---
title: Zero Trust
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Zero Trust

#### Zero TrustDevices

##### [List devices (deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/methods/list)

Deprecated

client.ZeroTrust.Devices.List(ctx, query) (\*SinglePage\[[Device](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices

##### [Get device (deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/methods/get)

Deprecated

client.ZeroTrust.Devices.Get(ctx, deviceID, query) (\*[DeviceGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices%20%3E%20(model)%20DeviceGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/{device\_id}

##### ModelsExpand Collapse

<details>

<summary>

type Device struct{…}

</summary>

ID stringOptional

Registration ID. Equal to Device ID except for accounts which enabled <a href="https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/windows-multiuser/">multi-user mode</a>.

maxLength36

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Created TimeOptional

When the device was created.

formatdate-time

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

Deleted boolOptional

True if the device was deleted.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20deleted">Link to this property</a>

<details>

<summary>

DeviceType DeviceDeviceTypeOptional

</summary>

One of the following:

const DeviceDeviceTypeWindows DeviceDeviceType = "windows"

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type%20%3E%20(member)%200">Link to this property</a>

const DeviceDeviceTypeMac DeviceDeviceType = "mac"

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type%20%3E%20(member)%201">Link to this property</a>

const DeviceDeviceTypeLinux DeviceDeviceType = "linux"

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type%20%3E%20(member)%202">Link to this property</a>

const DeviceDeviceTypeAndroid DeviceDeviceType = "android"

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type%20%3E%20(member)%203">Link to this property</a>

const DeviceDeviceTypeIos DeviceDeviceType = "ios"

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type%20%3E%20(member)%204">Link to this property</a>

const DeviceDeviceTypeChromeos DeviceDeviceType = "chromeos"

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20device_type">Link to this property</a>

IP stringOptional

IPv4 or IPv6 address.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

Key stringOptional

The device’s public key.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20key">Link to this property</a>

LastSeen TimeOptional

When the device last connected to Cloudflare services.

formatdate-time

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20last_seen">Link to this property</a>

MacAddress stringOptional

The device mac address.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20mac_address">Link to this property</a>

Manufacturer stringOptional

The device manufacturer name.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20manufacturer">Link to this property</a>

Model stringOptional

The device model name.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20model">Link to this property</a>

Name stringOptional

The device name.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

OSDistroName stringOptional

The Linux distro name.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20os_distro_name">Link to this property</a>

OSDistroRevision stringOptional

The Linux distro revision.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20os_distro_revision">Link to this property</a>

OSVersion stringOptional

The operating system version.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20os_version">Link to this property</a>

OSVersionExtra stringOptional

Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20os_version_extra">Link to this property</a>

RevokedAt TimeOptional

When the device was revoked.

formatdate-time

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20revoked_at">Link to this property</a>

SerialNumber stringOptional

The device serial number.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20serial_number">Link to this property</a>

Updated TimeOptional

When the device was updated.

formatdate-time

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20updated">Link to this property</a>

<details>

<summary>

User DeviceUserOptional

</summary>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20user%20%3E%20(property)%20id">Link to this property</a>

Email stringOptional

The contact email address of the user.

maxLength90

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20user%20%3E%20(property)%20email">Link to this property</a>

Name stringOptional

The enrolled device user’s name.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20user%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

Version stringOptional

The WARP client version.

<a href="#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices%20%3E%20(model)%20device%20%3E%20(schema)>)

#### Zero TrustDevicesDevices

##### [List devices](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/devices/methods/list)

client.ZeroTrust.Devices.Devices.List(ctx, params) (\*CursorPagination\[[DeviceDeviceListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.devices%20%3E%20(model)%20DeviceDeviceListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/physical-devices

##### [Get device](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/devices/methods/get)

client.ZeroTrust.Devices.Devices.Get(ctx, deviceID, params) (\*[DeviceDeviceGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.devices%20%3E%20(model)%20DeviceDeviceGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/physical-devices/{device\_id}

##### [Delete device](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/devices/methods/delete)

client.ZeroTrust.Devices.Devices.Delete(ctx, deviceID, body) (\*[DeviceDeviceDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.devices%20%3E%20(model)%20DeviceDeviceDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/physical-devices/{device\_id}

##### [Revoke device registrations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/devices/methods/revoke)

Deprecated

client.ZeroTrust.Devices.Devices.Revoke(ctx, deviceID, body) (\*[DeviceDeviceRevokeResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.devices%20%3E%20(model)%20DeviceDeviceRevokeResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/physical-devices/{device\_id}/revoke

#### Zero TrustDevicesResilience

#### Zero TrustDevicesResilienceGlobal WARP Override

##### [Get Global Disconnect](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/resilience/subresources/global_warp_override/methods/get)

client.ZeroTrust.Devices.Resilience.GlobalWARPOverride.Get(ctx, query) (\*[DeviceResilienceGlobalWARPOverrideGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.resilience.global_warp_override%20%3E%20(model)%20DeviceResilienceGlobalWARPOverrideGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/resilience/disconnect

##### [Set Global Disconnect](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/resilience/subresources/global_warp_override/methods/create)

client.ZeroTrust.Devices.Resilience.GlobalWARPOverride.New(ctx, params) (\*[DeviceResilienceGlobalWARPOverrideNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.resilience.global_warp_override%20%3E%20(model)%20DeviceResilienceGlobalWARPOverrideNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/resilience/disconnect

#### Zero TrustDevicesRegistrations

##### [List registrations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/registrations/methods/list)

client.ZeroTrust.Devices.Registrations.List(ctx, params) (\*CursorPagination\[[DeviceRegistrationListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.registrations%20%3E%20(model)%20DeviceRegistrationListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/registrations

##### [Get registration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/registrations/methods/get)

client.ZeroTrust.Devices.Registrations.Get(ctx, registrationID, params) (\*[DeviceRegistrationGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.registrations%20%3E%20(model)%20DeviceRegistrationGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/registrations/{registration\_id}

##### [Delete registration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/registrations/methods/delete)

client.ZeroTrust.Devices.Registrations.Delete(ctx, registrationID, body) (\*[DeviceRegistrationDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.registrations%20%3E%20(model)%20DeviceRegistrationDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/registrations/{registration\_id}

##### [Delete registrations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/registrations/methods/bulk_delete)

client.ZeroTrust.Devices.Registrations.BulkDelete(ctx, params) (\*[DeviceRegistrationBulkDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.registrations%20%3E%20(model)%20DeviceRegistrationBulkDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/registrations

##### [Revoke registrations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/registrations/methods/revoke)

Deprecated

client.ZeroTrust.Devices.Registrations.Revoke(ctx, params) (\*[DeviceRegistrationRevokeResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.registrations%20%3E%20(model)%20DeviceRegistrationRevokeResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/registrations/revoke

##### [Unrevoke registrations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/registrations/methods/unrevoke)

Deprecated

client.ZeroTrust.Devices.Registrations.Unrevoke(ctx, params) (\*[DeviceRegistrationUnrevokeResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.registrations%20%3E%20(model)%20DeviceRegistrationUnrevokeResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/registrations/unrevoke

#### Zero TrustDevicesDEX Tests

##### [List Device DEX tests](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/list)

client.ZeroTrust.Devices.DEXTests.List(ctx, params) (\*V4PagePaginationArray\[[SchemaHTTP](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/dex/devices/dex\_tests

##### [Get Device DEX test](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/get)

client.ZeroTrust.Devices.DEXTests.Get(ctx, dexTestID, query) (\*[SchemaHTTP](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/dex/devices/dex\_tests/{dex\_test\_id}

##### [Create Device DEX test](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/create)

client.ZeroTrust.Devices.DEXTests.New(ctx, params) (\*[SchemaHTTP](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/dex/devices/dex\_tests

##### [Update Device DEX test](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/update)

client.ZeroTrust.Devices.DEXTests.Update(ctx, dexTestID, params) (\*[SchemaHTTP](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/dex/devices/dex\_tests/{dex\_test\_id}

##### [Delete Device DEX test](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/delete)

client.ZeroTrust.Devices.DEXTests.Delete(ctx, dexTestID, body) (\*[DeviceDEXTestDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20DeviceDEXTestDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/dex/devices/dex\_tests/{dex\_test\_id}

##### ModelsExpand Collapse

<details>

<summary>

type SchemaData struct{…}

The configuration object which contains the details for the WARP client to conduct the test.

</summary>

Host string

The desired endpoint to test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)%20%3E%20(property)%20host">Link to this property</a>

<details>

<summary>

Kind SchemaDataKind

The type of test.

</summary>

One of the following:

const SchemaDataKindHTTP SchemaDataKind = "http"

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

const SchemaDataKindTraceroute SchemaDataKind = "traceroute"

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)%20%3E%20(property)%20kind">Link to this property</a>

Method SchemaDataMethodOptional

The HTTP request method type.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)%20%3E%20(property)%20method">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)>)

<details>

<summary>

type SchemaHTTP struct{…}

</summary>

Data <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_data%20%3E%20(schema)">SchemaData</a>

The configuration object which contains the details for the WARP client to conduct the test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

Enabled bool

Determines whether or not the test is active.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Interval string

How often the test will run.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20interval">Link to this property</a>

Name string

The name of the DEX test. Must be unique.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Created TimeOptional

Date the test was created, in RFC 3339 format.

formatdate-time

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

Description stringOptional

Additional details about the test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

TargetPolicies \[]SchemaHTTPTargetPolicyOptional

DEX rules targeted by this test

</summary>

ID string

The id of the DEX rule.

maxLength36

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20target_policies%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

Default boolOptional

Whether the DEX rule is the account default.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20target_policies%20%3E%20(items)%20%3E%20(property)%20default">Link to this property</a>

Name stringOptional

The name of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20target_policies%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20target_policies">Link to this property</a>

Targeted boolOptional

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20targeted">Link to this property</a>

TestID stringOptional

The unique identifier for the test.

maxLength32

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20test_id">Link to this property</a>

Updated TimeOptional

Date the test was last updated, in RFC 3339 format.

formatdate-time

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)%20%3E%20(property)%20updated">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(model)%20schema_http%20%3E%20(schema)>)

#### Zero TrustDevicesIP Profiles

##### [List IP profiles](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/list)

client.ZeroTrust.Devices.IPProfiles.List(ctx, params) (\*V4PagePaginationArray\[[IPProfile](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/ip-profiles

##### [Get IP profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/get)

client.ZeroTrust.Devices.IPProfiles.Get(ctx, profileID, query) (\*[IPProfile](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/ip-profiles/{profile\_id}

##### [Create IP profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/create)

client.ZeroTrust.Devices.IPProfiles.New(ctx, params) (\*[IPProfile](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/ip-profiles

##### [Update IP profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/update)

client.ZeroTrust.Devices.IPProfiles.Update(ctx, profileID, params) (\*[IPProfile](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)>), error)

PATCH/accounts/{account\_id}/devices/ip-profiles/{profile\_id}

##### [Delete IP profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/delete)

client.ZeroTrust.Devices.IPProfiles.Delete(ctx, profileID, body) (\*[DeviceIPProfileDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20DeviceIPProfileDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/ip-profiles/{profile\_id}

##### ModelsExpand Collapse

<details>

<summary>

type IPProfile struct{…}

</summary>

ID string

The ID of the Device IP profile.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

CreatedAt string

The RFC3339Nano timestamp when the Device IP profile was created.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Description string

An optional description of the Device IP profile.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

Enabled bool

Whether the Device IP profile is enabled.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Match string

The wirefilter expression to match registrations. Available values: “identity.name”, “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.saml\_attributes”.

maxLength10000

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20match">Link to this property</a>

Name string

A user-friendly name for the Device IP profile.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Precedence int64

The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20precedence">Link to this property</a>

SubnetID string

The ID of the Subnet.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20subnet_id">Link to this property</a>

UpdatedAt string

The RFC3339Nano timestamp when the Device IP profile was last updated.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(model)%20ip_profile%20%3E%20(schema)>)

#### Zero TrustDevicesDeployment Groups

##### [List deployment groups](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/list)

client.ZeroTrust.Devices.DeploymentGroups.List(ctx, params) (\*V4PagePaginationArray\[[DeploymentGroup](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/deployment-groups

##### [Get deployment group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/get)

client.ZeroTrust.Devices.DeploymentGroups.Get(ctx, groupID, query) (\*[DeploymentGroup](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/deployment-groups/{group\_id}

##### [Create deployment group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/create)

client.ZeroTrust.Devices.DeploymentGroups.New(ctx, params) (\*[DeploymentGroup](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/deployment-groups

##### [Update deployment group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/edit)

client.ZeroTrust.Devices.DeploymentGroups.Edit(ctx, groupID, params) (\*[DeploymentGroup](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)>), error)

PATCH/accounts/{account\_id}/devices/deployment-groups/{group\_id}

##### [Delete deployment group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/delete)

client.ZeroTrust.Devices.DeploymentGroups.Delete(ctx, groupID, body) (\*[DeviceDeploymentGroupDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20DeviceDeploymentGroupDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/deployment-groups/{group\_id}

##### ModelsExpand Collapse

<details>

<summary>

type DeploymentGroup struct{…}

</summary>

ID string

The ID of the deployment group.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

CreatedAt string

The RFC3339Nano timestamp when the deployment group was created.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Name string

A user-friendly name for the deployment group.

maxLength255

minLength1

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

UpdatedAt string

The RFC3339Nano timestamp when the deployment group was last updated.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

VersionConfig \[]DeploymentGroupVersionConfig

Contains version configurations for different target environments.

</summary>

TargetEnvironment string

The target environment for the client version (e.g., windows, macos).

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20version_config%20%3E%20(items)%20%3E%20(property)%20target_environment">Link to this property</a>

Version string

The specific client version to deploy.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20version_config%20%3E%20(items)%20%3E%20(property)%20version">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20version_config">Link to this property</a>

PolicyIDs \[]stringOptional

Contains a list of policy IDs assigned to this deployment group.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)%20%3E%20(property)%20policy_ids">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(model)%20deployment_group%20%3E%20(schema)>)

#### Zero TrustDevicesNetworks

##### [List your device managed networks](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/networks/methods/list)

client.ZeroTrust.Devices.Networks.List(ctx, query) (\*SinglePage\[[DeviceNetwork](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/networks

##### [Get device managed network details](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/networks/methods/get)

client.ZeroTrust.Devices.Networks.Get(ctx, networkID, query) (\*[DeviceNetwork](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/networks/{network\_id}

##### [Create a device managed network](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/networks/methods/create)

client.ZeroTrust.Devices.Networks.New(ctx, params) (\*[DeviceNetwork](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/networks

##### [Update a device managed network](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/networks/methods/update)

client.ZeroTrust.Devices.Networks.Update(ctx, networkID, params) (\*[DeviceNetwork](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/devices/networks/{network\_id}

##### [Delete a device managed network](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/networks/methods/delete)

client.ZeroTrust.Devices.Networks.Delete(ctx, networkID, body) (\*SinglePage\[[DeviceNetwork](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)>)], error)

DELETE/accounts/{account\_id}/devices/networks/{network\_id}

##### ModelsExpand Collapse

<details>

<summary>

type DeviceNetwork struct{…}

</summary>

<details>

<summary>

Config DeviceNetworkConfigOptional

The configuration object containing information for the WARP client to detect the managed network.

