---
title: Access
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Zero Trust](https://developers.cloudflare.com/api/go/resources/zero_trust)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Access

#### AccessAI Controls

#### AccessAI ControlsMcp

#### AccessAI ControlsMcpPortals

##### [List MCP Portals](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/list)

client.ZeroTrust.Access.AIControls.Mcp.Portals.List(ctx, params) (\*V4PagePaginationArray\[[AccessAIControlMcpPortalListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Create a new MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/create)

client.ZeroTrust.Access.AIControls.Mcp.Portals.New(ctx, params) (\*[AccessAIControlMcpPortalNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Read details of an MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/read)

client.ZeroTrust.Access.AIControls.Mcp.Portals.Read(ctx, id, query) (\*[AccessAIControlMcpPortalReadResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalReadResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Update an MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/update)

client.ZeroTrust.Access.AIControls.Mcp.Portals.Update(ctx, id, params) (\*[AccessAIControlMcpPortalUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Delete an MCP Portal](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/delete)

client.ZeroTrust.Access.AIControls.Mcp.Portals.Delete(ctx, id, body) (\*[AccessAIControlMcpPortalDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20AccessAIControlMcpPortalDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

#### AccessAI ControlsMcpServers

##### [List MCP Servers](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/list)

client.ZeroTrust.Access.AIControls.Mcp.Servers.List(ctx, params) (\*V4PagePaginationArray\[[AccessAIControlMcpServerListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Create a new MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/create)

client.ZeroTrust.Access.AIControls.Mcp.Servers.New(ctx, params) (\*[AccessAIControlMcpServerNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Read the details of an MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/read)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Read(ctx, id, query) (\*[AccessAIControlMcpServerReadResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerReadResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Update an MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/update)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Update(ctx, id, params) (\*[AccessAIControlMcpServerUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Delete an MCP Server](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/delete)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Delete(ctx, id, body) (\*[AccessAIControlMcpServerDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Sync MCP Server Capabilities](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/sync)

client.ZeroTrust.Access.AIControls.Mcp.Servers.Sync(ctx, id, body) (\*[AccessAIControlMcpServerSyncResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20AccessAIControlMcpServerSyncResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}/sync

#### AccessGateway CA

##### [List SSH Certificate Authorities (CA)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/list)

client.ZeroTrust.Access.GatewayCA.List(ctx, query) (\*SinglePage\[[AccessGatewayCAListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20AccessGatewayCAListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/gateway\_ca

##### [Add a new SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/create)

client.ZeroTrust.Access.GatewayCA.New(ctx, body) (\*[AccessGatewayCANewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20AccessGatewayCANewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/gateway\_ca

##### [Delete an SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/delete)

client.ZeroTrust.Access.GatewayCA.Delete(ctx, certificateID, body) (\*[AccessGatewayCADeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20AccessGatewayCADeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/gateway\_ca/{certificate\_id}

#### AccessIdP Federation Grants

##### [List IdP federation grants](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/list)

client.ZeroTrust.Access.IdPFederationGrants.List(ctx, query) (\*\[] [IdPFederationGrant](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/idp\_federation\_grants

##### [Create an IdP federation grant](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/create)

client.ZeroTrust.Access.IdPFederationGrants.New(ctx, params) (\*[IdPFederationGrant](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/idp\_federation\_grants

##### [Get an IdP federation grant](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/get)

client.ZeroTrust.Access.IdPFederationGrants.Get(ctx, grantID, query) (\*[IdPFederationGrant](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### [Delete an IdP federation grant](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/delete)

client.ZeroTrust.Access.IdPFederationGrants.Delete(ctx, grantID, body) (\*[AccessIdPFederationGrantDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20AccessIdPFederationGrantDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### ModelsExpand Collapse

<details>

<summary>

type IdPFederationGrant struct{…}

</summary>

ID string

UID of the IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

IdPID string

UID of the identity provider being federated.

formatuuid

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20idp_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>)

#### AccessSAML Certificates

##### [List SAML certificate sets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/list)

client.ZeroTrust.Access.SAMLCertificates.List(ctx, params) (\*V4PagePaginationArray\[[AccessSAMLCertificateListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20AccessSAMLCertificateListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/saml\_certificates

