Skip to content
Start here

Update a payment rule

PATCH/zones/{zone_id}/monetization/rules/{rule_id}

Applies a partial update to a single Payment Required rule. Only the fields present in the request body are changed; omitted fields keep their current values. Returns the full resulting rule collection.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Path ParametersExpand Collapse
zone_id: string

The unique ID of the zone.

rule_id: string
maxLength32
Body ParametersJSONExpand Collapse
address: optional string

0x-prefixed 20-byte hexadecimal Ethereum address. Mixed-case addresses must carry a valid EIP-55 checksum; all-lowercase or all-uppercase addresses are also accepted. The effective address must pass wallet screening whenever the rule is patched.

description: optional string
maxLength512
enabled: optional boolean
expression: optional string

Wirefilter expression identifying the requests that require payment. Forwarded verbatim to the Rulesets API, which validates its syntax.

price: optional string

Price in the smallest indivisible unit of the configured payment token, encoded as a decimal string. Must be a canonical decimal integer in [1000, 100000000]: no leading zeros, and a bare JSON number is rejected. The price is required for the fixed-price schemes (“exact” and “upto”) and must be at least 1000, the smallest amount the payment facilitator can settle ($0.001 for a 6-decimal token such as USDC), and at most 100000000 ($100 for a 6-decimal token). When the scheme is “origin_controlled” the origin server sets pricing dynamically and the rule carries no price: the field must be omitted — any provided value, including “0”, is rejected because it would not be enforced. Responses always encode this as a string and omit it for “origin_controlled” rules; the pattern matches exactly the set of values the server accepts.

scheme: optional "exact" or "upto" or "origin_controlled"

X402 payment scheme. “exact” requires the specified payment amount; “upto” permits a payment up to the specified amount; “origin_controlled” lets the origin server set pricing dynamically, in which case the rule carries no price and the price field must be omitted.

One of the following:
"exact"
"upto"
"origin_controlled"
ReturnsExpand Collapse
errors: array of object { code, message }
code: optional number
message: optional string
messages: array of object { code, message }
code: optional number
message: optional string
result: MonetizationRuleCollection { rules }

The zone’s payment rules. Mirrors the shape of the ruleset submitted to the deploy endpoint, so the response can be read back as the desired state.

rules: array of MonetizationRule

The zone’s payment rules, in the order they are evaluated. Empty when the zone has no payment rules.

One of the following:
MonetizationRulesMonetizationRuleInputFixedPrice = MonetizationRuleInputFixedPrice { address, expression, price, 4 more }

Payment rule with a fixed price set at configuration time.

id: string

The server-assigned unique ID of the payment rule. Stable across full-ruleset replacements.

maxLength32
MonetizationRulesMonetizationRuleInputOriginControlled = MonetizationRuleInputOriginControlled { address, expression, scheme, 3 more }

Payment rule whose price the origin server sets dynamically. The rule carries no price and the price field must be omitted — any provided value, including “0”, is rejected because it would not be enforced.

id: string

The server-assigned unique ID of the payment rule. Stable across full-ruleset replacements.

maxLength32
success: true

Update a payment rule

curl https://api.cloudflare.com/client/v4/zones/$ZONE_ID/monetization/rules/$RULE_ID \
    -X PATCH \
    -H 'Content-Type: application/json' \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
    -d '{
          "address": "0x1234567890abcdef1234567890abcdef12345678===",
          "description": "Premium API endpoint",
          "expression": "(http.request.uri.path eq \\"/premium\\" and http.request.method in {\\"GET\\" \\"POST\\"})",
          "price": "250000",
          "scheme": "exact"
        }'
{
  "errors": [
    {
      "code": 0,
      "message": "message"
    }
  ],
  "messages": [
    {
      "code": 0,
      "message": "message"
    }
  ],
  "result": {
    "rules": [
      {
        "address": "0x1234567890abcdef1234567890abcdef12345678===",
        "expression": "(http.request.uri.path eq \"/premium\" and http.request.method in {\"GET\" \"POST\"})",
        "price": "250000",
        "scheme": "exact",
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "description": "Premium API endpoint",
        "enabled": true
      }
    ]
  },
  "success": true
}
Returns Examples
{
  "errors": [
    {
      "code": 0,
      "message": "message"
    }
  ],
  "messages": [
    {
      "code": 0,
      "message": "message"
    }
  ],
  "result": {
    "rules": [
      {
        "address": "0x1234567890abcdef1234567890abcdef12345678===",
        "expression": "(http.request.uri.path eq \"/premium\" and http.request.method in {\"GET\" \"POST\"})",
        "price": "250000",
        "scheme": "exact",
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "description": "Premium API endpoint",
        "enabled": true
      }
    ]
  },
  "success": true
}