Skip to content
Coritan Docs

Organization API: Organization deployments: Protection

The 4 Organization API operations for protection.

View as Markdown

Part of Organization deployments.

Method Path Summary
GET /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection Get protection
PUT /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection Change protection
POST /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass A new bypass token, shown this once; the one before stops working
DELETE /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass Remove the bypass token; 404 when there is none

GET /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection

How the deployment is protected: mode (none, password, login), scope (previews: only its preview addresses; all), whether a password and a bypass token are set (never either one), the header a bypass token goes in, where members sign in, and each address with whether protection covers it.

Name In Type Required
deployment_uuid path string (uuid) yes
org_slug path string yes
Status Meaning
200 Success.
422 The request is not valid. detail lists each problem.

PUT /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection

Set the mode and scope, and in password mode the password (8 characters or more, 72 bytes at most). Password mode without password keeps the saved one; any other mode drops it. In either mode the owner, their team and, for an organization's deployment, its members can sign in with their account instead. A new mode or password signs out every visitor the edge let in. 402 without deploy_protection on the owner's plan, except to switch it off.

Name In Type Required
deployment_uuid path string (uuid) yes
org_slug path string yes

application/json (required)

Field Type Required Description
mode string yes none, password or login
scope string or null no previews or all; left out: kept
password string or null no Password mode only; left out: the saved one is kept
Status Meaning
200 Success.
422 The request is not valid. detail lists each problem.

A new bypass token, shown this once; the one before stops working

Section titled A new bypass token, shown this once; the one before stops working

POST /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass

A new bypass token, shown this once; the one before stops working. Automation sends it in the x-coritan-protection-bypass header to get past protection without signing in. 402 without deploy_protection on the owner's plan.

Name In Type Required
deployment_uuid path string (uuid) yes
org_slug path string yes
Status Meaning
201 Success.
422 The request is not valid. detail lists each problem.

Remove the bypass token; 404 when there is none

Section titled Remove the bypass token; 404 when there is none

DELETE /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass

Remove the bypass token; 404 when there is none.

Name In Type Required
deployment_uuid path string (uuid) yes
org_slug path string yes
Status Meaning
200 Success.
422 The request is not valid. detail lists each problem.