/api/v2/vps/{id}/firewall Add one inbound firewall rule to a VPS.
This customer-facing v2 route manages inbound allow/drop/reject rules only, so request type must be in.
Outbound rules or shared firewall-group references may appear in the read response from upstream, but they are not created through this per-VPS write endpoint.
When dport or sport is set, proto must be tcp or udp; ICMP and all-protocol rules cannot include ports.
Omit source or send null for any source across IPv4 and IPv6; 0.0.0.0/0 is an explicit IPv4-only source filter and ::/0 is an explicit IPv6-only source filter.
Read the firewall list first to check actions.canAddRule and rule limits.
The create response may have pos: null; re-read GET /api/v2/vps/{id}/firewall to get authoritative positions before editing or deleting.
write:vm
Authenticate with an API key in the Authorization: Bearer <token> header.
id string required
Example: vps_01hxa3b4c5d6e7f8g9h0j1k2m3 Public VPS ID from GET /api/v2/vps data[].id. Do not invent this value; use the exact ID returned by the referenced API response.
Authorization Bearer <token> Accept application/json Content-Type application/json type string · enum required
· Example: in Inbound rule. Per-VPS v2 firewall writes do not create outbound rules or firewall-group references.
in action string · enum required
· Example: ACCEPT ACCEPT DROP REJECT enabled boolean
· Example: true Omit to keep the platform default for newly staged rules; send true to enable immediately.
proto string · nullable
· Example: tcp Protocol for the rule. Required as tcp or udp when dport or sport is set.
dport string · nullable
· Example: 22 Destination port or port range. Requires proto to be tcp or udp.
sport string · nullable
· Example: null Source port or port range. Requires proto to be tcp or udp.
source string · nullable
· Example: 198.51.100.10 Source IP or CIDR. Omit or send null for any source across IPv4 and IPv6.
dest string · nullable
· Example: null description string · nullable
· Example: Allow SSH from office Single-line human-readable label for the rule.
pos integer · nullable required
· Example: 0 type string · nullable · enum required
· Example: in Created per-VPS rules are inbound. The list endpoint can still show read-only out or group rules that already exist upstream.
in action string · nullable · enum required
· Example: ACCEPT ACCEPT DROP REJECT enabled boolean required
· Example: true proto string · nullable required
· Example: tcp dport string · nullable required
· Example: 22 sport string · nullable required
· Example: null source string · nullable required
· Example: 198.51.100.10 dest string · nullable required
· Example: null description string · nullable required
· Example: Allow SSH from office isSystem boolean required
· Example: false editable boolean required
· Example: true type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object Retry-After seconds plus X-RateLimit-* headers. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object https://cloud.hostup.se/api/v2/vps/{id}/firewall curl -X POST "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/firewall" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{
"type": "in",
"action": "ACCEPT",
"enabled": true,
"proto": "tcp",
"dport": "22",
"source": "198.51.100.10",
"description": "Allow SSH from office"
}' {
"pos": null,
"type": "in",
"action": "ACCEPT",
"enabled": true,
"proto": "tcp",
"dport": "22",
"sport": null,
"source": "198.51.100.10",
"dest": null,
"description": "Allow SSH from office",
"isSystem": false,
"editable": true
} {
"type": "in",
"action": "ACCEPT",
"enabled": true,
"proto": "tcp",
"dport": "22",
"source": "198.51.100.10",
"description": "Allow SSH from office"
}