</summary>

TLSSockaddr string

A network address of the form “host:port” that the WARP client will use to detect the presence of a TLS host.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20tls_sockaddr">Link to this property</a>

Sha256 stringOptional

The SHA-256 hash of the TLS certificate presented by the host found at tls\_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20sha256">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

Name stringOptional

The name of the device managed network. This name must be unique.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

NetworkID stringOptional

API UUID.

maxLength36

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)%20%3E%20(property)%20network_id">Link to this property</a>

Type DeviceNetworkTypeOptional

The type of device managed network.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(model)%20device_network%20%3E%20(schema)>)

#### Zero TrustDevicesFleet Status

##### [Get the latest status of a device.](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/fleet_status/methods/get)

client.ZeroTrust.Devices.FleetStatus.Get(ctx, deviceID, params) (\*[DeviceFleetStatusGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.fleet_status%20%3E%20(model)%20DeviceFleetStatusGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/dex/devices/{device\_id}/fleet-status/live

#### Zero TrustDevicesPolicies

##### ModelsExpand Collapse

<details>

<summary>

type DevicePolicyCertificates struct{…}

</summary>

Enabled bool

The current status of the device policy certificate provisioning feature for WARP clients.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20device_policy_certificates%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20device_policy_certificates%20%3E%20(schema)>)

<details>

<summary>

type FallbackDomain struct{…}

</summary>

Suffix string

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)%20%3E%20(property)%20suffix">Link to this property</a>

Description stringOptional

A description of the fallback domain, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

DNSServer \[]stringOptional

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)%20%3E%20(property)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)>)

<details>

<summary>

type SettingsPolicy struct{…}

</summary>

AllowModeSwitch boolOptional

Whether to allow the user to switch WARP between modes.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20allow_mode_switch">Link to this property</a>

AllowUpdates boolOptional

Whether to receive update notifications when a new version of the client is available.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20allow_updates">Link to this property</a>

AllowedToLeave boolOptional

Whether to allow devices to leave the organization.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20allowed_to_leave">Link to this property</a>

AutoConnect float64Optional

The amount of time in seconds to reconnect after having been disabled.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20auto_connect">Link to this property</a>

<details>

<summary>

BrowserExtensionConfig SettingsPolicyBrowserExtensionConfigOptional

Browser extension proxy settings. Required when profile\_type is browser\_extension and invalid for WARP profiles.

</summary>

<details>

<summary>

ProxyControl SettingsPolicyBrowserExtensionConfigProxyControl

Whether the user may disable the browser extension proxy.

</summary>

One of the following:

const SettingsPolicyBrowserExtensionConfigProxyControlUnlocked SettingsPolicyBrowserExtensionConfigProxyControl = "unlocked"

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20browser_extension_config%20%3E%20(property)%20proxy_control%20%3E%20(member)%200">Link to this property</a>

const SettingsPolicyBrowserExtensionConfigProxyControlLocked SettingsPolicyBrowserExtensionConfigProxyControl = "locked"

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20browser_extension_config%20%3E%20(property)%20proxy_control%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20browser_extension_config%20%3E%20(property)%20proxy_control">Link to this property</a>

ProxyEnabled bool

Whether the browser extension proxy is active.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20browser_extension_config%20%3E%20(property)%20proxy_enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20browser_extension_config">Link to this property</a>

CaptivePortal float64Optional

Turn on the captive portal after the specified amount of time.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20captive_portal">Link to this property</a>

Default boolOptional

Whether the policy is the account default. WARP group profiles cannot set this field.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20default">Link to this property</a>

Description stringOptional

A description of the policy.

maxLength500

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

DisableAutoFallback boolOptional

If the <code>dns_server</code> field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to <code>true</code>.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20disable_auto_fallback">Link to this property</a>

<details>

<summary>

DNSSearchSuffixes \[]SettingsPolicyDNSSearchSuffixOptional

List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.

</summary>

Suffix string

The DNS search suffix to append when resolving short hostnames.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20dns_search_suffixes%20%3E%20(items)%20%3E%20(property)%20suffix">Link to this property</a>

Description stringOptional

A description of the DNS search suffix.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20dns_search_suffixes%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20dns_search_suffixes">Link to this property</a>

Enabled boolOptional

Whether the policy will be applied to matching devices.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Exclude \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)">SplitTunnelExclude</a>Optional

List of routes excluded in the WARP client’s tunnel.

</summary>

One of the following:

<details>

<summary>

type SplitTunnelExcludeTeamsDevicesExcludeSplitTunnelWithAddress struct{…}

</summary>

Address string

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20address">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

type SplitTunnelExcludeTeamsDevicesExcludeSplitTunnelWithHost struct{…}

</summary>

Host string

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20host">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

ExcludeOfficeIPs boolOptional

Whether to add Microsoft IPs to Split Tunnel exclusions.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20exclude_office_ips">Link to this property</a>

<details>

<summary>

FallbackDomains \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)">FallbackDomain</a>Optional

</summary>

Suffix string

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)%20%3E%20(property)%20suffix">Link to this property</a>

Description stringOptional

A description of the fallback domain, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

DNSServer \[]stringOptional

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)%20%3E%20(property)%20dns_server">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20fallback_domains">Link to this property</a>

GatewayUniqueID stringOptional

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20gateway_unique_id">Link to this property</a>

<details>

<summary>

GlobalAcceleration SettingsPolicyGlobalAccelerationOptional

Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See <a href="https://developers.cloudflare.com/china-network/concepts/global-acceleration/">https://developers.cloudflare.com/china-network/concepts/global-acceleration/</a>.

</summary>

APIEndpoints \[]string

IP:port entries for the API endpoints.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20global_acceleration%20%3E%20(property)%20api_endpoints">Link to this property</a>

Enabled bool

Global acceleration settings are used only when “enabled”.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20global_acceleration%20%3E%20(property)%20enabled">Link to this property</a>

MasqueEndpoints \[]string

IP:port entries for the MASQUE tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20global_acceleration%20%3E%20(property)%20masque_endpoints">Link to this property</a>

WireguardEndpoints \[]string

IP:port entries for the WireGuard tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20global_acceleration%20%3E%20(property)%20wireguard_endpoints">Link to this property</a>

Autoswitch boolOptional

Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20global_acceleration%20%3E%20(property)%20autoswitch">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20global_acceleration">Link to this property</a>

<details>

<summary>

Include \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)">SplitTunnelInclude</a>Optional

List of routes included in the WARP client’s tunnel.

</summary>

One of the following:

<details>

<summary>

type SplitTunnelIncludeTeamsDevicesIncludeSplitTunnelWithAddress struct{…}

</summary>

Address string

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20address">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

type SplitTunnelIncludeTeamsDevicesIncludeSplitTunnelWithHost struct{…}

</summary>

Host string

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20host">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20include">Link to this property</a>

LANAllowMinutes float64Optional

The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20lan_allow_minutes">Link to this property</a>

LANAllowSubnetSize float64Optional

The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20lan_allow_subnet_size">Link to this property</a>

Match stringOptional

The wirefilter expression to match devices. Available values: “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.service\_token\_uuid”, “identity.saml\_attributes”, “network”, “os.name”, “os.version”.

maxLength500

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20match">Link to this property</a>

Name stringOptional

The name of the device settings profile.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

PolicyID stringOptional

maxLength36

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20policy_id">Link to this property</a>

Precedence float64Optional

The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20precedence">Link to this property</a>

<details>

<summary>

ProfileType SettingsPolicyProfileTypeOptional

The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.

</summary>

One of the following:

const SettingsPolicyProfileTypeWARP SettingsPolicyProfileType = "warp"

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20profile_type%20%3E%20(member)%200">Link to this property</a>

const SettingsPolicyProfileTypeBrowserExtension SettingsPolicyProfileType = "browser\_extension"

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20profile_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20profile_type">Link to this property</a>

RegisterInterfaceIPWithDNS boolOptional

Determines if the operating system will register WARP’s local interface IP with your on-premises DNS server.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20register_interface_ip_with_dns">Link to this property</a>

SccmVpnBoundarySupport boolOptional

Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only).

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20sccm_vpn_boundary_support">Link to this property</a>

<details>

<summary>

ServiceModeV2 SettingsPolicyServiceModeV2Optional

</summary>

Mode stringOptional

The mode to run the WARP client under.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20service_mode_v2%20%3E%20(property)%20mode">Link to this property</a>

Port float64Optional

The port number when used with proxy mode.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20service_mode_v2%20%3E%20(property)%20port">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20service_mode_v2">Link to this property</a>

SupportURL stringOptional

The URL to launch when the Send Feedback button is clicked.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20support_url">Link to this property</a>

SwitchLocked boolOptional

Whether to allow the user to turn off the WARP switch and disconnect the client.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20switch_locked">Link to this property</a>

<details>

<summary>

DeprecatedTargetTests \[]SettingsPolicyTargetTestOptional

</summary>

ID stringOptional

The id of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20target_tests%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

Name stringOptional

The name of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20target_tests%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20target_tests">Link to this property</a>

TunnelProtocol stringOptional

Determines which tunnel protocol to use.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20tunnel_protocol">Link to this property</a>

UninstallProtection boolOptional

Determines whether uninstalling the WARP client requires an override code. (Windows only).

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20uninstall_protection">Link to this property</a>

<details>

<summary>

VirtualNetworks SettingsPolicyVirtualNetworksOptional

Virtual network access settings for the device.

</summary>

Allowed \[]string

List of virtual network IDs the device is allowed to access. When virtual\_networks is set, at least one entry is required.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20virtual_networks%20%3E%20(property)%20allowed">Link to this property</a>

Default string

The default virtual network ID. Must be included in the <code>allowed</code> list.

formatuuid

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20virtual_networks%20%3E%20(property)%20default">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)%20%3E%20(property)%20virtual_networks">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)>)

<details>

<summary>

type SplitTunnelExclude interface{…}

</summary>

One of the following:

<details>

<summary>

type SplitTunnelExcludeTeamsDevicesExcludeSplitTunnelWithAddress struct{…}

</summary>

Address string

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20address">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

type SplitTunnelExcludeTeamsDevicesExcludeSplitTunnelWithHost struct{…}

</summary>

Host string

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20host">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)>)

<details>

<summary>

type SplitTunnelInclude interface{…}

</summary>

One of the following:

<details>

<summary>

type SplitTunnelIncludeTeamsDevicesIncludeSplitTunnelWithAddress struct{…}

</summary>

Address string

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20address">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

type SplitTunnelIncludeTeamsDevicesIncludeSplitTunnelWithHost struct{…}

</summary>

Host string

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20host">Link to this property</a>

Description stringOptional

A description of the Split Tunnel item, displayed in the client UI.

maxLength100

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)>)

#### Zero TrustDevicesPoliciesDefault

##### [Get the default device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/methods/get)

client.ZeroTrust.Devices.Policies.Default.Get(ctx, query) (\*[DevicePolicyDefaultGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies.default%20%3E%20(model)%20DevicePolicyDefaultGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/policy

##### [Update the default device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/methods/edit)

client.ZeroTrust.Devices.Policies.Default.Edit(ctx, params) (\*[DevicePolicyDefaultEditResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies.default%20%3E%20(model)%20DevicePolicyDefaultEditResponse%20%3E%20(schema)>), error)

PATCH/accounts/{account\_id}/devices/policy

#### Zero TrustDevicesPoliciesDefaultExcludes

##### [Get the Split Tunnel exclude list](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/excludes/methods/get)

client.ZeroTrust.Devices.Policies.Default.Excludes.Get(ctx, query) (\*SinglePage\[[SplitTunnelExclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policy/exclude

##### [Set the Split Tunnel exclude list](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/excludes/methods/update)

client.ZeroTrust.Devices.Policies.Default.Excludes.Update(ctx, params) (\*SinglePage\[[SplitTunnelExclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/devices/policy/exclude

#### Zero TrustDevicesPoliciesDefaultIncludes

##### [Get the Split Tunnel include list](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/includes/methods/get)

client.ZeroTrust.Devices.Policies.Default.Includes.Get(ctx, query) (\*SinglePage\[[SplitTunnelInclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policy/include

##### [Set the Split Tunnel include list](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/includes/methods/update)

client.ZeroTrust.Devices.Policies.Default.Includes.Update(ctx, params) (\*SinglePage\[[SplitTunnelInclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/devices/policy/include

#### Zero TrustDevicesPoliciesDefaultFallback Domains

##### [Get your Local Domain Fallback list](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/fallback_domains/methods/get)

client.ZeroTrust.Devices.Policies.Default.FallbackDomains.Get(ctx, query) (\*SinglePage\[[FallbackDomain](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policy/fallback\_domains

##### [Set your Local Domain Fallback list](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/fallback_domains/methods/update)

client.ZeroTrust.Devices.Policies.Default.FallbackDomains.Update(ctx, params) (\*SinglePage\[[FallbackDomain](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/devices/policy/fallback\_domains

#### Zero TrustDevicesPoliciesDefaultCertificates

##### [Get device certificate provisioning status](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/certificates/methods/get)

client.ZeroTrust.Devices.Policies.Default.Certificates.Get(ctx, query) (\*[DevicePolicyCertificates](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20device_policy_certificates%20%3E%20(schema)>), error)

GET/zones/{zone\_id}/devices/policy/certificates

##### [Update device certificate provisioning status](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/certificates/methods/edit)

client.ZeroTrust.Devices.Policies.Default.Certificates.Edit(ctx, params) (\*[DevicePolicyCertificates](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20device_policy_certificates%20%3E%20(schema)>), error)

PATCH/zones/{zone\_id}/devices/policy/certificates

#### Zero TrustDevicesPoliciesCustom

##### [List device settings profiles](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/list)

client.ZeroTrust.Devices.Policies.Custom.List(ctx, params) (\*SinglePage\[[SettingsPolicy](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policies

##### [Get device settings profile by ID](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/get)

client.ZeroTrust.Devices.Policies.Custom.Get(ctx, policyID, query) (\*[SettingsPolicy](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/policy/{policy\_id}

##### [Create a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/create)

client.ZeroTrust.Devices.Policies.Custom.New(ctx, params) (\*[SettingsPolicy](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/policy

##### [Update a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/edit)

client.ZeroTrust.Devices.Policies.Custom.Edit(ctx, policyID, params) (\*[SettingsPolicy](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)>), error)

PATCH/accounts/{account\_id}/devices/policy/{policy\_id}

##### [Delete a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/delete)

client.ZeroTrust.Devices.Policies.Custom.Delete(ctx, policyID, body) (\*SinglePage\[[SettingsPolicy](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20settings_policy%20%3E%20(schema)>)], error)

DELETE/accounts/{account\_id}/devices/policy/{policy\_id}

#### Zero TrustDevicesPoliciesCustomExcludes

##### [Get the Split Tunnel exclude list for a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/excludes/methods/get)

client.ZeroTrust.Devices.Policies.Custom.Excludes.Get(ctx, policyID, query) (\*SinglePage\[[SplitTunnelExclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policy/{policy\_id}/exclude

##### [Set the Split Tunnel exclude list for a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/excludes/methods/update)

client.ZeroTrust.Devices.Policies.Custom.Excludes.Update(ctx, policyID, params) (\*SinglePage\[[SplitTunnelExclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_exclude%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/devices/policy/{policy\_id}/exclude

#### Zero TrustDevicesPoliciesCustomIncludes

##### [Get the Split Tunnel include list for a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/includes/methods/get)

client.ZeroTrust.Devices.Policies.Custom.Includes.Get(ctx, policyID, query) (\*SinglePage\[[SplitTunnelInclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policy/{policy\_id}/include

##### [Set the Split Tunnel include list for a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/includes/methods/update)

client.ZeroTrust.Devices.Policies.Custom.Includes.Update(ctx, policyID, params) (\*SinglePage\[[SplitTunnelInclude](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20split_tunnel_include%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/devices/policy/{policy\_id}/include

