DEVELOPER · DEVELOPER
Pull zones, DNS records, storage zones, and edge rules on their own key.
Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.
Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.
Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
bunnycdn_delete_compute_script_by_idWRITEDelete Edge Script via DELETE /compute/script/{id}
bunnycdn_delete_compute_script_by_id_secrets_by_secretidWRITEDelete Secret via DELETE /compute/script/{id}/secrets/{secretId}
bunnycdn_delete_compute_script_by_id_variables_by_variableidWRITEDelete Variable via DELETE /compute/script/{id}/variables/{variableId}
bunnycdn_delete_dnszone_by_idWRITEDelete DNS Zone via DELETE /dnszone/{id}
bunnycdn_delete_dnszone_by_id_dnssecWRITEDisable DNSSEC on a DNS Zone via DELETE /dnszone/{id}/dnssec
bunnycdn_delete_dnszone_by_zoneid_records_by_idWRITEDelete DNS Record via DELETE /dnszone/{zoneId}/records/{id}
bunnycdn_delete_pullzone_by_idWRITEDelete Pull Zone via DELETE /pullzone/{id}
bunnycdn_delete_pullzone_by_id_removecertificateWRITERemove Certificate via DELETE /pullzone/{id}/removeCertificate
bunnycdn_delete_pullzone_by_id_removehostnameWRITERemove Custom Hostname via DELETE /pullzone/{id}/removeHostname
bunnycdn_delete_pullzone_by_pullzoneid_edgerules_by_edgeruleidWRITEDelete Edge Rule via DELETE /pullzone/{pullZoneId}/edgerules/{edgeRuleId}
bunnycdn_delete_shield_rate_limit_by_idWRITEDelete a Rate Limit on your Shield Zone via DELETE /shield/rate-limit/{id}
bunnycdn_delete_shield_shield_zone_by_shieldzoneid_access_lists_by_idWRITEDelete the specified Custom Access List associated with a Shield Zone via DELETE /shield/shield-zone/{shieldZoneId}/access-lists/{id}
bunnycdn_delete_shield_shield_zone_by_shieldzoneid_custom_page_by_pagetypeWRITEDelete a custom HTML response page for a Shield Zone via DELETE /shield/shield-zone/{shieldZoneId}/custom-page/{pageType}
bunnycdn_delete_shield_waf_custom_rule_by_idWRITEDelete a custom WAF rule via DELETE /shield/waf/custom-rule/{id}
bunnycdn_delete_storagezone_by_idWRITEDelete Storage Zone via DELETE /storagezone/{id}
bunnycdn_delete_videolibrary_by_idWRITEDelete Video Library via DELETE /videolibrary/{id}
bunnycdn_delete_videolibrary_by_id_live_thumbnailWRITEDelete Live Thumbnail via DELETE /videolibrary/{id}/live/thumbnail
bunnycdn_delete_videolibrary_by_id_live_watermarkWRITEDelete Live Watermark via DELETE /videolibrary/{id}/live/watermark
bunnycdn_delete_videolibrary_by_id_watermarkWRITEDelete Watermark via DELETE /videolibrary/{id}/watermark
bunnycdn_get_apikeyREADList API Keys via GET /apikey
bunnycdn_get_billingREADGet Billing Details -- Get the billing status details via GET /billing
bunnycdn_get_billing_affiliateREADGet affiliate details via GET /billing/affiliate
bunnycdn_get_billing_payment_request_invoice_by_id_pdfREADDownload Payment Request Invoice PDF via GET /billing/payment-request-invoice/{id}/pdf
bunnycdn_get_billing_payment_requestsREADGet Pending Payment Requests via GET /billing/payment-requests
bunnycdn_get_billing_summaryREADGet Billing Summary via GET /billing/summary
bunnycdn_get_billing_summary_by_billingrecordid_pdfREADGet Billing Summary Document via GET /billing/summary/{billingRecordId}/pdf
bunnycdn_get_by_date_by_pullzoneid_logREADQuery logs (legacy) via GET /{date}/{pullZoneId}.log Served from https://logging.bunnycdn.com, not https://api.bunny.net.
