---
title: WAF
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Firewall](https://developers.cloudflare.com/api/go/resources/firewall)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# WAF

#### WAFOverrides

##### [List WAF overrides](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/overrides/methods/list)

Deprecated

client.Firewall.WAF.Overrides.List(ctx, params) error

GET/zones/{zone\_id}/firewall/waf/overrides

##### [Get a WAF override](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/overrides/methods/get)

Deprecated

client.Firewall.WAF.Overrides.Get(ctx, overridesID, query) error

GET/zones/{zone\_id}/firewall/waf/overrides/{overrides\_id}

##### [Create a WAF override](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/overrides/methods/create)

Deprecated

client.Firewall.WAF.Overrides.New(ctx, params) error

POST/zones/{zone\_id}/firewall/waf/overrides

##### [Update WAF override](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/overrides/methods/update)

Deprecated

client.Firewall.WAF.Overrides.Update(ctx, overridesID, params) error

PUT/zones/{zone\_id}/firewall/waf/overrides/{overrides\_id}

##### [Delete a WAF override](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/overrides/methods/delete)

Deprecated

client.Firewall.WAF.Overrides.Delete(ctx, overridesID, body) error

DELETE/zones/{zone\_id}/firewall/waf/overrides/{overrides\_id}

##### ModelsExpand Collapse

type OverrideURL string

[Link to this property](<#(resource)%20firewall.waf.overrides%20%3E%20(model)%20override_url%20%3E%20(schema)>)

<details>

<summary>

type RewriteAction struct{…}

Specifies that, when a WAF rule matches, its configured action will be replaced by the action configured in this object.

</summary>

<details>

<summary>

Block RewriteActionBlockOptional

The WAF rule action to apply.

</summary>

One of the following:

const RewriteActionBlockChallenge RewriteActionBlock = "challenge"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20block%20%3E%20(member)%200">Link to this property</a>

const RewriteActionBlockBlock RewriteActionBlock = "block"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20block%20%3E%20(member)%201">Link to this property</a>

const RewriteActionBlockSimulate RewriteActionBlock = "simulate"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20block%20%3E%20(member)%202">Link to this property</a>

const RewriteActionBlockDisable RewriteActionBlock = "disable"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20block%20%3E%20(member)%203">Link to this property</a>

const RewriteActionBlockDefault RewriteActionBlock = "default"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20block%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20block">Link to this property</a>

<details>

<summary>

Challenge RewriteActionChallengeOptional

The WAF rule action to apply.

</summary>

One of the following:

const RewriteActionChallengeChallenge RewriteActionChallenge = "challenge"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20challenge%20%3E%20(member)%200">Link to this property</a>

const RewriteActionChallengeBlock RewriteActionChallenge = "block"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20challenge%20%3E%20(member)%201">Link to this property</a>

const RewriteActionChallengeSimulate RewriteActionChallenge = "simulate"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20challenge%20%3E%20(member)%202">Link to this property</a>

const RewriteActionChallengeDisable RewriteActionChallenge = "disable"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20challenge%20%3E%20(member)%203">Link to this property</a>

const RewriteActionChallengeDefault RewriteActionChallenge = "default"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20challenge%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20challenge">Link to this property</a>

<details>

<summary>

Default RewriteActionDefaultOptional

The WAF rule action to apply.

</summary>

One of the following:

const RewriteActionDefaultChallenge RewriteActionDefault = "challenge"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20default%20%3E%20(member)%200">Link to this property</a>

const RewriteActionDefaultBlock RewriteActionDefault = "block"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20default%20%3E%20(member)%201">Link to this property</a>

const RewriteActionDefaultSimulate RewriteActionDefault = "simulate"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20default%20%3E%20(member)%202">Link to this property</a>

const RewriteActionDefaultDisable RewriteActionDefault = "disable"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20default%20%3E%20(member)%203">Link to this property</a>

const RewriteActionDefaultDefault RewriteActionDefault = "default"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20default%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20default">Link to this property</a>

<details>

<summary>

Disable RewriteActionDisableOptional

The WAF rule action to apply.