#### Zero TrustDevicesPoliciesCustomFallback Domains

##### [Get the Local Domain Fallback list for a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/fallback_domains/methods/get)

client.ZeroTrust.Devices.Policies.Custom.FallbackDomains.Get(ctx, policyID, query) (\*SinglePage\[[FallbackDomain](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/policy/{policy\_id}/fallback\_domains

##### [Set the Local Domain Fallback list for a device settings profile](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/fallback_domains/methods/update)

client.ZeroTrust.Devices.Policies.Custom.FallbackDomains.Update(ctx, policyID, params) (\*SinglePage\[[FallbackDomain](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.policies%20%3E%20(model)%20fallback_domain%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/devices/policy/{policy\_id}/fallback\_domains

#### Zero TrustDevicesPosture

##### [List posture rules](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/methods/list)

client.ZeroTrust.Devices.Posture.List(ctx, query) (\*SinglePage\[[DevicePostureRule](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/posture

##### [Get posture rule](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/methods/get)

client.ZeroTrust.Devices.Posture.Get(ctx, ruleID, query) (\*[DevicePostureRule](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/posture/{rule\_id}

##### [Create posture rule](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/methods/create)

client.ZeroTrust.Devices.Posture.New(ctx, params) (\*[DevicePostureRule](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/posture

##### [Update posture rule](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/methods/update)

client.ZeroTrust.Devices.Posture.Update(ctx, ruleID, params) (\*[DevicePostureRule](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/devices/posture/{rule\_id}

##### [Delete posture rule](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/methods/delete)

client.ZeroTrust.Devices.Posture.Delete(ctx, ruleID, body) (\*[DevicePostureDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20DevicePostureDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/posture/{rule\_id}

##### ModelsExpand Collapse

type CarbonblackInput string

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20carbonblack_input%20%3E%20(schema)>)

<details>

<summary>

type ClientCertificateInput struct{…}

</summary>

CertificateID string

UUID of Cloudflare managed certificate.

maxLength36

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20client_certificate_input%20%3E%20(schema)%20%3E%20(property)%20certificate_id">Link to this property</a>

Cn string

Common Name that is protected by the certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20client_certificate_input%20%3E%20(schema)%20%3E%20(property)%20cn">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20client_certificate_input%20%3E%20(schema)>)

<details>

<summary>

type CrowdstrikeInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

LastSeen stringOptional

For more details on last seen, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20last_seen">Link to this property</a>

<details>

<summary>

Operator CrowdstrikeInputOperatorOptional

Operator.

</summary>

One of the following:

const CrowdstrikeInputOperatorLess CrowdstrikeInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const CrowdstrikeInputOperatorLessOrEquals CrowdstrikeInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const CrowdstrikeInputOperatorGreater CrowdstrikeInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const CrowdstrikeInputOperatorGreaterOrEquals CrowdstrikeInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const CrowdstrikeInputOperatorEquals CrowdstrikeInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

OS stringOptional

Os Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20os">Link to this property</a>

Overall stringOptional

Overall.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20overall">Link to this property</a>

SensorConfig stringOptional

SensorConfig.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20sensor_config">Link to this property</a>

<details>

<summary>

State CrowdstrikeInputStateOptional

For more details on state, please refer to the Crowdstrike documentation.

</summary>

One of the following:

const CrowdstrikeInputStateOnline CrowdstrikeInputState = "online"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state%20%3E%20(member)%200">Link to this property</a>

const CrowdstrikeInputStateOffline CrowdstrikeInputState = "offline"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state%20%3E%20(member)%201">Link to this property</a>

const CrowdstrikeInputStateUnknown CrowdstrikeInputState = "unknown"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state">Link to this property</a>

Version stringOptional

Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

<details>

<summary>

VersionOperator CrowdstrikeInputVersionOperatorOptional

Version Operator.

</summary>

One of the following:

const CrowdstrikeInputVersionOperatorLess CrowdstrikeInputVersionOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%200">Link to this property</a>

const CrowdstrikeInputVersionOperatorLessOrEquals CrowdstrikeInputVersionOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%201">Link to this property</a>

const CrowdstrikeInputVersionOperatorGreater CrowdstrikeInputVersionOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%202">Link to this property</a>

const CrowdstrikeInputVersionOperatorGreaterOrEquals CrowdstrikeInputVersionOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%203">Link to this property</a>

const CrowdstrikeInputVersionOperatorEquals CrowdstrikeInputVersionOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)>)

<details>

<summary>

type DeviceInput interface{…}

The value to be checked against.

</summary>

One of the following:

<details>

<summary>

type FileInput struct{…}

</summary>

<details>

<summary>

OperatingSystem FileInputOperatingSystem

Operating system.

</summary>

One of the following:

const FileInputOperatingSystemWindows FileInputOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const FileInputOperatingSystemLinux FileInputOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const FileInputOperatingSystemMac FileInputOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

Path string

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20path">Link to this property</a>

Exists boolOptional

Whether or not file exists.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20exists">Link to this property</a>

Sha256 stringOptional

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20sha256">Link to this property</a>

Thumbprint stringOptional

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20thumbprint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type UniqueClientIDInput struct{…}

</summary>

ID string

List ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

OperatingSystem UniqueClientIDInputOperatingSystem

Operating System.

</summary>

One of the following:

const UniqueClientIDInputOperatingSystemAndroid UniqueClientIDInputOperatingSystem = "android"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const UniqueClientIDInputOperatingSystemIos UniqueClientIDInputOperatingSystem = "ios"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const UniqueClientIDInputOperatingSystemChromeos UniqueClientIDInputOperatingSystem = "chromeos"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainJoinedInput struct{…}

</summary>

OperatingSystem DomainJoinedInputOperatingSystem

Operating System.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20domain_joined_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

Domain stringOptional

Domain.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20domain_joined_input%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20domain_joined_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OSVersionInput struct{…}

</summary>

OperatingSystem OSVersionInputOperatingSystem

Operating System.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

<details>

<summary>

Operator OSVersionInputOperator

Operator.

</summary>

One of the following:

const OSVersionInputOperatorLess OSVersionInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const OSVersionInputOperatorLessOrEquals OSVersionInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const OSVersionInputOperatorGreater OSVersionInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const OSVersionInputOperatorGreaterOrEquals OSVersionInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const OSVersionInputOperatorEquals OSVersionInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

Version string

Version of OS.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

OSDistroName stringOptional

Operating System Distribution Name (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20os_distro_name">Link to this property</a>

OSDistroRevision stringOptional

Version of OS Distribution (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20os_distro_revision">Link to this property</a>

OSVersionExtra stringOptional

Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20os_version_extra">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type FirewallInput struct{…}

</summary>

Enabled bool

Enabled.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

OperatingSystem FirewallInputOperatingSystem

Operating System.

</summary>

One of the following:

const FirewallInputOperatingSystemWindows FirewallInputOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const FirewallInputOperatingSystemMac FirewallInputOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SentineloneInput struct{…}

</summary>

<details>

<summary>

OperatingSystem SentineloneInputOperatingSystem

Operating system.

</summary>

One of the following:

const SentineloneInputOperatingSystemWindows SentineloneInputOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const SentineloneInputOperatingSystemLinux SentineloneInputOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const SentineloneInputOperatingSystemMac SentineloneInputOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

Path string

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20path">Link to this property</a>

Sha256 stringOptional

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20sha256">Link to this property</a>

Thumbprint stringOptional

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20thumbprint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DeviceInputTeamsDevicesCarbonblackInputRequest struct{…}

</summary>

<details>

<summary>

OperatingSystem DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystem

Operating system.

</summary>

One of the following:

const DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystemWindows DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystemLinux DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystemMac DeviceInputTeamsDevicesCarbonblackInputRequestOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20operating_system">Link to this property</a>

Path string

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20path">Link to this property</a>

Sha256 stringOptional

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20sha256">Link to this property</a>

Thumbprint stringOptional

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20thumbprint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type DeviceInputTeamsDevicesAccessSerialNumberListInputRequest struct{…}

</summary>

ID string

UUID of Access List.

maxLength36

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

<details>

<summary>

type DiskEncryptionInput struct{…}

</summary>

CheckDisks \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20carbonblack_input%20%3E%20(schema)">CarbonblackInput</a>Optional

List of volume names to be checked for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20disk_encryption_input%20%3E%20(schema)%20%3E%20(property)%20checkDisks">Link to this property</a>

RequireAll boolOptional

Whether to check all disks for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20disk_encryption_input%20%3E%20(schema)%20%3E%20(property)%20requireAll">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20disk_encryption_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DeviceInputTeamsDevicesApplicationInputRequest struct{…}

</summary>

<details>

<summary>

OperatingSystem DeviceInputTeamsDevicesApplicationInputRequestOperatingSystem

Operating system.

</summary>

One of the following:

const DeviceInputTeamsDevicesApplicationInputRequestOperatingSystemWindows DeviceInputTeamsDevicesApplicationInputRequestOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const DeviceInputTeamsDevicesApplicationInputRequestOperatingSystemLinux DeviceInputTeamsDevicesApplicationInputRequestOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const DeviceInputTeamsDevicesApplicationInputRequestOperatingSystemMac DeviceInputTeamsDevicesApplicationInputRequestOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20operating_system">Link to this property</a>

Path string

Path for the application.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20path">Link to this property</a>

Sha256 stringOptional

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20sha256">Link to this property</a>

Thumbprint stringOptional

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20thumbprint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%209">Link to this property</a>

<details>

<summary>

type ClientCertificateInput struct{…}

</summary>

CertificateID string

UUID of Cloudflare managed certificate.

maxLength36

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20client_certificate_input%20%3E%20(schema)%20%3E%20(property)%20certificate_id">Link to this property</a>

Cn string

Common Name that is protected by the certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20client_certificate_input%20%3E%20(schema)%20%3E%20(property)%20cn">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20client_certificate_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DeviceInputTeamsDevicesClientCertificateV2InputRequest struct{…}

</summary>

CertificateID string

UUID of Cloudflare managed certificate.

maxLength36

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20certificate_id">Link to this property</a>

CheckPrivateKey bool

Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20check_private_key">Link to this property</a>

<details>

<summary>

OperatingSystem DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystem

Operating system.

</summary>

One of the following:

const DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystemWindows DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystemLinux DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystemMac DeviceInputTeamsDevicesClientCertificateV2InputRequestOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20operating_system">Link to this property</a>

Cn stringOptional

Certificate Common Name. This may include one or more variables in the ${ } notation. Only ${serial\_number} and ${hostname} are valid variables.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20cn">Link to this property</a>

<details>

<summary>

ExtendedKeyUsage \[]DeviceInputTeamsDevicesClientCertificateV2InputRequestExtendedKeyUsageOptional

List of values indicating purposes for which the certificate public key can be used.

</summary>

One of the following:

const DeviceInputTeamsDevicesClientCertificateV2InputRequestExtendedKeyUsageClientAuth DeviceInputTeamsDevicesClientCertificateV2InputRequestExtendedKeyUsage = "clientAuth"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20extended_key_usage%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const DeviceInputTeamsDevicesClientCertificateV2InputRequestExtendedKeyUsageEmailProtection DeviceInputTeamsDevicesClientCertificateV2InputRequestExtendedKeyUsage = "emailProtection"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20extended_key_usage%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20extended_key_usage">Link to this property</a>

<details>

<summary>

Locations DeviceInputTeamsDevicesClientCertificateV2InputRequestLocationsOptional

</summary>

Paths \[]stringOptional

List of paths to check for client certificate on linux.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20locations%20%3E%20(property)%20paths">Link to this property</a>

<details>

<summary>

TrustStores \[]DeviceInputTeamsDevicesClientCertificateV2InputRequestLocationsTrustStoreOptional

List of trust stores to check for client certificate.

</summary>

One of the following:

const DeviceInputTeamsDevicesClientCertificateV2InputRequestLocationsTrustStoreSystem DeviceInputTeamsDevicesClientCertificateV2InputRequestLocationsTrustStore = "system"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20locations%20%3E%20(property)%20trust_stores%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const DeviceInputTeamsDevicesClientCertificateV2InputRequestLocationsTrustStoreUser DeviceInputTeamsDevicesClientCertificateV2InputRequestLocationsTrustStore = "user"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20locations%20%3E%20(property)%20trust_stores%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20locations%20%3E%20(property)%20trust_stores">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20locations">Link to this property</a>

SubjectAlternativeNames \[]stringOptional

List of certificate Subject Alternative Names.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20subject_alternative_names">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2011">Link to this property</a>

<details>

<summary>

type DeviceInputTeamsDevicesAntivirusInputRequest struct{…}

</summary>

UpdateWindowDays float64Optional

Number of days that the antivirus should be updated within.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20update_window_days">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2012">Link to this property</a>

<details>

<summary>

type WorkspaceOneInput struct{…}

</summary>

<details>

<summary>

ComplianceStatus WorkspaceOneInputComplianceStatus

Compliance Status.

</summary>

One of the following:

const WorkspaceOneInputComplianceStatusCompliant WorkspaceOneInputComplianceStatus = "compliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%200">Link to this property</a>

const WorkspaceOneInputComplianceStatusNoncompliant WorkspaceOneInputComplianceStatus = "noncompliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%201">Link to this property</a>

const WorkspaceOneInputComplianceStatusUnknown WorkspaceOneInputComplianceStatus = "unknown"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status">Link to this property</a>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CrowdstrikeInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

LastSeen stringOptional

For more details on last seen, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20last_seen">Link to this property</a>

<details>

<summary>

Operator CrowdstrikeInputOperatorOptional

Operator.

</summary>

One of the following:

const CrowdstrikeInputOperatorLess CrowdstrikeInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const CrowdstrikeInputOperatorLessOrEquals CrowdstrikeInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const CrowdstrikeInputOperatorGreater CrowdstrikeInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const CrowdstrikeInputOperatorGreaterOrEquals CrowdstrikeInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const CrowdstrikeInputOperatorEquals CrowdstrikeInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

OS stringOptional

Os Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20os">Link to this property</a>

Overall stringOptional

Overall.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20overall">Link to this property</a>

SensorConfig stringOptional

SensorConfig.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20sensor_config">Link to this property</a>

<details>

<summary>

State CrowdstrikeInputStateOptional

For more details on state, please refer to the Crowdstrike documentation.

</summary>

One of the following:

const CrowdstrikeInputStateOnline CrowdstrikeInputState = "online"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state%20%3E%20(member)%200">Link to this property</a>

const CrowdstrikeInputStateOffline CrowdstrikeInputState = "offline"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state%20%3E%20(member)%201">Link to this property</a>

const CrowdstrikeInputStateUnknown CrowdstrikeInputState = "unknown"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20state">Link to this property</a>

Version stringOptional

Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

<details>

<summary>

VersionOperator CrowdstrikeInputVersionOperatorOptional

Version Operator.

</summary>

One of the following:

const CrowdstrikeInputVersionOperatorLess CrowdstrikeInputVersionOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%200">Link to this property</a>

const CrowdstrikeInputVersionOperatorLessOrEquals CrowdstrikeInputVersionOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%201">Link to this property</a>

const CrowdstrikeInputVersionOperatorGreater CrowdstrikeInputVersionOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%202">Link to this property</a>

const CrowdstrikeInputVersionOperatorGreaterOrEquals CrowdstrikeInputVersionOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%203">Link to this property</a>

const CrowdstrikeInputVersionOperatorEquals CrowdstrikeInputVersionOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)%20%3E%20(property)%20versionOperator">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20crowdstrike_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IntuneInput struct{…}

</summary>

<details>

<summary>

ComplianceStatus IntuneInputComplianceStatus

Compliance Status.

