Skip to content

Update Location

PATCH/locations/{id}

DNS Protection API · Locations

Updates given Location.

Required permissionswgaas.config:write

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
id path string (uuid) Yes A unique identifier of the Location.

Request body

Content type: application/json

Request body fields

namestring
Location name.
Must match the pattern ^[a-zA-Z0-9\-_ ]+$. Must be 1–100 characters long.
isDefaultboolean
Indicates if this is the default location.
descriptionstring
The description of this location.
Must be at most 250 characters long.
ipAddressesOption 1 or Option 2
The IPv4 and/or IPv6 list of addresses for this location. The combined number of items in ipAddresses and domainNames must not exceed 100.
As Option 1: must contain at most 100 items. As Option 1: items must be unique.

Option 1

Option 2

Extension of JSON patch for sets of strings. - add: items to be added. Ignore duplicate items in the target set. - remove: items to be removed. Ignore missing items in the target set.
Show child attributesHide child attributes
addarray of string
Must contain at most 100 items. Items must be unique.
removearray of string
Must contain at most 100 items. Items must be unique.
domainNamesOption 1 or Option 2
The list of domain names for this location. The combined number of items in ipAddresses and domainNames must not exceed 100. Send an empty array to remove all domain names.
As Option 1: must contain at most 100 items. As Option 1: items must be unique.

Option 1

Option 2

Extension of JSON patch for sets of strings. - add: items to be added. Ignore duplicate items in the target set. - remove: items to be removed. Ignore missing items in the target set.
Show child attributesHide child attributes
addarray of string
Must contain at most 100 items. Items must be unique.
removearray of string
Must contain at most 100 items. Items must be unique.
dohEnabledboolean
Indicates if the DNS Over HTTPS is enabled for this location.
typestring
Indicates the type of this location.
Must be one of: standard, sfos, protectedBrowser.
labelstring
An optional label for this location.
Must be at most 256 characters long.
deletedAtstring (date-time)
The date/time when this location was soft deleted.

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"name\": \"HQ - Dublin\",
  \"label\": \"Main HQ\",
  \"ipAddresses\": {
    \"add\": [
      \"2001:0db8:85a3:0000:0000:8a2e:0370:7334\"
    ]
  },
  \"domainNames\": {
    \"add\": [
      \"hq.company.com\",
      \"office.example.org\"
    ],
    \"remove\": [
      \"home.lab.org\"
    ]
  },
  \"dohEnabled\": false,
  \"deletedAt\": null
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'name': 'HQ - Dublin',
    'label': 'Main HQ',
    'ipAddresses': {'add': ['2001:0db8:85a3:0000:0000:8a2e:0370:7334']},
    'domainNames': {   'add': ['hq.company.com', 'office.example.org'],
                       'remove': ['home.lab.org']},
    'dohEnabled': False,
    'deletedAt': None},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "name": "HQ - Dublin",
  "label": "Main HQ",
  "ipAddresses": {
    "add": [
      "2001:0db8:85a3:0000:0000:8a2e:0370:7334"
    ]
  },
  "domainNames": {
    "add": [
      "hq.company.com",
      "office.example.org"
    ],
    "remove": [
      "home.lab.org"
    ]
  },
  "dohEnabled": false,
  "deletedAt": null
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>", strings.NewReader(`{
  "name": "HQ - Dublin",
  "label": "Main HQ",
  "ipAddresses": {
    "add": [
      "2001:0db8:85a3:0000:0000:8a2e:0370:7334"
    ]
  },
  "domainNames": {
    "add": [
      "hq.company.com",
      "office.example.org"
    ],
    "remove": [
      "home.lab.org"
    ]
  },
  "dohEnabled": false,
  "deletedAt": null
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/dns-protection/v2/locations/<id>", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "name": "HQ - Dublin",
  "label": "Main HQ",
  "ipAddresses": {
    "add": [
      "2001:0db8:85a3:0000:0000:8a2e:0370:7334"
    ]
  },
  "domainNames": {
    "add": [
      "hq.company.com",
      "office.example.org"
    ],
    "remove": [
      "home.lab.org"
    ]
  },
  "dohEnabled": false,
  "deletedAt": null
}),
});
const data = await response.json();
console.log(data);

Responses

200 — OK.

Response fields

namestring
Location name.
Must match the pattern ^[a-zA-Z0-9\-_ ]+$. Must be 1–100 characters long.
idstring (uuid)
The unique ID of this location.
isDefaultboolean
Indicates if this is the default location.
descriptionstring
The description of this location.
Must be at most 250 characters long.
createdAtstring (date-time)
The date/time when this location was created.
updatedAtstring (date-time)
The date/time when this location was updated.
ipAddressesarray of string
The IPv4 and/or IPv6 list of addresses for this location. The combined number of items in ipAddresses and domainNames must not exceed 100.
Must contain at most 100 items. Items must be unique.
domainNamesarray of string
The list of domain names for this location. The combined number of items in ipAddresses and domainNames must not exceed 100.
Must contain at most 100 items. Items must be unique.
dohSecureLocationIdstring
The DNS Over HTTPS secure location ID, which is is a globally unique random ID generated for this location.
dohEnabledboolean
Indicates if the DNS Over HTTPS is enabled for this location.
policyIdstring (uuid)
The policy ID associated with this location.
dohUrlstring
typestring
Represents the type of a location.
Must be one of: standard, sfos, protectedBrowser.
labelstring
An optional label for this location.
Must be at most 256 characters long.
deletedAtstring (date-time)
The date/time when this location was soft deleted.
policyWebcatVersioninteger
Webcat version of the policy associated with this location.

Errors

Status Meaning
400 Bad request.
401 Unauthorized.
403 Forbidden.
404 Not found.
409 Conflict.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "name": "Headquarters",
  "id": "d4e1aee7-6c4e-4c9e-a8e2-1b1f4f7c4e3e",
  "isDefault": false,
  "description": "Main office location with secure DNS configuration.",
  "type": "standard",
  "label": "Main HQ",
  "createdAt": "2025-01-01T12:00:00.686+00:00",
  "updatedAt": "2025-08-01T08:30:00.200+00:00",
  "deletedAt": "2025-10-01T08:30:00.200+00:00",
  "ipAddresses": [
    "192.168.1.1",
    "192.168.1.2"
  ],
  "domainNames": [
    "hq.company.com",
    "internal.company.com"
  ],
  "dohSecureLocationId": "392oj0e54880r",
  "dohEnabled": true,
  "policyId": "e4f558e2-9f3a-44e0-a7a3-6b2f7b8b3d5d",
  "dohUrl": "https://392oj0e54880r.secure.dev.dnsprotection.sophos.com/dns-query",
  "policyWebcatVersion": 1
}

See the guide for a narrative walkthrough of this API.