Update Location¶
PATCH/
DNS Protection API · Locations
Updates given Location.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
id | path | string (uuid) | Yes | A unique identifier of the Location. |
Request body¶
Content type: application/json
Request body fields
namestringLocation name.
Must match the pattern
Must match the pattern
^[a-zA-Z0-9\-_ ]+$. Must be 1–100 characters long.isDefaultbooleanIndicates if this is the default location.
descriptionstringThe description of this location.
Must be at most 250 characters long.
Must be at most 250 characters long.
ipAddressesOption 1 or Option 2The IPv4 and/or IPv6 list of addresses for this location. The combined number of items in
As Option 1: must contain at most 100 items. As Option 1: items must be unique.
ipAddresses and domainNames must not exceed 100.As Option 1: must contain at most 100 items. As Option 1: items must be unique.
Option 1
Option 2
Extension of JSON patch for sets of strings. -
add: items to be added. Ignore duplicate items in the target set. - remove: items to be removed. Ignore missing items in the target set.Show child attributesHide child attributes
addarray of stringMust contain at most 100 items. Items must be unique.
removearray of stringMust contain at most 100 items. Items must be unique.
domainNamesOption 1 or Option 2The list of domain names for this location. The combined number of items in
As Option 1: must contain at most 100 items. As Option 1: items must be unique.
ipAddresses and domainNames must not exceed 100. Send an empty array to remove all domain names.As Option 1: must contain at most 100 items. As Option 1: items must be unique.
Option 1
Option 2
Extension of JSON patch for sets of strings. -
add: items to be added. Ignore duplicate items in the target set. - remove: items to be removed. Ignore missing items in the target set.Show child attributesHide child attributes
addarray of stringMust contain at most 100 items. Items must be unique.
removearray of stringMust contain at most 100 items. Items must be unique.
dohEnabledbooleanIndicates if the DNS Over HTTPS is enabled for this location.
typestringIndicates the type of this location.
Must be one of:
Must be one of:
standard, sfos, protectedBrowser.labelstringAn optional label for this location.
Must be at most 256 characters long.
Must be at most 256 characters long.
deletedAtstring (date-time)The date/time when this location was soft deleted.
Request samples¶
curl -X PATCH "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"name\": \"HQ - Dublin\",
\"label\": \"Main HQ\",
\"ipAddresses\": {
\"add\": [
\"2001:0db8:85a3:0000:0000:8a2e:0370:7334\"
]
},
\"domainNames\": {
\"add\": [
\"hq.company.com\",
\"office.example.org\"
],
\"remove\": [
\"home.lab.org\"
]
},
\"dohEnabled\": false,
\"deletedAt\": null
}"
import requests
response = requests.patch(
"https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={ 'name': 'HQ - Dublin',
'label': 'Main HQ',
'ipAddresses': {'add': ['2001:0db8:85a3:0000:0000:8a2e:0370:7334']},
'domainNames': { 'add': ['hq.company.com', 'office.example.org'],
'remove': ['home.lab.org']},
'dohEnabled': False,
'deletedAt': None},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"name": "HQ - Dublin",
"label": "Main HQ",
"ipAddresses": {
"add": [
"2001:0db8:85a3:0000:0000:8a2e:0370:7334"
]
},
"domainNames": {
"add": [
"hq.company.com",
"office.example.org"
],
"remove": [
"home.lab.org"
]
},
"dohEnabled": false,
"deletedAt": null
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>", strings.NewReader(`{
"name": "HQ - Dublin",
"label": "Main HQ",
"ipAddresses": {
"add": [
"2001:0db8:85a3:0000:0000:8a2e:0370:7334"
]
},
"domainNames": {
"add": [
"hq.company.com",
"office.example.org"
],
"remove": [
"home.lab.org"
]
},
"dohEnabled": false,
"deletedAt": null
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>", {
method: "PATCH",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"name": "HQ - Dublin",
"label": "Main HQ",
"ipAddresses": {
"add": [
"2001:0db8:85a3:0000:0000:8a2e:0370:7334"
]
},
"domainNames": {
"add": [
"hq.company.com",
"office.example.org"
],
"remove": [
"home.lab.org"
]
},
"dohEnabled": false,
"deletedAt": null
}),
});
const data = await response.json();
console.log(data);
Responses¶
200 — OK.¶
Response fields
namestringLocation name.
Must match the pattern
Must match the pattern
^[a-zA-Z0-9\-_ ]+$. Must be 1–100 characters long.idstring (uuid)The unique ID of this location.
isDefaultbooleanIndicates if this is the default location.
descriptionstringThe description of this location.
Must be at most 250 characters long.
Must be at most 250 characters long.
createdAtstring (date-time)The date/time when this location was created.
updatedAtstring (date-time)The date/time when this location was updated.
ipAddressesarray of stringThe IPv4 and/or IPv6 list of addresses for this location. The combined number of items in
Must contain at most 100 items. Items must be unique.
ipAddresses and domainNames must not exceed 100.Must contain at most 100 items. Items must be unique.
domainNamesarray of stringThe list of domain names for this location. The combined number of items in
Must contain at most 100 items. Items must be unique.
ipAddresses and domainNames must not exceed 100.Must contain at most 100 items. Items must be unique.
dohSecureLocationIdstringThe DNS Over HTTPS secure location ID, which is is a globally unique random ID generated for this location.
dohEnabledbooleanIndicates if the DNS Over HTTPS is enabled for this location.
policyIdstring (uuid)The policy ID associated with this location.
dohUrlstringtypestringRepresents the type of a location.
Must be one of:
Must be one of:
standard, sfos, protectedBrowser.labelstringAn optional label for this location.
Must be at most 256 characters long.
Must be at most 256 characters long.
deletedAtstring (date-time)The date/time when this location was soft deleted.
policyWebcatVersionintegerWebcat version of the policy associated with this location.
Errors¶
| Status | Meaning |
|---|---|
400 | Bad request. |
401 | Unauthorized. |
403 | Forbidden. |
404 | Not found. |
409 | Conflict. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"name": "Headquarters",
"id": "d4e1aee7-6c4e-4c9e-a8e2-1b1f4f7c4e3e",
"isDefault": false,
"description": "Main office location with secure DNS configuration.",
"type": "standard",
"label": "Main HQ",
"createdAt": "2025-01-01T12:00:00.686+00:00",
"updatedAt": "2025-08-01T08:30:00.200+00:00",
"deletedAt": "2025-10-01T08:30:00.200+00:00",
"ipAddresses": [
"192.168.1.1",
"192.168.1.2"
],
"domainNames": [
"hq.company.com",
"internal.company.com"
],
"dohSecureLocationId": "392oj0e54880r",
"dohEnabled": true,
"policyId": "e4f558e2-9f3a-44e0-a7a3-6b2f7b8b3d5d",
"dohUrl": "https://392oj0e54880r.secure.dev.dnsprotection.sophos.com/dns-query",
"policyWebcatVersion": 1
}
See the guide for a narrative walkthrough of this API.