bunnycdn_get_compute_scriptREADList Edge Scripts via GET /compute/script
bunnycdn_get_compute_script_by_idREADGet Edge Script via GET /compute/script/{id}
bunnycdn_get_compute_script_by_id_codeREADGet Code via GET /compute/script/{id}/code
bunnycdn_get_compute_script_by_id_releasesREADGet Releases via GET /compute/script/{id}/releases
bunnycdn_get_compute_script_by_id_releases_activeREADGet Active Release via GET /compute/script/{id}/releases/active
bunnycdn_get_compute_script_by_id_secretsREADList Secrets via GET /compute/script/{id}/secrets
bunnycdn_get_compute_script_by_id_statisticsREADGet Edge Script Statistics via GET /compute/script/{id}/statistics
bunnycdn_get_compute_script_by_id_variables_by_variableidREADGet Variable via GET /compute/script/{id}/variables/{variableId}
bunnycdn_get_countryREADGet Country List via GET /country
bunnycdn_get_dnszoneREADList DNS Zones via GET /dnszone
bunnycdn_get_dnszone_by_idREADGet DNS Zone via GET /dnszone/{id}
bunnycdn_get_dnszone_by_id_statisticsREADGet DNS Query Statistics via GET /dnszone/{id}/statistics
bunnycdn_get_dnszone_by_zoneid_recordsREADList DNS Zone Records via GET /dnszone/{zoneId}/records
bunnycdn_get_dnszone_by_zoneid_records_scanREADGet the latest DNS record scan result for a DNS Zone via GET /dnszone/{zoneId}/records/scan
bunnycdn_get_pullzoneREADList Pull Zones via GET /pullzone
bunnycdn_get_pullzone_by_idREADGet Pull Zone via GET /pullzone/{id}
bunnycdn_get_pullzone_by_pullzoneid_optimizer_statisticsREADGet optimizer statistics via GET /pullzone/{pullZoneId}/optimizer/statistics
bunnycdn_get_pullzone_by_pullzoneid_originshield_queuestatisticsREADGet Origin Shield Queue Statistics via GET /pullzone/{pullZoneId}/originshield/queuestatistics
bunnycdn_get_pullzone_by_pullzoneid_safehop_statisticsREADGet SafeHop Statistics via GET /pullzone/{pullZoneId}/safehop/statistics
bunnycdn_get_pullzone_countREADCount Pull Zones via GET /pullzone/count
bunnycdn_get_pullzone_loadfreecertificateREADLoad Free Certificate via GET /pullzone/loadFreeCertificate
bunnycdn_get_regionREADRegion list via GET /region
bunnycdn_get_searchREADGlobal Search via GET /search
bunnycdn_get_shield_ddos_enumsREADList of all DDoS Enum Mappings via GET /shield/ddos/enums
bunnycdn_get_shield_event_logs_by_shieldzoneid_by_date_by_continuationtokenREADGet Event Logs for Shield Zone via GET /shield/event-logs/{shieldZoneId}/{date}/{continuationToken}
bunnycdn_get_shield_metrics_overages_by_shieldzoneidREADGet the overage breakdown for the specified Shield Zone for a given month, segmented by billing plan changes via GET /shield/metrics/overages/{shieldZoneId}
bunnycdn_get_shield_metrics_overview_by_shieldzoneidREADGet an overview of metrics for the specified Shield Zone via GET /shield/metrics/overview/{shieldZoneId}
bunnycdn_get_shield_metrics_overview_by_shieldzoneid_detailedREADGet a detailed metrics overview for the specified Shield Zone within the selected time range and resolution via GET /shield/metrics/overview/{shieldZoneId}/detailed
bunnycdn_get_shield_metrics_rate_limit_by_idREADGet detailed metrics for the specified Rate Limit via GET /shield/metrics/rate-limit/{id}
bunnycdn_get_shield_metrics_rate_limits_by_shieldzoneidREADGet aggregated rate limit metrics for the specified Shield Zone via GET /shield/metrics/rate-limits/{shieldZoneId}
bunnycdn_get_shield_metrics_shield_zone_by_shieldzoneid_api_guardianREADGet API Guardian metrics for the specified Shield Zone via GET /shield/metrics/shield-zone/{shieldZoneId}/api-guardian
bunnycdn_get_shield_metrics_shield_zone_by_shieldzoneid_api_guardian_endpoint_by_endpointidREADGet metrics for a specific API Guardian endpoint within the specified Shield Zone via GET /shield/metrics/shield-zone/{shieldZoneId}/api-guardian/endpoint/{endpointId}