</summary>

One of the following:

const RewriteActionDisableChallenge RewriteActionDisable = "challenge"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20disable%20%3E%20(member)%200">Link to this property</a>

const RewriteActionDisableBlock RewriteActionDisable = "block"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20disable%20%3E%20(member)%201">Link to this property</a>

const RewriteActionDisableSimulate RewriteActionDisable = "simulate"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20disable%20%3E%20(member)%202">Link to this property</a>

const RewriteActionDisableDisable RewriteActionDisable = "disable"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20disable%20%3E%20(member)%203">Link to this property</a>

const RewriteActionDisableDefault RewriteActionDisable = "default"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20disable%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20disable">Link to this property</a>

<details>

<summary>

Simulate RewriteActionSimulateOptional

The WAF rule action to apply.

</summary>

One of the following:

const RewriteActionSimulateChallenge RewriteActionSimulate = "challenge"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20simulate%20%3E%20(member)%200">Link to this property</a>

const RewriteActionSimulateBlock RewriteActionSimulate = "block"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20simulate%20%3E%20(member)%201">Link to this property</a>

const RewriteActionSimulateSimulate RewriteActionSimulate = "simulate"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20simulate%20%3E%20(member)%202">Link to this property</a>

const RewriteActionSimulateDisable RewriteActionSimulate = "disable"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20simulate%20%3E%20(member)%203">Link to this property</a>

const RewriteActionSimulateDefault RewriteActionSimulate = "default"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20simulate%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)%20%3E%20(property)%20simulate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.waf.overrides%20%3E%20(model)%20rewrite_action%20%3E%20(schema)>)

<details>

<summary>

type WAFRule map\[string, WAFRuleItem]

An object that allows you to override the action of specific WAF rules. Each key of this object must be the ID of a WAF rule, and each value must be a valid WAF action. Unless you are disabling a rule, ensure that you also enable the rule group that this WAF rule belongs to. When creating a new URI-based WAF override, you must provide a <code>groups</code> object or a <code>rules</code> object.

</summary>

One of the following:

const WAFRuleItemChallenge WAFRuleItem = "challenge"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20waf_rule%20%3E%20(schema)%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const WAFRuleItemBlock WAFRuleItem = "block"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20waf_rule%20%3E%20(schema)%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const WAFRuleItemSimulate WAFRuleItem = "simulate"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20waf_rule%20%3E%20(schema)%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const WAFRuleItemDisable WAFRuleItem = "disable"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20waf_rule%20%3E%20(schema)%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const WAFRuleItemDefault WAFRuleItem = "default"

<a href="#(resource)%20firewall.waf.overrides%20%3E%20(model)%20waf_rule%20%3E%20(schema)%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.waf.overrides%20%3E%20(model)%20waf_rule%20%3E%20(schema)>)

#### WAFPackages

##### [List WAF packages](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/methods/list)

Deprecated

client.Firewall.WAF.Packages.List(ctx, params) (\*V4PagePaginationArray\[[WAFPackageListResponse](<https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.waf.packages%20%3E%20(model)%20WAFPackageListResponse%20%3E%20(schema)>)], error)

GET/zones/{zone\_id}/firewall/waf/packages

##### [Get a WAF package](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/methods/get)

Deprecated

client.Firewall.WAF.Packages.Get(ctx, packageID, query) (\*unknown, error)

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}

#### WAFPackagesGroups

##### [List WAF rule groups](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/subresources/groups/methods/list)

Deprecated

client.Firewall.WAF.Packages.Groups.List(ctx, packageID, params) (\*V4PagePaginationArray\[[Group](<https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)>)], error)

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/groups

##### [Get a WAF rule group](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/subresources/groups/methods/get)

Deprecated

client.Firewall.WAF.Packages.Groups.Get(ctx, packageID, groupID, query) (\*unknown, error)

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/groups/{group\_id}

##### [Update a WAF rule group](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/subresources/groups/methods/edit)

Deprecated

client.Firewall.WAF.Packages.Groups.Edit(ctx, packageID, groupID, params) (\*unknown, error)

PATCH/zones/{zone\_id}/firewall/waf/packages/{package\_id}/groups/{group\_id}

##### ModelsExpand Collapse

<details>

<summary>

type Group struct{…}

</summary>

ID string

Defines the unique identifier of the rule group.

maxLength32

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Description string

Defines an informative summary of what the rule group does.

