Skip to content
Start here

Create Token

client.Accounts.Tokens.New(ctx, params) (*TokenNewResponse, error)
POST/accounts/{account_id}/tokens

Create a new Account Owned API token.

Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
Accepted Permissions (at least one required)
Account API Tokens Write
ParametersExpand Collapse
params TokenNewParams
AccountID param.Field[string]

Path param: Account identifier tag.

maxLength32
minLength32
Name param.Field[string]

Body param: Token name.

maxLength120
Policies param.Field[[]TokenPolicy]

Body param: List of access policies assigned to the token.

ID string

Policy identifier.

Effect TokenPolicyEffect

Allow or deny operations against the resources.

One of the following:
const TokenPolicyEffectAllow TokenPolicyEffect = "allow"
const TokenPolicyEffectDeny TokenPolicyEffect = "deny"
PermissionGroups []TokenPolicyPermissionGroup

A set of permission groups that are specified to the policy.

ID string

Identifier of the permission group.

Meta TokenPolicyPermissionGroupsMetaOptional

Attributes associated to the permission group.

Category stringOptional

A category used to group permission groups.

Deprecated stringOptional

Indicates whether the permission group is deprecated.

Description stringOptional

Additional information about the permission group.

Editable stringOptional

Indicates whether the permission group can be edited.

EolAt TimeOptional

The planned end-of-life date and time, when provided.

formatdate-time
Label stringOptional

A label identifying the permission group.

Scopes stringOptional

The scope associated with the permission group.

Visibility stringOptional

Indicates the permission group’s availability or visibility.

Name stringOptional

Name of the permission group.

Resources TokenPolicyResourcesUnion

A list of resource names that the policy applies to.

One of the following:
type TokenPolicyResourcesIAMResourcesTypeObjectString map[string, string]

Map of simple string resource permissions

type TokenPolicyResourcesIAMResourcesTypeObjectNested map[string, map[string, string]]

Map of nested resource permissions

Condition param.Field[TokenNewParamsCondition]Optional

Body param

RequestIP TokenNewParamsConditionRequestIPOptional

Client IP restrictions.

List of IPv4/IPv6 CIDR addresses.

NotIn []TokenConditionCIDRListOptional

List of IPv4/IPv6 CIDR addresses.

ExpiresOn param.Field[Time]Optional

Body param: The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time
NotBefore param.Field[Time]Optional

Body param: The time before which the token MUST NOT be accepted for processing.

formatdate-time
ReturnsExpand Collapse
type TokenNewResponse struct{…}
ID stringOptional

Token identifier tag.

maxLength32
Condition TokenNewResponseConditionOptional
RequestIP TokenNewResponseConditionRequestIPOptional

Client IP restrictions.

List of IPv4/IPv6 CIDR addresses.

NotIn []TokenConditionCIDRListOptional

List of IPv4/IPv6 CIDR addresses.

CreatorEmailAtCreation stringOptional

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

maxLength90
ExpiresOn TimeOptional

The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time
IssuedOn TimeOptional

The time on which the token was created.

formatdate-time
LastUsedOn TimeOptional

Last time the token was used.

formatdate-time
ModifiedOn TimeOptional

Last time the token was modified.

formatdate-time
Name stringOptional

Token name.

maxLength120
NotBefore TimeOptional

The time before which the token MUST NOT be accepted for processing.

formatdate-time
Policies []TokenPolicyOptional

List of access policies assigned to the token.

ID string

Policy identifier.

Effect TokenPolicyEffect

Allow or deny operations against the resources.

One of the following:
const TokenPolicyEffectAllow TokenPolicyEffect = "allow"
const TokenPolicyEffectDeny TokenPolicyEffect = "deny"
PermissionGroups []TokenPolicyPermissionGroup

A set of permission groups that are specified to the policy.

ID string

Identifier of the permission group.

Meta TokenPolicyPermissionGroupsMetaOptional

Attributes associated to the permission group.

Category stringOptional

A category used to group permission groups.

Deprecated stringOptional

Indicates whether the permission group is deprecated.

Description stringOptional

Additional information about the permission group.

Editable stringOptional

Indicates whether the permission group can be edited.

EolAt TimeOptional

The planned end-of-life date and time, when provided.

formatdate-time
Label stringOptional

A label identifying the permission group.

Scopes stringOptional

The scope associated with the permission group.

Visibility stringOptional

Indicates the permission group’s availability or visibility.

Name stringOptional

Name of the permission group.

Resources TokenPolicyResourcesUnion

A list of resource names that the policy applies to.

