Skip to navigation

Retrieve a website's Patch & Protect settings

View as MarkdownOpen in Claude

Returns how Patch & Protect protects one website: whether the protection is on, how it is doing against the security provider, when its attack figures were last read and the settings it runs with. Use it to check that a website is protected and how. The id in the path is the id of the website’s protection record, not the website id: read it from the site_preset_patchstack include of “Retrieve a website” or “List websites” (?include=site_preset_patchstack).

connection_status is one of connected, sync_error, disconnected, site_not_found, api_unreachable, site_not_linked, or unknown before the first health check.

The settings (firewall, hardening, .htaccess, login, CAPTCHA and activity log) are read-only here: editing them stays in the dashboard, where an edit on one website forks the shared configuration. Three kinds of value never leave the server: the CAPTCHA secret keys, which are credentials of the customer’s provider account; the custom login slug, because a hidden login URL that is handed out is not hidden; and the firewall’s own defences (detection thresholds, trusted IP header, whitelist rules, IP block list) and custom .htaccess rules, which are replaced by the booleans has_whitelist_rules, has_ip_block_list and has_custom_rules. custom_login_enabled is returned, so a reader knows the login was moved without learning where.

A website with no protection has no record at all: read has_patchstack and filter[patchstack] on “List websites” instead. Switching the protection on is “Switch Patch & Protect for websites”.

Authentication

AuthorizationBearer

Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints.

Path parameters

site_preset_patchstackstringRequired

Response

200 - A protected website

dataobjectOptional
jsonapiobjectOptional