SAAS & API SERVICES

Clear access rules for every API

Classify access to the console, open API, and static resources, and configure different protection strategies for login, query, and callback while maintaining business compatibility.

THE CHALLENGE

Start with the workload

Browser users, system calls, and third-party callbacks are accessed differently. Using the same rule for all requests may affect normal API calls.

  • Enterprise application platform
  • Open API service
  • Multi-tenant business system
BUILT AROUND YOUR WORKLOAD

Protect each critical path

01

Configure policies by endpoint

Set WAF and access control conditions around request paths, sources, and behaviors to distinguish user operations from system calls.

02

Keep private responses private

Configure appropriate back-to-origin and caching rules for user information, authentication, and business APIs to avoid caching personalized responses.

03

Assess regional entry points

For multi-region deployment or self-owned infrastructure business, Anycast-Boundless’ ingress and back-to-source solutions can be further evaluated.

Suggested integration path Confirm the protocol and delivery scope
  1. 01Browser/API caller
  2. 02SCDN / WAF · Rules by endpoint
  3. 03Business API/Application origin server
FROM PLAN TO PRODUCTION

Integration, step by step

  1. 01

    Inventory your endpoints

    Mark access methods such as login, query, write, webhook and real-time connection.

  2. 02

    Integrate and test compatibility

    Configure SCDN, HTTPS and rules, check callbacks and actual protocols used.

  3. 03

    Observe logs and adjust

    Based on normal requests and interception records, the thresholds and necessary exceptions are gradually refined.

Verify before launch

  • Verify that tenant, account, and authentication information are not cached.
  • Check for webhook signatures, cross-origin requests, and normal system calls.
  • Use long connections, larger request bodies, and typical business operations to verify compatibility.
Monitor after launch

Taking key interface availability and false interception as the main observation items, let the protection strategy follow business iterations.

QUESTIONS & ANSWERS

Frequently asked questions

Which plan should I choose for WebSocket?

All three types of lines support WebSocket (WS) starting from the Basic, but not the Personal. If you need WAF at the same time, you should choose the Standard or higher. When accessing, you still need to confirm the origin server and connection timeout configuration.

Will WAF replace the business's own login authentication?

No. Applications still need to maintain account permissions and interface authentication; SCDN plans that support WAF add application layer protection for external access.

Have other questions?Contact a technical advisor

BUILD WITH CONFIDENCE

Make every connection safer.

From personal projects to corporate operations, find the protection solution that's right for you.

Contact us