bc0eab1598"
]
}
'import requests
url = "https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder"
payload = { "groups": ["72a4a737-236f-456f-827f-6145d9c95727", "437b596c-78c9-47e4-abc9-94bc0eab1598"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
groups: ['72a4a737-236f-456f-827f-6145d9c95727', '437b596c-78c9-47e4-abc9-94bc0eab1598']
})
};
fetch('https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'groups' => [
'72a4a737-236f-456f-827f-6145d9c95727',
'437b596c-78c9-47e4-abc9-94bc0eab1598'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder"
payload := strings.NewReader("{\n \"groups\": [\n \"72a4a737-236f-456f-827f-6145d9c95727\",\n \"437b596c-78c9-47e4-abc9-94bc0eab1598\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"groups\": [\n \"72a4a737-236f-456f-827f-6145d9c95727\",\n \"437b596c-78c9-47e4-abc9-94bc0eab1598\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/servers/{server}/firewall-groups/reorder")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"groups\": [\n \"72a4a737-236f-456f-827f-6145d9c95727\",\n \"437b596c-78c9-47e4-abc9-94bc0eab1598\"\n ]\n}"
response = http.request(request)
puts response.read_body[
{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": true,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": true
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}
]{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Authorizations
Your API key, sent as a bearer token. Create one in the control panel under API Keys, give it only the permissions the integration needs, and copy it when it is created. It cannot be shown again. Each key is restricted to one owned team. The key determines the team for every request.
Path Parameters
The server UUID
"ecc6f4f1"
Body
Send a JSON object containing the fields below. Required fields are marked in the schema.
The value of groups.
136Response
The whole set, as a JSON array. There is no envelope and no paging.
The id ID.
"72a4a737-236f-456f-827f-6145d9c95727"
The first eight characters of the UUID. Either form can identify the group.
"Uuid short"
The name shown to customers.
"Lambda Complex ingress"
Whether the group is applied to the requested server. Always false when no server was requested.
false
The value of rules.
Show child attributes
Show child attributes
[
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
]
The value of servers.
Show child attributes
Show child attributes
[
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "synced",
"sync_error": null,
"is_current": false
}
]
The date and time for created at, in UTC.
"2026-03-02T19:31:08+00:00"
[
{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": true,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": true
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}
]