> ## Documentation Index
> Fetch the complete documentation index at: https://docs.storiza.store/llms.txt
> Use this file to discover all available pages before exploring further.

# Add a new firewall rule to a VPS instance

> Validates and appends a firewall rule to the VPS. Inbound rules may not carry a destination and outbound rules may not carry a source; ports must be a number, a range, or `all`, and source/destination must be an IPv4 address, a CIDR, or `all`. Returns the rule as it was stored.

**Required API key permission:** `vps:write`



## OpenAPI

````yaml /openapi.json post /vps/{vmId}/firewall/rules
openapi: 3.0.0
info:
  title: Storiza API
  version: '1.0'
  description: Manage Storiza servers, apps and subscriptions programmatically.
servers:
  - url: https://api.storiza.store
security:
  - bearerAuth: []
tags:
  - name: Servers
    description: Create, order, renew and upgrade VPS servers, and read their details.
  - name: Server power & commands
    description: >-
      Start, stop, reboot and force-stop a server, check its status and run
      commands on it.
  - name: Server settings
    description: >-
      Rename a server, reinstall its operating system and follow its
      installation.
  - name: Server firewall
    description: Turn a server's firewall on or off and manage its rules.
  - name: Server metrics
    description: CPU, memory, disk and network usage, now and over time.
  - name: Server backups
    description: Order the backup add-on, and take, list and delete backups.
  - name: Server snapshots
    description: Take, list and delete snapshots of a server.
  - name: Server sharing
    description: A share link that lets someone else open the server.
  - name: Server catalog
    description: >-
      Plans, operating systems, categories, datacenters and backup plans. Public
      — no key needed.
  - name: Apps
    description: >-
      Deploy, order, renew and configure apps — game servers, databases and
      bots.
  - name: App lifecycle & console
    description: >-
      Start, stop, restart and kill an app, read its output and metrics, and
      send it commands.
  - name: App files
    description: >-
      Read, write, move and delete the files in an app's volume, and its SFTP
      access.
  - name: App backups
    description: Back up an app, download a backup, and restore from one.
  - name: App domains
    description: Your own domains for an app, and their DNS verification.
  - name: App groups
    description: Private networks that let your apps reach each other by hostname.
  - name: App catalog
    description: Templates, plans and locations for apps.
  - name: Subscriptions
    description: What you pay for, how often it renews, and stopping or resuming it.
  - name: Payments
    description: >-
      Follow a payment after an order, and the methods and currencies you can
      pay with.
  - name: Account
    description: Your profile, and a summary of everything you own.
  - name: SSH keys
    description: Public keys you can install on new Linux servers.
paths:
  /vps/{vmId}/firewall/rules:
    post:
      tags:
        - Server firewall
      summary: Add a new firewall rule to a VPS instance
      description: >-
        Validates and appends a firewall rule to the VPS. Inbound rules may not
        carry a destination and outbound rules may not carry a source; ports
        must be a number, a range, or `all`, and source/destination must be an
        IPv4 address, a CIDR, or `all`. Returns the rule as it was stored.


        **Required API key permission:** `vps:write`
      parameters:
        - schema:
            type: string
            minLength: 1
          required: true
          name: vmId
          in: path
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                type:
                  type: string
                  enum:
                    - inbound
                    - outbound
                protocol:
                  type: string
                  enum:
                    - tcp
                    - udp
                    - icmp
                port:
                  type: string
                source:
                  type: string
                destination:
                  type: string
                action:
                  type: string
                  enum:
                    - allow
                    - deny
                  default: allow
                comment:
                  type: string
                enabled:
                  type: boolean
                  default: true
              required:
                - type
                - protocol
      responses:
        '201':
          description: Firewall rule added successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
                  message:
                    type: string
                    enum:
                      - Firewall rule added successfully
                  data:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - inbound
                          - outbound
                      protocol:
                        type: string
                        enum:
                          - tcp
                          - udp
                          - icmp
                      port:
                        type: string
                      source:
                        type: string
                      destination:
                        type: string
                      action:
                        type: string
                        enum:
                          - allow
                          - deny
                        default: allow
                      comment:
                        type: string
                      enabled:
                        type: boolean
                        default: true
                    required:
                      - type
                      - protocol
                required:
                  - success
                  - message
                  - data
        '400':
          description: >-
            Cannot update VPS at this time. VPS must be in active state. |
            Invalid firewall rule: Inbound rules cannot have destination |
            Invalid firewall rule: Outbound rules cannot have source | Invalid
            port specification | Invalid source specification | Invalid
            destination specification | Failed to add firewall rule
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                vpsNotActive:
                  summary: Cannot update VPS at this time. VPS must be in active state.
                  value:
                    success: false
                    type: API
                    code: VPS_NOT_ACTIVE
                    error: >-
                      Cannot update VPS at this time. VPS must be in active
                      state.
                inboundRuleWithDestination:
                  summary: 'Invalid firewall rule: Inbound rules cannot have destination'
                  value:
                    success: false
                    type: API
                    code: FIREWALL_RULE_VALIDATION_ERROR
                    error: >-
                      Invalid firewall rule: Inbound rules cannot have
                      destination
                outboundRuleWithSource:
                  summary: 'Invalid firewall rule: Outbound rules cannot have source'
                  value:
                    success: false
                    type: API
                    code: FIREWALL_RULE_VALIDATION_ERROR
                    error: 'Invalid firewall rule: Outbound rules cannot have source'
                invalidPort:
                  summary: Invalid port specification
                  value:
                    success: false
                    type: API
                    code: INVALID_FIREWALL_PORT
                    error: Invalid port specification
                invalidSource:
                  summary: Invalid source specification
                  value:
                    success: false
                    type: API
                    code: INVALID_FIREWALL_SOURCE
                    error: Invalid source specification
                invalidDestination:
                  summary: Invalid destination specification
                  value:
                    success: false
                    type: API
                    code: INVALID_FIREWALL_DESTINATION
                    error: Invalid destination specification
                addFirewallRuleFailed:
                  summary: Failed to add firewall rule
                  value:
                    success: false
                    type: API
                    code: FIREWALL_CONFIGURATION_ERROR
                    error: Failed to add firewall rule
        '401':
          description: >-
            Authentication required | Authentication required: use session or
            shareToken
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                authenticationRequired:
                  summary: Authentication required
                  value:
                    success: false
                    type: API
                    code: AUTHENTICATION_ERROR
                    error: Authentication required
                vpsAuthenticationRequired:
                  summary: 'Authentication required: use session or shareToken'
                  value:
                    success: false
                    type: API
                    code: AUTHENTICATION_ERROR
                    error: 'Authentication required: use session or shareToken'
        '403':
          description: >-
            This resource is not running | This resource has no subscription |
            Renew this resource's subscription to use it again | Account is
            banned | Account is suspended | Insufficient permissions
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                resourceNotActive:
                  summary: This resource is not running
                  value:
                    success: false
                    type: API
                    code: RESOURCE_NOT_ACTIVE
                    error: This resource is not running
                subscriptionRequired:
                  summary: This resource has no subscription
                  value:
                    success: false
                    type: API
                    code: SUBSCRIPTION_REQUIRED
                    error: This resource has no subscription
                subscriptionExpired:
                  summary: Renew this resource's subscription to use it again
                  value:
                    success: false
                    type: API
                    code: SUBSCRIPTION_EXPIRED
                    error: Renew this resource's subscription to use it again
                accountBanned:
                  summary: Account is banned
                  value:
                    success: false
                    type: API
                    code: ACCOUNT_BANNED
                    error: Account is banned
                accountSuspended:
                  summary: Account is suspended
                  value:
                    success: false
                    type: API
                    code: ACCOUNT_SUSPENDED
                    error: Account is suspended
                insufficientPermissions:
                  summary: Insufficient permissions
                  value:
                    success: false
                    type: API
                    code: AUTHORIZATION_ERROR
                    error: Insufficient permissions
        '404':
          description: VPS not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                vpsNotFound:
                  summary: VPS not found
                  value:
                    success: false
                    type: API
                    code: NOT_FOUND
                    error: VPS not found
        '422':
          description: Validation error
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                    enum:
                      - API
                  code:
                    type: string
                    enum:
                      - VALIDATION_ERROR
                  error:
                    type: string
                    enum:
                      - Validation error
                  details:
                    type: object
                    additionalProperties:
                      type: object
                      properties:
                        _errors:
                          type: array
                          items:
                            type: string
                required:
                  - success
                  - type
                  - code
                  - error
                  - details
              example:
                success: false
                type: API
                code: VALIDATION_ERROR
                error: Validation error
                details:
                  _errors:
                    - The whole schema has some validation problems
                  some_field:
                    _errors:
                      - This field has some validation problem
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                    enum:
                      - API
                  code:
                    type: string
                    enum:
                      - INTERNAL_ERROR
                  error:
                    type: string
                    enum:
                      - Internal server error
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              example:
                success: false
                type: API
                code: INTERNAL_ERROR
                error: Internal server error
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        An API key from the Storiza dashboard (API & Integrations), sent as
        `Authorization: Bearer stz_…`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.