##### [Get SAML certificate set](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get)

client.ZeroTrust.Access.SAMLCertificates.Get(ctx, samlCERTSetID, query) (\*[AccessSAMLCertificateGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20AccessSAMLCertificateGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}

##### [Rotate SAML certificate](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/rotate)

client.ZeroTrust.Access.SAMLCertificates.Rotate(ctx, samlCERTSetID, body) (\*[AccessSAMLCertificateRotateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20AccessSAMLCertificateRotateResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/rotate

##### [Download current certificate in PEM format](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get_pem)

client.ZeroTrust.Access.SAMLCertificates.GetPem(ctx, samlCERTSetID, query) (\*Response, error)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/pem

#### AccessInfrastructure

#### AccessInfrastructureTargets

##### [List all targets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/list)

client.ZeroTrust.Access.Infrastructure.Targets.List(ctx, params) (\*V4PagePaginationArray\[[AccessInfrastructureTargetListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/infrastructure/targets

##### [Get target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/get)

client.ZeroTrust.Access.Infrastructure.Targets.Get(ctx, targetID, query) (\*[AccessInfrastructureTargetGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/create)

client.ZeroTrust.Access.Infrastructure.Targets.New(ctx, params) (\*[AccessInfrastructureTargetNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/infrastructure/targets

##### [Update target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/update)

client.ZeroTrust.Access.Infrastructure.Targets.Update(ctx, targetID, params) (\*[AccessInfrastructureTargetUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Delete target](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/delete)

client.ZeroTrust.Access.Infrastructure.Targets.Delete(ctx, targetID, body) error

DELETE/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new targets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_update)

client.ZeroTrust.Access.Infrastructure.Targets.BulkUpdate(ctx, params) (\*SinglePage\[[AccessInfrastructureTargetBulkUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20AccessInfrastructureTargetBulkUpdateResponse%20%3E%20(schema)>)], error)

PUT/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets (Deprecated)](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete)

Deprecated

client.ZeroTrust.Access.Infrastructure.Targets.BulkDelete(ctx, body) error

DELETE/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete_v2)

client.ZeroTrust.Access.Infrastructure.Targets.BulkDeleteV2(ctx, params) error

POST/accounts/{account\_id}/infrastructure/targets/batch\_delete

#### AccessApplications

##### [List Access applications](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/list)

client.ZeroTrust.Access.Applications.List(ctx, params) (\*V4PagePaginationArray\[[AccessApplicationListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Get an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/get)

client.ZeroTrust.Access.Applications.Get(ctx, appID, query) (\*[AccessApplicationGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationGetResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Add an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/create)

client.ZeroTrust.Access.Applications.New(ctx, params) (\*[AccessApplicationNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationNewResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Update an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/update)

client.ZeroTrust.Access.Applications.Update(ctx, appID, params) (\*[AccessApplicationUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationUpdateResponse%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Delete an Access application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/delete)

client.ZeroTrust.Access.Applications.Delete(ctx, appID, body) (\*[AccessApplicationDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Revoke application tokens](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/methods/revoke_tokens)

client.ZeroTrust.Access.Applications.RevokeTokens(ctx, appID, body) (\*[AccessApplicationRevokeTokensResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20AccessApplicationRevokeTokensResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/revoke\_tokens

##### ModelsExpand Collapse

type AllowedHeaders string

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)>)

type AllowedIdPs string

The identity providers selected for application.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)>)

<details>

<summary>

type AllowedMethods string

</summary>

One of the following:

const AllowedMethodsGet <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const AllowedMethodsPost <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const AllowedMethodsHead <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const AllowedMethodsPut <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const AllowedMethodsDelete <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const AllowedMethodsConnect <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const AllowedMethodsOptions <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const AllowedMethodsTrace <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const AllowedMethodsPatch <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)>)

type AllowedOrigins string

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)>)

type AppID string

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)

<details>

<summary>

type Application interface{…}

</summary>

One of the following:

<details>

<summary>

ApplicationSelfHostedApplication

</summary>

Domain string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

AllowIframe boolOptional

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allow_iframe">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CORSHeaders <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a>Optional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20cors_headers">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

CustomDenyMessage stringOptional

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_message">Link to this property</a>

CustomDenyURL stringOptional

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_url">Link to this property</a>