One of the following:
type TokenPolicyResourcesIAMResourcesTypeObjectString map[string, string]

Map of simple string resource permissions

type TokenPolicyResourcesIAMResourcesTypeObjectNested map[string, map[string, string]]

Map of nested resource permissions

ProvisionerID stringOptional

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when provisioner_type is present and null when the identifier is unavailable.

ProvisionerType stringOptional

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

Status TokenNewResponseStatusOptional

Status of the token.

One of the following:
const TokenNewResponseStatusActive TokenNewResponseStatus = "active"
const TokenNewResponseStatusDisabled TokenNewResponseStatus = "disabled"
const TokenNewResponseStatusExpired TokenNewResponseStatus = "expired"
Value TokenValueOptional

The token value.

maxLength80
minLength40

Create Token

package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/accounts"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/shared"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  token, err := client.Accounts.Tokens.New(context.TODO(), accounts.TokenNewParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
    Name: cloudflare.F("readonly token"),
    Policies: cloudflare.F([]shared.TokenPolicyParam{shared.TokenPolicyParam{
      Effect: cloudflare.F(shared.TokenPolicyEffectAllow),
      PermissionGroups: cloudflare.F([]shared.TokenPolicyPermissionGroupParam{shared.TokenPolicyPermissionGroupParam{
        ID: cloudflare.F("c8fed203ed3043cba015a93ad1616f1f"),
      }, shared.TokenPolicyPermissionGroupParam{
        ID: cloudflare.F("82e64a83756745bbbb1c9c2701bf816b"),
      }}),
      Resources: cloudflare.F[shared.TokenPolicyResourcesUnionParam](shared.TokenPolicyResourcesIAMResourcesTypeObjectStringParam(map[string]string{
      "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*",
      })),
    }}),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", token.ID)
}
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "ed17574386854bf78a67040be0a770b0",
    "condition": {
      "request_ip": {
        "in": [
          "123.123.123.0/24",
          "2606:4700::/32"
        ],
        "not_in": [
          "123.123.123.100/24",
          "2606:4700:4700::/48"
        ]
      }
    },
    "creator_email_at_creation": "user@example.com",
    "expires_on": "2020-01-01T00:00:00Z",
    "issued_on": "2018-07-01T05:20:00Z",
    "last_used_on": "2020-01-02T12:34:00Z",
    "modified_on": "2018-07-02T05:20:00Z",
    "name": "readonly token",
    "not_before": "2018-07-01T05:20:00Z",
    "policies": [
      {
        "id": "f267e341f3dd4697bd3b9f71dd96247f",
        "effect": "allow",
        "permission_groups": [
          {
            "id": "c8fed203ed3043cba015a93ad1616f1f",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "load_balancer_admin",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Zone Read"
          },
          {
            "id": "82e64a83756745bbbb1c9c2701bf816b",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "fbm_user",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Magic Network Monitoring"
          }
        ],
        "resources": {
          "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
        }
      }
    ],
    "provisioner_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
    "provisioner_type": "com.cloudflare.api.oauthtoken",
    "status": "active",
    "value": "8M7wS6hCpXVc-DoRnPPY_UCWPgy8aea4Wy6kCe5T"
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "ed17574386854bf78a67040be0a770b0",
    "condition": {
      "request_ip": {
        "in": [
          "123.123.123.0/24",
          "2606:4700::/32"
        ],
        "not_in": [
          "123.123.123.100/24",
          "2606:4700:4700::/48"
        ]
      }
    },
    "creator_email_at_creation": "user@example.com",
    "expires_on": "2020-01-01T00:00:00Z",
    "issued_on": "2018-07-01T05:20:00Z",
    "last_used_on": "2020-01-02T12:34:00Z",
    "modified_on": "2018-07-02T05:20:00Z",
    "name": "readonly token",
    "not_before": "2018-07-01T05:20:00Z",
    "policies": [
      {
        "id": "f267e341f3dd4697bd3b9f71dd96247f",
        "effect": "allow",
        "permission_groups": [
          {
            "id": "c8fed203ed3043cba015a93ad1616f1f",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "load_balancer_admin",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Zone Read"
          },
          {
            "id": "82e64a83756745bbbb1c9c2701bf816b",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "fbm_user",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Magic Network Monitoring"
          }
        ],
        "resources": {
          "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
        }
      }
    ],
    "provisioner_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
    "provisioner_type": "com.cloudflare.api.oauthtoken",
    "status": "active",
    "value": "8M7wS6hCpXVc-DoRnPPY_UCWPgy8aea4Wy6kCe5T"
  }
}