bunnycdn_get_shield_metrics_shield_zone_by_shieldzoneid_bot_detectionREADGet bot detection metrics for the specified Shield Zone via GET /shield/metrics/shield-zone/{shieldZoneId}/bot-detection
bunnycdn_get_shield_metrics_shield_zone_by_shieldzoneid_upload_scanningREADGet upload scanning metrics for the specified Shield Zone via GET /shield/metrics/shield-zone/{shieldZoneId}/upload-scanning
bunnycdn_get_shield_metrics_shield_zone_by_shieldzoneid_waf_rule_by_ruleidREADGet metrics for a specific WAF Rule within the specified Shield Zone via GET /shield/metrics/shield-zone/{shieldZoneId}/waf-rule/{ruleId}
bunnycdn_get_shield_promo_stateREADGet the current Promotion State for your Account via GET /shield/promo/state
bunnycdn_get_shield_rate_limit_by_idREADGet Individual Rate Limit for your Shield Zone via GET /shield/rate-limit/{id}
bunnycdn_get_shield_rate_limits_by_shieldzoneidREADGet Rate Limits for your Shield Zone via GET /shield/rate-limits/{shieldZoneId}
bunnycdn_get_shield_shield_zone_by_shieldzoneidREADGet Singular Shield Zone Configuration via GET /shield/shield-zone/{shieldZoneId}
bunnycdn_get_shield_shield_zone_by_shieldzoneid_access_listsREADGet all Access Lists available for a Shield Zone via GET /shield/shield-zone/{shieldZoneId}/access-lists
bunnycdn_get_shield_shield_zone_by_shieldzoneid_access_lists_by_idREADGet the specified Custom Access List associated with a Shield Zone via GET /shield/shield-zone/{shieldZoneId}/access-lists/{id}
bunnycdn_get_shield_shield_zone_by_shieldzoneid_access_lists_enumsREADGet all Access Lists API enumeration types and their values via GET /shield/shield-zone/{shieldZoneId}/access-lists/enums
bunnycdn_get_shield_shield_zone_by_shieldzoneid_api_guardianREADGet the API Guardian configuration and endpoints. via GET /shield/shield-zone/{shieldZoneId}/api-guardian
bunnycdn_get_shield_shield_zone_by_shieldzoneid_api_guardian_enumsREADGet all API Guardian enumeration types and their values via GET /shield/shield-zone/{shieldZoneId}/api-guardian/enums
bunnycdn_get_shield_shield_zone_by_shieldzoneid_bot_categorizationREADList bots available for explicit allow/block configuration on this Shield Zone, grouped by category. via GET /shield/shield-zone/{shieldZoneId}/bot-categorization
bunnycdn_get_shield_shield_zone_by_shieldzoneid_bot_detectionREADYour current Bot Detection configuration via GET /shield/shield-zone/{shieldZoneId}/bot-detection
bunnycdn_get_shield_shield_zone_by_shieldzoneid_custom_page_by_pagetypeREADGet a custom HTML response page for a Shield Zone via GET /shield/shield-zone/{shieldZoneId}/custom-page/{pageType}
bunnycdn_get_shield_shield_zone_by_shieldzoneid_upload_scanningREADGet your Current Upload Scanning Configuration via GET /shield/shield-zone/{shieldZoneId}/upload-scanning
bunnycdn_get_shield_shield_zone_defaultsREADGet the recommended defaults for creating a Shield Zone via GET /shield/shield-zone/defaults
bunnycdn_get_shield_shield_zone_get_by_pullzone_by_pullzoneidREADGet Singular Shield Zone Configuration for PullZone via GET /shield/shield-zone/get-by-pullzone/{pullZoneId}
bunnycdn_get_shield_shield_zonesREADGet all of your Shield Zone Configurations via GET /shield/shield-zones
bunnycdn_get_shield_shield_zones_pullzone_mappingREADGet Active Shield Zones for Pullzone Mapping via GET /shield/shield-zones/pullzone-mapping
bunnycdn_get_shield_waf_custom_rule_by_idREADRetrieve a specific custom WAF rule via GET /shield/waf/custom-rule/{id}
bunnycdn_get_shield_waf_custom_rules_by_shieldzoneidREADRetrieve custom WAF rules configured for the specified Shield Zone via GET /shield/waf/custom-rules/{shieldZoneId}
