> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rafftechnologies.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List firewalls

> List the account's security groups. Pass `X-Project-ID` to scope to one project, or omit it to list across all accessible projects.


<sub>Updated May 8, 2026</sub>


## OpenAPI

````yaml GET /api/v1/security-groups
openapi: 3.0.3
info:
  title: Raff API
  description: >
    REST API for managing cloud infrastructure on Raff.


    ## Authentication

    Most endpoints require authentication via API key. Catalog endpoints under
    `/api/v1/public/` are open and require no authentication.


    ### API Key Authentication

    Include your API key in the `X-API-Key` header:
      ```
      curl -H "X-API-Key: YOUR_API_KEY" https://api.rafftechnologies.com/api/v1/vms
      ```

    ## Catalog

    Use the public catalog endpoints to discover available regions, OS
    templates, and pricing plans before creating resources:

    - `GET /api/v1/public/regions` — list available regions

    - `GET /api/v1/public/templates` — list OS templates (use the `id` as
    `template_id` when creating a VM)

    - `GET /api/v1/public/pricing/vm` — list VM pricing plans (use the `id` as
    `pricing_id` when creating a VM)

    - `GET /api/v1/public/pricing/volume` — volume storage pricing

    - `GET /api/v1/public/pricing/snapshot` — snapshot storage pricing

    - `GET /api/v1/public/pricing/backup` — backup storage pricing

    - `GET /api/v1/public/pricing/ip` — IP address pricing
  version: 1.0.0
  contact:
    name: Raff Technologies
    url: https://rafftechnologies.com
servers:
  - url: https://api.rafftechnologies.com
    description: Production
security:
  - ApiKeyAuth: []
tags:
  - name: Catalog
    description: >-
      Discover available regions, OS templates, and pricing plans. No
      authentication required.
  - name: Health
    description: Health check endpoints
  - name: Projects
    description: Organize resources into projects for billing and access control
  - name: Virtual Machines
    description: Create, manage, and control virtual machines
  - name: Networking
    description: >-
      Attach and detach VPCs, floating IPs, and security groups to VM network
      interfaces
  - name: Snapshots
    description: Point-in-time copies of VMs and volumes for quick rollback or cloning
  - name: Backups
    description: Scheduled and on-demand VM backups with restore capability
  - name: Backup Schedules
    description: Recurring daily or weekly backup schedules attached to a VM
  - name: SSH Keys
    description: Manage account-level SSH keys for VM provisioning
  - name: Members
    description: Account-level members — invite, list, update role, remove
  - name: Project Members
    description: Members of a specific project — same model as Members but project-scoped
  - name: Roles
    description: Custom roles bundling account or project permissions
  - name: Permissions
    description: List the catalog of permission strings used by roles
  - name: API Keys
    description: Create and manage API keys for programmatic access
  - name: Invitations
    description: Create and cancel email-based invitations to join the account or a project
paths:
  /api/v1/security-groups:
    get:
      tags:
        - Networking
      summary: List security groups
      description: >
        List the account's security groups. Pass `X-Project-ID` to scope to one
        project, or omit it to list across all accessible projects.
      operationId: listSecurityGroups
      parameters:
        - name: X-Project-ID
          in: header
          required: false
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: List of security groups
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/SecurityGroup'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    SecurityGroup:
      type: object
      description: >-
        A security group — a named set of inbound/outbound rules that can be
        attached to VM NICs.
      required:
        - id
        - name
        - rules
      properties:
        id:
          type: string
          format: uuid
          description: Security group ID.
        name:
          type: string
          example: web-server
        description:
          type: string
        rules:
          type: array
          items:
            $ref: '#/components/schemas/SecurityGroupRule'
        vm_count:
          type: integer
          description: Number of VM NICs currently using this security group.
        project_id:
          type: string
          format: uuid
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    SecurityGroupRule:
      type: object
      description: A single inbound or outbound rule.
      required:
        - protocol
        - rule_type
      properties:
        protocol:
          type: string
          enum:
            - TCP
            - UDP
            - ICMP
            - ICMPV6
            - IPSEC
            - ALL
          description: Network protocol.
        rule_type:
          type: string
          enum:
            - INBOUND
            - OUTBOUND
          description: Direction of traffic.
        range:
          type: string
          description: >-
            Port or port range. Single port (`80`) or range (`8000:9000`). Empty
            for ICMP/ALL.
          example: '80'
        ip:
          type: string
          description: Source/destination IP for the rule. Empty means any.
          example: 0.0.0.0
        size:
          type: integer
          description: >-
            CIDR block size (e.g. `24` for /24). Used with `ip` to allow a
            network range.
        icmp_type:
          type: integer
          description: ICMP message type (only for ICMP/ICMPV6 protocols).
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
  responses:
    Unauthorized:
      description: Authentication required
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: API key for authentication. Each key is bound to a specific account.

````