Block an abusive source prefix (admin).
const url = 'https://api.opdns.io/v1/admin/source-blocks';const options = { method: 'POST', headers: { cookie: 'opdns_session=<opdns_session>', 'Content-Type': 'application/json' }, body: '{"cidr":"example","reason":"example","pops":["example"],"jurisdictions":["example"],"expires_at":"2026-04-15T12:00:00Z"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.opdns.io/v1/admin/source-blocks \ --header 'Content-Type: application/json' \ --cookie opdns_session=<opdns_session> \ --data '{ "cidr": "example", "reason": "example", "pops": [ "example" ], "jurisdictions": [ "example" ], "expires_at": "2026-04-15T12:00:00Z" }'Republishes operator/sources.json (announced on NATS
operator.changed) in the same transaction; edges in scope refuse plain DNS
(Do53) queries from the prefix (REFUSED, no recursion) and close DoT, DoH
and DoQ connections from it after the handshake, counting both. expires_at
defaults to 7 days ahead and may be at most 90 days ahead. Prefixes wider
than /8 (IPv4) or /19 (IPv6) are refused. Audited.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”Makes the POST safe to retry: a repeat with the same key and the same request
within 24 h returns the stored response (with Idempotent-Replayed: true)
without creating again. 1 to 255 visible ASCII characters (a UUID is fine).
Request Bodyrequired
Section titled “Request Bodyrequired”object
Prefix or single address, e.g. 192.0.2.0/24.
Ticket id and cause; published to edges, never to clients.
Examplegenerated
{ "cidr": "example", "reason": "example", "pops": [ "example" ], "jurisdictions": [ "example" ], "expires_at": "2026-04-15T12:00:00Z"}Responses
Section titled “Responses”Added and published.
object
object
Masked prefix, e.g. 192.0.2.0/24.
Examplegenerated
{ "block": { "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "cidr": "example", "reason": "example", "pops": [ "example" ], "jurisdictions": [ "example" ], "expires_at": "2026-04-15T12:00:00Z", "created_by": "example", "created_at": "2026-04-15T12:00:00Z", "removed_by": "example", "removed_at": "2026-04-15T12:00:00Z" }, "file_version": 1}Malformed request.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/bad_request", "title": "Bad Request", "status": 400, "code": "bad_request", "detail": "invalid JSON body", "request_id": "5f2c9a0e7b1d4c38"}Not authenticated.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/unauthenticated", "title": "Unauthorized", "status": 401, "code": "unauthenticated", "detail": "authentication required", "request_id": "5f2c9a0e7b1d4c38"}Authenticated but not allowed: insufficient_scope, session_required, csrf_rejected, mfa_enrolment_required (restricted session), mfa_required (an operator action, or an admin-scoped token, from a session signed in with the password alone; not in dev), reauth_required (sign in again within five minutes), account_pending_deletion (the account is in its deletion cooling-off).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/insufficient_scope", "title": "Forbidden", "status": 403, "code": "insufficient_scope", "detail": "the token lacks the profiles:write scope", "request_id": "5f2c9a0e7b1d4c38"}block_exists: a live entry has this prefix.
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/block_exists", "title": "Conflict", "status": 409, "code": "block_exists", "detail": "a live entry has this prefix", "request_id": "5f2c9a0e7b1d4c38"}Field validation failed (validation_failed, unknown_list).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/validation_failed", "title": "Unprocessable Content", "status": 422, "code": "validation_failed", "detail": "the request has invalid fields", "errors": [ { "field": "settings.block_mode", "message": "one of nxdomain, refused, null, block-page" } ], "request_id": "5f2c9a0e7b1d4c38"}not_implemented (cloud log queries not configured on this server) or shape_unsupported (node too old).
object
Stable machine code.
object
Seconds, repeating the Retry-After header (rate limits, offline nodes).
Example
{ "type": "https://opdns.io/problems/not_implemented", "title": "Not Implemented", "status": 501, "code": "not_implemented", "detail": "cloud log queries are not configured on this server", "request_id": "5f2c9a0e7b1d4c38"}