Set App/API Exceptions

최신 업데이트:2026-03-19 15:12:33

Reading time: About 2 minutes
Prerequisites: A hostname has been onboarded, and a managed rule with the DDoS Managed Challenge action has been enabled

When You Need to Configure an App/API Exception

Managed rules with the DDoS Managed Challenge action issue a Cookie or JavaScript challenge to requests, which only works for Web/H5 website types. If your website serves the following types of business, you need to configure an exception based on your APP/API request characteristics:

  • Native APP
  • Hybrid APP
  • Callback API or other server-side API

Once an exception is configured, matching requests skip protection from managed rules that use the DDoS Managed Challenge action and proceed directly to the next stage of processing.

Business Category Reference

When configuring an exception, choose the appropriate match condition based on your business type:

Business Category Exception Needed? Recommended Match Condition
Native APP (native iOS/Android development, no WebView) Generally not needed, unless a browser User-Agent is used If a browser UA is used, configure the exception based on the User-Agent characteristic
Hybrid APP (native + H5 hybrid, some pages use WebView) Needed, but only for the native layer’s interfaces Configure based on a characteristic that distinguishes native requests (e.g., User-Agent contains the app name/version)
Callback API (third-party system callbacks, such as payment callbacks) Needed Configure based on the callback path characteristic (e.g., URI=/api/callback)
Other server-side API (backend-only calls that don’t support JS verification) Needed Configure based on the API path or a custom request header

Configuration Steps

  1. Go to Security part: Configurations > Shared Configurations.
  2. Under the App/API Exceptions tab, click Create.
  3. Choose the Type according to the actual business situation, input the App/API Name, and set the Match Conditions, Click Confirm after the configuration is complete.
  4. In the App/API Exceptions list, click the association icon for the exception, select the hostnames to apply the exception to in the hostname association dialog that appears, and click Confirm to complete the association.
이 문서의 내용이 도움이 되었습니까?
아니오
정상적으로 제출되었습니다.피드백을 주셔서 감사합니다.앞으로도 개선을 위해 노력하겠습니다.