bunnycdn_get_shield_waf_engine_configREADRetrieve the default WAF engine configuration via GET /shield/waf/engine-config
bunnycdn_get_shield_waf_enumsREADRetrieve all available WAF enum mappings via GET /shield/waf/enums
bunnycdn_get_shield_waf_profilesREADRetrieve all available WAF profiles via GET /shield/waf/profiles
bunnycdn_get_shield_waf_rules_by_shieldzoneidREADRetrieve all available WAF rules for a Shield Zone via GET /shield/waf/rules/{shieldZoneId}
bunnycdn_get_shield_waf_rules_plan_segmentationREADRetrieve WAF rules segmented by subscription plan via GET /shield/waf/rules/plan-segmentation
bunnycdn_get_shield_waf_rules_review_triggered_ai_recommendation_by_shieldzoneid_by_ruleidREADRetrieve an AI recommendation for a triggered WAF rule via GET /shield/waf/rules/review-triggered/ai-recommendation/{shieldZoneId}/{ruleId}
bunnycdn_get_shield_waf_rules_review_triggered_by_shieldzoneidREADReview all triggered WAF rules for the specified Shield Zone via GET /shield/waf/rules/review-triggered/{shieldZoneId}
bunnycdn_get_statisticsREADGet Statistics via GET /statistics
bunnycdn_get_storagezoneREADList Storage Zones via GET /storagezone
bunnycdn_get_storagezone_by_idREADGet Storage Zone via GET /storagezone/{id}
bunnycdn_get_storagezone_by_id_statisticsREADGet Storage Zone Statistics via GET /storagezone/{id}/statistics
bunnycdn_get_storagezone_by_id_statistics_egressREADGet Storage Zone Egress Statistics via GET /storagezone/{id}/statistics/egress
bunnycdn_get_storagezone_regionsREADGet Storage Zone Regions via GET /storagezone/regions
bunnycdn_get_user_audit_by_dateREADGet User Audit Log via GET /user/audit/{date}
bunnycdn_get_v1_pricing_by_source_by_resourceidREADGet active price for a resource and optionally cost estimate if usage amount provided via GET /v1/pricing/{source}/{resourceId}
bunnycdn_get_v2_pullzones_by_pullzoneid_logsREADQuery CDN access logs for a pull zone. -- Authenticate with either an `Authorization` bearer JWT or an `AccessKey` header. Filter pushdown happens in ClickHouse where possible; `country` and free-text `search` are applied in-process after fetch. via GET /v2/pullzones/{pullZoneId}/logs Served from https://logging.bunnycdn.com, not https://api.bunny.net.
bunnycdn_get_videolibraryREADList Video Libraries via GET /videolibrary
bunnycdn_get_videolibrary_by_idREADGet Video Library via GET /videolibrary/{id}
bunnycdn_get_videolibrary_by_id_drm_statisticsREADGet Video Library DRM Statistics via GET /videolibrary/{id}/drm/statistics
bunnycdn_get_videolibrary_by_id_transcribing_statisticsREADGet Video Library Transcribing Statistics via GET /videolibrary/{id}/transcribing/statistics
bunnycdn_get_videolibrary_languagesREADGet Languages via GET /videolibrary/languages
bunnycdn_patch_shield_rate_limit_by_idWRITEUpdate a Rate Limit configuration on your Shield Zone via PATCH /shield/rate-limit/{id}
bunnycdn_patch_shield_shield_zoneWRITEUpdate your Shield Zone configuration via PATCH /shield/shield-zone
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_access_lists_by_idWRITEUpdate the specified Custom Access List associated with a Shield Zone via PATCH /shield/shield-zone/{shieldZoneId}/access-lists/{id}
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_access_lists_configurations_by_idWRITEUpdate Access List Configuration for a Shield Zone via PATCH /shield/shield-zone/{shieldZoneId}/access-lists/configurations/{id}
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_api_guardianWRITEUpdate the API Guardian configuration (enabled, execution mode, body limit action) via PATCH /shield/shield-zone/{shieldZoneId}/api-guardian
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_api_guardian_endpoint_by_endpointidWRITEUpdate your API Guardian Endpoint configuration via PATCH /shield/shield-zone/{shieldZoneId}/api-guardian/endpoint/{endpointId}
