/api/v2/vps/{id}/firewall/{pos} Replace one inbound firewall rule at a specific position.
Get {pos} from GET /api/v2/vps/{id}/firewall rules[].pos; only rules with editable: true should be updated through this endpoint.
The request body is the full rule replacement, not a partial patch.
Per-VPS v2 firewall writes require type: "in"; outbound rules and firewall-group references from the read response are read-only on this endpoint.
When dport or sport is set, proto must be tcp or udp; ICMP and all-protocol rules cannot include ports.
Omit source or send null for any source across IPv4 and IPv6; 0.0.0.0/0 is an explicit IPv4-only source filter and ::/0 is an explicit IPv6-only source filter.
IPv4 CIDR inputs are canonicalized to the network address before being sent upstream, for example 198.51.100.42/24 is stored as 198.51.100.0/24.
write:vm
Authenticate with an API key in the Authorization: Bearer <token> header.
id string required
Example: vps_01hxa3b4c5d6e7f8g9h0j1k2m3 Public VPS ID from GET /api/v2/vps data[].id. Do not invent this value; use the exact ID returned by the referenced API response.
pos integer required
Example: 0 Firewall rule position from GET /api/v2/vps/{id}/firewall rules[].pos.
Authorization Bearer <token> Accept application/json Content-Type application/json type string · enum required
· Example: in Inbound rule. Per-VPS v2 firewall writes do not replace outbound rules or firewall-group references.
in action string · enum required
· Example: ACCEPT ACCEPT DROP REJECT enabled boolean
· Example: true Omit to keep the platform default for newly staged rules; send true to enable immediately.
proto string · nullable
· Example: tcp Protocol for the rule. Required as tcp or udp when dport or sport is set.
dport string · nullable
· Example: 22 Destination port or port range. Requires proto to be tcp or udp.
sport string · nullable
· Example: null Source port or port range. Requires proto to be tcp or udp.
source string · nullable
· Example: 198.51.100.0/24 Source IP or CIDR. Omit or send null for any source across IPv4 and IPv6. IPv4 CIDR values are canonicalized to their network address.
dest string · nullable
· Example: null description string · nullable
· Example: Allow SSH from office Single-line human-readable label for the rule.
pos integer · nullable required
· Example: 0 type string · nullable · enum required
· Example: in Replaced per-VPS rules are inbound. The list endpoint can still show read-only out or group rules that already exist upstream.
in action string · nullable · enum required
· Example: ACCEPT ACCEPT DROP REJECT enabled boolean required
· Example: true proto string · nullable required
· Example: tcp dport string · nullable required
· Example: 22 sport string · nullable required
· Example: null source string · nullable required
· Example: 198.51.100.10 dest string · nullable required
· Example: null description string · nullable required
· Example: Allow SSH from office isSystem boolean required
· Example: false editable boolean required
· Example: true type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object Retry-After seconds plus X-RateLimit-* headers. 10 fields type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object type string
· Example: https://developer.hostup.se/errors/invalid_request title string
· Example: Validation failed status integer
· Example: 400 detail string
· Example: The request body failed validation. code string
· Example: invalid_request Stable machine-readable code. Branch on this field, not on detail.
instance string
· Example: /api/v2/orders requestId string
· Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3 timestamp string
· Example: 2026-04-27T12:34:56.000Z errors array<object> Field-level validation errors when code is invalid_request.
errors[].pointer string required
· Example: /items/0/eppCode errors[].detail string required
· Example: `eppCode` is required for this transfer. errors[].code string required
· Example: missing_required extensions object https://cloud.hostup.se/api/v2/vps/{id}/firewall/{pos} curl -X PUT "https://cloud.hostup.se/api/v2/vps/vps_01hxa3b4c5d6e7f8g9h0j1k2m3/firewall/0" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{
"type": "in",
"action": "ACCEPT",
"enabled": true,
"proto": "tcp",
"dport": "443",
"source": null,
"description": "Allow HTTPS"
}' {
"pos": 0,
"type": "in",
"action": "ACCEPT",
"enabled": true,
"proto": "tcp",
"dport": "443",
"sport": null,
"source": null,
"dest": null,
"description": "Allow HTTPS",
"isSystem": false,
"editable": true
} {
"type": "in",
"action": "ACCEPT",
"enabled": true,
"proto": "tcp",
"dport": "443",
"source": null,
"description": "Allow HTTPS"
}