DNSFilter Tools
Written By Christopher Scaminaci
Last updated 7 days ago
DNSFilter Tools
dnsfilter_ · 238 tools · Free 151 · Pro 87
Protective DNS for MSPs. The credential is an API token sent as the entire Authorization value with no Bearer prefix - adding a scheme fails every call. The host is fixed and global. Paths carry their own version: v1 and v2 coexist on one host, sometimes for the same resource. Paging is page[number] with page[size] on 43 operations - a plain page parameter is ignored silently - with a page cap of 1000 applied here because the vendor declares no maximum. Filter parameters come in three shapes: comma-separated strings, repeated array parameters, and bracket filters carrying a value and an operator. A 403 is not declared anywhere in this API, so permission failures arrive as 401 and a 401 is not proof of a bad token.
All connector tools · DNSFilter setup guide
DNSFilter tool groups
- Traffic Reports & Query Logs — 53 tools
- API Keys — 5 tools
- Block Pages — 6 tools
- Organizations & Users — 24 tools
- Networks & Sites — 39 tools
- Roaming Clients (Agents) — 25 tools
- Policies & Filtering Lists — 26 tools
- Agent Local Users — 11 tools
- Categories & Applications — 12 tools
- Domain Lookups & Notes — 8 tools
- MAC Addresses — 6 tools
- Scheduled Policies — 6 tools
- Scheduled Reports — 7 tools
- Usage Metrics & Exports — 4 tools
- Dashboards — 3 tools
- Account — 3 tools
Traffic Reports & Query Logs
dnsfilter_traffic_qps details
dnsfilter_traffic_qps details
[DNSFilter] Query rate (queries per second) over a time window — the load view, as opposed to the raw counts total_requests returns. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.
dnsfilter_traffic_qps_active_agents details
dnsfilter_traffic_qps_active_agents details
[DNSFilter] Roaming client agents actively sending DNS queries in the window, with their query rate. Use it to confirm which machines are reporting in. Returns raw DNSFilter JSON.
dnsfilter_traffic_qps_active_collections details
dnsfilter_traffic_qps_active_collections details
[DNSFilter] Collections actively sending DNS queries in the window, with their query rate. Returns raw DNSFilter JSON.
dnsfilter_traffic_qps_active_organizations details
dnsfilter_traffic_qps_active_organizations details
[DNSFilter] Organizations actively sending DNS queries in the window, with their query rate. Use it to see which clients are actually live. Returns raw DNSFilter JSON.
dnsfilter_traffic_qps_active_users details
dnsfilter_traffic_qps_active_users details
[DNSFilter] Users actively sending DNS queries in the window, with their query rate. Returns raw DNSFilter JSON.
dnsfilter_traffic_query_logs details
dnsfilter_traffic_query_logs details
[DNSFilter] Search the raw DNS query log — every individual lookup, with the domain asked for and whether it was allowed or blocked. This is the investigation tool: use it to answer what a specific machine resolved before it got infected, or what a user was reaching at a particular time. Narrow it with a time window plus any combination of domain, category, network, agent or user filters, then page through the results. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_agents details
dnsfilter_traffic_top_agents details
[DNSFilter] The busiest roaming client agents in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_application_categories details
dnsfilter_traffic_top_application_categories details
[DNSFilter] The most-used application categories in the window, ranked. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_categories details
dnsfilter_traffic_top_categories details
[DNSFilter] The most-requested content categories in the window, ranked. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_collections details
dnsfilter_traffic_top_collections details
[DNSFilter] The busiest collections in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_domains details
dnsfilter_traffic_top_domains details
[DNSFilter] The most-requested domains in the window, ranked. The report to reach for when asked what a network or machine has been visiting. Narrow with domain, fqdn or categoryIds. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_networks details
dnsfilter_traffic_top_networks details
[DNSFilter] The busiest networks in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_organizations details
dnsfilter_traffic_top_organizations details
[DNSFilter] The busiest organizations in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_organizations_requests details
dnsfilter_traffic_top_organizations_requests details
[DNSFilter] Organizations ranked by request count within a single parent organization's scope. Takes a singular organizationId rather than the plural filter the other reports use. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_top_users details
dnsfilter_traffic_top_users details
[DNSFilter] The busiest users in the window, ranked by request volume. Paginated. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_applications_agents_stats details
dnsfilter_traffic_total_applications_agents_stats details
[DNSFilter] Application usage statistics over a time window, attributed to roaming client agents. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_applications_collections_stats details
dnsfilter_traffic_total_applications_collections_stats details
[DNSFilter] Application usage statistics over a time window, attributed to collections. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_applications_networks_stats details
dnsfilter_traffic_total_applications_networks_stats details
[DNSFilter] Application usage statistics over a time window, attributed to networks. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_applications_organizations_stats details
dnsfilter_traffic_total_applications_organizations_stats details
[DNSFilter] Application usage statistics over a time window, attributed to organizations. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_applications_stats details
dnsfilter_traffic_total_applications_stats details
[DNSFilter] Application usage statistics over a time window — which SaaS and web applications are being reached. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_applications_users_stats details
dnsfilter_traffic_total_applications_users_stats details
[DNSFilter] Application usage statistics over a time window, attributed to users. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_categories details
dnsfilter_traffic_total_categories details
[DNSFilter] DNS traffic broken down by content category over a time window — what people are browsing, grouped the way the filtering policy groups it. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_categories_agents details
dnsfilter_traffic_total_categories_agents details
[DNSFilter] Content-category traffic over a time window, attributed to roaming client agents. Set showIndividualAgents for one series per agent. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_categories_collections details
dnsfilter_traffic_total_categories_collections details
[DNSFilter] Content-category traffic over a time window, attributed to collections. Set showIndividualCollections for one series per collection. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_categories_organizations details
dnsfilter_traffic_total_categories_organizations details
[DNSFilter] Content-category traffic over a time window, attributed to organizations. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_categories_users details
dnsfilter_traffic_total_categories_users details
[DNSFilter] Content-category traffic over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_category_stats details
dnsfilter_traffic_total_category_stats details
[DNSFilter] Summary statistics for content categories over a time window. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_client_stats details
dnsfilter_traffic_total_client_stats details
[DNSFilter] Summary client statistics over a time window. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_collections details
dnsfilter_traffic_total_collections details
[DNSFilter] DNS traffic broken down by collection over a time window. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_collections_agents details
dnsfilter_traffic_total_collections_agents details
[DNSFilter] Collection traffic over a time window, attributed to roaming client agents. Set showIndividualAgents for one series per agent. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_collections_organizations details
dnsfilter_traffic_total_collections_organizations details
[DNSFilter] Collection traffic over a time window, attributed to organizations. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_collections_users details
dnsfilter_traffic_total_collections_users details
[DNSFilter] Collection traffic over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_deployments details
dnsfilter_traffic_total_deployments details
[DNSFilter] Current deployment count for an organization. A point-in-time count, so it takes no time window. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_domain_requests details
dnsfilter_traffic_total_domain_requests details
[DNSFilter] Request totals for one domain over a time window. Unlike the domain statistics report this takes no fqdn filter. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_domain_stats details
dnsfilter_traffic_total_domain_stats details
[DNSFilter] Summary statistics for one domain over a time window. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_domains details
dnsfilter_traffic_total_domains details
[DNSFilter] DNS traffic broken down by domain over a time window. Narrow it with the domain or categoryIds filters. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_domains_collections details
dnsfilter_traffic_total_domains_collections details
[DNSFilter] Domain traffic over a time window, attributed to collections. Set showIndividualCollections for one series per collection. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_domains_organizations details
dnsfilter_traffic_total_domains_organizations details
[DNSFilter] Domain traffic over a time window, attributed to organizations. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_domains_users details
dnsfilter_traffic_total_domains_users details
[DNSFilter] Domain traffic over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_organizations_requests details
dnsfilter_traffic_total_organizations_requests details
[DNSFilter] Request totals for organizations within a parent organization's scope. The one report that takes BOTH the singular organizationId scope and the plural organizationIds filter. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_organizations_stats details
dnsfilter_traffic_total_organizations_stats details
[DNSFilter] Summary statistics for a single organization over a time window. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_requests details
dnsfilter_traffic_total_requests details
[DNSFilter] Total DNS requests over a time window, returned as a time series for charting. The headline volume report — use it to see overall query load and how it moves. Set showIndividualNetworks to break the series out per network. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_requests_agents details
dnsfilter_traffic_total_requests_agents details
[DNSFilter] Total DNS requests over a time window, attributed to roaming client agents. Set showIndividualAgents to return one series per agent rather than a combined total. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_requests_collections details
dnsfilter_traffic_total_requests_collections details
[DNSFilter] Total DNS requests over a time window, attributed to collections. Set showIndividualCollections to return one series per collection rather than a combined total. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_requests_geo details
dnsfilter_traffic_total_requests_geo details
[DNSFilter] DNS request volume broken down by geography, for the requested number of top locations. Unlike every other traffic report this one REQUIRES a limit. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_requests_organizations details
dnsfilter_traffic_total_requests_organizations details
[DNSFilter] Total DNS requests over a time window, attributed to organizations. Set showIndividualOrganizations to return one series per organization rather than a combined total. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_requests_users details
dnsfilter_traffic_total_requests_users details
[DNSFilter] Total DNS requests over a time window, attributed to users. Set showIndividualUsers to return one series per user rather than a combined total. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_roaming_clients details
dnsfilter_traffic_total_roaming_clients details
[DNSFilter] Current roaming client count for an organization. A point-in-time count, so it takes neither a time window nor a network filter. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_threats details
dnsfilter_traffic_total_threats details
[DNSFilter] Total threat lookups blocked over a time window, as a time series. Use it to show security value and spot an infection spike. This report is already scoped to security traffic, so it takes no securityReport flag. Set showIndividualNetworks to break it out per network. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_threats_agents details
dnsfilter_traffic_total_threats_agents details
[DNSFilter] Threat lookups blocked over a time window, attributed to roaming client agents — use it to find the specific machines generating threat traffic. Set showIndividualAgents for one series per agent. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_threats_collections details
dnsfilter_traffic_total_threats_collections details
[DNSFilter] Threat lookups blocked over a time window, attributed to collections. Set showIndividualCollections for one series per collection. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_threats_organizations details
dnsfilter_traffic_total_threats_organizations details
[DNSFilter] Threat lookups blocked over a time window, attributed to organizations — the report that answers which client is most at risk. Set showIndividualOrganizations for one series per organization. Returns raw DNSFilter JSON.