EagerRedirectCookieSetting boolOptional

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

EnableBindingCookie boolOptional

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

HTTPOnlyCookieAttribute boolOptional

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

OptionsPreflightBypass boolOptional

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

SameSiteCookieAttribute stringOptional

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationSelfHostedApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationSelfHostedApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config">Link to this property</a>

ServiceAuth401Redirect boolOptional

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20session_duration">Link to this property</a>

SkipInterstitial boolOptional

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20skip_interstitial">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

UseClientlessIsolationAppLauncherURL boolOptional

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplication

</summary>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SaaSApp ApplicationSaaSApplicationSaaSAppOptional

</summary>

One of the following:

<details>

<summary>

ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2

</summary>

<details>

<summary>

AuthType ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthTypeOptional

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthTypeSAML ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthTypeOIDC ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2AuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type">Link to this property</a>

ConsumerServiceURL stringOptional

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20consumer_service_url">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

CustomAttributes \[]ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributeOptional

</summary>

FriendlyName stringOptional

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

Name stringOptional

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameFormat ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatOptional

A globally unique name for an identity or service provider.

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatUnspecified ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatBasic ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatURI ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

Required boolOptional

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Source ApplicationSaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributesSourceOptional

</summary>

Name stringOptional

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

NameByIdP map\[string, string]Optional

A mapping from IdP ID to attribute name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes">Link to this property</a>

IdPEntityID stringOptional

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20idp_entity_id">Link to this property</a>

NameIDFormat <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a>Optional

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_format">Link to this property</a>

NameIDTransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20public_key">Link to this property</a>

SPEntityID stringOptional

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sp_entity_id">Link to this property</a>

SSOEndpoint stringOptional

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sso_endpoint">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2

</summary>

AccessTokenLifetime stringOptional

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

AllowPKCEWithoutClientSecret boolOptional

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

AppLauncherURL stringOptional

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

AuthType ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthTypeOptional

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthTypeSAML ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthTypeOIDC ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2AuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type">Link to this property</a>

ClientID stringOptional

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_secret">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

CustomClaims \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimOptional

</summary>

Name stringOptional

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

Required boolOptional

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Scope ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeOptional

The scope of the claim.

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeGroups ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeProfile ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeEmail ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScopeOpenid ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsScope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

Source ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsSourceOptional

</summary>

Name stringOptional

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameByIdP \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimsSourceNameByIdPOptional

A mapping from IdP ID to attribute name.

</summary>

IdPID stringOptional

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

SourceName stringOptional

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

GrantTypes \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeOptional

The OIDC flows supported by this application

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeAuthorizationCode ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeAuthorizationCodeWithPKCE ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeRefreshTokens ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeHybrid ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantTypeImplicit ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2GrantType = "implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types">Link to this property</a>

GroupFilterRegex stringOptional

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

HybridAndImplicitOptions ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2HybridAndImplicitOptionsOptional

</summary>

ReturnAccessTokenFromAuthorizationEndpoint boolOptional

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

ReturnIDTokenFromAuthorizationEndpoint boolOptional

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20public_key">Link to this property</a>

RedirectURIs \[]stringOptional

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

RefreshTokenOptions ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2RefreshTokenOptionsOptional

</summary>

Lifetime stringOptional

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

Scopes \[]ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeOptional

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeOpenid ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeGroups ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeEmail ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2ScopeProfile ApplicationSaaSApplicationSaaSAppAccessOIDCSaaSApp2Scope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationSaaSApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationSaaSApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationSaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

Type stringOptional

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplication

</summary>

Domain string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

AllowIframe boolOptional

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allow_iframe">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CORSHeaders <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a>Optional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20cors_headers">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20created_at">Link to this property</a>

CustomDenyMessage stringOptional

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_message">Link to this property</a>

CustomDenyURL stringOptional

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_url">Link to this property</a>

EagerRedirectCookieSetting boolOptional

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

EnableBindingCookie boolOptional

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

HTTPOnlyCookieAttribute boolOptional

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

OptionsPreflightBypass boolOptional

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

SameSiteCookieAttribute stringOptional

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBrowserSSHApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBrowserSSHApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

ServiceAuth401Redirect boolOptional

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20session_duration">Link to this property</a>

SkipInterstitial boolOptional

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20skip_interstitial">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20updated_at">Link to this property</a>