</summary>

One of the following:

const IntuneInputComplianceStatusCompliant IntuneInputComplianceStatus = "compliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%200">Link to this property</a>

const IntuneInputComplianceStatusNoncompliant IntuneInputComplianceStatus = "noncompliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%201">Link to this property</a>

const IntuneInputComplianceStatusUnknown IntuneInputComplianceStatus = "unknown"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%202">Link to this property</a>

const IntuneInputComplianceStatusNotapplicable IntuneInputComplianceStatus = "notapplicable"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%203">Link to this property</a>

const IntuneInputComplianceStatusIngraceperiod IntuneInputComplianceStatus = "ingraceperiod"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%204">Link to this property</a>

const IntuneInputComplianceStatusError IntuneInputComplianceStatus = "error"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status">Link to this property</a>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type KolideInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

<details>

<summary>

AuthState \[]KolideInputAuthStateOptional

The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states.

</summary>

One of the following:

const KolideInputAuthStateGood KolideInputAuthState = "Good"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const KolideInputAuthStateNotified KolideInputAuthState = "Notified"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const KolideInputAuthStateWillBlock KolideInputAuthState = "Will Block"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const KolideInputAuthStateBlocked KolideInputAuthState = "Blocked"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state">Link to this property</a>

<details>

<summary>

CountOperator KolideInputCountOperatorOptional

Count Operator.

</summary>

One of the following:

const KolideInputCountOperatorLess KolideInputCountOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%200">Link to this property</a>

const KolideInputCountOperatorLessOrEquals KolideInputCountOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%201">Link to this property</a>

const KolideInputCountOperatorGreater KolideInputCountOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%202">Link to this property</a>

const KolideInputCountOperatorGreaterOrEquals KolideInputCountOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%203">Link to this property</a>

const KolideInputCountOperatorEquals KolideInputCountOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator">Link to this property</a>

IssueCount stringOptional

The Number of Issues.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20issue_count">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type TaniumInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

EidLastSeen stringOptional

For more details on eid last seen, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20eid_last_seen">Link to this property</a>

<details>

<summary>

Operator TaniumInputOperatorOptional

Operator to evaluate risk\_level or eid\_last\_seen.

</summary>

One of the following:

const TaniumInputOperatorLess TaniumInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const TaniumInputOperatorLessOrEquals TaniumInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const TaniumInputOperatorGreater TaniumInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const TaniumInputOperatorGreaterOrEquals TaniumInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const TaniumInputOperatorEquals TaniumInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

<details>

<summary>

RiskLevel TaniumInputRiskLevelOptional

For more details on risk level, refer to the Tanium documentation.

</summary>

One of the following:

const TaniumInputRiskLevelLow TaniumInputRiskLevel = "low"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%200">Link to this property</a>

const TaniumInputRiskLevelMedium TaniumInputRiskLevel = "medium"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%201">Link to this property</a>

const TaniumInputRiskLevelHigh TaniumInputRiskLevel = "high"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%202">Link to this property</a>

const TaniumInputRiskLevelCritical TaniumInputRiskLevel = "critical"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level">Link to this property</a>

<details>

<summary>

ScoreOperator TaniumInputScoreOperatorOptional

Score Operator.

</summary>

One of the following:

const TaniumInputScoreOperatorLess TaniumInputScoreOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%200">Link to this property</a>

const TaniumInputScoreOperatorLessOrEquals TaniumInputScoreOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%201">Link to this property</a>

const TaniumInputScoreOperatorGreater TaniumInputScoreOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%202">Link to this property</a>

const TaniumInputScoreOperatorGreaterOrEquals TaniumInputScoreOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%203">Link to this property</a>

const TaniumInputScoreOperatorEquals TaniumInputScoreOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator">Link to this property</a>

TotalScore float64Optional

For more details on total score, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20total_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SentineloneS2sInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

ActiveThreats float64Optional

The Number of active threats.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20active_threats">Link to this property</a>

Infected boolOptional

Whether device is infected.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20infected">Link to this property</a>

IsActive boolOptional

Whether device is active.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20is_active">Link to this property</a>

<details>

<summary>

NetworkStatus SentineloneS2sInputNetworkStatusOptional

Network status of device.

</summary>

One of the following:

const SentineloneS2sInputNetworkStatusConnected SentineloneS2sInputNetworkStatus = "connected"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%200">Link to this property</a>

const SentineloneS2sInputNetworkStatusDisconnected SentineloneS2sInputNetworkStatus = "disconnected"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%201">Link to this property</a>

const SentineloneS2sInputNetworkStatusDisconnecting SentineloneS2sInputNetworkStatus = "disconnecting"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%202">Link to this property</a>

const SentineloneS2sInputNetworkStatusConnecting SentineloneS2sInputNetworkStatus = "connecting"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status">Link to this property</a>

<details>

<summary>

OperationalState SentineloneS2sInputOperationalStateOptional

Agent operational state.

</summary>

One of the following:

const SentineloneS2sInputOperationalStateNa SentineloneS2sInputOperationalState = "na"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%200">Link to this property</a>

const SentineloneS2sInputOperationalStatePartiallyDisabled SentineloneS2sInputOperationalState = "partially\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%201">Link to this property</a>

const SentineloneS2sInputOperationalStateAutoFullyDisabled SentineloneS2sInputOperationalState = "auto\_fully\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%202">Link to this property</a>

const SentineloneS2sInputOperationalStateFullyDisabled SentineloneS2sInputOperationalState = "fully\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%203">Link to this property</a>

const SentineloneS2sInputOperationalStateAutoPartiallyDisabled SentineloneS2sInputOperationalState = "auto\_partially\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%204">Link to this property</a>

const SentineloneS2sInputOperationalStateDisabledError SentineloneS2sInputOperationalState = "disabled\_error"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%205">Link to this property</a>

const SentineloneS2sInputOperationalStateDBCorruption SentineloneS2sInputOperationalState = "db\_corruption"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state">Link to this property</a>

<details>

<summary>

Operator SentineloneS2sInputOperatorOptional

Operator.

</summary>

One of the following:

const SentineloneS2sInputOperatorLess SentineloneS2sInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const SentineloneS2sInputOperatorLessOrEquals SentineloneS2sInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const SentineloneS2sInputOperatorGreater SentineloneS2sInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const SentineloneS2sInputOperatorGreaterOrEquals SentineloneS2sInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const SentineloneS2sInputOperatorEquals SentineloneS2sInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DeviceInputTeamsDevicesCustomS2sInputRequest struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20connection_id">Link to this property</a>

<details>

<summary>

Operator DeviceInputTeamsDevicesCustomS2sInputRequestOperator

Operator.

</summary>

One of the following:

const DeviceInputTeamsDevicesCustomS2sInputRequestOperatorLess DeviceInputTeamsDevicesCustomS2sInputRequestOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const DeviceInputTeamsDevicesCustomS2sInputRequestOperatorLessOrEquals DeviceInputTeamsDevicesCustomS2sInputRequestOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const DeviceInputTeamsDevicesCustomS2sInputRequestOperatorGreater DeviceInputTeamsDevicesCustomS2sInputRequestOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const DeviceInputTeamsDevicesCustomS2sInputRequestOperatorGreaterOrEquals DeviceInputTeamsDevicesCustomS2sInputRequestOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const DeviceInputTeamsDevicesCustomS2sInputRequestOperatorEquals DeviceInputTeamsDevicesCustomS2sInputRequestOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20operator">Link to this property</a>

Score float64

A value between 0-100 assigned to devices set by the 3rd party posture provider.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019%20%3E%20(property)%20score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)%20%3E%20(variant)%2019">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)>)

<details>

<summary>

type DeviceMatch struct{…}

</summary>

<details>

<summary>

Platform DeviceMatchPlatformOptional

</summary>

One of the following:

const DeviceMatchPlatformWindows DeviceMatchPlatform = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%200">Link to this property</a>

const DeviceMatchPlatformMac DeviceMatchPlatform = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%201">Link to this property</a>

const DeviceMatchPlatformLinux DeviceMatchPlatform = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%202">Link to this property</a>

const DeviceMatchPlatformAndroid DeviceMatchPlatform = "android"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%203">Link to this property</a>

const DeviceMatchPlatformIos DeviceMatchPlatform = "ios"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%204">Link to this property</a>

const DeviceMatchPlatformChromeos DeviceMatchPlatform = "chromeos"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)>)

<details>

<summary>

type DevicePostureRule struct{…}

</summary>

ID stringOptional

API UUID.

maxLength36

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Description stringOptional

The description of the device posture rule.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

Enabled boolOptional

Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue\_count input, and true otherwise.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Expiration stringOptional

Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20expiration">Link to this property</a>

Input <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_input%20%3E%20(schema)">DeviceInput</a>Optional

The value to be checked against.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20input">Link to this property</a>

<details>

<summary>

Match \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)">DeviceMatch</a>Optional

The conditions that the client must match to run the rule.

</summary>

<details>

<summary>

Platform DeviceMatchPlatformOptional

</summary>

One of the following:

const DeviceMatchPlatformWindows DeviceMatchPlatform = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%200">Link to this property</a>

const DeviceMatchPlatformMac DeviceMatchPlatform = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%201">Link to this property</a>

const DeviceMatchPlatformLinux DeviceMatchPlatform = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%202">Link to this property</a>

const DeviceMatchPlatformAndroid DeviceMatchPlatform = "android"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%203">Link to this property</a>

const DeviceMatchPlatformIos DeviceMatchPlatform = "ios"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%204">Link to this property</a>

const DeviceMatchPlatformChromeos DeviceMatchPlatform = "chromeos"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_match%20%3E%20(schema)%20%3E%20(property)%20platform">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20match">Link to this property</a>

Name stringOptional

The name of the device posture rule.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Schedule stringOptional

Polling frequency for the WARP client posture check. Default: <code>5m</code> (poll every five minutes). Minimum: <code>1m</code>.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20schedule">Link to this property</a>

<details>

<summary>

Type DevicePostureRuleTypeOptional

The type of device posture rule.

</summary>

One of the following:

const DevicePostureRuleTypeFile DevicePostureRuleType = "file"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const DevicePostureRuleTypeApplication DevicePostureRuleType = "application"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const DevicePostureRuleTypeTanium DevicePostureRuleType = "tanium"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const DevicePostureRuleTypeGateway DevicePostureRuleType = "gateway"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const DevicePostureRuleTypeWARP DevicePostureRuleType = "warp"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const DevicePostureRuleTypeDiskEncryption DevicePostureRuleType = "disk\_encryption"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const DevicePostureRuleTypeSerialNumber DevicePostureRuleType = "serial\_number"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const DevicePostureRuleTypeSentinelone DevicePostureRuleType = "sentinelone"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const DevicePostureRuleTypeCarbonblack DevicePostureRuleType = "carbonblack"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

const DevicePostureRuleTypeFirewall DevicePostureRuleType = "firewall"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%209">Link to this property</a>

const DevicePostureRuleTypeOSVersion DevicePostureRuleType = "os\_version"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2010">Link to this property</a>

const DevicePostureRuleTypeDomainJoined DevicePostureRuleType = "domain\_joined"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2011">Link to this property</a>

const DevicePostureRuleTypeClientCertificate DevicePostureRuleType = "client\_certificate"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2012">Link to this property</a>

const DevicePostureRuleTypeClientCertificateV2 DevicePostureRuleType = "client\_certificate\_v2"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2013">Link to this property</a>

const DevicePostureRuleTypeAntivirus DevicePostureRuleType = "antivirus"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2014">Link to this property</a>

const DevicePostureRuleTypeUniqueClientID DevicePostureRuleType = "unique\_client\_id"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2015">Link to this property</a>

const DevicePostureRuleTypeKolide DevicePostureRuleType = "kolide"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2016">Link to this property</a>

const DevicePostureRuleTypeTaniumS2s DevicePostureRuleType = "tanium\_s2s"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2017">Link to this property</a>

const DevicePostureRuleTypeCrowdstrikeS2s DevicePostureRuleType = "crowdstrike\_s2s"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2018">Link to this property</a>

const DevicePostureRuleTypeIntune DevicePostureRuleType = "intune"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2019">Link to this property</a>

const DevicePostureRuleTypeWorkspaceOne DevicePostureRuleType = "workspace\_one"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2020">Link to this property</a>

const DevicePostureRuleTypeSentineloneS2s DevicePostureRuleType = "sentinelone\_s2s"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2021">Link to this property</a>

const DevicePostureRuleTypeCustomS2s DevicePostureRuleType = "custom\_s2s"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%2022">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20device_posture_rule%20%3E%20(schema)>)

<details>

<summary>

type DiskEncryptionInput struct{…}

</summary>

CheckDisks \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20carbonblack_input%20%3E%20(schema)">CarbonblackInput</a>Optional

List of volume names to be checked for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20disk_encryption_input%20%3E%20(schema)%20%3E%20(property)%20checkDisks">Link to this property</a>

RequireAll boolOptional

Whether to check all disks for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20disk_encryption_input%20%3E%20(schema)%20%3E%20(property)%20requireAll">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20disk_encryption_input%20%3E%20(schema)>)

<details>

<summary>

type DomainJoinedInput struct{…}

</summary>

OperatingSystem DomainJoinedInputOperatingSystem

Operating System.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20domain_joined_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

Domain stringOptional

Domain.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20domain_joined_input%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20domain_joined_input%20%3E%20(schema)>)

<details>

<summary>

type FileInput struct{…}

</summary>

<details>

<summary>

OperatingSystem FileInputOperatingSystem

Operating system.

</summary>

One of the following:

const FileInputOperatingSystemWindows FileInputOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const FileInputOperatingSystemLinux FileInputOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const FileInputOperatingSystemMac FileInputOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

Path string

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20path">Link to this property</a>

Exists boolOptional

Whether or not file exists.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20exists">Link to this property</a>

Sha256 stringOptional

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20sha256">Link to this property</a>

Thumbprint stringOptional

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)%20%3E%20(property)%20thumbprint">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20file_input%20%3E%20(schema)>)

<details>

<summary>

type FirewallInput struct{…}

</summary>

Enabled bool

Enabled.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

OperatingSystem FirewallInputOperatingSystem

Operating System.

</summary>

One of the following:

const FirewallInputOperatingSystemWindows FirewallInputOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const FirewallInputOperatingSystemMac FirewallInputOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20firewall_input%20%3E%20(schema)>)

<details>

<summary>

type IntuneInput struct{…}

</summary>

<details>

<summary>

ComplianceStatus IntuneInputComplianceStatus

Compliance Status.

</summary>

One of the following:

const IntuneInputComplianceStatusCompliant IntuneInputComplianceStatus = "compliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%200">Link to this property</a>

const IntuneInputComplianceStatusNoncompliant IntuneInputComplianceStatus = "noncompliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%201">Link to this property</a>

const IntuneInputComplianceStatusUnknown IntuneInputComplianceStatus = "unknown"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%202">Link to this property</a>

const IntuneInputComplianceStatusNotapplicable IntuneInputComplianceStatus = "notapplicable"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%203">Link to this property</a>

const IntuneInputComplianceStatusIngraceperiod IntuneInputComplianceStatus = "ingraceperiod"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%204">Link to this property</a>

const IntuneInputComplianceStatusError IntuneInputComplianceStatus = "error"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status">Link to this property</a>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20intune_input%20%3E%20(schema)>)

<details>

<summary>

type KolideInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

<details>

<summary>

AuthState \[]KolideInputAuthStateOptional

The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states.