dnsfilter_traffic_total_threats_users details
dnsfilter_traffic_total_threats_users details
[DNSFilter] Threat lookups blocked over a time window, attributed to users. Set showIndividualUsers for one series per user. Returns raw DNSFilter JSON.
API Keys
dnsfilter_create_api_key details
dnsfilter_create_api_key details
[DNSFilter] Mint a new DNSFilter API key. Body (fieldsJson) is a JSON object; fields: name (label for the key), expiry (when it stops working). Not destructive — it only adds a credential and changes nothing that already exists. The response carries the token value, and this is the ONLY time DNSFilter returns it: afterwards only the last four characters are readable. Returns raw DNSFilter JSON.
dnsfilter_delete_api_key details
dnsfilter_delete_api_key details
[DNSFilter] Permanently delete a DNSFilter API key by ID (from dnsfilter_list_api_keys). Destructive and irreversible — the key stops authenticating immediately and its token value cannot be recovered or recreated. Anything built on that key breaks, INCLUDING this StackJack connection if the id belongs to the key StackJack authenticates with. Confirm which key you are removing with dnsfilter_get_api_key first. Returns raw DNSFilter JSON.
dnsfilter_get_api_key details
dnsfilter_get_api_key details
[DNSFilter] Get one DNSFilter API key by ID (from dnsfilter_list_api_keys). Returns the key's metadata — name, expiry, last four characters, scope — never the token value, which DNSFilter shows only once at creation. Returns raw DNSFilter JSON.
dnsfilter_list_api_keys details
dnsfilter_list_api_keys details
[DNSFilter] List the DNSFilter API keys belonging to the account this connection authenticates as. Scoped to the token's OWN user, not the whole organization — an empty result does not prove the organization has no keys. Filter by name, by the last four characters of the token, by expiry state or by organization. Token values are never returned, only metadata. Returns raw DNSFilter JSON.
dnsfilter_revoke_api_key details
dnsfilter_revoke_api_key details
[DNSFilter] Revoke a DNSFilter API key by ID (from dnsfilter_list_api_keys), invalidating the token while leaving the record in place. Destructive and irreversible — the token stops authenticating immediately and cannot be un-revoked; a replacement must be minted with dnsfilter_create_api_key. Every integration using that token breaks, INCLUDING this StackJack connection if the id belongs to the key StackJack authenticates with. Returns raw DNSFilter JSON.
Block Pages
dnsfilter_create_block_page details
dnsfilter_create_block_page details
[DNSFilter] Create a block page — the branded page end users see when DNSFilter blocks a lookup. Not destructive: it adds a new page and changes nothing that already exists, and nothing sees it until a policy is pointed at it. Returns raw DNSFilter JSON.
dnsfilter_delete_block_page details
dnsfilter_delete_block_page details
[DNSFilter] Permanently delete a block page by ID (from dnsfilter_list_block_pages). Destructive and irreversible — the branding is gone and any policy still pointing at this page falls back to whatever DNSFilter serves by default, which changes what real users see at block time. Check what references it with dnsfilter_get_block_page first. Returns raw DNSFilter JSON.
dnsfilter_get_block_page details
dnsfilter_get_block_page details
[DNSFilter] Get one block page by ID (from dnsfilter_list_block_pages), including its branding fields and, by default, the related records that reference it. Returns raw DNSFilter JSON.
dnsfilter_list_all_block_pages details
dnsfilter_list_all_block_pages details
[DNSFilter] List ALL block pages the account can see, DNSFilter's wider counterpart to dnsfilter_list_block_pages. The vendor documents the two only as "extant" versus "all" and does not say what it excludes from the narrower read, so prefer this one when auditing coverage and the other for the working set. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_block_pages details
dnsfilter_list_block_pages details
[DNSFilter] List the block pages available to the account this connection authenticates as — the branded pages DNSFilter serves when it blocks a lookup. Paginated. DNSFilter calls this the "extant" list and offers a separate wider read, dnsfilter_list_all_block_pages; when a page you expect is missing, try that one before concluding it does not exist. Returns raw DNSFilter JSON.
dnsfilter_update_block_page details
dnsfilter_update_block_page details
[DNSFilter] Update a block page by ID (from dnsfilter_list_block_pages). Send only the fields you want changed. Not destructive: it edits one record's own fields, affects no other object, and any field can be set back by a second update — but the change IS live immediately for every user any policy serves this page to, so confirm the id with dnsfilter_get_block_page first. Returns raw DNSFilter JSON.
Organizations & Users
dnsfilter_add_collection_user details
dnsfilter_add_collection_user details
[DNSFilter] Add an existing user to a collection. Not destructive: it is a reversible membership change that dnsfilter_remove_collection_user undoes exactly, and it creates nothing. It does take effect on live filtering, because policies scoped to the collection now apply to this user. Body: {"collection_id": N, "id": N}. Returns raw DNSFilter JSON.
dnsfilter_bulk_update_organizations details
dnsfilter_bulk_update_organizations details
[DNSFilter] Apply settings to MANY organizations in one call — agent auto-update, uninstall notifications and their recipient list, VPN settings. Destructive: the target set is whatever organization_ids (or an msp_id minus exclude_organization_ids) resolves to, which can be every customer under an MSP, and the previous per-organization values are overwritten with no record of what they were. Read the current state with dnsfilter_get_organization_settings first. Body fields: organization_ids, msp_id, exclude_organization_ids, send_uninstall_notifications_to_admin_users, user_agent_uninstall_notification, user_agent_uninstall_notification_recipient_emails, user_agents_auto_update, vpn_settings_organization_attributes. Returns raw DNSFilter JSON.
dnsfilter_cancel_organization details
dnsfilter_cancel_organization details
[DNSFilter] Set an organization to "Canceled". Destructive: it ends the customer's service state in DNSFilter and has billing consequences with the vendor that StackJack cannot see or undo. Returns raw DNSFilter JSON.
dnsfilter_change_user_password details
dnsfilter_change_user_password details
[DNSFilter] Change the password of the currently authenticated DNSFilter user — the account behind this connection, NOT an arbitrary user. Destructive: it immediately invalidates the old password for a real person, may sign their sessions out, and cannot be undone without the new value. Body: {"new_password": "..."}. Returns raw DNSFilter JSON.
