---
title: read-firewall-actions-by-project
product: vercel
url: /docs/rest-api/security/read-firewall-actions-by-project
canonical_url: "https://vercel.com/docs/rest-api/security/read-firewall-actions-by-project"
last_updated: 2026-10-04
type: reference
prerequisites:
  []
related:
  - /docs/rest-api
summary: Learn about read-firewall-actions-by-project on Vercel.
install_vercel_plugin: npx plugins add vercel/vercel-plugin
---

# Read Firewall Actions by Project

```http
GET /v1/security/firewall/events
```

Retrieve firewall actions for a project Rule names are resolved against the project's *current* active firewall configuration and the team's active rulesets, so a rule that has since been renamed reports its new name and one that has been deleted reports `null`. System rules such as `sys_dos_mitigation` and `ip_blocking` have no configured name and always report `null`. Filters (`ip`, `isActive`, `action`, `actionType`, `ruleKind`, `ruleId`, `hosts`) are ANDed across params and ORed within a repeated param. They are applied to the policies before `limit`/`cursor`, so pages only count matching policies. A policy with no matching requests yields no action row, so a page can hold fewer than `limit` actions; only `pagination.next` signals the end. A `cursor` is only valid with the filters it was issued for.

## Authentication

**bearerToken**: HTTP bearer

## Query parameters

| Name | Type | Required | Description |
|---|---|---|---|
| `sort` | string. enum: startTime:desc, startTime:asc | No |  |
| `limit` | number. min: 1; max: 5000 | No |  |
| `cursor` | string | No |  |
| `projectId` | string | Yes |  |
| `startTimestamp` | number | No |  |
| `endTimestamp` | number | No |  |
| `hosts` | string. maxLength: 10000 | No |  |
| `ip` | array | No |  |
| `isActive` | boolean | No |  |
| `action` | array | No |  |
| `actionType` | array | No |  |
| `ruleKind` | string. enum: system, custom | No |  |
| `ruleId` | array | No |  |
| `teamId` | string | No | The Team identifier to perform the request on behalf of. |
| `slug` | string | No | The Team slug to perform the request on behalf of. |


## Example request

### TypeScript

```typescript
const response = await fetch('https://api.vercel.com/v1/security/firewall/events?sort=string&limit=123&cursor=string&projectId=string&startTimestamp=123&endTimestamp=123&hosts=string&ip=[]&isActive=true&action=[]&actionType=[]&ruleKind=string&ruleId=[]&teamId=string&slug=string', {
  method: 'GET',
  headers: {
    'Authorization': 'Bearer YOUR_ACCESS_TOKEN',
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
```

### Next.js

```typescript
'use server';

export async function callEndpoint() {
  const response = await fetch('https://api.vercel.com/v1/security/firewall/events?sort=string&limit=123&cursor=string&projectId=string&startTimestamp=123&endTimestamp=123&hosts=string&ip=[]&isActive=true&action=[]&actionType=[]&ruleKind=string&ruleId=[]&teamId=string&slug=string', {
    method: 'GET',
    headers: {
      'Authorization': `Bearer ${process.env.VERCEL_ACCESS_TOKEN}`,
      'Content-Type': 'application/json',
    },
    next: { revalidate: 3600 }
  });

  if (!response.ok) {
    throw new Error('Request failed');
  }

  return response.json();
}
```

### cURL

```bash
curl -X GET 'https://api.vercel.com/v1/security/firewall/events?sort=string&limit=123&cursor=string&projectId=string&startTimestamp=123&endTimestamp=123&hosts=string&ip=[]&isActive=true&action=[]&actionType=[]&ruleKind=string&ruleId=[]&teamId=string&slug=string' \
  -H 'Authorization: Bearer YOUR_ACCESS_TOKEN' \
  -H 'Content-Type: application/json'
```

## Example response

```json
{
  "actions": [
    {
      "action": "string",
      "action_type": "string",
      "count": "123",
      "endTime": "string",
      "host": "string",
      "isActive": "false",
      "public_ip": "string",
      "ruleId": "example_id",
      "ruleName": "Example Name",
      "startTime": "string"
    }
  ],
  "pagination": {
    "hasMore": "false",
    "next": "string"
  }
}
```

## Responses

### 200: No description

Content-Type: `application/json`

```json
{
  "type": "object",
  "required": [
    "actions",
    "pagination"
  ],
  "properties": {
    "actions": {
      "type": "array",
      "items": {
        "type": "object",
        "required": [
          "action",
          "action_type",
          "count",
          "endTime",
          "host",
          "isActive",
          "public_ip",
          "ruleId",
          "ruleName",
          "startTime"
        ],
        "properties": {
          "action": {
            "type": "string"
          },
          "action_type": {
            "type": "string"
          },
          "count": {
            "type": "number"
          },
          "endTime": {
            "type": "string"
          },
          "host": {
            "type": "string"
          },
          "isActive": {
            "type": "boolean",
            "enum": [
              false,
              true
            ]
          },
          "public_ip": {
            "type": "string"
          },
          "ruleId": {
            "type": "string",
            "nullable": true
          },
          "ruleName": {
            "type": "string",
            "nullable": true
          },
          "startTime": {
            "type": "string"
          }
        }
      }
    },
    "pagination": {
      "type": "object",
      "required": [
        "hasMore",
        "next"
      ],
      "properties": {
        "hasMore": {
          "type": "boolean",
          "enum": [
            false,
            true
          ]
        },
        "next": {
          "type": "string",
          "description": "Pass as `cursor` to fetch the next page; null when there are no more.",
          "nullable": true
        }
      }
    }
  }
}
```

### 400: One of the provided values in the request query is invalid.

### 401: The request is not authorized.

### 403: You do not have permission to access this resource.

### 404: No description

### 408: No description

### 410: No description

### 500: No description

---

## Related

- [security endpoints](/docs/rest-api#security)

- [REST API overview](/docs/rest-api)

- [OpenAPI spec](https://vercel.com/openapi.json) (machine-readable, all endpoints)

---

[View full sitemap](/docs/sitemap)