</summary>

One of the following:

const KolideInputAuthStateGood KolideInputAuthState = "Good"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const KolideInputAuthStateNotified KolideInputAuthState = "Notified"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const KolideInputAuthStateWillBlock KolideInputAuthState = "Will Block"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const KolideInputAuthStateBlocked KolideInputAuthState = "Blocked"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20auth_state">Link to this property</a>

<details>

<summary>

CountOperator KolideInputCountOperatorOptional

Count Operator.

</summary>

One of the following:

const KolideInputCountOperatorLess KolideInputCountOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%200">Link to this property</a>

const KolideInputCountOperatorLessOrEquals KolideInputCountOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%201">Link to this property</a>

const KolideInputCountOperatorGreater KolideInputCountOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%202">Link to this property</a>

const KolideInputCountOperatorGreaterOrEquals KolideInputCountOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%203">Link to this property</a>

const KolideInputCountOperatorEquals KolideInputCountOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20countOperator">Link to this property</a>

IssueCount stringOptional

The Number of Issues.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)%20%3E%20(property)%20issue_count">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20kolide_input%20%3E%20(schema)>)

<details>

<summary>

type OSVersionInput struct{…}

</summary>

OperatingSystem OSVersionInputOperatingSystem

Operating System.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

<details>

<summary>

Operator OSVersionInputOperator

Operator.

</summary>

One of the following:

const OSVersionInputOperatorLess OSVersionInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const OSVersionInputOperatorLessOrEquals OSVersionInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const OSVersionInputOperatorGreater OSVersionInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const OSVersionInputOperatorGreaterOrEquals OSVersionInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const OSVersionInputOperatorEquals OSVersionInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

Version string

Version of OS.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

OSDistroName stringOptional

Operating System Distribution Name (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20os_distro_name">Link to this property</a>

OSDistroRevision stringOptional

Version of OS Distribution (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20os_distro_revision">Link to this property</a>

OSVersionExtra stringOptional

Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)%20%3E%20(property)%20os_version_extra">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20os_version_input%20%3E%20(schema)>)

<details>

<summary>

type SentineloneInput struct{…}

</summary>

<details>

<summary>

OperatingSystem SentineloneInputOperatingSystem

Operating system.

</summary>

One of the following:

const SentineloneInputOperatingSystemWindows SentineloneInputOperatingSystem = "windows"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const SentineloneInputOperatingSystemLinux SentineloneInputOperatingSystem = "linux"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const SentineloneInputOperatingSystemMac SentineloneInputOperatingSystem = "mac"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

Path string

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20path">Link to this property</a>

Sha256 stringOptional

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20sha256">Link to this property</a>

Thumbprint stringOptional

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)%20%3E%20(property)%20thumbprint">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_input%20%3E%20(schema)>)

<details>

<summary>

type SentineloneS2sInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

ActiveThreats float64Optional

The Number of active threats.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20active_threats">Link to this property</a>

Infected boolOptional

Whether device is infected.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20infected">Link to this property</a>

IsActive boolOptional

Whether device is active.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20is_active">Link to this property</a>

<details>

<summary>

NetworkStatus SentineloneS2sInputNetworkStatusOptional

Network status of device.

</summary>

One of the following:

const SentineloneS2sInputNetworkStatusConnected SentineloneS2sInputNetworkStatus = "connected"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%200">Link to this property</a>

const SentineloneS2sInputNetworkStatusDisconnected SentineloneS2sInputNetworkStatus = "disconnected"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%201">Link to this property</a>

const SentineloneS2sInputNetworkStatusDisconnecting SentineloneS2sInputNetworkStatus = "disconnecting"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%202">Link to this property</a>

const SentineloneS2sInputNetworkStatusConnecting SentineloneS2sInputNetworkStatus = "connecting"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20network_status">Link to this property</a>

<details>

<summary>

OperationalState SentineloneS2sInputOperationalStateOptional

Agent operational state.

</summary>

One of the following:

const SentineloneS2sInputOperationalStateNa SentineloneS2sInputOperationalState = "na"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%200">Link to this property</a>

const SentineloneS2sInputOperationalStatePartiallyDisabled SentineloneS2sInputOperationalState = "partially\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%201">Link to this property</a>

const SentineloneS2sInputOperationalStateAutoFullyDisabled SentineloneS2sInputOperationalState = "auto\_fully\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%202">Link to this property</a>

const SentineloneS2sInputOperationalStateFullyDisabled SentineloneS2sInputOperationalState = "fully\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%203">Link to this property</a>

const SentineloneS2sInputOperationalStateAutoPartiallyDisabled SentineloneS2sInputOperationalState = "auto\_partially\_disabled"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%204">Link to this property</a>

const SentineloneS2sInputOperationalStateDisabledError SentineloneS2sInputOperationalState = "disabled\_error"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%205">Link to this property</a>

const SentineloneS2sInputOperationalStateDBCorruption SentineloneS2sInputOperationalState = "db\_corruption"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operational_state">Link to this property</a>

<details>

<summary>

Operator SentineloneS2sInputOperatorOptional

Operator.

</summary>

One of the following:

const SentineloneS2sInputOperatorLess SentineloneS2sInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const SentineloneS2sInputOperatorLessOrEquals SentineloneS2sInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const SentineloneS2sInputOperatorGreater SentineloneS2sInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const SentineloneS2sInputOperatorGreaterOrEquals SentineloneS2sInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const SentineloneS2sInputOperatorEquals SentineloneS2sInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20sentinelone_s2s_input%20%3E%20(schema)>)

<details>

<summary>

type TaniumInput struct{…}

</summary>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

EidLastSeen stringOptional

For more details on eid last seen, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20eid_last_seen">Link to this property</a>

<details>

<summary>

Operator TaniumInputOperatorOptional

Operator to evaluate risk\_level or eid\_last\_seen.

</summary>

One of the following:

const TaniumInputOperatorLess TaniumInputOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%200">Link to this property</a>

const TaniumInputOperatorLessOrEquals TaniumInputOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%201">Link to this property</a>

const TaniumInputOperatorGreater TaniumInputOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%202">Link to this property</a>

const TaniumInputOperatorGreaterOrEquals TaniumInputOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%203">Link to this property</a>

const TaniumInputOperatorEquals TaniumInputOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20operator">Link to this property</a>

<details>

<summary>

RiskLevel TaniumInputRiskLevelOptional

For more details on risk level, refer to the Tanium documentation.

</summary>

One of the following:

const TaniumInputRiskLevelLow TaniumInputRiskLevel = "low"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%200">Link to this property</a>

const TaniumInputRiskLevelMedium TaniumInputRiskLevel = "medium"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%201">Link to this property</a>

const TaniumInputRiskLevelHigh TaniumInputRiskLevel = "high"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%202">Link to this property</a>

const TaniumInputRiskLevelCritical TaniumInputRiskLevel = "critical"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20risk_level">Link to this property</a>

<details>

<summary>

ScoreOperator TaniumInputScoreOperatorOptional

Score Operator.

</summary>

One of the following:

const TaniumInputScoreOperatorLess TaniumInputScoreOperator = "&lt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%200">Link to this property</a>

const TaniumInputScoreOperatorLessOrEquals TaniumInputScoreOperator = "&lt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%201">Link to this property</a>

const TaniumInputScoreOperatorGreater TaniumInputScoreOperator = "&gt;"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%202">Link to this property</a>

const TaniumInputScoreOperatorGreaterOrEquals TaniumInputScoreOperator = "&gt;="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%203">Link to this property</a>

const TaniumInputScoreOperatorEquals TaniumInputScoreOperator = "=="

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20scoreOperator">Link to this property</a>

TotalScore float64Optional

For more details on total score, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)%20%3E%20(property)%20total_score">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20tanium_input%20%3E%20(schema)>)

<details>

<summary>

type UniqueClientIDInput struct{…}

</summary>

ID string

List ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

OperatingSystem UniqueClientIDInputOperatingSystem

Operating System.

</summary>

One of the following:

const UniqueClientIDInputOperatingSystemAndroid UniqueClientIDInputOperatingSystem = "android"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%200">Link to this property</a>

const UniqueClientIDInputOperatingSystemIos UniqueClientIDInputOperatingSystem = "ios"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%201">Link to this property</a>

const UniqueClientIDInputOperatingSystemChromeos UniqueClientIDInputOperatingSystem = "chromeos"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)%20%3E%20(property)%20operating_system">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20unique_client_id_input%20%3E%20(schema)>)

<details>

<summary>

type WorkspaceOneInput struct{…}

</summary>

<details>

<summary>

ComplianceStatus WorkspaceOneInputComplianceStatus

Compliance Status.

</summary>

One of the following:

const WorkspaceOneInputComplianceStatusCompliant WorkspaceOneInputComplianceStatus = "compliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%200">Link to this property</a>

const WorkspaceOneInputComplianceStatusNoncompliant WorkspaceOneInputComplianceStatus = "noncompliant"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%201">Link to this property</a>

const WorkspaceOneInputComplianceStatusUnknown WorkspaceOneInputComplianceStatus = "unknown"

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20compliance_status">Link to this property</a>

ConnectionID string

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)%20%3E%20(property)%20connection_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(model)%20workspace_one_input%20%3E%20(schema)>)

#### Zero TrustDevicesPostureIntegrations

##### [List posture integrations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/list)

client.ZeroTrust.Devices.Posture.Integrations.List(ctx, query) (\*SinglePage\[[Integration](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/devices/posture/integration

##### [Get posture integration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/get)

client.ZeroTrust.Devices.Posture.Integrations.Get(ctx, integrationID, query) (\*[Integration](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/posture/integration/{integration\_id}

##### [Create posture integration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/create)

client.ZeroTrust.Devices.Posture.Integrations.New(ctx, params) (\*[Integration](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/devices/posture/integration

##### [Update posture integration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/edit)

client.ZeroTrust.Devices.Posture.Integrations.Edit(ctx, integrationID, params) (\*[Integration](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)>), error)

PATCH/accounts/{account\_id}/devices/posture/integration/{integration\_id}

##### [Delete posture integration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/delete)

client.ZeroTrust.Devices.Posture.Integrations.Delete(ctx, integrationID, body) (\*unknown, error)

DELETE/accounts/{account\_id}/devices/posture/integration/{integration\_id}

##### ModelsExpand Collapse

<details>

<summary>

type Integration struct{…}

</summary>

ID stringOptional

API UUID.

maxLength36

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Config IntegrationConfigOptional

The configuration object containing third-party integration information.

</summary>

APIURL string

The Workspace One API URL provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20api_url">Link to this property</a>

AuthURL string

The Workspace One Authorization URL depending on your region.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20auth_url">Link to this property</a>

ClientID string

The Workspace One client ID provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

Interval stringOptional

The interval between each posture check with the third-party API. Use <code>m</code> for minutes (e.g. <code>5m</code>) and <code>h</code> for hours (e.g. <code>12h</code>).

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20interval">Link to this property</a>

Name stringOptional

The name of the device posture integration.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type IntegrationTypeOptional

The type of device posture integration.

</summary>

One of the following:

const IntegrationTypeWorkspaceOne IntegrationType = "workspace\_one"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const IntegrationTypeCrowdstrikeS2s IntegrationType = "crowdstrike\_s2s"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const IntegrationTypeUptycs IntegrationType = "uptycs"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const IntegrationTypeIntune IntegrationType = "intune"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const IntegrationTypeKolide IntegrationType = "kolide"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const IntegrationTypeTaniumS2s IntegrationType = "tanium\_s2s"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const IntegrationTypeSentineloneS2s IntegrationType = "sentinelone\_s2s"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const IntegrationTypeCustomS2s IntegrationType = "custom\_s2s"

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(model)%20integration%20%3E%20(schema)>)

#### Zero TrustDevicesRevoke

##### [Revoke devices (deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/revoke/methods/create)

Deprecated

client.ZeroTrust.Devices.Revoke.New(ctx, params) (\*unknown, error)

POST/accounts/{account\_id}/devices/revoke

#### Zero TrustDevicesSettings

##### [Get device settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/settings/methods/get)

client.ZeroTrust.Devices.Settings.Get(ctx, query) (\*[DeviceSettings](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/settings

##### [Update device settings (deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/settings/methods/update)

Deprecated

client.ZeroTrust.Devices.Settings.Update(ctx, params) (\*[DeviceSettings](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/devices/settings

##### [Update device settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/settings/methods/edit)

client.ZeroTrust.Devices.Settings.Edit(ctx, params) (\*[DeviceSettings](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)>), error)

PATCH/accounts/{account\_id}/devices/settings

##### [Reset device settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/settings/methods/delete)

client.ZeroTrust.Devices.Settings.Delete(ctx, body) (\*[DeviceSettings](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/devices/settings

##### ModelsExpand Collapse

<details>

<summary>

type DeviceSettings struct{…}

</summary>

DisableForTime float64Optional

Sets the time limit, in seconds, that a user can use an override code to bypass WARP.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20disable_for_time">Link to this property</a>

ExternalEmergencySignalEnabled boolOptional

Controls whether the external emergency disconnect feature is enabled.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20external_emergency_signal_enabled">Link to this property</a>

ExternalEmergencySignalFingerprint stringOptional

The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external\_emergency\_signal\_url. If provided, the WARP client will use this value to verify the server’s identity. The device will ignore any response if the server’s certificate fingerprint does not exactly match this value.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20external_emergency_signal_fingerprint">Link to this property</a>

ExternalEmergencySignalInterval stringOptional

The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., “5m”, “2m30s”, “1h”). Minimum 30 seconds.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20external_emergency_signal_interval">Link to this property</a>

ExternalEmergencySignalURL stringOptional

The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20external_emergency_signal_url">Link to this property</a>

GatewayProxyEnabled boolOptional

Enable gateway proxy filtering on TCP.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20gateway_proxy_enabled">Link to this property</a>

GatewayUdpProxyEnabled boolOptional

Enable gateway proxy filtering on UDP.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20gateway_udp_proxy_enabled">Link to this property</a>

RootCertificateInstallationEnabled boolOptional

Enable installation of cloudflare managed root certificate.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20root_certificate_installation_enabled">Link to this property</a>

UseZtVirtualIP boolOptional

Enable using CGNAT virtual IPv4.