dnsfilter_create_organization details
dnsfilter_create_organization details
[DNSFilter] Create an organization (for an MSP, a new customer tenant). Not destructive: it adds a tenant and changes nothing that already exists. Note this may consume licence quantity against the parent MSP's plan depending on the sku and quantity you send. Returns raw DNSFilter JSON.
dnsfilter_create_organization_user details
dnsfilter_create_organization_user details
[DNSFilter] Grant a person access to an organization by email, creating the DNSFilter user if it does not already exist. Not destructive — it adds access and alters nothing existing — but it DOES email an invitation to a real person, and the role plus organization_permission_ids you send decide what they can change. Returns raw DNSFilter JSON.
dnsfilter_delete_organization details
dnsfilter_delete_organization details
[DNSFilter] Delete an MSP customer organization by ID. Destructive and irreversible — it removes the tenant along with its networks, policies and roaming-client enrolment, and DNS filtering stops for everyone in it. Returns raw DNSFilter JSON.
dnsfilter_delete_organization_user details
dnsfilter_delete_organization_user details
[DNSFilter] Remove a person's access to an organization. Destructive: a real administrator loses access to this organization immediately, and if it was their only one they lose the dashboard entirely. Their DNSFilter user account itself is NOT deleted, so the removal can be undone by re-adding them, but their permission set is not preserved. Returns raw DNSFilter JSON.
dnsfilter_get_collection_user details
dnsfilter_get_collection_user details
[DNSFilter] Get one user's details within a collection. Returns raw DNSFilter JSON.
dnsfilter_get_organization details
dnsfilter_get_organization details
[DNSFilter] Get one organization by ID (from dnsfilter_list_organizations), optionally with its current MRR. Returns raw DNSFilter JSON.
dnsfilter_get_organization_settings details
dnsfilter_get_organization_settings details
[DNSFilter] Read organization-level settings — the account-wide toggles (agent auto-update, uninstall notifications, VPN settings) that dnsfilter_bulk_update_organizations writes. Scope it to one organization, several, or a whole MSP. Returns raw DNSFilter JSON.
dnsfilter_get_organization_user details
dnsfilter_get_organization_user details
[DNSFilter] Get one organization user with their role and permission set. Returns raw DNSFilter JSON.
dnsfilter_get_user details
dnsfilter_get_user details
[DNSFilter] Get one DNSFilter console user by ID. Pass the literal string "self" to read the account this connection authenticates as — the id accepts either a numeric ID or "self", which is why it is a string here. Returns raw DNSFilter JSON.
dnsfilter_list_all_organizations details
dnsfilter_list_all_organizations details
[DNSFilter] List ALL organizations the account can see, DNSFilter's wider counterpart to dnsfilter_list_organizations. The vendor documents the two only as "extant" versus "all", so prefer this one when auditing coverage. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_all_users details
dnsfilter_list_all_users details
[DNSFilter] List ALL DNSFilter console users, the wider counterpart to dnsfilter_list_users. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_collection_users details
dnsfilter_list_collection_users details
[DNSFilter] List the users belonging to a collection — the grouping DNSFilter uses to scope policies and reporting to a set of people. Paginated and filterable by name. Returns raw DNSFilter JSON.
dnsfilter_list_organization_users details
dnsfilter_list_organization_users details
[DNSFilter] List the DNSFilter console users who have access to an organization, with their roles. This is administrator access to the DNSFilter dashboard, not the end users whose DNS traffic is filtered. Returns raw DNSFilter JSON.
dnsfilter_list_organizations details
dnsfilter_list_organizations details
[DNSFilter] List the organizations this account can see — for an MSP, the customer tenants. Start here: nearly every other DNSFilter tool is scoped by an organization ID. Paginated, and filterable by name, type or parent MSP. DNSFilter calls this the "extant" list; dnsfilter_list_all_organizations is the wider read. Returns raw DNSFilter JSON.
dnsfilter_list_users details
dnsfilter_list_users details
[DNSFilter] List the DNSFilter console users visible to this account. Paginated. DNSFilter calls this the "extant" list; dnsfilter_list_all_users is the wider read. For who can access a PARTICULAR organization use dnsfilter_list_organization_users. Returns raw DNSFilter JSON.
dnsfilter_promote_organization_to_msp details
dnsfilter_promote_organization_to_msp details
[DNSFilter] Promote an organization to MSP status, letting it own sub-organizations. Destructive: it changes the account's tier and billing plan with DNSFilter, fires the vendor's Zapier hooks, and there is no documented demote operation. Returns raw DNSFilter JSON.
dnsfilter_remove_collection_user details
dnsfilter_remove_collection_user details
[DNSFilter] Remove a user from a collection. Not destructive: it is the exact inverse of dnsfilter_add_collection_user and restores the prior state, and the user account is untouched. It does take effect on live filtering — policies scoped to this collection stop applying to them. Returns raw DNSFilter JSON.
dnsfilter_resend_organization_user_invite details
dnsfilter_resend_organization_user_invite details
[DNSFilter] Resend the DNSFilter invitation email for a user in an organization. Marked destructive because its ONLY effect is reaching a real person's inbox — nothing in DNSFilter changes, and an email cannot be recalled, so repeated calls simply spam them. Returns raw DNSFilter JSON.
dnsfilter_update_organization details
dnsfilter_update_organization details
[DNSFilter] Update one organization by ID (from dnsfilter_list_organizations). Send only the fields you want changed. Not destructive: it edits one record's own fields and any value can be set back. Changing privacy_mode is the exception worth care — it governs how much end-user detail DNSFilter retains in reporting, so tightening it can drop visibility your reports depend on. Returns raw DNSFilter JSON.
dnsfilter_update_organization_user details
dnsfilter_update_organization_user details
[DNSFilter] Update an organization user's details, role or permissions. Send only the fields you want changed. Not destructive: every field can be set back, and the account itself is untouched. Note that organization_permission_ids REPLACES the permission set rather than adding to it, so send the full list you intend them to end up with. Returns raw DNSFilter JSON.
Networks & Sites
dnsfilter_bulk_create_networks details
dnsfilter_bulk_create_networks details
[DNSFilter] Create many networks in one call. Not destructive: it only adds sites. ASYNCHRONOUS — the response is a job ID, not the created networks; poll dnsfilter_get_bulk_create_networks_status with it to find out whether the work succeeded. Returns raw DNSFilter JSON.
dnsfilter_bulk_delete_networks details
dnsfilter_bulk_delete_networks details
[DNSFilter] Delete MANY networks in one call. Destructive and irreversible — filtering stops for everything behind every listed site. ASYNCHRONOUS — the response is a job ID; poll dnsfilter_get_bulk_delete_networks_status. Confirm the id list against dnsfilter_list_networks before calling. Returns raw DNSFilter JSON.
dnsfilter_bulk_update_networks details
dnsfilter_bulk_update_networks details
[DNSFilter] Reassign policy, scheduled policy or block page across MANY networks at once. Destructive: every listed site's previous assignment is overwritten with no record of what it was, which changes live filtering for everyone behind those sites. ASYNCHRONOUS — the response is a job ID; poll dnsfilter_get_bulk_update_networks_status. Body fields: ids (comma-separated network IDs), organization_id, policy_id, scheduled_policy_id, block_page_id, is_legacy_vpn_active. Returns raw DNSFilter JSON.
dnsfilter_create_ip_address details
dnsfilter_create_ip_address details
[DNSFilter] Register a public IP address against a network, which is what makes traffic from that address get filtered by the site's policy. Not destructive: it adds an address and changes nothing existing. Verify it is unclaimed first with dnsfilter_verify_ip_address. Returns raw DNSFilter JSON.
dnsfilter_create_network details
dnsfilter_create_network details
[DNSFilter] Create a network (site). Not destructive: it adds a site and changes nothing existing. A site with no policy_ids filters nothing, so include the policies you want applied. Returns raw DNSFilter JSON.
dnsfilter_create_network_secret_key details
dnsfilter_create_network_secret_key details
[DNSFilter] Create the secret key agents use to enrol against a network. Destructive: on a site that already has one this supersedes it, and every roaming client still holding the old key stops enrolling — an outage that only shows up as machines drifting unprotected. Returns raw DNSFilter JSON.
dnsfilter_create_network_subnet details
dnsfilter_create_network_subnet details
[DNSFilter] Add a subnet to a network so an internal address range gets its own policy. Not destructive: it adds a rule and changes nothing existing, though traffic from that range starts being filtered by the new policy as soon as it exists. Returns raw DNSFilter JSON.
