> ## Documentation Index
> Fetch the complete documentation index at: https://docs.storiza.store/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the firewall configuration for a VPS instance

> Reads the VPS firewall state live from the hypervisor: whether the firewall is enabled, the default inbound/outbound policies, and the list of rules.

**Required API key permission:** `vps:read`



## OpenAPI

````yaml /openapi.json get /vps/{vmId}/firewall
openapi: 3.0.0
info:
  title: Storiza API
  version: '1.0'
  description: Manage Storiza servers, apps and subscriptions programmatically.
servers:
  - url: https://api.storiza.store
security:
  - bearerAuth: []
tags:
  - name: Servers
    description: Create, order, renew and upgrade VPS servers, and read their details.
  - name: Server power & commands
    description: >-
      Start, stop, reboot and force-stop a server, check its status and run
      commands on it.
  - name: Server settings
    description: >-
      Rename a server, reinstall its operating system and follow its
      installation.
  - name: Server firewall
    description: Turn a server's firewall on or off and manage its rules.
  - name: Server metrics
    description: CPU, memory, disk and network usage, now and over time.
  - name: Server backups
    description: Order the backup add-on, and take, list and delete backups.
  - name: Server snapshots
    description: Take, list and delete snapshots of a server.
  - name: Server sharing
    description: A share link that lets someone else open the server.
  - name: Server catalog
    description: >-
      Plans, operating systems, categories, datacenters and backup plans. Public
      — no key needed.
  - name: Apps
    description: >-
      Deploy, order, renew and configure apps — game servers, databases and
      bots.
  - name: App lifecycle & console
    description: >-
      Start, stop, restart and kill an app, read its output and metrics, and
      send it commands.
  - name: App files
    description: >-
      Read, write, move and delete the files in an app's volume, and its SFTP
      access.
  - name: App backups
    description: Back up an app, download a backup, and restore from one.
  - name: App domains
    description: Your own domains for an app, and their DNS verification.
  - name: App groups
    description: Private networks that let your apps reach each other by hostname.
  - name: App catalog
    description: Templates, plans and locations for apps.
  - name: Subscriptions
    description: What you pay for, how often it renews, and stopping or resuming it.
  - name: Payments
    description: >-
      Follow a payment after an order, and the methods and currencies you can
      pay with.
  - name: Account
    description: Your profile, and a summary of everything you own.
  - name: SSH keys
    description: Public keys you can install on new Linux servers.
paths:
  /vps/{vmId}/firewall:
    get:
      tags:
        - Server firewall
      summary: Get the firewall configuration for a VPS instance
      description: >-
        Reads the VPS firewall state live from the hypervisor: whether the
        firewall is enabled, the default inbound/outbound policies, and the list
        of rules.


        **Required API key permission:** `vps:read`
      parameters:
        - schema:
            type: string
            minLength: 1
          required: true
          name: vmId
          in: path
      responses:
        '200':
          description: Firewall configuration retrieved successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - true
                  message:
                    type: string
                    enum:
                      - Firewall configuration retrieved successfully
                  data:
                    type: object
                    properties:
                      enabled:
                        type: boolean
                      inboundPolicy:
                        type: string
                        enum:
                          - allow
                          - deny
                      outboundPolicy:
                        type: string
                        enum:
                          - allow
                          - deny
                      rules:
                        type: array
                        items:
                          type: object
                          properties:
                            id:
                              type: integer
                            type:
                              type: string
                              enum:
                                - inbound
                                - outbound
                            protocol:
                              type: string
                              enum:
                                - tcp
                                - udp
                                - icmp
                            port:
                              type: string
                            source:
                              type: string
                            destination:
                              type: string
                            action:
                              type: string
                              enum:
                                - allow
                                - deny
                            comment:
                              type: string
                            enabled:
                              type: boolean
                          required:
                            - id
                            - type
                            - protocol
                            - action
                            - enabled
                    required:
                      - enabled
                      - inboundPolicy
                      - outboundPolicy
                      - rules
                required:
                  - success
                  - message
                  - data
        '400':
          description: >-
            Cannot update VPS at this time. VPS must be in active state. |
            Failed to get firewall configuration
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                vpsNotActive:
                  summary: Cannot update VPS at this time. VPS must be in active state.
                  value:
                    success: false
                    type: API
                    code: VPS_NOT_ACTIVE
                    error: >-
                      Cannot update VPS at this time. VPS must be in active
                      state.
                getFirewallConfigFailed:
                  summary: Failed to get firewall configuration
                  value:
                    success: false
                    type: API
                    code: FIREWALL_CONFIGURATION_ERROR
                    error: Failed to get firewall configuration
        '401':
          description: >-
            Authentication required | Authentication required: use session or
            shareToken
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                authenticationRequired:
                  summary: Authentication required
                  value:
                    success: false
                    type: API
                    code: AUTHENTICATION_ERROR
                    error: Authentication required
                vpsAuthenticationRequired:
                  summary: 'Authentication required: use session or shareToken'
                  value:
                    success: false
                    type: API
                    code: AUTHENTICATION_ERROR
                    error: 'Authentication required: use session or shareToken'
        '403':
          description: Account is banned | Account is suspended | Insufficient permissions
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                accountBanned:
                  summary: Account is banned
                  value:
                    success: false
                    type: API
                    code: ACCOUNT_BANNED
                    error: Account is banned
                accountSuspended:
                  summary: Account is suspended
                  value:
                    success: false
                    type: API
                    code: ACCOUNT_SUSPENDED
                    error: Account is suspended
                insufficientPermissions:
                  summary: Insufficient permissions
                  value:
                    success: false
                    type: API
                    code: AUTHORIZATION_ERROR
                    error: Insufficient permissions
        '404':
          description: VPS not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                  code:
                    type: string
                  error:
                    type: string
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              examples:
                vpsNotFound:
                  summary: VPS not found
                  value:
                    success: false
                    type: API
                    code: NOT_FOUND
                    error: VPS not found
        '422':
          description: Validation error
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                    enum:
                      - API
                  code:
                    type: string
                    enum:
                      - VALIDATION_ERROR
                  error:
                    type: string
                    enum:
                      - Validation error
                  details:
                    type: object
                    additionalProperties:
                      type: object
                      properties:
                        _errors:
                          type: array
                          items:
                            type: string
                required:
                  - success
                  - type
                  - code
                  - error
                  - details
              example:
                success: false
                type: API
                code: VALIDATION_ERROR
                error: Validation error
                details:
                  _errors:
                    - The whole schema has some validation problems
                  some_field:
                    _errors:
                      - This field has some validation problem
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    enum:
                      - false
                  type:
                    type: string
                    enum:
                      - API
                  code:
                    type: string
                    enum:
                      - INTERNAL_ERROR
                  error:
                    type: string
                    enum:
                      - Internal server error
                  details:
                    nullable: true
                required:
                  - success
                  - type
                  - code
                  - error
              example:
                success: false
                type: API
                code: INTERNAL_ERROR
                error: Internal server error
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        An API key from the Storiza dashboard (API & Integrations), sent as
        `Authorization: Bearer stz_…`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.