<a href="#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)%20%3E%20(property)%20use_zt_virtual_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(model)%20device_settings%20%3E%20(schema)>)

#### Zero TrustDevicesUnrevoke

##### [Unrevoke devices (deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/unrevoke/methods/create)

Deprecated

client.ZeroTrust.Devices.Unrevoke.New(ctx, params) (\*unknown, error)

POST/accounts/{account\_id}/devices/unrevoke

#### Zero TrustDevicesOverride Codes

##### [Get override codes (deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/override_codes/methods/list)

Deprecated

client.ZeroTrust.Devices.OverrideCodes.List(ctx, deviceID, query) (\*[DeviceOverrideCodeListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.override_codes%20%3E%20(model)%20DeviceOverrideCodeListResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/{device\_id}/override\_codes

##### [Get override codes](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/devices/subresources/override_codes/methods/get)

client.ZeroTrust.Devices.OverrideCodes.Get(ctx, registrationID, query) (\*[DeviceOverrideCodeGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.devices.override_codes%20%3E%20(model)%20DeviceOverrideCodeGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/devices/registrations/{registration\_id}/override\_codes

#### Zero TrustIdentity Providers

##### [List Access identity providers](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/methods/list)

client.ZeroTrust.IdentityProviders.List(ctx, params) (\*V4PagePaginationArray\[[IdentityProviderListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers

##### [Get an Access identity provider](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/methods/get)

client.ZeroTrust.IdentityProviders.Get(ctx, identityProviderID, query) (\*[IdentityProvider](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers/{identity\_provider\_id}

##### [Add an Access identity provider](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/methods/create)

client.ZeroTrust.IdentityProviders.New(ctx, params) (\*[IdentityProvider](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers

##### [Update an Access identity provider](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/methods/update)

client.ZeroTrust.IdentityProviders.Update(ctx, identityProviderID, params) (\*[IdentityProvider](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers/{identity\_provider\_id}

##### [Delete an Access identity provider](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/methods/delete)

client.ZeroTrust.IdentityProviders.Delete(ctx, identityProviderID, body) (\*[IdentityProviderDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers/{identity\_provider\_id}

##### ModelsExpand Collapse

<details>

<summary>

type AzureAD struct{…}

</summary>

<details>

<summary>

Config AzureADConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

ConditionalAccessEnabled boolOptional

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20conditional_access_enabled">Link to this property</a>

DirectoryID stringOptional

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20directory_id">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

Prompt AzureADConfigPromptOptional

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

</summary>

One of the following:

const AzureADConfigPromptLogin AzureADConfigPrompt = "login"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

const AzureADConfigPromptSelectAccount AzureADConfigPrompt = "select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

const AzureADConfigPromptNone AzureADConfigPrompt = "none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

SupportGroups boolOptional

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20support_groups">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet AzureADSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate AzureADSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)>)

<details>

<summary>

type GenericOAuthConfig struct{…}

</summary>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)>)

<details>

<summary>

type IdentityProvider interface{…}

</summary>

One of the following:

<details>

<summary>

type AzureAD struct{…}

</summary>

<details>

<summary>

Config AzureADConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

ConditionalAccessEnabled boolOptional

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20conditional_access_enabled">Link to this property</a>

DirectoryID stringOptional

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20directory_id">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

Prompt AzureADConfigPromptOptional

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

</summary>

One of the following:

const AzureADConfigPromptLogin AzureADConfigPrompt = "login"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

const AzureADConfigPromptSelectAccount AzureADConfigPrompt = "select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

const AzureADConfigPromptNone AzureADConfigPrompt = "none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

SupportGroups boolOptional

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20support_groups">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet AzureADSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate AzureADSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessCentrify struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessCentrifyConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

CentrifyAccount stringOptional

Your centrify account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20centrify_account">Link to this property</a>

CentrifyAppID stringOptional

Your centrify app id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20centrify_app_id">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessCentrifySAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessCentrifySAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessFacebook struct{…}

</summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessFacebookSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessFacebookSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessGitHub struct{…}

</summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessGitHubSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessGitHubSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessGoogle struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessGoogleConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessGoogleSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessGoogleSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessGoogleApps struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessGoogleAppsConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

AppsDomain stringOptional

Your companies TLD

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20apps_domain">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

Prompt IdentityProviderAccessGoogleAppsConfigPromptOptional

Configures the prompt behavior for Google authentication.

</summary>

One of the following:

const IdentityProviderAccessGoogleAppsConfigPromptNone IdentityProviderAccessGoogleAppsConfigPrompt = "none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderAccessGoogleAppsConfigPromptConsent IdentityProviderAccessGoogleAppsConfigPrompt = "consent"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderAccessGoogleAppsConfigPromptSelectAccount IdentityProviderAccessGoogleAppsConfigPrompt = "select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

UseLoginHint boolOptional

Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20use_login_hint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessGoogleAppsSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessGoogleAppsSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessLinkedin struct{…}

</summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessLinkedinSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessLinkedinSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessOIDC struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessOIDCConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

AuthURL stringOptional

The authorization\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20auth_url">Link to this property</a>

CERTsURL stringOptional

The jwks\_uri endpoint of your IdP to allow the IdP keys to sign the tokens

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20certs_url">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

PKCEEnabled boolOptional

Enable Proof Key for Code Exchange (PKCE)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20pkce_enabled">Link to this property</a>

Scopes \[]stringOptional

OAuth scopes

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20scopes">Link to this property</a>

TokenURL stringOptional

The token\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20token_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessOIDCSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessOIDCSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessOkta struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessOktaConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

AuthorizationServerID stringOptional

Your okta authorization server id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20authorization_server_id">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

OktaAccount stringOptional

Your okta account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20okta_account">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessOktaSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessOktaSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%208">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessOnelogin struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessOneloginConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

OneloginAccount stringOptional

Your OneLogin account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20onelogin_account">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessOneloginSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessOneloginSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%209">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessPingone struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessPingoneConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

PingEnvID stringOptional

Your PingOne environment identifier

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20ping_env_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessPingoneSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessPingoneSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2010">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessSAML struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessSAMLConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Attributes \[]stringOptional

A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20attributes">Link to this property</a>

EmailAttributeName stringOptional

The attribute name for email in the SAML response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20email_attribute_name">Link to this property</a>

EnableEncryption boolOptional

Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set.

To enable encryption:

1. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>
2. Set this field to <code>true</code> and include <code>saml_certificate_set_id</code> in the PUT request
3. Configure the public certificate in your external Identity Provider

Note: Requires <code>saml_certificate_set_id</code> to be set when <code>true</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20enable_encryption">Link to this property</a>

ForceAuthn boolOptional

Asks the IdP to reauthenticate the user for each SAML authentication request.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20force_authn">Link to this property</a>

<details>

<summary>

HeaderAttributes \[]IdentityProviderAccessSAMLConfigHeaderAttributeOptional

Add a list of attribute names that will be returned in the response header from the Access callback.

</summary>

AttributeName stringOptional

attribute name from the IDP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes%20%3E%20(items)%20%3E%20(property)%20attribute_name">Link to this property</a>

HeaderName stringOptional

header that will be added on the request to the origin

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes%20%3E%20(items)%20%3E%20(property)%20header_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes">Link to this property</a>

IdPPublicCERTs \[]stringOptional

X509 certificate to verify the signature in the SAML authentication response

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20idp_public_certs">Link to this property</a>

IssuerURL stringOptional

IdP Entity ID or Issuer URL

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20issuer_url">Link to this property</a>

MaxSSOURLLength int64Optional

The maximum URL length the IdP accepts for the SSO redirect URL. When the constructed SSO URL would exceed this length, the RelayState is stored server-side and a short nonce is passed to the IdP instead. Set this if your IdP enforces a URL length limit.

maximum100000

minimum512

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20max_sso_url_length">Link to this property</a>

SignRequest boolOptional

Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20sign_request">Link to this property</a>

SSOTargetURL stringOptional

URL to send the SAML authentication requests to

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20sso_target_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessSAMLSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessSAMLSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2011">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessYandex struct{…}

</summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessYandexSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessYandexSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2012">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessOnetimepin struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessOnetimepinConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

RedirectURL stringOptional

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessOnetimepinSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessOnetimepinSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2013">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessCloudflare struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessCloudflareConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

RedirectURL stringOptional

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

RestrictToAccountMembers boolOptional

When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config%20%3E%20(property)%20restrict_to_account_members">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessCloudflareSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessCloudflareSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2014">Link to this property</a>

<details>

<summary>

type IdentityProviderAccessPasskeys struct{…}

</summary>

<details>

<summary>

Config IdentityProviderAccessPasskeysConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

LoginPageAutoPrompt boolOptional

When enabled, the Access login page automatically prompts the user to authenticate with a passkey.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config%20%3E%20(property)%20login_page_auto_prompt">Link to this property</a>

RedirectURL stringOptional

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20name">Link to this property</a>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderAccessPasskeysSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderAccessPasskeysSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)%20%3E%20(variant)%2015">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider%20%3E%20(schema)>)

<details>

<summary>

type IdentityProviderSCIMConfig struct{…}

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)>)

<details>

<summary>

type IdentityProviderType string

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)>)

#### Zero TrustIdentity ProvidersSCIM

#### Zero TrustIdentity ProvidersSCIMGroups

##### [List SCIM Group resources](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/subresources/scim/subresources/groups/methods/list)

client.ZeroTrust.IdentityProviders.SCIM.Groups.List(ctx, identityProviderID, params) (\*V4PagePaginationArray\[[ZeroTrustGroup](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/identity\_providers/{identity\_provider\_id}/scim/groups

#### Zero TrustIdentity ProvidersSCIMUsers

##### [List SCIM User resources](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/subresources/scim/subresources/users/methods/list)

client.ZeroTrust.IdentityProviders.SCIM.Users.List(ctx, identityProviderID, params) (\*V4PagePaginationArray\[[AccessUser](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/identity\_providers/{identity\_provider\_id}/scim/users

#### Zero TrustIdentity ProvidersSAML Certificate

##### [Create SAML encryption certificate for Identity Provider](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers/subresources/saml_certificate/methods/create)

client.ZeroTrust.IdentityProviders.SAMLCertificate.New(ctx, identityProviderID, body) (\*[IdentityProviderSAMLCertificateNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers.saml_certificate%20%3E%20(model)%20IdentityProviderSAMLCertificateNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/identity\_providers/{identity\_provider\_id}/saml\_certificate

#### Zero TrustOrganizations

##### [Get your Zero Trust organization](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/list)

client.ZeroTrust.Organizations.List(ctx, query) (\*[OrganizationListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20OrganizationListResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Create your Zero Trust organization](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/create)

client.ZeroTrust.Organizations.New(ctx, params) (\*[Organization](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Update your Zero Trust organization](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/update)

client.ZeroTrust.Organizations.Update(ctx, params) (\*[Organization](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Revoke all Access tokens for a user](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/revoke_users)

client.ZeroTrust.Organizations.RevokeUsers(ctx, params) (\*[OrganizationRevokeUsersResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20OrganizationRevokeUsersResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations/revoke\_user

##### ModelsExpand Collapse

<details>

<summary>

type LoginDesign struct{…}

</summary>

BackgroundColor stringOptional

The background color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20background_color">Link to this property</a>

FooterText stringOptional

The text at the bottom of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20footer_text">Link to this property</a>

HeaderText stringOptional

The text at the top of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20header_text">Link to this property</a>

LogoPath stringOptional

The URL of the logo on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20logo_path">Link to this property</a>

TextColor stringOptional

The text color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20text_color">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)>)

<details>

<summary>

type Organization struct{…}

</summary>

AllowAuthenticateViaWARP boolOptional

When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20allow_authenticate_via_warp">Link to this property</a>

AuthDomain stringOptional

The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format <code>adjective-noun-hex4</code> (e.g. <code>frosty-moon-7a3b.cloudflareaccess.com</code>).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20auth_domain">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

<details>

<summary>

CustomPages OrganizationCustomPagesOptional

</summary>

Forbidden stringOptional

The uid of the custom page to use when a user is denied access after failing a non-identity rule.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20forbidden">Link to this property</a>

IdentityDenied stringOptional

The uid of the custom page to use when a user is denied access.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20identity_denied">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages">Link to this property</a>

DenyUnmatchedRequests boolOptional

Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the <code>deny_unmatched_requests_exempted_zone_names</code> array.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests">Link to this property</a>

DenyUnmatchedRequestsExemptedZoneNames \[]stringOptional

Contains zone names to exempt from the <code>deny_unmatched_requests</code> feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests_exempted_zone_names">Link to this property</a>

IsUIReadOnly boolOptional

Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20is_ui_read_only">Link to this property</a>

LoginDesign <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)">LoginDesign</a>Optional

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design">Link to this property</a>

<details>

<summary>

MfaConfig OrganizationMfaConfigOptional

Configures multi-factor authentication (MFA) settings for an organization.

</summary>

<details>

<summary>

AllowedAuthenticators \[]OrganizationMfaConfigAllowedAuthenticatorOptional

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

</summary>

One of the following:

const OrganizationMfaConfigAllowedAuthenticatorTotp OrganizationMfaConfigAllowedAuthenticator = "totp"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorBiometrics OrganizationMfaConfigAllowedAuthenticator = "biometrics"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorSecurityKey OrganizationMfaConfigAllowedAuthenticator = "security\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorPivKey OrganizationMfaConfigAllowedAuthenticator = "piv\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorSSHFido2Key OrganizationMfaConfigAllowedAuthenticator = "ssh\_fido2\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

AmrMatchingSessionDuration stringOptional

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20amr_matching_session_duration">Link to this property</a>

RequiredAaguids stringOptional

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

formatuuid

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20required_aaguids">Link to this property</a>

SessionDuration stringOptional

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

<details>

<summary>

MfaPivKeyRequirements OrganizationMfaPivKeyRequirementsOptional

Configures PIV key requirements for MFA using hardware security keys.

</summary>

<details>

<summary>

PinPolicy OrganizationMfaPivKeyRequirementsPinPolicyOptional

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsPinPolicyNever OrganizationMfaPivKeyRequirementsPinPolicy = "never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsPinPolicyOnce OrganizationMfaPivKeyRequirementsPinPolicy = "once"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsPinPolicyAlways OrganizationMfaPivKeyRequirementsPinPolicy = "always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy">Link to this property</a>

RequireFipsDevice boolOptional

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20require_fips_device">Link to this property</a>

<details>

<summary>

SSHKeySize \[]OrganizationMfaPivKeyRequirementsSSHKeySizeOptional

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsSSHKeySize256 OrganizationMfaPivKeyRequirementsSSHKeySize = 256

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize384 OrganizationMfaPivKeyRequirementsSSHKeySize = 384

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize521 OrganizationMfaPivKeyRequirementsSSHKeySize = 521

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize2048 OrganizationMfaPivKeyRequirementsSSHKeySize = 2048

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize3072 OrganizationMfaPivKeyRequirementsSSHKeySize = 3072

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize4096 OrganizationMfaPivKeyRequirementsSSHKeySize = 4096

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size">Link to this property</a>

<details>

<summary>

SSHKeyType \[]OrganizationMfaPivKeyRequirementsSSHKeyTypeOptional

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsSSHKeyTypeEcdsa OrganizationMfaPivKeyRequirementsSSHKeyType = "ecdsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeyTypeEd25519 OrganizationMfaPivKeyRequirementsSSHKeyType = "ed25519"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeyTypeRSA OrganizationMfaPivKeyRequirementsSSHKeyType = "rsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type">Link to this property</a>

<details>

<summary>

TouchPolicy OrganizationMfaPivKeyRequirementsTouchPolicyOptional

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsTouchPolicyNever OrganizationMfaPivKeyRequirementsTouchPolicy = "never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsTouchPolicyAlways OrganizationMfaPivKeyRequirementsTouchPolicy = "always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsTouchPolicyCached OrganizationMfaPivKeyRequirementsTouchPolicy = "cached"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements">Link to this property</a>

MfaRequiredForAllApps boolOptional

Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_required_for_all_apps">Link to this property</a>

Name stringOptional

The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

ServiceTokenInactivity OrganizationServiceTokenInactivityOptional

Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

<details>

<summary>

Action OrganizationServiceTokenInactivityAction

The action applied to an inactive service token.