dnsfilter_create_networks_csv_export details
dnsfilter_create_networks_csv_export details
[DNSFilter] Start a CSV export of networks, filtered the same way the list reads are. Not destructive: it creates an export record and changes no filtering. The response is an export record, not the file — read it back with dnsfilter_get_networks_csv_export, which returns a JSON envelope carrying the link. Returns raw DNSFilter JSON.
dnsfilter_delete_ip_address details
dnsfilter_delete_ip_address details
[DNSFilter] Remove a registered IP address. Destructive: queries arriving from that address stop matching the site, so everything behind it silently loses filtering while still resolving normally — the failure mode nobody notices. Returns raw DNSFilter JSON.
dnsfilter_delete_network details
dnsfilter_delete_network details
[DNSFilter] Delete a network (site) by ID. Destructive and irreversible — filtering stops for everything behind that site's IP addresses, and its subnets and IP assignments go with it. Returns raw DNSFilter JSON.
dnsfilter_delete_network_secret_key details
dnsfilter_delete_network_secret_key details
[DNSFilter] Revoke a network's agent enrolment secret key. Destructive and irreversible — no agent can enrol against this site until a new key is created, and the old value cannot be recovered. Returns raw DNSFilter JSON.
dnsfilter_delete_network_subnet details
dnsfilter_delete_network_subnet details
[DNSFilter] Delete a subnet from a network. Destructive and irreversible — the address range reverts to the parent network's policy, which usually means it is filtered differently rather than not at all, and the range definition is gone. Returns raw DNSFilter JSON.
dnsfilter_get_bulk_create_networks_status details
dnsfilter_get_bulk_create_networks_status details
[DNSFilter] Check the outcome of a dnsfilter_bulk_create_networks job. Returns raw DNSFilter JSON.
dnsfilter_get_bulk_delete_networks_status details
dnsfilter_get_bulk_delete_networks_status details
[DNSFilter] Check the outcome of a dnsfilter_bulk_delete_networks job. Returns raw DNSFilter JSON.
dnsfilter_get_bulk_update_networks_status details
dnsfilter_get_bulk_update_networks_status details
[DNSFilter] Check the outcome of a dnsfilter_bulk_update_networks job. Returns raw DNSFilter JSON.
dnsfilter_get_ip_address details
dnsfilter_get_ip_address details
[DNSFilter] Get one registered IP address by ID, including the network it belongs to. Returns raw DNSFilter JSON.
dnsfilter_get_my_ip details
dnsfilter_get_my_ip details
[DNSFilter] Return the public IP address DNSFilter sees this request coming from. Note that is StackJack's egress address, not the customer site's — useful for confirming what a caller looks like from outside, not for registering a site. Returns raw DNSFilter JSON.
dnsfilter_get_network details
dnsfilter_get_network details
[DNSFilter] Get one network by ID, including its assigned policies, block page and IP addresses. Returns raw DNSFilter JSON.
dnsfilter_get_network_counts details
dnsfilter_get_network_counts details
[DNSFilter] Counts of networks grouped by status — the cheap health read to run before listing anything, and across an MSP's customers in one call. Returns raw DNSFilter JSON.
dnsfilter_get_network_lan_ip details
dnsfilter_get_network_lan_ip details
[DNSFilter] Get one recorded LAN IP behind a network. Returns raw DNSFilter JSON.
dnsfilter_get_network_subnet details
dnsfilter_get_network_subnet details
[DNSFilter] Get one subnet of a network, including the policy and block page assigned to its address range. Returns raw DNSFilter JSON.
dnsfilter_get_networks_csv_export details
dnsfilter_get_networks_csv_export details
[DNSFilter] Read back a networks CSV export by ID (from dnsfilter_create_networks_csv_export). Returns the export record as JSON — DNSFilter hands back an envelope carrying a link rather than CSV bytes. Returns raw DNSFilter JSON.
dnsfilter_get_networks_geo details
dnsfilter_get_networks_geo details
[DNSFilter] List the account's networks with their geographic information only — the map view of where sites are. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_all_ip_addresses details
dnsfilter_list_all_ip_addresses details
[DNSFilter] List ALL registered public IP addresses, the wider counterpart to dnsfilter_list_ip_addresses. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_all_msp_networks details
dnsfilter_list_all_msp_networks details
[DNSFilter] List ALL networks of one organization from an MSP account, the wider counterpart to dnsfilter_list_msp_networks. organizationId is REQUIRED. Note this one does not accept basic_info. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_all_network_subnets details
dnsfilter_list_all_network_subnets details
[DNSFilter] List every site subnet the account can see, across networks. Subnets let one site apply different policies to different internal address ranges. Returns raw DNSFilter JSON.
dnsfilter_list_all_networks details
dnsfilter_list_all_networks details
[DNSFilter] List ALL networks the account can see, DNSFilter's wider counterpart to dnsfilter_list_networks. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_ip_addresses details
dnsfilter_list_ip_addresses details
[DNSFilter] List the public IP addresses registered to the account's networks — the addresses DNSFilter matches inbound queries against to decide which site, and therefore which policy, a query belongs to. Paginated and searchable. Returns raw DNSFilter JSON.
dnsfilter_list_msp_networks details
dnsfilter_list_msp_networks details
[DNSFilter] List the networks of one organization from an MSP account. organizationId is REQUIRED here, unlike dnsfilter_list_networks. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_network_lan_ips details
dnsfilter_list_network_lan_ips details
[DNSFilter] List the LAN IP addresses DNSFilter has recorded behind a network — the internal addresses it has seen making queries. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_network_subnets details
dnsfilter_list_network_subnets details
[DNSFilter] List the subnets defined on one network. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_networks details
dnsfilter_list_networks details
[DNSFilter] List networks (sites) — a fixed location identified by its public IP, where filtering applies to everything behind that IP rather than to an installed agent. Paginated, searchable, and filterable to protected or unprotected sites. Pass unprotected=true to find sites with no policy assigned, which are not being filtered at all. Returns raw DNSFilter JSON.
dnsfilter_lookup_network_by_ip details
dnsfilter_lookup_network_by_ip details
[DNSFilter] Find which network owns a public IP address. Use this to turn an IP seen in a query log or an alert into the site it belongs to. Returns raw DNSFilter JSON.
dnsfilter_rotate_network_secret_key details
dnsfilter_rotate_network_secret_key details
[DNSFilter] Rotate a network's agent enrolment secret key. Destructive: the previous key stops working immediately and anything still using it — deployment scripts, imaging templates, un-enrolled agents — must be updated with the new value. Returns raw DNSFilter JSON.
dnsfilter_update_ip_address details
dnsfilter_update_ip_address details
[DNSFilter] Update a registered IP address — its value, its dynamic hostname, or the network it belongs to. Not destructive: every field can be set back. Be aware that moving it to a different network changes which policy filters that traffic. Returns raw DNSFilter JSON.
dnsfilter_update_network details
dnsfilter_update_network details
[DNSFilter] Update one network by ID. Send only the fields you want changed. Not destructive — every field can be set back — but policy_ids REPLACES the assigned policy set rather than adding to it, so sending a partial list silently unassigns the policies you left out and changes what is filtered at that site. Read the current value with dnsfilter_get_network first. Returns raw DNSFilter JSON.
dnsfilter_update_network_lan_ip details
dnsfilter_update_network_lan_ip details
[DNSFilter] Rename a recorded LAN IP so reports show a machine name instead of a bare address. Not destructive: name is the only editable field and it can be set back. Returns raw DNSFilter JSON.
dnsfilter_update_network_subnet details
dnsfilter_update_network_subnet details
[DNSFilter] Update a subnet's range, policy or block page. Send only the fields you want changed. Not destructive — every field can be set back — but the change is live for the addresses in that range. Returns raw DNSFilter JSON.
dnsfilter_verify_ip_address details
dnsfilter_verify_ip_address details
[DNSFilter] Check whether an IP address is already registered in DNSFilter before you try to add it. Read-only — it verifies and changes nothing. Call this first when adding a site, because an address claimed by another organization cannot be registered twice. Returns raw DNSFilter JSON.