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_api_guardian_specWRITEUpdate your OpenAPI specification via PATCH /shield/shield-zone/{shieldZoneId}/api-guardian/spec
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_bot_detectionWRITEUpdate your current Bot Detection configuration via PATCH /shield/shield-zone/{shieldZoneId}/bot-detection
bunnycdn_patch_shield_shield_zone_by_shieldzoneid_upload_scanningWRITEUpdate your Upload Scanning Configuration via PATCH /shield/shield-zone/{shieldZoneId}/upload-scanning
bunnycdn_patch_shield_waf_custom_rule_by_idWRITEUpdate an existing custom WAF rule via PATCH /shield/waf/custom-rule/{id}
bunnycdn_post_compute_scriptWRITEAdd Edge Script via POST /compute/script
bunnycdn_post_compute_script_by_idWRITEUpdate Edge Script via POST /compute/script/{id}
bunnycdn_post_compute_script_by_id_codeWRITESet Code via POST /compute/script/{id}/code
bunnycdn_post_compute_script_by_id_deploymentkey_rotateWRITERotate Deployment Key via POST /compute/script/{id}/deploymentKey/rotate DESTRUCTIVE: this replaces the edge script's deployment key, so every pipeline holding the old key stops being able to deploy.
bunnycdn_post_compute_script_by_id_publishWRITEPublish Release via POST /compute/script/{id}/publish
bunnycdn_post_compute_script_by_id_publish_by_uuidWRITEPublish Release via POST /compute/script/{id}/publish/{uuid}
bunnycdn_post_compute_script_by_id_secretsWRITEAdd Secret via POST /compute/script/{id}/secrets
bunnycdn_post_compute_script_by_id_secrets_by_secretidWRITEUpdate Secret via POST /compute/script/{id}/secrets/{secretId}
bunnycdn_post_compute_script_by_id_variables_addWRITEAdd Variable via POST /compute/script/{id}/variables/add
bunnycdn_post_compute_script_by_id_variables_by_variableidWRITEUpdate Variable via POST /compute/script/{id}/variables/{variableId}
bunnycdn_post_dnszoneWRITEAdd DNS Zone via POST /dnszone
bunnycdn_post_dnszone_by_idWRITEUpdate DNS Zones via POST /dnszone/{id}
bunnycdn_post_dnszone_by_id_dnssecWRITEEnable DNSSEC on a DNS Zone via POST /dnszone/{id}/dnssec
bunnycdn_post_dnszone_by_zoneid_certificate_issueWRITEIssue new wildcard certificate via POST /dnszone/{zoneId}/certificate/issue
bunnycdn_post_dnszone_by_zoneid_importWRITEImport DNS Records via POST /dnszone/{zoneId}/import
bunnycdn_post_dnszone_by_zoneid_records_by_idWRITEUpdate DNS Record via POST /dnszone/{zoneId}/records/{id}
bunnycdn_post_dnszone_checkavailabilityWRITECheck the DNS zone availability via POST /dnszone/checkavailability
bunnycdn_post_dnszone_records_scanWRITETrigger a background scan for pre-existing DNS records. Can use ZoneId for existing zones or Domain for pre-zone creation scenarios. via POST /dnszone/records/scan
bunnycdn_post_pullzoneWRITEAdd Pull Zone via POST /pullzone
bunnycdn_post_pullzone_by_idWRITEUpdate Pull Zone via POST /pullzone/{id}
bunnycdn_post_pullzone_by_id_addallowedreferrerWRITEAdd Allowed Referer via POST /pullzone/{id}/addAllowedReferrer
bunnycdn_post_pullzone_by_id_addblockedipWRITEAdd Blocked IP via POST /pullzone/{id}/addBlockedIp
bunnycdn_post_pullzone_by_id_addblockedreferrerWRITEAdd Blocked Referer via POST /pullzone/{id}/addBlockedReferrer
bunnycdn_post_pullzone_by_id_addcertificateWRITEAdd Custom Certificate via POST /pullzone/{id}/addCertificate
bunnycdn_post_pullzone_by_id_addhostnameWRITEAdd Custom Hostname via POST /pullzone/{id}/addHostname
bunnycdn_post_pullzone_by_id_purgecacheWRITEPurge Cache via POST /pullzone/{id}/purgeCache DESTRUCTIVE: this discards the pull zone's cached content across the edge network; the origin absorbs every refill until the cache warms again.
