Skip to content

Get Sites

GET/site-lists/{siteListId}/sites

Web Filtering API · Web Filter Site List Management

Fetch sites that belong to the site list.

Required permissionweb-profiles:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
siteListId path string (uuid) Yes Site list ID.
page query integer No The page number to fetch, starting with 1.
pageSize query integer No The size of the page requested.
pageTotal query boolean No Whether the number of pages should be calculated and returned in the response.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/web-filters/v1/site-lists/<siteListId>/sites", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — Success.

Response fields

itemsarray of objectrequired
The list of sites.
Site in the web filter site list.
Show child attributesHide child attributes
idstring (uuid)
Site ID.
sitestringrequired
Site value.
Must be 1–2048 characters long.
siteTypestring
Web filter site type: - domain - Scheme-less hostname only: no URI scheme, no port, no path (e.g. example.com). - url - URI with a scheme (e.g. http://www.example.com/news, wss://api.example.com/stream). - urlPattern - Scheme-less URL-like pattern (e.g. example.com:8443, www.example.com/news, api.example.com:8080/v1). - tld - Top-level domain for broad matching (e.g. .com, .co.uk). - ipv4 / ipv6 - Single IP address. - ipv4Cidr / ipv6Cidr - Network in CIDR notation.
Must be one of: domain, url, urlPattern, tld, ipv4, ipv6, ipv4Cidr, ipv6Cidr.
createdAtstring (date-time)
Time the site was added to the site list.
pagesobjectrequired
Show child attributesHide child attributes
currentintegerrequired
The 1-based page number being returned.
sizeintegerrequired
The size of the page being returned.
totalinteger
(Optional) The total number of pages that exist, if pageTotal=true in the request.
itemsinteger
(Optional) The total number of items across all pages.
maxSizeintegerrequired
The maximum page size that can be requested.

Errors

Status Meaning
400 Invalid request.
404 Resource not found.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "site": "string",
      "siteType": "domain",
      "createdAt": "2026-07-28T00:00:00Z"
    }
  ],
  "pages": {
    "current": 0,
    "size": 0,
    "total": 0,
    "items": 0,
    "maxSize": 0
  }
}