</summary>

One of the following:

const OrganizationServiceTokenInactivityActionDisable OrganizationServiceTokenInactivityAction = "disable"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

const OrganizationServiceTokenInactivityActionDelete OrganizationServiceTokenInactivityAction = "delete"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action">Link to this property</a>

Enabled bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20enabled">Link to this property</a>

InactivityThresholdDays int64

The number of days a service token must be inactive before the configured action is applied.

maximum365

minimum30

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20inactivity_threshold_days">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for applications will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

StrictServiceTokenAuth boolOptional

Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20strict_service_token_auth">Link to this property</a>

UIReadOnlyToggleReason stringOptional

A description of the reason why the UI read only field is being toggled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20ui_read_only_toggle_reason">Link to this property</a>

UserSeatExpirationInactiveTime stringOptional

The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: <code>ns</code>, <code>us</code> (or <code>µs</code>), <code>ms</code>, <code>s</code>, <code>m</code>, <code>h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20user_seat_expiration_inactive_time">Link to this property</a>

WARPAuthNonBrowser401 boolOptional

When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20warp_auth_non_browser_401">Link to this property</a>

WARPAuthSessionDuration stringOptional

The amount of time that tokens issued for applications will be valid. Must be in the format <code>30m</code> or <code>2h45m</code>. Valid time units are: m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20warp_auth_session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>)

#### Zero TrustOrganizationsDOH

##### [Get your Zero Trust organization DoH settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/subresources/doh/methods/get)

client.ZeroTrust.Organizations.DOH.Get(ctx, query) (\*[OrganizationDOHGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20OrganizationDOHGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/organizations/doh

##### [Update your Zero Trust organization DoH settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/subresources/doh/methods/update)

client.ZeroTrust.Organizations.DOH.Update(ctx, params) (\*[OrganizationDOHUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20OrganizationDOHUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/organizations/doh

#### Zero TrustSeats

##### [Update a user seat](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/seats/methods/edit)

client.ZeroTrust.Seats.Edit(ctx, params) (\*SinglePage\[[Seat](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)>)], error)

PATCH/accounts/{account\_id}/access/seats

##### ModelsExpand Collapse

<details>

<summary>

type Seat struct{…}

</summary>

AccessSeat boolOptional

True if the seat is part of Access.

<a href="#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)%20%3E%20(property)%20access_seat">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

GatewaySeat boolOptional

True if the seat is part of Gateway.

<a href="#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)%20%3E%20(property)%20gateway_seat">Link to this property</a>

SeatUID stringOptional

The unique API identifier for the Zero Trust seat.

maxLength36

<a href="#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)%20%3E%20(property)%20seat_uid">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.seats%20%3E%20(model)%20seat%20%3E%20(schema)>)

#### Zero TrustAccess

#### Zero TrustAccessAI Controls

#### Zero TrustAccessAI ControlsMcp

#### Zero TrustAccessAI ControlsMcpPortals

##### [List MCP Portals](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/list)

client.ZeroTrust.Access.AIControls.Mcp.Portals.List(ctx, params) (\*V4PagePaginationArray\[[AccessAIControlMcpPortalListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Create a new MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/create)

client.ZeroTrust.Access.AIControls.Mcp.Portals.New(ctx, params) (\*[AccessAIControlMcpPortalNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Read details of an MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/read)

client.ZeroTrust.Access.AIControls.Mcp.Portals.Read(ctx, id, query) (\*[AccessAIControlMcpPortalReadResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalReadResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Update an MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/update)

client.ZeroTrust.Access.AIControls.Mcp.Portals.Update(ctx, id, params) (\*[AccessAIControlMcpPortalUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Delete an MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/delete)

client.ZeroTrust.Access.AIControls.Mcp.Portals.Delete(ctx, id, body) (\*[AccessAIControlMcpPortalDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

#### Zero TrustAccessAI ControlsMcpServers

##### [List MCP Servers](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/list)

client.ZeroTrust.Access.AIControls.Mcp.Servers.List(ctx, params) (\*V4PagePaginationArray\[[AccessAIControlMcpServerListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Create a new MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/create)

client.ZeroTrust.Access.AIControls.Mcp.Servers.New(ctx, params) (\*[AccessAIControlMcpServerNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Read the details of an MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/read)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Read(ctx, id, query) (\*[AccessAIControlMcpServerReadResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerReadResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Update an MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/update)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Update(ctx, id, params) (\*[AccessAIControlMcpServerUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Delete an MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/delete)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Delete(ctx, id, body) (\*[AccessAIControlMcpServerDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Sync MCP Server Capabilities](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/sync)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Sync(ctx, id, body) (\*[AccessAIControlMcpServerSyncResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerSyncResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}/sync

#### Zero TrustAccessGateway CA

##### [List SSH Certificate Authorities (CA)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/list)

client.ZeroTrust.Access.GatewayCA.List(ctx, query) (\*SinglePage\[[AccessGatewayCAListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20AccessGatewayCAListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/gateway\_ca

##### [Add a new SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/create)

client.ZeroTrust.Access.GatewayCA.New(ctx, body) (\*[AccessGatewayCANewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20AccessGatewayCANewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/gateway\_ca

##### [Delete an SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/delete)

client.ZeroTrust.Access.GatewayCA.Delete(ctx, certificateID, body) (\*[AccessGatewayCADeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20AccessGatewayCADeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/gateway\_ca/{certificate\_id}

#### Zero TrustAccessIdP Federation Grants

##### [List IdP federation grants](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/list)

client.ZeroTrust.Access.IdPFederationGrants.List(ctx, query) (\*\[] [IdPFederationGrant](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/idp\_federation\_grants

##### [Create an IdP federation grant](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/create)

client.ZeroTrust.Access.IdPFederationGrants.New(ctx, params) (\*[IdPFederationGrant](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/idp\_federation\_grants

##### [Get an IdP federation grant](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/get)

client.ZeroTrust.Access.IdPFederationGrants.Get(ctx, grantID, query) (\*[IdPFederationGrant](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### [Delete an IdP federation grant](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/delete)

client.ZeroTrust.Access.IdPFederationGrants.Delete(ctx, grantID, body) (\*[AccessIdPFederationGrantDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20AccessIdPFederationGrantDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### ModelsExpand Collapse

<details>

<summary>

type IdPFederationGrant struct{…}

</summary>

ID string

UID of the IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

IdPID string

UID of the identity provider being federated.

formatuuid

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20idp_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>)

#### Zero TrustAccessSAML Certificates

##### [List SAML certificate sets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/list)

client.ZeroTrust.Access.SAMLCertificates.List(ctx, params) (\*V4PagePaginationArray\[[AccessSAMLCertificateListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20AccessSAMLCertificateListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/saml\_certificates

##### [Get SAML certificate set](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get)

client.ZeroTrust.Access.SAMLCertificates.Get(ctx, samlCERTSetID, query) (\*[AccessSAMLCertificateGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20AccessSAMLCertificateGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}

##### [Rotate SAML certificate](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/rotate)

client.ZeroTrust.Access.SAMLCertificates.Rotate(ctx, samlCERTSetID, body) (\*[AccessSAMLCertificateRotateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20AccessSAMLCertificateRotateResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/rotate

##### [Download current certificate in PEM format](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get_pem)

client.ZeroTrust.Access.SAMLCertificates.GetPem(ctx, samlCERTSetID, query) (\*Response, error)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/pem

#### Zero TrustAccessInfrastructure

#### Zero TrustAccessInfrastructureTargets

##### [List all targets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/list)

client.ZeroTrust.Access.Infrastructure.Targets.List(ctx, params) (\*V4PagePaginationArray\[[AccessInfrastructureTargetListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/infrastructure/targets

##### [Get target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/get)

client.ZeroTrust.Access.Infrastructure.Targets.Get(ctx, targetID, query) (\*[AccessInfrastructureTargetGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/create)

client.ZeroTrust.Access.Infrastructure.Targets.New(ctx, params) (\*[AccessInfrastructureTargetNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/infrastructure/targets

##### [Update target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/update)

client.ZeroTrust.Access.Infrastructure.Targets.Update(ctx, targetID, params) (\*[AccessInfrastructureTargetUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Delete target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/delete)

client.ZeroTrust.Access.Infrastructure.Targets.Delete(ctx, targetID, body) error

DELETE/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new targets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_update)

client.ZeroTrust.Access.Infrastructure.Targets.BulkUpdate(ctx, params) (\*SinglePage\[[AccessInfrastructureTargetBulkUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetBulkUpdateResponse%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets (Deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete)

Deprecated

client.ZeroTrust.Access.Infrastructure.Targets.BulkDelete(ctx, body) error

DELETE/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete_v2)

client.ZeroTrust.Access.Infrastructure.Targets.BulkDeleteV2(ctx, params) error

POST/accounts/{account\_id}/infrastructure/targets/batch\_delete

#### Zero TrustAccessApplications

##### [List Access applications](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/list)

client.ZeroTrust.Access.Applications.List(ctx, params) (\*V4PagePaginationArray\[[AccessApplicationListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Get an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/get)

client.ZeroTrust.Access.Applications.Get(ctx, appID, query) (\*[AccessApplicationGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationGetResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Add an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/create)

client.ZeroTrust.Access.Applications.New(ctx, params) (\*[AccessApplicationNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationNewResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Update an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/update)

client.ZeroTrust.Access.Applications.Update(ctx, appID, params) (\*[AccessApplicationUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationUpdateResponse%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Delete an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/delete)

client.ZeroTrust.Access.Applications.Delete(ctx, appID, body) (\*[AccessApplicationDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Revoke application tokens](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/revoke_tokens)

client.ZeroTrust.Access.Applications.RevokeTokens(ctx, appID, body) (\*[AccessApplicationRevokeTokensResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationRevokeTokensResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/revoke\_tokens

##### ModelsExpand Collapse

type AllowedHeaders string

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)>)

type AllowedIdPs string

The identity providers selected for application.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)>)

<details>

<summary>

type AllowedMethods string

</summary>

One of the following:

const AllowedMethodsGet <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const AllowedMethodsPost <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const AllowedMethodsHead <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const AllowedMethodsPut <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const AllowedMethodsDelete <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const AllowedMethodsConnect <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const AllowedMethodsOptions <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const AllowedMethodsTrace <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const AllowedMethodsPatch <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)>)

type AllowedOrigins string

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)>)

type AppID string

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)

<details>

<summary>

type Application interface{…}

</summary>

One of the following:

<details>

<summary>

ApplicationSelfHostedApplication

</summary>

Domain string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

AllowIframe boolOptional

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allow_iframe">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CORSHeaders <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a>Optional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20cors_headers">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

CustomDenyMessage stringOptional

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_message">Link to this property</a>

CustomDenyURL stringOptional

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_url">Link to this property</a>

EagerRedirectCookieSetting boolOptional

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

EnableBindingCookie boolOptional

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

HTTPOnlyCookieAttribute boolOptional

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

OptionsPreflightBypass boolOptional

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

SameSiteCookieAttribute stringOptional

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationSelfHostedApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationSelfHostedApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config">Link to this property</a>

ServiceAuth401Redirect boolOptional

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20session_duration">Link to this property</a>

SkipInterstitial boolOptional

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20skip_interstitial">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

UseClientlessIsolationAppLauncherURL boolOptional

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplication

</summary>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SaaSApp ApplicationSaaSApplicationSaaSAppOptional

</summary>

One of the following:

<details>

<summary>

ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2

</summary>

<details>

<summary>

AuthType ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthTypeOptional

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthTypeSAML ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthTypeOIDC ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type">Link to this property</a>

ConsumerServiceURL stringOptional

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20consumer_service_url">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

CustomAttributes \[]ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributeOptional

</summary>

FriendlyName stringOptional

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

Name stringOptional

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameFormat ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatOptional

A globally unique name for an identity or service provider.

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatUnspecified ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatBasic ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatURI ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

Required boolOptional

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Source ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesSourceOptional

</summary>

Name stringOptional

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

NameByIdP map\[string, string]Optional

A mapping from IdP ID to attribute name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes">Link to this property</a>

IdPEntityID stringOptional

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20idp_entity_id">Link to this property</a>

NameIDFormat <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a>Optional

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_format">Link to this property</a>

NameIDTransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20public_key">Link to this property</a>

SPEntityID stringOptional

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sp_entity_id">Link to this property</a>

SSOEndpoint stringOptional

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sso_endpoint">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2

</summary>

AccessTokenLifetime stringOptional

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

AllowPKCEWithoutClientSecret boolOptional

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

AppLauncherURL stringOptional

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

AuthType ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthTypeOptional

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthTypeSAML ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthTypeOIDC ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type">Link to this property</a>

ClientID stringOptional

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_secret">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

CustomClaims \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimOptional

</summary>

Name stringOptional

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

Required boolOptional

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Scope ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeOptional

The scope of the claim.

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeGroups ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeProfile ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeEmail ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeOpenid ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

Source ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsSourceOptional

</summary>

Name stringOptional

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameByIdP \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsSourceNameByIdPOptional

A mapping from IdP ID to attribute name.

</summary>

IdPID stringOptional

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

SourceName stringOptional

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

GrantTypes \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeOptional

The OIDC flows supported by this application

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeAuthorizationCode ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeAuthorizationCodeWithPKCE ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeRefreshTokens ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeHybrid ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeImplicit ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types">Link to this property</a>

GroupFilterRegex stringOptional

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

HybridAndImplicitOptions ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2HybridAndImplicitOptionsOptional

</summary>

ReturnAccessTokenFromAuthorizationEndpoint boolOptional

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

ReturnIDTokenFromAuthorizationEndpoint boolOptional

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20public_key">Link to this property</a>

RedirectURIs \[]stringOptional

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

RefreshTokenOptions ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2RefreshTokenOptionsOptional

</summary>

Lifetime stringOptional

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

Scopes \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeOptional

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeOpenid ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeGroups ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeEmail ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeProfile ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationSaaSApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationSaaSApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

Type stringOptional

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplication

</summary>

Domain string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

AllowIframe boolOptional

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allow_iframe">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CORSHeaders <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a>Optional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20cors_headers">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20created_at">Link to this property</a>

CustomDenyMessage stringOptional

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_message">Link to this property</a>

CustomDenyURL stringOptional

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_url">Link to this property</a>

EagerRedirectCookieSetting boolOptional

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

EnableBindingCookie boolOptional

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

HTTPOnlyCookieAttribute boolOptional

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

OptionsPreflightBypass boolOptional

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

SameSiteCookieAttribute stringOptional

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBrowserSSHApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBrowserSSHApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

ServiceAuth401Redirect boolOptional

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20session_duration">Link to this property</a>

SkipInterstitial boolOptional

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20skip_interstitial">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20updated_at">Link to this property</a>

UseClientlessIsolationAppLauncherURL boolOptional

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplication

</summary>

Domain string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

AllowIframe boolOptional

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allow_iframe">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CORSHeaders <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a>Optional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20cors_headers">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20created_at">Link to this property</a>

CustomDenyMessage stringOptional

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_message">Link to this property</a>

CustomDenyURL stringOptional

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_url">Link to this property</a>

EagerRedirectCookieSetting boolOptional

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

EnableBindingCookie boolOptional

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

HTTPOnlyCookieAttribute boolOptional

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

OptionsPreflightBypass boolOptional

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

SameSiteCookieAttribute stringOptional

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBrowserVNCApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBrowserVNCApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

ServiceAuth401Redirect boolOptional

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20session_duration">Link to this property</a>

SkipInterstitial boolOptional

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20skip_interstitial">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20updated_at">Link to this property</a>

UseClientlessIsolationAppLauncherURL boolOptional

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplication

</summary>

<details>

<summary>

Type ApplicationAppLauncherApplicationType

The application type.

</summary>

One of the following:

const ApplicationAppLauncherApplicationTypeSelfHosted ApplicationAppLauncherApplicationType = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const ApplicationAppLauncherApplicationTypeSaaS ApplicationAppLauncherApplicationType = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const ApplicationAppLauncherApplicationTypeSSH ApplicationAppLauncherApplicationType = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const ApplicationAppLauncherApplicationTypeVNC ApplicationAppLauncherApplicationType = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const ApplicationAppLauncherApplicationTypeAppLauncher ApplicationAppLauncherApplicationType = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const ApplicationAppLauncherApplicationTypeWARP ApplicationAppLauncherApplicationType = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const ApplicationAppLauncherApplicationTypeBISO ApplicationAppLauncherApplicationType = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const ApplicationAppLauncherApplicationTypeBookmark ApplicationAppLauncherApplicationType = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const ApplicationAppLauncherApplicationTypeDashSSO ApplicationAppLauncherApplicationType = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20allowed_idps">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20created_at">Link to this property</a>

Domain stringOptional

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20domain">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationAppLauncherApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationAppLauncherApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplication

</summary>

<details>

<summary>

Type ApplicationDeviceEnrollmentPermissionsApplicationType

The application type.

