How it works
The CloudFilt API gives your own code the decision that protects your site. POST /v1/waf/evaluate runs the exact rule chain of your site, in the same order: your lists, your countries, your URL rules and rate limits, bans, bot, Tor, proxy, scraping and spam detection. What the API answers is what your site would have answered, nothing is re-implemented for it.
Send the IP of the visitor, and every signal you have: URL, User-Agent, referer, session, form content to screen for spam. The more you send, the closer the verdict is to what your site sees. The answer says allowed, the action (allow, block or rate_limited) and the reason, with the same wording and the same evidence as your ban history.
IP reputation
GET /v1/reputation returns the report of the public lookup page for any address: a score out of 100, one line per family of sources, and whether each source is fresh enough to prove anything. A missing feed reads unavailable, never clean.
Built to fail safe
When filtering does not apply (site disabled, quota exhausted, engine out of reach), the answer says skip: your visitor goes through, and you know nothing was checked. Each call uses one request of the site you name, like the rest of its traffic.
Keys are created from your dashboard, limited to the scopes you pick, to an IP allowlist and to an expiry date. Every refusal returns the same answer, so a stolen or guessed key learns nothing.
The full contract is available as an OpenAPI 3.1 document.