curl --request PUT \
--url https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"servers": [
"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"304e1794-a5b7-41f2-9a20-c0d444eb6683"
]
}
'import requests
url = "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers"
payload = { "servers": ["ecc6f4f1-c89b-4dce-a20b-a330641c5b0b", "304e1794-a5b7-41f2-9a20-c0d444eb6683"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
servers: ['ecc6f4f1-c89b-4dce-a20b-a330641c5b0b', '304e1794-a5b7-41f2-9a20-c0d444eb6683']
})
};
fetch('https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'servers' => [
'ecc6f4f1-c89b-4dce-a20b-a330641c5b0b',
'304e1794-a5b7-41f2-9a20-c0d444eb6683'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers"
payload := strings.NewReader("{\n \"servers\": [\n \"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b\",\n \"304e1794-a5b7-41f2-9a20-c0d444eb6683\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"servers\": [\n \"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b\",\n \"304e1794-a5b7-41f2-9a20-c0d444eb6683\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"servers\": [\n \"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b\",\n \"304e1794-a5b7-41f2-9a20-c0d444eb6683\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": false,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": false
},
{
"id": "304e1794-a5b7-41f2-9a20-c0d444eb6683",
"uuid_short": "304e1794",
"name": "sector-c-db",
"hostname": "sector-c-db.blackmesa.example.com",
"template_name": "Debian 13",
"template_icon_url": "https://img.icons8.com/color/48/debian.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.57",
"synced_at": null,
"sync_state": "pending",
"sync_error": null,
"is_current": false
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Set a firewall group's servers
Overview
Replaces the group’s assigned servers. Send the complete servers list; omitted servers are detached and an empty list detaches all servers. Every ID must identify an accessible server in the group’s team. If any ID is invalid, the request returns 404 and nothing changes. Returns the group with affected assignments marked pending while rules are applied in the background.
Permissions
Requires the firewall.update (Change the firewall) permission for the selected team. Resources outside that team return 404.
curl --request PUT \
--url https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"servers": [
"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"304e1794-a5b7-41f2-9a20-c0d444eb6683"
]
}
'import requests
url = "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers"
payload = { "servers": ["ecc6f4f1-c89b-4dce-a20b-a330641c5b0b", "304e1794-a5b7-41f2-9a20-c0d444eb6683"] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
servers: ['ecc6f4f1-c89b-4dce-a20b-a330641c5b0b', '304e1794-a5b7-41f2-9a20-c0d444eb6683']
})
};
fetch('https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'servers' => [
'ecc6f4f1-c89b-4dce-a20b-a330641c5b0b',
'304e1794-a5b7-41f2-9a20-c0d444eb6683'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers"
payload := strings.NewReader("{\n \"servers\": [\n \"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b\",\n \"304e1794-a5b7-41f2-9a20-c0d444eb6683\"\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"servers\": [\n \"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b\",\n \"304e1794-a5b7-41f2-9a20-c0d444eb6683\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://console.advinservers.com/api/v1/client/firewall-groups/{firewallGroup}/servers")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"servers\": [\n \"ecc6f4f1-c89b-4dce-a20b-a330641c5b0b\",\n \"304e1794-a5b7-41f2-9a20-c0d444eb6683\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "72a4a737-236f-456f-827f-6145d9c95727",
"uuid_short": "Uuid short",
"name": "Lambda Complex ingress",
"applied": false,
"rules": [
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
],
"servers": [
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "pending",
"sync_error": null,
"is_current": false
},
{
"id": "304e1794-a5b7-41f2-9a20-c0d444eb6683",
"uuid_short": "304e1794",
"name": "sector-c-db",
"hostname": "sector-c-db.blackmesa.example.com",
"template_name": "Debian 13",
"template_icon_url": "https://img.icons8.com/color/48/debian.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.57",
"synced_at": null,
"sync_state": "pending",
"sync_error": null,
"is_current": false
}
],
"created_at": "2026-03-02T19:31:08+00:00"
}{
"message": "Unauthenticated."
}{
"message": "This API key is not allowed to do that in this team. It needs the \"snapshot.delete\" permission."
}{
"message": "Not found."
}{
"message": "The name field is required.",
"errors": {}
}{
"message": "Too Many Attempts."
}Authorizations
Your API key, sent as a bearer token. Create one in the control panel under API Keys, give it only the permissions the integration needs, and copy it when it is created. It cannot be shown again. Each key is restricted to one owned team. The key determines the team for every request.
Path Parameters
The firewall group uuid short
"72a4a737-236f-456f-827f-6145d9c95727"
Body
Send a JSON object containing the fields below. Required fields are marked in the schema.
The value of servers.
36Response
The record, as a JSON object. There is no envelope.
A reusable set of firewall rules.
The id ID.
"72a4a737-236f-456f-827f-6145d9c95727"
The first eight characters of the UUID. Either form can identify the group.
"Uuid short"
The name shown to customers.
"Lambda Complex ingress"
Whether the group is applied to the requested server. Always false when no server was requested.
false
The value of rules.
Show child attributes
Show child attributes
[
{
"id": "986f78ba-68f7-4dd3-8f15-1bac745f5ab1",
"position": 0,
"type": "in",
"action": "ACCEPT",
"macro": "Web",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": null,
"dest": null,
"enabled": true
},
{
"id": "23f9fb19-d43a-4144-af19-95348d88c247",
"position": 1,
"type": "in",
"action": "ACCEPT",
"macro": "SSH",
"proto": null,
"sport": null,
"dport": null,
"source": null,
"source_ip_group": {
"id": "145e6e6f-a6b0-4b9e-9060-2d4f017baff8",
"name": "Sector C lab"
},
"dest": null,
"enabled": true
},
{
"id": "97fd3850-8315-4eae-be31-4ef1211f6d76",
"position": 2,
"type": "in",
"action": "ACCEPT",
"macro": null,
"proto": "tcp",
"sport": null,
"dport": "9100",
"source": "10.24.0.0/24",
"source_ip_group": null,
"dest": null,
"enabled": true
}
]
The value of servers.
Show child attributes
Show child attributes
[
{
"id": "ecc6f4f1-c89b-4dce-a20b-a330641c5b0b",
"uuid_short": "ecc6f4f1",
"name": "lambda-core",
"hostname": "lambda-core.blackmesa.example.com",
"template_name": "Ubuntu 24.04",
"template_icon_url": "https://img.icons8.com/color/48/ubuntu.png",
"windows": false,
"location": "Kansas City, MO",
"address": "203.0.113.24",
"synced_at": "2026-09-14T15:58:21+00:00",
"sync_state": "synced",
"sync_error": null,
"is_current": false
}
]
The date and time for created at, in UTC.
"2026-03-02T19:31:08+00:00"