bunnycdn_post_pullzone_by_id_removeallowedreferrerWRITERemove Allowed Referer via POST /pullzone/{id}/removeAllowedReferrer
bunnycdn_post_pullzone_by_id_removeblockedipWRITERemove Blocked IP via POST /pullzone/{id}/removeBlockedIp
bunnycdn_post_pullzone_by_id_removeblockedreferrerWRITERemove Blocked Referer via POST /pullzone/{id}/removeBlockedReferrer
bunnycdn_post_pullzone_by_id_resetsecuritykeyWRITEReset Token Key via POST /pullzone/{id}/resetSecurityKey DESTRUCTIVE: this replaces the pull zone's token-authentication signing key, so every URL already signed with the old key stops validating and every signer holding it must be updated.
bunnycdn_post_pullzone_by_id_setforcesslWRITESet Force SSL via POST /pullzone/{id}/setForceSSL
bunnycdn_post_pullzone_by_id_updateprivatekeytypeWRITEChange hostname private key type via POST /pullzone/{id}/updatePrivateKeyType
bunnycdn_post_pullzone_by_pullzoneid_edgerules_addorupdateWRITEAdd/Update Edge Rule via POST /pullzone/{pullZoneId}/edgerules/addOrUpdate
bunnycdn_post_pullzone_by_pullzoneid_edgerules_by_edgeruleid_setedgeruleenabledWRITESet Edge Rule Enabled via POST /pullzone/{pullZoneId}/edgerules/{edgeRuleId}/setEdgeRuleEnabled
bunnycdn_post_pullzone_checkavailabilityWRITECheck the pull zone availability via POST /pullzone/checkavailability
bunnycdn_post_pullzone_completeexternaldnscertificateWRITEComplete External DNS Certificate via POST /pullzone/completeExternalDnsCertificate
bunnycdn_post_pullzone_completeexternalhttpcertificateWRITEComplete External HTTP Certificate via POST /pullzone/completeExternalHttpCertificate
bunnycdn_post_pullzone_requestexternaldnscertificateWRITERequest External DNS Certificate via POST /pullzone/requestExternalDnsCertificate
bunnycdn_post_pullzone_requestexternalhttpcertificateWRITERequest External HTTP Certificate via POST /pullzone/requestExternalHttpCertificate
bunnycdn_post_purgeWRITEPurge URL via POST /purge DESTRUCTIVE: this discards the cached content for the given URL across the edge network.
bunnycdn_post_shield_event_logs_by_shieldzoneid_exportWRITEExport the full filtered Event Logs set for a Shield Zone as CSV via POST /shield/event-logs/{shieldZoneId}/export
bunnycdn_post_shield_event_logs_by_shieldzoneid_searchWRITESearch, filter and group Event Logs for a Shield Zone via POST /shield/event-logs/{shieldZoneId}/search
bunnycdn_post_shield_rate_limitWRITECreate a Rate Limit for your Shield Zone via POST /shield/rate-limit
bunnycdn_post_shield_shield_zoneWRITECreate a Shield Zone for your PullZone via POST /shield/shield-zone
bunnycdn_post_shield_shield_zone_by_shieldzoneid_access_listsWRITECreate a new Custom Access List associated with a Shield Zone via POST /shield/shield-zone/{shieldZoneId}/access-lists
bunnycdn_post_shield_shield_zone_by_shieldzoneid_api_guardian_specWRITEUpload your OpenAPI specification via POST /shield/shield-zone/{shieldZoneId}/api-guardian/spec
bunnycdn_post_shield_shield_zone_under_attackWRITECreate a Shield Zone in under-attack mode for your PullZone via POST /shield/shield-zone/under-attack
bunnycdn_post_shield_waf_custom_ruleWRITECreate a new custom WAF rule via POST /shield/waf/custom-rule
bunnycdn_post_shield_waf_rules_review_triggered_by_shieldzoneidWRITEReview and update the action of a triggered WAF rule via POST /shield/waf/rules/review-triggered/{shieldZoneId}
bunnycdn_post_storagezoneWRITEAdd Storage Zone via POST /storagezone
bunnycdn_post_storagezone_by_idWRITEUpdate Storage Zone via POST /storagezone/{id}
bunnycdn_post_storagezone_by_id_resetpasswordWRITEReset Password via POST /storagezone/{id}/resetPassword DESTRUCTIVE: this immediately invalidates the storage zone's current password, which is also its Edge Storage API key -- every FTP client, upload pipeline and application holding the old value stops authenticating, and the old value cannot be restored.
