Try for free Log in

CloudFilt on API

Ask CloudFilt for a verdict from your own code: send the request of a visitor, get back the decision your site would have made, and why, in the words of your dashboard.

Not part of the free plan: PRO or BUSINESS, from $29 per month, cancel anytime.

REST API PRO

In the box

1×
HTTPS client, in any language
1×
API key, scoped to what you call
1×
call per request you want judged

Fitting instructions

4 steps, from sign-up to the first verdict.

  1. Create your account and pick a paid plan

    The API is not part of the free plan: it starts with PRO.

  2. Create an API key

    In your dashboard, Account › API keys: pick its scopes, an optional IP allowlist and an expiry date. The key is shown once, then stored hashed.

  3. Test with dry_run

    Call /v1/waf/evaluate with "dry_run": true for a real verdict with no quota consumed, no log and no ban. Then drop it and call on every request.

  4. Watch the verdicts

    Every call that is not a dry run shows up in your logs and live counters, like the rest of your traffic.

    Allowed Challenge Blocked

How it works

The CloudFilt API gives your own code the decision that protects your site. POST /v1/waf/evaluate runs the exact rule chain of your site, in the same order: your lists, your countries, your URL rules and rate limits, bans, bot, Tor, proxy, scraping and spam detection. What the API answers is what your site would have answered, nothing is re-implemented for it.

Send the IP of the visitor, and every signal you have: URL, User-Agent, referer, session, form content to screen for spam. The more you send, the closer the verdict is to what your site sees. The answer says allowed, the action (allow, block or rate_limited) and the reason, with the same wording and the same evidence as your ban history.

IP reputation

GET /v1/reputation returns the report of the public lookup page for any address: a score out of 100, one line per family of sources, and whether each source is fresh enough to prove anything. A missing feed reads unavailable, never clean.

Built to fail safe

When filtering does not apply (site disabled, quota exhausted, engine out of reach), the answer says skip: your visitor goes through, and you know nothing was checked. Each call uses one request of the site you name, like the rest of its traffic.

Keys are created from your dashboard, limited to the scopes you pick, to an IP allowlist and to an expiry date. Every refusal returns the same answer, so a stolen or guessed key learns nothing.

The full contract is available as an OpenAPI 3.1 document.

What you get

  • The verdict your site would get: same rules, same order
  • The reason and its evidence, as in your dashboard
  • Dry run to test with no side effect
  • Scoped keys, IP allowlist and expiry
  • IP reputation score, with the freshness of each source

One call, the verdict of your site

Forward what you know about the visitor. CloudFilt answers whether to let them through, and why.

Request
POST /v1/waf/evaluate
X-CloudFilt-Key: cf_…

{
  "site_id": 42,
  "ip": "203.0.113.10",
  "url": "https://example.com/cart?step=2",
  "user_agent": "Mozilla/5.0 …",
  "session_id": "a1b2c3d4e5f6"
}
Verdict
{
  "allowed": false,
  "action": "rate_limited",
  "reason": "flood_url",
  "reason_label": "Traffic rate limit (URL)",
  "details": { "rate": 940, "limit": 300 },
  "quota": { "consumed": true, "remaining": 418221 }
}

Other integration options

All integrations