Roaming Clients (Agents)
dnsfilter_check_user_agent_bulk_update_mixed details
dnsfilter_check_user_agent_bulk_update_mixed details
[DNSFilter] Report which attributes differ across the selected roaming clients. Read-only despite being a POST — it inspects and changes nothing. Use it before a bulk update to see which fields you would be flattening to a single value. Returns raw DNSFilter JSON.
dnsfilter_create_user_agent_bulk_delete details
dnsfilter_create_user_agent_bulk_delete details
[DNSFilter] Delete or uninstall MANY roaming clients at once. Destructive and the highest blast radius in the connector: with queueUninstall=true every selected machine is queued to remove its own agent and stops being filtered, and the target set is whatever the filters match rather than a list you wrote out. Always run dnsfilter_get_user_agent_bulk_delete_counts with the identical filters first. Returns raw DNSFilter JSON.
dnsfilter_create_user_agent_bulk_update details
dnsfilter_create_user_agent_bulk_update details
[DNSFilter] Apply one changeset to MANY roaming clients. The target set is whatever the query filters select, narrowed by ids or exclude_ids in the body. Destructive: it overwrites policy, network, block page, tags or release channel across a set the caller may not have enumerated, with no record of the previous per-agent values, and it changes live filtering on real machines. Preview the target with dnsfilter_get_user_agent_bulk_update_counts and check for mixed values with dnsfilter_check_user_agent_bulk_update_mixed first. Returns raw DNSFilter JSON.
dnsfilter_create_user_agent_cleanup details
dnsfilter_create_user_agent_cleanup details
[DNSFilter] Create a cleanup that removes roaming clients inactive for longer than a given number of days. Destructive: it defines a mass deletion whose target set is a time threshold rather than a list, so a small inactiveFor value can sweep machines that are merely powered off rather than genuinely retired. Creating it does not start it — dnsfilter_update_user_agent_cleanup with start=true does. Returns raw DNSFilter JSON.
dnsfilter_create_user_agent_csv_export details
dnsfilter_create_user_agent_csv_export details
[DNSFilter] Start a CSV export of roaming clients, filtered the same way the list reads are. Not destructive: it creates an export record and changes no filtering. Read the result back with dnsfilter_get_user_agent_csv_export, which returns a JSON envelope carrying the link rather than CSV bytes. Returns raw DNSFilter JSON.
dnsfilter_delete_user_agent details
dnsfilter_delete_user_agent details
[DNSFilter] Remove a roaming client. Destructive: by default this soft-deletes the record, and with queueUninstall=true it queues the agent to uninstall itself from the machine, which ends DNS protection there and needs a re-deployment to restore. clearRegistry additionally wipes the agent's registry keys during uninstall. To cancel an uninstall you have already queued, use dnsfilter_dequeue_uninstall_user_agent. Returns raw DNSFilter JSON.
dnsfilter_dequeue_uninstall_user_agent details
dnsfilter_dequeue_uninstall_user_agent details
[DNSFilter] Take a roaming client OFF the uninstall queue. DNSFilter's own summary for this operation is "Remove queue", and the operation that PUTS an agent on that queue is dnsfilter_delete_user_agent with queueUninstall=true — so this cancels a pending uninstall rather than performing one. Marked destructive because it changes a pending fleet action on a real machine and the two readings of its name have opposite consequences. Returns raw DNSFilter JSON.
dnsfilter_export_user_agents_csv details
dnsfilter_export_user_agents_csv details
[DNSFilter] Export an organization's roaming clients. Read-only — it changes nothing. Despite the name, DNSFilter declares this response as JSON, so what comes back is the export payload as raw JSON rather than CSV bytes. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent details
dnsfilter_get_user_agent details
[DNSFilter] Get one roaming client by UUID, with its hostname, platform, version, assigned policy, tags and current state. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_bulk_delete details
dnsfilter_get_user_agent_bulk_delete details
[DNSFilter] Read back a bulk delete job by ID to see how it went. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_bulk_delete_counts details
dnsfilter_get_user_agent_bulk_delete_counts details
[DNSFilter] Count the roaming clients a given filter set would delete. Run this with the exact filters you intend to pass to dnsfilter_create_user_agent_bulk_delete — it is the only preview of how many machines would lose their agent. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_bulk_update details
dnsfilter_get_user_agent_bulk_update details
[DNSFilter] Read back a bulk update job by ID to see how it went. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_bulk_update_counts details
dnsfilter_get_user_agent_bulk_update_counts details
[DNSFilter] Count the roaming clients a given filter set would select. Run this with the exact filters you intend to pass to dnsfilter_create_user_agent_bulk_update — it is the only way to see the blast radius before committing to it. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_cleanup details
dnsfilter_get_user_agent_cleanup details
[DNSFilter] Read a stale-agent cleanup by ID, including its threshold and progress. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_counts details
dnsfilter_get_user_agent_counts details
[DNSFilter] Counts of roaming clients per status — the cheap fleet-health read. Answers "how many machines are unprotected right now" without paging the whole inventory. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_csv_export details
dnsfilter_get_user_agent_csv_export details
[DNSFilter] Read back a roaming-client CSV export by ID (from dnsfilter_create_user_agent_csv_export). Returns the export record as JSON. Returns raw DNSFilter JSON.
dnsfilter_get_user_agent_uninstall_pin details
dnsfilter_get_user_agent_uninstall_pin details
[DNSFilter] Get the PIN that authorizes uninstalling the DNSFilter agent on an organization's machines. Read-only, but the value IS a secret — it is what stops an end user removing their own protection, and it works for the organization's whole fleet — which is why this sits behind its own permission (read:uninstall-pins) and the Pro tier rather than the general agent-read permission. Returns raw DNSFilter JSON.
dnsfilter_list_all_user_agents details
dnsfilter_list_all_user_agents details
[DNSFilter] List ALL roaming clients, DNSFilter's wider counterpart to dnsfilter_list_user_agents with a narrower filter set — it takes a single organizationId rather than a list, and none of the operator filters. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_relay_releases details
dnsfilter_list_relay_releases details
[DNSFilter] List the latest DNSFilter relay releases per architecture, release channel and white label. Relays are the on-premises forwarders, distinct from the roaming client. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_user_agent_releases details
dnsfilter_list_user_agent_releases details
[DNSFilter] List the latest agent release per platform, architecture, release channel and white label. Compare against the versions in dnsfilter_list_user_agents to find machines running something older than what is shipping. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_user_agent_tags details
dnsfilter_list_user_agent_tags details
[DNSFilter] List the tags in use across roaming clients. Tags are how bulk operations select machines, so read this before targeting a bulk update or delete by tag. Returns raw DNSFilter JSON.
dnsfilter_list_user_agents details
dnsfilter_list_user_agents details
[DNSFilter] List roaming clients (agents) — the DNSFilter software installed on individual machines, which filters them wherever they are rather than only behind a site IP. This is the main fleet inventory read and the widest filter surface in the connector: protection state, connectivity, version, VPN status, browser-extension status, CyberSight status, tags, policy and more. To find unprotected machines, filter agentState=unprotected. Paginated. Returns raw DNSFilter JSON.
dnsfilter_update_user_agent details
dnsfilter_update_user_agent details
[DNSFilter] Update one roaming client — friendly name, tags, assigned network, policy, scheduled policy, block page, VPN settings, or status. Send only the fields you want changed. Not destructive as a field edit, and any value can be set back, but two fields carry real weight: status accepts "uninstalled", which removes protection from that machine, and tags REPLACES the tag set rather than adding to it — and tags are how bulk operations select machines. Returns raw DNSFilter JSON.
dnsfilter_update_user_agent_cleanup details
dnsfilter_update_user_agent_cleanup details
[DNSFilter] Update a stale-agent cleanup, and START it by sending start=true. Destructive: starting one deletes every roaming client that matches the inactivity threshold, in bulk and without a further confirmation. Check the threshold with dnsfilter_get_user_agent_cleanup before starting. Returns raw DNSFilter JSON.
dnsfilter_update_user_agent_settings details
dnsfilter_update_user_agent_settings details
[DNSFilter] Update a roaming client's device and filtering-client settings — CyberSight, the filtering client itself, diagnostics level, and the connection, filtering and failover methods. Not destructive: these are reversible settings on one machine. Note this is the connector's /v2 endpoint for agents while the ordinary update is /v1; they edit different fields and neither is a newer version of the other. Returns raw DNSFilter JSON.