bunnycdn_post_storagezone_checkavailabilityWRITECheck the storage zone availability via POST /storagezone/checkavailability
bunnycdn_post_storagezone_resetreadonlypasswordWRITEReset Read-Only Password via POST /storagezone/resetReadOnlyPassword DESTRUCTIVE: this immediately invalidates the storage zone's current read-only password, which is also its read-only Edge Storage API key -- every client holding the old value stops authenticating, and the old value cannot be restored.
bunnycdn_post_user_closeaccountWRITEClose the account -- Close the current user account via POST /user/closeaccount DESTRUCTIVE: this closes the entire bunny.net account, not a single resource.
bunnycdn_post_videolibraryWRITEAdd Video Library via POST /videolibrary
bunnycdn_post_videolibrary_by_idWRITEUpdate Video Library via POST /videolibrary/{id}
bunnycdn_post_videolibrary_by_id_addallowedreferrerWRITEAdd Allowed Referer via POST /videolibrary/{id}/addAllowedReferrer
bunnycdn_post_videolibrary_by_id_addblockedreferrerWRITEAdd Blocked Referer via POST /videolibrary/{id}/addBlockedReferrer
bunnycdn_post_videolibrary_by_id_removeallowedreferrerWRITERemove Allowed Referer via POST /videolibrary/{id}/removeAllowedReferrer
bunnycdn_post_videolibrary_by_id_removeblockedreferrerWRITERemove Blocked Referer via POST /videolibrary/{id}/removeBlockedReferrer
bunnycdn_post_videolibrary_by_id_resetapikeyWRITEReset API Key via POST /videolibrary/{id}/resetApiKey DESTRUCTIVE: this immediately invalidates the video library's current API key -- every Stream client holding the old key stops authenticating, and the old key cannot be restored.
bunnycdn_post_videolibrary_by_id_resetreadonlyapikeyWRITEReset Read Only API Key via POST /videolibrary/{id}/resetReadOnlyApiKey DESTRUCTIVE: this immediately invalidates the video library's current read-only API key -- every client holding the old key stops authenticating, and the old key cannot be restored.
bunnycdn_put_compute_script_by_id_secretsWRITEUpsert Secret via PUT /compute/script/{id}/secrets
bunnycdn_put_compute_script_by_id_variablesWRITEUpsert Variable via PUT /compute/script/{id}/variables
bunnycdn_put_dnszone_by_zoneid_recordsWRITEAdd DNS Record via PUT /dnszone/{zoneId}/records
bunnycdn_put_shield_shield_zone_by_shieldzoneid_bot_categorization_bots_by_botidWRITESet or clear the action applied to a categorised bot for this Shield Zone. via PUT /shield/shield-zone/{shieldZoneId}/bot-categorization/bots/{botId}
bunnycdn_put_shield_shield_zone_by_shieldzoneid_bot_categorization_categories_by_categoryWRITESet or clear the action applied to every bot in a category for this Shield Zone. via PUT /shield/shield-zone/{shieldZoneId}/bot-categorization/categories/{category}
bunnycdn_put_shield_shield_zone_by_shieldzoneid_custom_page_by_pagetypeWRITEUpload a custom HTML response page for a Shield Zone via PUT /shield/shield-zone/{shieldZoneId}/custom-page/{pageType}
bunnycdn_put_shield_waf_custom_rule_by_idWRITEUpdate an existing custom WAF rule via PUT /shield/waf/custom-rule/{id}
bunnycdn_put_videolibrary_by_id_live_thumbnailWRITEAdd Live Thumbnail via PUT /videolibrary/{id}/live/thumbnail
bunnycdn_put_videolibrary_by_id_live_watermarkWRITEAdd Live Watermark via PUT /videolibrary/{id}/live/watermark
bunnycdn_put_videolibrary_by_id_watermarkWRITEAdd Watermark via PUT /videolibrary/{id}/watermark
Put bunny.net behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.