# Organization API: Organization deployments: Protection

> The 4 Organization API operations for protection.

Source: https://www.coritan.com/docs/api/reference/organizations/organization-deployments/deployments-protection/

Part of [Organization deployments](/docs/api/reference/organizations/organization-deployments/).

## Operations

| Method | Path | Summary |
| --- | --- | --- |
| GET | [`/api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection`](#op-get-api-v1-orgs-org-slug-deployments-deployment-uuid-protection) | Get protection |
| PUT | [`/api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection`](#op-put-api-v1-orgs-org-slug-deployments-deployment-uuid-protection) | Change protection |
| POST | [`/api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass`](#op-post-api-v1-orgs-org-slug-deployments-deployment-uuid-protection-bypass) | A new bypass token, shown this once; the one before stops working |
| DELETE | [`/api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass`](#op-delete-api-v1-orgs-org-slug-deployments-deployment-uuid-protection-bypass) | Remove the bypass token; 404 when there is none |

### Get protection {#op-get-api-v1-orgs-org-slug-deployments-deployment-uuid-protection}

`GET /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection`

How the deployment is protected: ``mode`` (``none``, ``password``,
``login``), ``scope`` (``previews``: only its preview addresses;
``all``), whether a password and a bypass token are set (never either
one), the header a bypass token goes in, where members sign in, and
each address with whether protection covers it.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `deployment_uuid` | path | string (uuid) | yes |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Change protection {#op-put-api-v1-orgs-org-slug-deployments-deployment-uuid-protection}

`PUT /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection`

Set the mode and scope, and in password mode the password (8
characters or more, 72 bytes at most). Password mode without
``password`` keeps the saved one; any other mode drops it. In either
mode the owner, their team and, for an organization's deployment, its
members can sign in with their account instead. A new mode or password
signs out every visitor the edge let in. 402 without
``deploy_protection`` on the owner's plan, except to switch it off.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `deployment_uuid` | path | string (uuid) | yes |
| `org_slug` | path | string | yes |

#### Request body

`application/json` (required)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `mode` | string | yes | none, password or login |
| `scope` | string or null | no | previews or all; left out: kept |
| `password` | string or null | no | Password mode only; left out: the saved one is kept |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### A new bypass token, shown this once; the one before stops working {#op-post-api-v1-orgs-org-slug-deployments-deployment-uuid-protection-bypass}

`POST /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass`

A new bypass token, shown this once; the one before stops working.
Automation sends it in the ``x-coritan-protection-bypass`` header to
get past protection without signing in. 402 without
``deploy_protection`` on the owner's plan.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `deployment_uuid` | path | string (uuid) | yes |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `201` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

### Remove the bypass token; 404 when there is none {#op-delete-api-v1-orgs-org-slug-deployments-deployment-uuid-protection-bypass}

`DELETE /api/v1/orgs/{org_slug}/deployments/{deployment_uuid}/protection/bypass`

Remove the bypass token; 404 when there is none.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `deployment_uuid` | path | string (uuid) | yes |
| `org_slug` | path | string | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |
