Skip to content

Create a site list

POST/site-lists

Web Filtering API · Web Filter Site List Management

Create a new web filter site list.

Required permissionweb-profiles:write

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

idstring (uuid)
Site list ID.
namestringrequired
Site list name.
Must be 1–50 characters long.
descriptionstring
Site list description.
Must be at most 250 characters long.
sitesarray of stringrequired
Sites that belong to the site list.
Must contain at least 1 item. Items must be unique. Each item must be 1–2048 characters long.
updatedAtstring (date-time)
Time the site list was last updated.
updatedByobject
Show child attributesHide child attributes
idstringrequired
Principal ID.
typestring (enum)required
Type of the Principal.
Must be one of: user, service, system.
namestring
Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
usedByarray of object
Web filtering profiles that reference this site list via their site list actions.
A reference to a web filtering profile.
Show child attributesHide child attributes
idstring (uuid)required
Web filtering profile ID.
namestringrequired
Web filtering profile name.
Must be at most 50 characters long.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"id\": \"00000000-0000-0000-0000-000000000000\",
  \"name\": \"string\",
  \"description\": \"string\",
  \"sites\": [
    \"string\"
  ],
  \"updatedAt\": \"2026-07-28T00:00:00Z\",
  \"updatedBy\": {
    \"id\": \"string\",
    \"type\": \"user\",
    \"name\": \"string\",
    \"accountType\": \"partner\",
    \"accountId\": \"00000000-0000-0000-0000-000000000000\"
  },
  \"usedBy\": [
    {
      \"id\": \"00000000-0000-0000-0000-000000000000\",
      \"name\": \"string\"
    }
  ]
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'id': '00000000-0000-0000-0000-000000000000',
    'name': 'string',
    'description': 'string',
    'sites': ['string'],
    'updatedAt': '2026-07-28T00:00:00Z',
    'updatedBy': {   'id': 'string',
                     'type': 'user',
                     'name': 'string',
                     'accountType': 'partner',
                     'accountId': '00000000-0000-0000-0000-000000000000'},
    'usedBy': [   {   'id': '00000000-0000-0000-0000-000000000000',
                      'name': 'string'}]},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "description": "string",
  "sites": [
    "string"
  ],
  "updatedAt": "2026-07-28T00:00:00Z",
  "updatedBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "usedBy": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string"
    }
  ]
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists", strings.NewReader(`{
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "description": "string",
  "sites": [
    "string"
  ],
  "updatedAt": "2026-07-28T00:00:00Z",
  "updatedBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "usedBy": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string"
    }
  ]
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "description": "string",
  "sites": [
    "string"
  ],
  "updatedAt": "2026-07-28T00:00:00Z",
  "updatedBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "usedBy": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string"
    }
  ]
}),
});
const data = await response.json();
console.log(data);

Responses

201 — Web filter site list created.

Response fields

idstring (uuid)
Site list ID.
namestringrequired
Site list name.
Must be 1–50 characters long.
descriptionstring
Site list description.
Must be at most 250 characters long.
sitesarray of stringrequired
Sites that belong to the site list.
Must contain at least 1 item. Items must be unique. Each item must be 1–2048 characters long.
updatedAtstring (date-time)
Time the site list was last updated.
updatedByobject
Show child attributesHide child attributes
idstringrequired
Principal ID.
typestring (enum)required
Type of the Principal.
Must be one of: user, service, system.
namestring
Principal name.
accountTypestring
Account type.
Must be one of: partner, tenant, organization.
accountIdstring (uuid)
Account ID.
usedByarray of object
Web filtering profiles that reference this site list via their site list actions.
A reference to a web filtering profile.
Show child attributesHide child attributes
idstring (uuid)required
Web filtering profile ID.
namestringrequired
Web filtering profile name.
Must be at most 50 characters long.

Errors

Status Meaning
400 Invalid request.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "description": "string",
  "sites": [
    "string"
  ],
  "updatedAt": "2026-07-28T00:00:00Z",
  "updatedBy": {
    "id": "string",
    "type": "user",
    "name": "string",
    "accountType": "partner",
    "accountId": "00000000-0000-0000-0000-000000000000"
  },
  "usedBy": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string"
    }
  ]
}