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

Mode GroupMode

Defines the state of the rules contained in the rule group. When <code>on</code>, the rules in the group are configurable/usable.

</summary>

One of the following:

const GroupModeOn GroupMode = "on"

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

const GroupModeOff GroupMode = "off"

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20mode">Link to this property</a>

Name string

Defines the name of the rule group.

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

RulesCount float64

Defines the number of rules in the current rule group.

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20rules_count">Link to this property</a>

<details>

<summary>

AllowedModes \[]GroupAllowedModeOptional

Defines the available states for the rule group.

</summary>

One of the following:

const GroupAllowedModeOn GroupAllowedMode = "on"

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const GroupAllowedModeOff GroupAllowedMode = "off"

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20allowed_modes">Link to this property</a>

ModifiedRulesCount float64Optional

Defines the number of rules within the group that have been modified from their default configuration.

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20modified_rules_count">Link to this property</a>

PackageID stringOptional

Defines the unique identifier of a WAF package.

maxLength32

<a href="#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)%20%3E%20(property)%20package_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.waf.packages.groups%20%3E%20(model)%20group%20%3E%20(schema)>)

#### WAFPackagesRules

##### [List WAF rules](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/subresources/rules/methods/list)

Deprecated

client.Firewall.WAF.Packages.Rules.List(ctx, packageID, params) (\*V4PagePaginationArray\[[WAFPackageRuleListResponse](<https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20WAFPackageRuleListResponse%20%3E%20(schema)>)], error)

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/rules

##### [Get a WAF rule](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/subresources/rules/methods/get)

Deprecated

client.Firewall.WAF.Packages.Rules.Get(ctx, packageID, ruleID, query) (\*unknown, error)

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/rules/{rule\_id}

##### [Update a WAF rule](https://developers.cloudflare.com/api/go/resources/firewall/subresources/waf/subresources/packages/subresources/rules/methods/edit)

Deprecated

client.Firewall.WAF.Packages.Rules.Edit(ctx, packageID, ruleID, params) (\*[WAFPackageRuleEditResponse](<https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20WAFPackageRuleEditResponse%20%3E%20(schema)>), error)

PATCH/zones/{zone\_id}/firewall/waf/packages/{package\_id}/rules/{rule\_id}

##### ModelsExpand Collapse

<details>

<summary>

type AllowedModesAnomaly string

Defines the mode anomaly. When set to <code>on</code>, the current WAF rule will be used when evaluating the request. Applies to anomaly detection WAF rules.

</summary>

One of the following:

const AllowedModesAnomalyOn <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20allowed_modes_anomaly%20%3E%20(schema)">AllowedModesAnomaly</a> = "on"

<a href="#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20allowed_modes_anomaly%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const AllowedModesAnomalyOff <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20allowed_modes_anomaly%20%3E%20(schema)">AllowedModesAnomaly</a> = "off"

<a href="#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20allowed_modes_anomaly%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20allowed_modes_anomaly%20%3E%20(schema)>)

<details>

<summary>

type WAFRuleGroup struct{…}

Defines the rule group to which the current WAF rule belongs.

</summary>

ID stringOptional

Defines the unique identifier of the rule group.

maxLength32

<a href="#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20waf_rule_group%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Name stringOptional

Defines the name of the rule group.

<a href="#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20waf_rule_group%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.waf.packages.rules%20%3E%20(model)%20waf_rule_group%20%3E%20(schema)>)