Policies & Filtering Lists
dnsfilter_add_policy_allowed_application details
dnsfilter_add_policy_allowed_application details
[DNSFilter] Allow one application in a policy. Not destructive: a single reversible list-membership change with an exact inverse. Application names come from dnsfilter_list_applications. Returns raw DNSFilter JSON.
dnsfilter_add_policy_allowed_domain details
dnsfilter_add_policy_allowed_domain details
[DNSFilter] Add one domain to a policy's allow list, exempting it from category and threat blocking for everyone the policy covers. Not destructive: a single reversible list-membership change with an exact inverse. Returns raw DNSFilter JSON.
dnsfilter_add_policy_blocked_application details
dnsfilter_add_policy_blocked_application details
[DNSFilter] Block one application in a policy — this stops it working for everyone the policy covers, so check what depends on it first. Not destructive: a single reversible list-membership change with an exact inverse. Returns raw DNSFilter JSON.
dnsfilter_add_policy_blocked_category details
dnsfilter_add_policy_blocked_category details
[DNSFilter] Block a whole content category in a policy. Wider in effect than a single domain — a category covers many sites — but still a single reversible list-membership change with an exact inverse, so it is not marked destructive. Category IDs come from dnsfilter_list_categories. Returns raw DNSFilter JSON.
dnsfilter_add_policy_blocked_domain details
dnsfilter_add_policy_blocked_domain details
[DNSFilter] Add one domain to a policy's block list. Takes effect on live filtering immediately for everyone the policy covers. Not destructive: it is a single reversible list-membership change that dnsfilter_remove_policy_blocked_domain undoes exactly, restoring the prior state. Returns raw DNSFilter JSON.
dnsfilter_bulk_add_policy_allowed_domains details
dnsfilter_bulk_add_policy_allowed_domains details
[DNSFilter] Add several domains to several policies' allow lists in one call. Not destructive: it only adds entries, changes nothing already there, and dnsfilter_bulk_remove_policy_allowed_domains is its exact inverse. It does exempt those domains from filtering everywhere the listed policies apply. Returns raw DNSFilter JSON.
dnsfilter_bulk_add_policy_blocked_domains details
dnsfilter_bulk_add_policy_blocked_domains details
[DNSFilter] Add several domains to several policies' block lists in one call — the fastest way to push an indicator of compromise across every customer. Not destructive: it only adds entries and has an exact inverse. Returns raw DNSFilter JSON.
dnsfilter_bulk_remove_policy_allowed_domains details
dnsfilter_bulk_remove_policy_allowed_domains details
[DNSFilter] Remove several domains from several policies' allow lists. Not destructive: it removes only the entries you name, leaving the rest of each list intact, and re-adding them restores the prior state exactly. Returns raw DNSFilter JSON.
dnsfilter_bulk_remove_policy_blocked_domains details
dnsfilter_bulk_remove_policy_blocked_domains details
[DNSFilter] Remove several domains from several policies' block lists, so they resolve again wherever those policies apply. Not destructive: it removes only the entries you name and re-adding them restores the prior state exactly. Returns raw DNSFilter JSON.
dnsfilter_create_policy details
dnsfilter_create_policy details
[DNSFilter] Create a filtering policy. Not destructive: it adds a rule set and nothing is filtered by it until a network, subnet or roaming client is assigned to it. Returns raw DNSFilter JSON.
dnsfilter_delete_policy details
dnsfilter_delete_policy details
[DNSFilter] Delete a policy. Destructive and irreversible — the whole rule set goes, and every network, subnet and roaming client assigned to it stops being filtered by those rules. Check what is assigned to it before calling. Returns raw DNSFilter JSON.
dnsfilter_get_application_policies details
dnsfilter_get_application_policies details
[DNSFilter] Show how each policy currently treats one application — which policies allow it and which block it. Run this before dnsfilter_update_application_policies, whose arrays replace that state wholesale. Returns raw DNSFilter JSON.
dnsfilter_get_policy details
dnsfilter_get_policy details
[DNSFilter] Get one policy by ID with its full rule set — allowed and blocked domains, blocked categories, application rules and the safe-search and YouTube-restriction flags. Read this before any change: the update tool replaces list fields wholesale by default. Returns raw DNSFilter JSON.
dnsfilter_get_policy_ip details
dnsfilter_get_policy_ip details
[DNSFilter] Get one policy IP by ID. Returns raw DNSFilter JSON.
dnsfilter_get_policy_permissive_mode details
dnsfilter_get_policy_permissive_mode details
[DNSFilter] Read whether a policy is in permissive mode. Returns raw DNSFilter JSON.
dnsfilter_list_all_policies details
dnsfilter_list_all_policies details
[DNSFilter] List ALL policies the account can see, the wider counterpart to dnsfilter_list_policies. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_policies details
dnsfilter_list_policies details
[DNSFilter] List filtering policies — the rule sets that decide which domains, categories and applications are allowed or blocked. Policies are what networks and roaming clients get assigned, so read this before assigning anything. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_policy_ips details
dnsfilter_list_policy_ips details
[DNSFilter] List the policy IPs — the DNSFilter resolver addresses a policy answers on, which is what a site or device points its DNS at. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_remove_policy_allowed_application details
dnsfilter_remove_policy_allowed_application details
[DNSFilter] Remove one application from a policy's allow list. Not destructive: the exact inverse of dnsfilter_add_policy_allowed_application. Returns raw DNSFilter JSON.
dnsfilter_remove_policy_allowed_domain details
dnsfilter_remove_policy_allowed_domain details
[DNSFilter] Remove one domain from a policy's allow list, so the ordinary category and threat rules apply to it again. Not destructive: the exact inverse of dnsfilter_add_policy_allowed_domain. Returns raw DNSFilter JSON.
dnsfilter_remove_policy_blocked_application details
dnsfilter_remove_policy_blocked_application details
[DNSFilter] Remove one application from a policy's block list, letting it work again. Not destructive: the exact inverse of dnsfilter_add_policy_blocked_application. Returns raw DNSFilter JSON.
dnsfilter_remove_policy_blocked_category details
dnsfilter_remove_policy_blocked_category details
[DNSFilter] Stop blocking a content category in a policy. Everything in that category resolves again unless another rule catches it, which is a real widening of what users can reach. Not destructive: the exact inverse of dnsfilter_add_policy_blocked_category. Returns raw DNSFilter JSON.
dnsfilter_remove_policy_blocked_domain details
dnsfilter_remove_policy_blocked_domain details
[DNSFilter] Remove one domain from a policy's block list, so it resolves normally again unless another rule still blocks it. Not destructive: the exact inverse of dnsfilter_add_policy_blocked_domain, restoring the prior state. Returns raw DNSFilter JSON.
dnsfilter_set_policy_permissive_mode details
dnsfilter_set_policy_permissive_mode details
[DNSFilter] Turn a policy's permissive mode on or off. Destructive: switching it ON relaxes enforcement for every network and machine assigned to this policy at once — traffic that was being blocked stops being blocked, silently and immediately. It is reversible by setting it back to false, but nothing records that it was ever changed. Returns raw DNSFilter JSON.
dnsfilter_update_application_policies details
dnsfilter_update_application_policies details
[DNSFilter] Set which policies allow and which block one application, in a single call. Destructive: both lists are REPLACED, not merged, so any policy you omit from both arrays loses whatever rule it had for this application — and this is live filtering for everyone those policies cover. Read the current state with dnsfilter_get_application_policies and send it back with your change applied. Returns raw DNSFilter JSON.
dnsfilter_update_policy details
dnsfilter_update_policy details
[DNSFilter] Update a policy. Send only the fields you want changed. Not destructive as a field edit — every value can be set back — but mind the list semantics: whitelist_domains, blacklist_domains, blacklist_categories and the application lists REPLACE the existing set unless you send append_domains=true, so a partial list silently drops the entries you left out and changes live filtering. To change one entry, prefer the add/remove tools (dnsfilter_add_policy_blocked_domain and its siblings), which cannot have that effect. Returns raw DNSFilter JSON.
