Skip to content

Add Site

POST/site-lists/{siteListId}/sites

Web Filtering API · Web Filter Site List Management

Add a new site to the web filter site list.

Required permissionweb-profiles:write

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
siteListId path string (uuid) Yes Site list ID.

Request body

Content type: application/json

Request body fields

idstring (uuid)
Site ID.
sitestringrequired
Site value.
Must be 1–2048 characters long.
siteTypestring
Web filter site type: - domain - Scheme-less hostname only: no URI scheme, no port, no path (e.g. example.com). - url - URI with a scheme (e.g. http://www.example.com/news, wss://api.example.com/stream). - urlPattern - Scheme-less URL-like pattern (e.g. example.com:8443, www.example.com/news, api.example.com:8080/v1). - tld - Top-level domain for broad matching (e.g. .com, .co.uk). - ipv4 / ipv6 - Single IP address. - ipv4Cidr / ipv6Cidr - Network in CIDR notation.
Must be one of: domain, url, urlPattern, tld, ipv4, ipv6, ipv4Cidr, ipv6Cidr.
createdAtstring (date-time)
Time the site was added to the site list.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"id\": \"00000000-0000-0000-0000-000000000000\",
  \"site\": \"string\",
  \"siteType\": \"domain\",
  \"createdAt\": \"2026-07-28T00:00:00Z\"
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'id': '00000000-0000-0000-0000-000000000000',
    'site': 'string',
    'siteType': 'domain',
    'createdAt': '2026-07-28T00:00:00Z'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "id": "00000000-0000-0000-0000-000000000000",
  "site": "string",
  "siteType": "domain",
  "createdAt": "2026-07-28T00:00:00Z"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites", strings.NewReader(`{
  "id": "00000000-0000-0000-0000-000000000000",
  "site": "string",
  "siteType": "domain",
  "createdAt": "2026-07-28T00:00:00Z"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "id": "00000000-0000-0000-0000-000000000000",
  "site": "string",
  "siteType": "domain",
  "createdAt": "2026-07-28T00:00:00Z"
}),
});
const data = await response.json();
console.log(data);

Responses

201 — New site added to list.

Response fields

idstring (uuid)
Site ID.
sitestringrequired
Site value.
Must be 1–2048 characters long.
siteTypestring
Web filter site type: - domain - Scheme-less hostname only: no URI scheme, no port, no path (e.g. example.com). - url - URI with a scheme (e.g. http://www.example.com/news, wss://api.example.com/stream). - urlPattern - Scheme-less URL-like pattern (e.g. example.com:8443, www.example.com/news, api.example.com:8080/v1). - tld - Top-level domain for broad matching (e.g. .com, .co.uk). - ipv4 / ipv6 - Single IP address. - ipv4Cidr / ipv6Cidr - Network in CIDR notation.
Must be one of: domain, url, urlPattern, tld, ipv4, ipv6, ipv4Cidr, ipv6Cidr.
createdAtstring (date-time)
Time the site was added to the site list.

Errors

Status Meaning
400 Invalid request.
404 Resource not found.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "id": "00000000-0000-0000-0000-000000000000",
  "site": "string",
  "siteType": "domain",
  "createdAt": "2026-07-28T00:00:00Z"
}