</summary>

One of the following:

const ApplicationDeviceEnrollmentPermissionsApplicationTypeSelfHosted ApplicationDeviceEnrollmentPermissionsApplicationType = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeSaaS ApplicationDeviceEnrollmentPermissionsApplicationType = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeSSH ApplicationDeviceEnrollmentPermissionsApplicationType = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeVNC ApplicationDeviceEnrollmentPermissionsApplicationType = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeAppLauncher ApplicationDeviceEnrollmentPermissionsApplicationType = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeWARP ApplicationDeviceEnrollmentPermissionsApplicationType = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeBISO ApplicationDeviceEnrollmentPermissionsApplicationType = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeBookmark ApplicationDeviceEnrollmentPermissionsApplicationType = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeDashSSO ApplicationDeviceEnrollmentPermissionsApplicationType = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20allowed_idps">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20created_at">Link to this property</a>

Domain stringOptional

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20domain">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplication

</summary>

<details>

<summary>

Type ApplicationBrowserIsolationPermissionsApplicationType

The application type.

</summary>

One of the following:

const ApplicationBrowserIsolationPermissionsApplicationTypeSelfHosted ApplicationBrowserIsolationPermissionsApplicationType = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeSaaS ApplicationBrowserIsolationPermissionsApplicationType = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeSSH ApplicationBrowserIsolationPermissionsApplicationType = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeVNC ApplicationBrowserIsolationPermissionsApplicationType = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeAppLauncher ApplicationBrowserIsolationPermissionsApplicationType = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeWARP ApplicationBrowserIsolationPermissionsApplicationType = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeBISO ApplicationBrowserIsolationPermissionsApplicationType = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeBookmark ApplicationBrowserIsolationPermissionsApplicationType = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeDashSSO ApplicationBrowserIsolationPermissionsApplicationType = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20allowed_idps">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20created_at">Link to this property</a>

Domain stringOptional

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20domain">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBrowserIsolationPermissionsApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplication

</summary>

Domain string

The URL or domain of the bookmark.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

AppLauncherVisible boolOptional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20aud">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20created_at">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBookmarkApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBookmarkApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)>)

<details>

<summary>

type ApplicationPolicy struct{…}

</summary>

ID stringOptional

The UUID of the policy

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

ApprovalGroups \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a>Optional

Administrators who can approve a temporary authentication request.

</summary>

ApprovalsNeeded float64

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

EmailAddresses \[]stringOptional

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

EmailListUUID stringOptional

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_groups">Link to this property</a>

ApprovalRequired boolOptional

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_required">Link to this property</a>

<details>

<summary>

ConnectionRules ApplicationPolicyConnectionRulesOptional

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

RDP ApplicationPolicyConnectionRulesRDPOptional

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

<details>

<summary>

AllowedClipboardLocalToRemoteFormats \[]ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormatOptional

Clipboard formats allowed when copying from local machine to remote RDP session.

</summary>

One of the following:

const ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormatText ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormat = "text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormatFile ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormat = "file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

<details>

<summary>

AllowedClipboardRemoteToLocalFormats \[]ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormatOptional

Clipboard formats allowed when copying from remote RDP session to local machine.

</summary>

One of the following:

const ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormatText ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormat = "text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormatFile ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormat = "file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Decision <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a>Optional

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

Exclude \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

Include \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20include">Link to this property</a>

IsolationRequired boolOptional

Require this application to be served in an isolated browser for users matching this policy. ‘Client Web Isolation’ must be on for the account in order to use this feature.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20isolation_required">Link to this property</a>

<details>

<summary>

MfaConfig ApplicationPolicyMfaConfigOptional

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

AllowedAuthenticators \[]ApplicationPolicyMfaConfigAllowedAuthenticatorOptional

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

const ApplicationPolicyMfaConfigAllowedAuthenticatorTotp ApplicationPolicyMfaConfigAllowedAuthenticator = "totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationPolicyMfaConfigAllowedAuthenticatorBiometrics ApplicationPolicyMfaConfigAllowedAuthenticator = "biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const ApplicationPolicyMfaConfigAllowedAuthenticatorSecurityKey ApplicationPolicyMfaConfigAllowedAuthenticator = "security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

MfaDisabled boolOptional

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

SessionDuration stringOptional

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

Name stringOptional

The name of the Access policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

PurposeJustificationPrompt stringOptional

A custom message that will appear on the purpose justification screen.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_prompt">Link to this property</a>

PurposeJustificationRequired boolOptional

Require users to enter a justification when they log in to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_required">Link to this property</a>

<details>

<summary>

Require \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20require">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for the application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)>)

<details>

<summary>

type ApplicationType string

The application type.

</summary>

One of the following:

const ApplicationTypeSelfHosted <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const ApplicationTypeEndUser <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "end\_user"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const ApplicationTypeSaaS <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const ApplicationTypeSSH <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const ApplicationTypeVNC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const ApplicationTypeAppLauncher <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const ApplicationTypeWARP <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const ApplicationTypeBISO <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const ApplicationTypeBookmark <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const ApplicationTypeDashSSO <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const ApplicationTypeInfrastructure <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "infrastructure"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const ApplicationTypeRDP <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "rdp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const ApplicationTypeMcp <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "mcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const ApplicationTypeMcpPortal <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "mcp\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const ApplicationTypeProxyEndpoint <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "proxy\_endpoint"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)>)

<details>

<summary>

type CORSHeaders struct{…}

</summary>

AllowAllHeaders boolOptional

Allows all HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_headers">Link to this property</a>

AllowAllMethods boolOptional

Allows all HTTP request methods.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_methods">Link to this property</a>

AllowAllOrigins boolOptional

Allows all origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_origins">Link to this property</a>

AllowCredentials boolOptional

When set to <code>true</code>, includes credentials (cookies, authorization headers, or TLS client certificates) with requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_credentials">Link to this property</a>

AllowedHeaders \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)">AllowedHeaders</a>Optional

Allowed HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_headers">Link to this property</a>

<details>

<summary>

AllowedMethods \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a>Optional

Allowed HTTP request methods.

</summary>

One of the following:

const AllowedMethodsGet <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const AllowedMethodsPost <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const AllowedMethodsHead <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const AllowedMethodsPut <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const AllowedMethodsDelete <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const AllowedMethodsConnect <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const AllowedMethodsOptions <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const AllowedMethodsTrace <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const AllowedMethodsPatch <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_methods">Link to this property</a>

AllowedOrigins \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)">AllowedOrigins</a>Optional

Allowed origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_origins">Link to this property</a>

MaxAge float64Optional

The maximum number of seconds the results of a preflight request can be cached.

maximum86400

minimum-1

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20max_age">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)>)

<details>

<summary>

type Decision string

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

</summary>

One of the following:

const DecisionAllow <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "allow"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const DecisionDeny <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "deny"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const DecisionNonIdentity <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "non\_identity"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const DecisionBypass <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "bypass"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)>)

<details>

<summary>

type OIDCSaaSApp struct{…}

</summary>

AccessTokenLifetime stringOptional

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

AllowPKCEWithoutClientSecret boolOptional

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

AppLauncherURL stringOptional

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

AuthType OIDCSaaSAppAuthTypeOptional

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

const OIDCSaaSAppAuthTypeSAML OIDCSaaSAppAuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppAuthTypeOIDC OIDCSaaSAppAuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

ClientID stringOptional

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

<details>

<summary>

CustomClaims \[]OIDCSaaSAppCustomClaimOptional

</summary>

Name stringOptional

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

Required boolOptional

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Scope OIDCSaaSAppCustomClaimsScopeOptional

The scope of the claim.

</summary>

One of the following:

const OIDCSaaSAppCustomClaimsScopeGroups OIDCSaaSAppCustomClaimsScope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppCustomClaimsScopeProfile OIDCSaaSAppCustomClaimsScope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

const OIDCSaaSAppCustomClaimsScopeEmail OIDCSaaSAppCustomClaimsScope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

const OIDCSaaSAppCustomClaimsScopeOpenid OIDCSaaSAppCustomClaimsScope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

Source OIDCSaaSAppCustomClaimsSourceOptional

</summary>

Name stringOptional

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

NameByIdP map\[string, string]Optional

A mapping from IdP ID to claim name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

GrantTypes \[]OIDCSaaSAppGrantTypeOptional

The OIDC flows supported by this application

</summary>

One of the following:

const OIDCSaaSAppGrantTypeAuthorizationCode OIDCSaaSAppGrantType = "authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppGrantTypeAuthorizationCodeWithPKCE OIDCSaaSAppGrantType = "authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OIDCSaaSAppGrantTypeRefreshTokens OIDCSaaSAppGrantType = "refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OIDCSaaSAppGrantTypeHybrid OIDCSaaSAppGrantType = "hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OIDCSaaSAppGrantTypeImplicit OIDCSaaSAppGrantType = "implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types">Link to this property</a>

GroupFilterRegex stringOptional

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

HybridAndImplicitOptions OIDCSaaSAppHybridAndImplicitOptionsOptional

</summary>

ReturnAccessTokenFromAuthorizationEndpoint boolOptional

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

ReturnIDTokenFromAuthorizationEndpoint boolOptional

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

RedirectURIs \[]stringOptional

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

RefreshTokenOptions OIDCSaaSAppRefreshTokenOptionsOptional

</summary>

Lifetime stringOptional

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

Scopes \[]OIDCSaaSAppScopeOptional

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

const OIDCSaaSAppScopeOpenid OIDCSaaSAppScope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppScopeGroups OIDCSaaSAppScope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OIDCSaaSAppScopeEmail OIDCSaaSAppScope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OIDCSaaSAppScopeProfile OIDCSaaSAppScope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)>)

<details>

<summary>

type SaaSAppNameIDFormat string

The format of the name identifier sent to the SaaS application.

</summary>

One of the following:

const SaaSAppNameIDFormatID <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a> = "id"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const SaaSAppNameIDFormatEmail <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a> = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)>)

<details>

<summary>

type SAMLSaaSApp struct{…}

</summary>

<details>

<summary>

AuthType SAMLSaaSAppAuthTypeOptional

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

const SAMLSaaSAppAuthTypeSAML SAMLSaaSAppAuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const SAMLSaaSAppAuthTypeOIDC SAMLSaaSAppAuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

ConsumerServiceURL stringOptional

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20consumer_service_url">Link to this property</a>

<details>

<summary>

CustomAttributes \[]SAMLSaaSAppCustomAttributeOptional

</summary>

FriendlyName stringOptional

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

Name stringOptional

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameFormat SAMLSaaSAppCustomAttributesNameFormatOptional

A globally unique name for an identity or service provider.

</summary>

One of the following:

const SAMLSaaSAppCustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatUnspecified SAMLSaaSAppCustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

const SAMLSaaSAppCustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatBasic SAMLSaaSAppCustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

const SAMLSaaSAppCustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatURI SAMLSaaSAppCustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

Required boolOptional

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Source SAMLSaaSAppCustomAttributesSourceOptional

</summary>

Name stringOptional

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameByIdP \[]SAMLSaaSAppCustomAttributesSourceNameByIdPOptional

A mapping from IdP ID to attribute name.

</summary>

IdPID stringOptional

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

SourceName stringOptional

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes">Link to this property</a>

DefaultRelayState stringOptional

The URL that the user will be redirected to after a successful login for IDP initiated logins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20default_relay_state">Link to this property</a>

IdPEntityID stringOptional

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20idp_entity_id">Link to this property</a>

NameIDFormat <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a>Optional

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_format">Link to this property</a>

NameIDTransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

SAMLAttributeTransformJsonata stringOptional

A \[JSONata] (<a href="https://jsonata.org/">https://jsonata.org/</a>) expression that transforms an application’s user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml\_attributes or oidc\_fields of the identity provider used to authenticate. The output of this expression must be a JSON object.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20saml_attribute_transform_jsonata">Link to this property</a>

SPEntityID stringOptional

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sp_entity_id">Link to this property</a>

SSOEndpoint stringOptional

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sso_endpoint">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigAuthenticationOAuthBearerToken struct{…}

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20token">Link to this property</a>

Scheme SCIMConfigAuthenticationOAuthBearerTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigMapping struct{…}

Transformations and filters applied to resources before they are provisioned in the remote SCIM service.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)>)

type SelfHostedDomains string

A domain that Access will secure.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20self_hosted_domains%20%3E%20(schema)>)

#### Zero TrustAccessApplicationsCAs

##### [List short-lived certificate CAs](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/list)

client.ZeroTrust.Access.Applications.CAs.List(ctx, params) (\*V4PagePaginationArray\[[CA](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/ca

##### [Get a short-lived certificate CA](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/get)

client.ZeroTrust.Access.Applications.CAs.Get(ctx, appID, query) (\*[CA](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### [Create a short-lived certificate CA](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/create)

client.ZeroTrust.Access.Applications.CAs.New(ctx, appID, body) (\*[CA](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### [Delete a short-lived certificate CA](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/delete)

client.ZeroTrust.Access.Applications.CAs.Delete(ctx, appID, body) (\*[AccessApplicationCADeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20AccessApplicationCADeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### ModelsExpand Collapse

<details>

<summary>

type CA struct{…}

</summary>

ID stringOptional

The ID of the CA.

maxLength48

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

AUD stringOptional

The Application Audience (AUD) tag. Identifies the application associated with the CA.

maxLength64

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)%20%3E%20(property)%20aud">Link to this property</a>

PublicKey stringOptional

The public key to add to your SSH server configuration.

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>)

#### Zero TrustAccessApplicationsUser Policy Checks

##### [Test Access policies](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/user_policy_checks/methods/list)

client.ZeroTrust.Access.Applications.UserPolicyChecks.List(ctx, appID, query) (\*[AccessApplicationUserPolicyCheckListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.user_policy_checks%20%3E%20(model)%20AccessApplicationUserPolicyCheckListResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/user\_policy\_checks

#### Zero TrustAccessApplicationsPolicies

##### [List Access application policies](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/list)

client.ZeroTrust.Access.Applications.Policies.List(ctx, appID, params) (\*V4PagePaginationArray\[[AccessApplicationPolicyListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies

##### [Get an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/get)

client.ZeroTrust.Access.Applications.Policies.Get(ctx, appID, policyID, query) (\*[AccessApplicationPolicyGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyGetResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### [Create an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/create)

client.ZeroTrust.Access.Applications.Policies.New(ctx, appID, params) (\*[AccessApplicationPolicyNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyNewResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies

##### [Update an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/update)

client.ZeroTrust.Access.Applications.Policies.Update(ctx, appID, policyID, params) (\*[AccessApplicationPolicyUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyUpdateResponse%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### [Delete an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/delete)

client.ZeroTrust.Access.Applications.Policies.Delete(ctx, appID, policyID, body) (\*[AccessApplicationPolicyDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### ModelsExpand Collapse

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)>)

<details>

<summary>

type AccessRule interface{…}

Matches an Access group.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

</details>

<!-- Cloudflare Markdown for Agents: incomplete conversion; source HTML truncated at the conversion size limit -->