Agent Local Users
dnsfilter_create_agent_local_user_bulk_delete details
dnsfilter_create_agent_local_user_bulk_delete details
[DNSFilter] Delete MANY agent local users at once. Destructive: the target set is whatever the operator filters match, narrowed by ids or exclude_ids in the body, so a broad filter can remove far more identities than intended — and every per-user policy assignment in that set goes with them. Check the size first with dnsfilter_get_agent_local_user_bulk_delete_count. Returns raw DNSFilter JSON.
dnsfilter_create_agent_local_users_csv_export details
dnsfilter_create_agent_local_users_csv_export details
[DNSFilter] Start a CSV export of agent local users. Not destructive: it creates an export record and changes no filtering. Read the result back with dnsfilter_get_agent_local_users_csv_export, which returns a JSON envelope carrying the link rather than CSV bytes. Returns raw DNSFilter JSON.
dnsfilter_delete_agent_local_user details
dnsfilter_delete_agent_local_user details
[DNSFilter] Delete an agent local user record. Destructive: their per-user policy assignment and their history as a distinct identity go with it, so traffic from that person stops being attributed to them in reporting. Returns raw DNSFilter JSON.
dnsfilter_get_agent_local_user details
dnsfilter_get_agent_local_user details
[DNSFilter] Get one agent local user by ID, with their assigned policy, scheduled policy and block page. Returns raw DNSFilter JSON.
dnsfilter_get_agent_local_user_bulk_delete details
dnsfilter_get_agent_local_user_bulk_delete details
[DNSFilter] Read back a bulk delete job by ID to see how it went. Returns raw DNSFilter JSON.
dnsfilter_get_agent_local_user_bulk_delete_count details
dnsfilter_get_agent_local_user_bulk_delete_count details
[DNSFilter] Count the users covered by a bulk delete job. Note this takes the JOB id as a query parameter rather than a filter set, so it reports on a job that already exists — unlike the roaming-client counts endpoints, which preview a filter before you commit to it. Returns raw DNSFilter JSON.
dnsfilter_get_agent_local_user_counts details
dnsfilter_get_agent_local_user_counts details
[DNSFilter] Counts of agent local users grouped by policy-assignment status — how many have a policy of their own versus inheriting one. The cheap read for spotting users nobody has scoped. Returns raw DNSFilter JSON.
dnsfilter_get_agent_local_users_csv_export details
dnsfilter_get_agent_local_users_csv_export details
[DNSFilter] Read back an agent local users CSV export. The id is a UUID string here, not a number — unlike the other export reads in this connector. Returns raw DNSFilter JSON.
dnsfilter_list_agent_local_users details
dnsfilter_list_agent_local_users details
[DNSFilter] List agent local users — the people signed in to machines running the roaming client, which is how DNSFilter attributes traffic and applies per-user policy. These are NOT DNSFilter console accounts (see dnsfilter_list_organization_users) and NOT collection members. Paginated, with operator filters on name, login, block page, collection and policy schedule. Returns raw DNSFilter JSON.
dnsfilter_list_all_agent_local_users details
dnsfilter_list_all_agent_local_users details
[DNSFilter] List ALL agent local users, the wider counterpart to dnsfilter_list_agent_local_users with a narrower filter set — none of the operator filters. Paginated. Returns raw DNSFilter JSON.
dnsfilter_update_agent_local_user details
dnsfilter_update_agent_local_user details
[DNSFilter] Update an agent local user's friendly name, or assign them a policy, scheduled policy or block page directly. Not destructive: every field can be set back. Assigning a policy here overrides whatever they would inherit from their network or collection, which is live filtering for that person. Returns raw DNSFilter JSON.
Categories & Applications
dnsfilter_get_application details
dnsfilter_get_application details
[DNSFilter] Get one application by ID. Returns raw DNSFilter JSON.
dnsfilter_get_application_category details
dnsfilter_get_application_category details
[DNSFilter] Get one application category by ID. Returns raw DNSFilter JSON.
dnsfilter_get_category details
dnsfilter_get_category details
[DNSFilter] Get one content category by ID. Returns raw DNSFilter JSON.
dnsfilter_list_ai_applications details
dnsfilter_list_ai_applications details
[DNSFilter] List the AI applications and websites DNSFilter recognises — the reference set behind AI-usage reporting and the starting point for building a policy around generative-AI access. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_all_applications details
dnsfilter_list_all_applications details
[DNSFilter] List ALL applications INCLUDING deleted ones, which dnsfilter_list_applications omits. Use this when a policy references an application that no longer appears in the ordinary list. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_all_categories details
dnsfilter_list_all_categories details
[DNSFilter] List ALL content categories INCLUDING DNSFilter's internal ones, which dnsfilter_list_categories omits. Use this when a category ID appears in a report or policy but does not show up in the ordinary list. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_application_categories details
dnsfilter_list_application_categories details
[DNSFilter] List the application categories — the grouping over applications, and a different axis from the CONTENT categories in dnsfilter_list_categories. Policies reference the two separately, so do not use an ID from one where the other is expected. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_applications details
dnsfilter_list_applications details
[DNSFilter] List the applications DNSFilter can allow or block by name — the vocabulary the policy application tools expect. Filterable by application category. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_categories details
dnsfilter_list_categories details
[DNSFilter] List DNSFilter's content categories — the buckets ("Malware", "Social Media", and so on) a policy blocks by ID. Read this to turn a category name into the ID that dnsfilter_add_policy_blocked_category and the traffic reports expect. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_cybersight_activity_types details
dnsfilter_list_cybersight_activity_types details
[DNSFilter] List the activity types CyberSight reports can contain. Read this to learn the vocabulary before filtering CyberSight data. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_qp_methods details
dnsfilter_list_qp_methods details
[DNSFilter] List DNSFilter's QP methods dictionary. The vendor publishes no description or expansion for this endpoint beyond its name, so treat the response as the authority on what it contains. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_vpn_settings_state_types details
dnsfilter_list_vpn_settings_state_types details
[DNSFilter] List the valid VPN settings state types. These are the IDs the vpn_settings_state_type_id field takes when updating an organization or a roaming client, so read this before sending one. Takes no parameters. Returns raw DNSFilter JSON.
Domain Lookups & Notes
dnsfilter_batch_delete_domain_notes details
dnsfilter_batch_delete_domain_notes details
[DNSFilter] Delete the notes for several domains at once. Destructive: the text for every listed domain is gone and unrecoverable. Filtering is unaffected — the domains stay on their lists. Returns raw DNSFilter JSON.
dnsfilter_batch_update_domain_notes details
dnsfilter_batch_update_domain_notes details
[DNSFilter] Set notes for many domains at once on a policy, MSP or organization. Not destructive: annotation only, no filtering changes. Mind that append defaults to FALSE, which REPLACES each domain's existing note rather than adding to it. Returns raw DNSFilter JSON.
dnsfilter_bulk_lookup_domains details
dnsfilter_bulk_lookup_domains details
[DNSFilter] Look up the classification of several FQDNs in one call. Use this to triage a list of indicators before deciding what to block. Returns raw DNSFilter JSON.
dnsfilter_delete_domain_note details
dnsfilter_delete_domain_note details
[DNSFilter] Delete the note recorded against one domain. Destructive in the sense that matters here: the text is gone and cannot be recovered, and it is often the only record of why a domain was allowed or blocked. Filtering itself is unaffected — the domain stays on whatever list it was on. Returns raw DNSFilter JSON.
dnsfilter_get_domain_notes details
dnsfilter_get_domain_notes details
[DNSFilter] Read the notes recorded against one domain on a policy, MSP or organization — the free-text record of WHY a domain was allowed or blocked. Returns raw DNSFilter JSON.
dnsfilter_lookup_domain details
dnsfilter_lookup_domain details
[DNSFilter] Look up how DNSFilter classifies one FQDN — the domains and content categories it is associated with. This is the tool for "why was this blocked?" and for checking a domain's reputation before allowing it. Returns raw DNSFilter JSON.
dnsfilter_suggest_threat details
dnsfilter_suggest_threat details
[DNSFilter] Submit an FQDN to DNSFilter for threat review, with your suggested security categories and notes. Destructive and open-world: this LEAVES the tenant boundary — the submission goes to DNSFilter's global threat-intelligence review, where it can affect classification for other customers, and there is no operation to retract it. Look the domain up with dnsfilter_lookup_domain first. Returns raw DNSFilter JSON.
dnsfilter_update_domain_note details
dnsfilter_update_domain_note details
[DNSFilter] Set the note recorded against one domain on a policy, MSP or organization. Not destructive: this is annotation only — it records why a domain is on an allow or block list and changes no filtering. Returns raw DNSFilter JSON.
