> ## Documentation Index
> Fetch the complete documentation index at: https://docs.chainstack.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a node access rule with the Chainstack Platform API v2

> Restrict a node endpoint to an IP address or origin using the Chainstack Platform API v2. Send a POST request to /v2/nodes/{node_id}/access-rules/ with the rule type and value.



## OpenAPI

````yaml post /v2/nodes/{node_id}/access-rules/
openapi: 3.0.3
info:
  x-logo:
    url: https://chainstack.com/assets/docs/api-docs-logo.svg
    backgroundColor: '#F5F8FC'
    altText: Chainstack
  title: 💙 CHAINSTACK PLATFORM API
  version: v2
  contact:
    name: API Support
    email: support@chainstack.com
  description: >
    A set of API endpoints to operate and manage the platform resources.<br>

    See also a [quick API
    tutorial](https://docs.chainstack.com/reference/quick-tutorial).
servers:
  - url: https://api.chainstack.com
    description: API endpoint
security: []
paths:
  /v2/nodes/{node_id}/access-rules/:
    parameters:
      - $ref: '#/components/parameters/NodeIdPath'
    post:
      tags:
        - Node access rules V2
      summary: Create node access rule
      description: >
        Create an access rule on a node. A new rule starts as `deactivated` —
        activate it with [Update node access
        rule](/reference/chainstack-platform-api-v2-update-node-access-rule) or
        [Bulk update node access rules
        status](/reference/chainstack-platform-api-v2-bulk-update-node-access-rules-status)
        to enforce it.

        <br> Access rules are available only on [Global
        Nodes](/docs/global-elastic-node), and your organization's plan must
        include them. Otherwise, the request returns `403`.
      operationId: createNodeAccessRuleV2
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NodeAccessRuleCreateV2'
            examples:
              ip:
                summary: Allow an IP address
                value:
                  type: ip
                  value: 203.0.113.10
              origin:
                summary: Allow an origin and its subdomains
                value:
                  type: origin
                  value: '*.example.com'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NodeAccessRuleV2'
              examples:
                rule:
                  value:
                    id: NAR-123-456-789
                    node_id: ND-123-456-789
                    type: ip
                    value: 203.0.113.10
                    status: deactivated
                    created_at: '2026-10-01T09:30:00.000000Z'
                    updated_at: '2026-10-01T09:30:00.000000Z'
          description: ''
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '404':
          $ref: '#/components/responses/NotFoundError'
      security:
        - APIKeyAuthentication: []
components:
  parameters:
    NodeIdPath:
      name: node_id
      in: path
      required: true
      description: ID of the node.
      schema:
        type: string
        example: ND-123-456-789
  schemas:
    NodeAccessRuleCreateV2:
      type: object
      required:
        - type
        - value
      properties:
        type:
          type: string
          enum:
            - ip
            - origin
          description: >
            Rule type:

            * `ip` — allow requests from an IP address.

            * `origin` — allow requests whose HTTP `Origin` header matches the
            value.
        value:
          type: string
          description: >
            The value to allow:

            * For `ip` — an IPv4 or IPv6 address, for example `203.0.113.10`.

            * For `origin` — a host name (`example.com`), a host name with a
            wildcard for its subdomains (`*.example.com`), or `*` for any
            origin. Up to 65 characters, no spaces.
          example: 203.0.113.10
    NodeAccessRuleV2:
      type: object
      properties:
        id:
          type: string
          readOnly: true
          description: ID of the access rule.
          example: NAR-123-456-789
        node_id:
          type: string
          readOnly: true
          description: ID of the node the rule belongs to.
          example: ND-123-456-789
        type:
          type: string
          readOnly: true
          enum:
            - ip
            - origin
          description: >
            Rule type:

            * `ip` — allow requests from an IP address.

            * `origin` — allow requests whose HTTP `Origin` header matches the
            value.
        value:
          type: string
          readOnly: true
          description: The allowed IP address or origin.
          example: 203.0.113.10
        status:
          type: string
          readOnly: true
          enum:
            - activated
            - deactivated
          description: Whether the rule is enforced. New rules start as `deactivated`.
        created_at:
          type: string
          format: date-time
          readOnly: true
          description: When the rule was created.
        updated_at:
          type: string
          format: date-time
          readOnly: true
          description: When the rule was last changed.
  responses:
    ValidationError:
      description: Validation error.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: object
                properties:
                  code:
                    type: string
                    description: A string indicating the kind of error.
                  message:
                    type: string
                    description: A human-readable description of the error.
                  fields:
                    type: object
                    additionalProperties:
                      type: array
                      items:
                        type: string
                    description: Optional. Field-level validation errors.
    UnauthorizedError:
      description: Authentication credentials were missing or incorrect.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: object
                properties:
                  code:
                    type: string
                    description: A string indicating the kind of error.
                  message:
                    type: string
                    description: A human-readable description of the error.
    ForbiddenError:
      description: The request is not allowed with the current permissions.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: object
                properties:
                  code:
                    type: string
                    description: A string indicating the kind of error.
                  message:
                    type: string
                    description: A human-readable description of the error.
    NotFoundError:
      description: >-
        Object does not exist or caller has insufficient permissions to access
        it.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: object
                properties:
                  code:
                    type: string
                    description: A string indicating the kind of error.
                  message:
                    type: string
                    description: A human-readable description of the error.
  securitySchemes:
    APIKeyAuthentication:
      type: http
      scheme: bearer
      description: >
        Chainstack API uses [API
        keys](https://docs.chainstack.com/reference/platform-api-getting-started)
        to authenticate requests. You can view and manage your API keys in the
        platform UI.

        Your API keys carry many privileges, so be sure to keep them secure!

        Provide your API key as the `Authorization` header. The value of the
        header consists of `Bearer` prefix and secret key generated through the
        platform UI.


        ```bash

        curl -X GET 'https://api.chainstack.com/v1/organization/' \

        --header 'Authorization: Bearer
        FX7CWlLg.FMpAO8cgCX2N7s41EncRru2nb5CmTZUt'

        ```


        All API requests must be made over HTTPS.

````