MAC Addresses
dnsfilter_create_mac_address details
dnsfilter_create_mac_address details
[DNSFilter] Register a MAC address so a specific device gets its own policy. Not destructive: it adds a rule and changes nothing existing, though the device starts being filtered by the assigned policy as soon as it exists. Returns raw DNSFilter JSON.
dnsfilter_delete_mac_address details
dnsfilter_delete_mac_address details
[DNSFilter] Delete a registered MAC address. Destructive: that device loses its own policy and falls back to whatever its network provides, which is usually a different rule set rather than none — the change is silent either way. Returns raw DNSFilter JSON.
dnsfilter_get_mac_address details
dnsfilter_get_mac_address details
[DNSFilter] Get one registered MAC address with the policy, scheduled policy and block page assigned to it. Returns raw DNSFilter JSON.
dnsfilter_list_all_mac_addresses details
dnsfilter_list_all_mac_addresses details
[DNSFilter] List ALL registered MAC addresses, the wider counterpart to dnsfilter_list_mac_addresses. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_mac_addresses details
dnsfilter_list_mac_addresses details
[DNSFilter] List registered MAC addresses — per-device filtering rules keyed to a hardware address, used where a device needs its own policy without running the roaming client. Paginated. Returns raw DNSFilter JSON.
dnsfilter_update_mac_address details
dnsfilter_update_mac_address details
[DNSFilter] Update a registered MAC address or the policy assigned to it. Send only the fields you want changed. Not destructive: every value can be set back. Returns raw DNSFilter JSON.
Scheduled Policies
dnsfilter_create_scheduled_policy details
dnsfilter_create_scheduled_policy details
[DNSFilter] Create a scheduled policy over a set of existing policies. Not destructive: it adds a schedule and nothing uses it until a network, subnet or client is assigned to it. Set timezone deliberately — the schedule is evaluated in it, so a wrong value shifts every transition. Returns raw DNSFilter JSON.
dnsfilter_delete_scheduled_policy details
dnsfilter_delete_scheduled_policy details
[DNSFilter] Delete a scheduled policy. Destructive and irreversible — anything assigned to it stops switching policies on schedule, so the time-based filtering silently stops applying while the underlying policies survive. Returns raw DNSFilter JSON.
dnsfilter_get_scheduled_policy details
dnsfilter_get_scheduled_policy details
[DNSFilter] Get one scheduled policy, including which policies it cycles between and the timezone the schedule is evaluated in. Returns raw DNSFilter JSON.
dnsfilter_list_all_scheduled_policies details
dnsfilter_list_all_scheduled_policies details
[DNSFilter] List ALL scheduled policies, the wider counterpart to dnsfilter_list_scheduled_policies. Paginated. Returns raw DNSFilter JSON.
dnsfilter_list_scheduled_policies details
dnsfilter_list_scheduled_policies details
[DNSFilter] List scheduled policies — the time-based wrappers that swap between ordinary policies on a schedule, so a site can filter differently during and outside working hours. Paginated. Returns raw DNSFilter JSON.
dnsfilter_update_scheduled_policy details
dnsfilter_update_scheduled_policy details
[DNSFilter] Update a scheduled policy. Send only the fields you want changed. Not destructive as a field edit, but policy_ids REPLACES the set the schedule cycles between, and changing timezone shifts when every transition happens for everyone assigned to it. Returns raw DNSFilter JSON.
Scheduled Reports
dnsfilter_create_scheduled_report details
dnsfilter_create_scheduled_report details
[DNSFilter] Create a recurring report that DNSFilter emails to the recipients you name. Marked NOT destructive deliberately, and the reason matters: it adds a configuration object whose sends are deferred and recurring rather than performing an immediate act that reaches a person, and deleting it stops the sends. Be aware all the same that every address in scheduled_report_recipients will start receiving mail on the schedule you set. Returns raw DNSFilter JSON.
dnsfilter_create_scheduled_report_preview details
dnsfilter_create_scheduled_report_preview details
[DNSFilter] Generate a preview of what a scheduled report would contain, without creating the schedule or emailing anyone. Not destructive: it starts a background generation and changes no configuration. Generation is ASYNCHRONOUS — read the result with dnsfilter_get_scheduled_report_preview using the ID returned here. Returns raw DNSFilter JSON.
dnsfilter_delete_scheduled_report details
dnsfilter_delete_scheduled_report details
[DNSFilter] Delete a scheduled report. Destructive and irreversible — the recurring send stops and the recipient list and content settings are gone, so recipients simply stop receiving reports with no notice to them. Returns raw DNSFilter JSON.
dnsfilter_get_scheduled_report details
dnsfilter_get_scheduled_report details
[DNSFilter] Get one scheduled report with its frequency, contents and recipient list. Returns raw DNSFilter JSON.
dnsfilter_get_scheduled_report_preview details
dnsfilter_get_scheduled_report_preview details
[DNSFilter] Read back a scheduled report preview by ID. Generation runs in the background, so a preview requested a moment ago may not be ready yet. Returns raw DNSFilter JSON.
dnsfilter_list_scheduled_reports details
dnsfilter_list_scheduled_reports details
[DNSFilter] List the scheduled reports configured for an organization — the recurring summary emails DNSFilter sends to named recipients. Read this before changing anything, because the recipient list is the part that reaches real people. Returns raw DNSFilter JSON.
dnsfilter_update_scheduled_report details
dnsfilter_update_scheduled_report details
[DNSFilter] Update a scheduled report's frequency, contents or recipients. Send only the fields you want changed. Not destructive: every value can be set back. Note scheduled_report_recipients REPLACES the recipient list rather than adding to it, so a partial list silently stops mail reaching the people you left out. Returns raw DNSFilter JSON.
Usage Metrics & Exports
dnsfilter_create_cybersight_csv_export details
dnsfilter_create_cybersight_csv_export details
[DNSFilter] Start a CSV export of a CyberSight report — activity logs, top websites, applications, categories, streaming, risky users, active clients or AI usage. Not destructive: it creates an export record and changes nothing. Two things to know: DNSFilter silently IGNORES invalid filters and column keys rather than erroring, generating the CSV from whatever remains, so a typo yields a quietly wrong export; and included_columns must be nested under cyber_sight_csv_export in the body. Read the result with dnsfilter_get_cybersight_csv_export. Returns raw DNSFilter JSON.
dnsfilter_get_cybersight_csv_export details
dnsfilter_get_cybersight_csv_export details
[DNSFilter] Read back a CyberSight CSV export. The id is a UUID string, not a number. Returns the export record as JSON — DNSFilter hands back an envelope carrying a link rather than CSV bytes. Returns raw DNSFilter JSON.
dnsfilter_get_organization_usage details
dnsfilter_get_organization_usage details
[DNSFilter] Usage figures for one organization over a date range — the seat and query counts behind what DNSFilter bills. Both dates are REQUIRED and the range cannot exceed 365 days. Returns raw DNSFilter JSON.
dnsfilter_get_organization_usage_detailed details
dnsfilter_get_organization_usage_detailed details
[DNSFilter] Usage figures for one organization with a roaming-client count included. This is not simply a richer version of dnsfilter_get_organization_usage: DNSFilter derives user_count and wifi_count differently here, so the two reads can legitimately disagree for the same window. Both dates are optional. Returns raw DNSFilter JSON.
Dashboards
dnsfilter_list_available_dashboards details
dnsfilter_list_available_dashboards details
[DNSFilter] List the dashboards available to this account, including ones other users have shared into the organizations it belongs to. Wider than dnsfilter_list_dashboards. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_dashboards details
dnsfilter_list_dashboards details
[DNSFilter] List the dashboards for the account this connection authenticates as, default first and the rest alphabetically. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_list_owned_dashboards details
dnsfilter_list_owned_dashboards details
[DNSFilter] List only the dashboards this account owns, as opposed to ones shared with it. Takes no parameters. Returns raw DNSFilter JSON.
Account
dnsfilter_get_current_user details
dnsfilter_get_current_user details
[DNSFilter] Read the DNSFilter account this connection authenticates as. This is also the endpoint the connector validates credentials against, so it is the right first call when diagnosing an auth problem: it is callable by every token regardless of permissions. Takes no parameters. Returns raw DNSFilter JSON.
dnsfilter_get_psa_integration_link details
dnsfilter_get_psa_integration_link details
[DNSFilter] Get the redirect link that starts DNSFilter's PSA integration flow for an organization. This is a GET with a SIDE EFFECT — DNSFilter creates the PSA integration record if one does not already exist, then returns the link — which is why it is not marked read-only. Not destructive: it only adds a record and hands back a URL that a human still has to complete. Returns raw DNSFilter JSON.
dnsfilter_update_current_user details
dnsfilter_update_current_user details
[DNSFilter] Update the profile of the account this connection authenticates as — first name, last name, phone. Not destructive: these are that account's own contact fields and every one can be set back. To change its password use dnsfilter_change_user_password. Returns raw DNSFilter JSON.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team