UseClientlessIsolationAppLauncherURL boolOptional

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplication

</summary>

Domain string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

AllowIframe boolOptional

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allow_iframe">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allowed_idps">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CORSHeaders <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a>Optional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20cors_headers">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20created_at">Link to this property</a>

CustomDenyMessage stringOptional

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_message">Link to this property</a>

CustomDenyURL stringOptional

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_url">Link to this property</a>

EagerRedirectCookieSetting boolOptional

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

EnableBindingCookie boolOptional

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

HTTPOnlyCookieAttribute boolOptional

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

OptionsPreflightBypass boolOptional

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

SameSiteCookieAttribute stringOptional

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBrowserVNCApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBrowserVNCApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

ServiceAuth401Redirect boolOptional

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20session_duration">Link to this property</a>

SkipInterstitial boolOptional

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20skip_interstitial">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20updated_at">Link to this property</a>

UseClientlessIsolationAppLauncherURL boolOptional

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplication

</summary>

<details>

<summary>

Type ApplicationAppLauncherApplicationType

The application type.

</summary>

One of the following:

const ApplicationAppLauncherApplicationTypeSelfHosted ApplicationAppLauncherApplicationType = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const ApplicationAppLauncherApplicationTypeSaaS ApplicationAppLauncherApplicationType = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const ApplicationAppLauncherApplicationTypeSSH ApplicationAppLauncherApplicationType = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const ApplicationAppLauncherApplicationTypeVNC ApplicationAppLauncherApplicationType = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const ApplicationAppLauncherApplicationTypeAppLauncher ApplicationAppLauncherApplicationType = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const ApplicationAppLauncherApplicationTypeWARP ApplicationAppLauncherApplicationType = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const ApplicationAppLauncherApplicationTypeBISO ApplicationAppLauncherApplicationType = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const ApplicationAppLauncherApplicationTypeBookmark ApplicationAppLauncherApplicationType = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const ApplicationAppLauncherApplicationTypeDashSSO ApplicationAppLauncherApplicationType = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20allowed_idps">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20created_at">Link to this property</a>

Domain stringOptional

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20domain">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationAppLauncherApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationAppLauncherApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationAppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplication

</summary>

<details>

<summary>

Type ApplicationDeviceEnrollmentPermissionsApplicationType

The application type.

</summary>

One of the following:

const ApplicationDeviceEnrollmentPermissionsApplicationTypeSelfHosted ApplicationDeviceEnrollmentPermissionsApplicationType = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeSaaS ApplicationDeviceEnrollmentPermissionsApplicationType = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeSSH ApplicationDeviceEnrollmentPermissionsApplicationType = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeVNC ApplicationDeviceEnrollmentPermissionsApplicationType = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeAppLauncher ApplicationDeviceEnrollmentPermissionsApplicationType = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeWARP ApplicationDeviceEnrollmentPermissionsApplicationType = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeBISO ApplicationDeviceEnrollmentPermissionsApplicationType = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeBookmark ApplicationDeviceEnrollmentPermissionsApplicationType = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const ApplicationDeviceEnrollmentPermissionsApplicationTypeDashSSO ApplicationDeviceEnrollmentPermissionsApplicationType = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20allowed_idps">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20created_at">Link to this property</a>

Domain stringOptional

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20domain">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationDeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplication

</summary>

<details>

<summary>

Type ApplicationBrowserIsolationPermissionsApplicationType

The application type.

</summary>

One of the following:

const ApplicationBrowserIsolationPermissionsApplicationTypeSelfHosted ApplicationBrowserIsolationPermissionsApplicationType = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeSaaS ApplicationBrowserIsolationPermissionsApplicationType = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeSSH ApplicationBrowserIsolationPermissionsApplicationType = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeVNC ApplicationBrowserIsolationPermissionsApplicationType = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeAppLauncher ApplicationBrowserIsolationPermissionsApplicationType = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeWARP ApplicationBrowserIsolationPermissionsApplicationType = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeBISO ApplicationBrowserIsolationPermissionsApplicationType = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeBookmark ApplicationBrowserIsolationPermissionsApplicationType = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

const ApplicationBrowserIsolationPermissionsApplicationTypeDashSSO ApplicationBrowserIsolationPermissionsApplicationType = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

AllowedIdPs \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>Optional

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20allowed_idps">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20aud">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20created_at">Link to this property</a>

Domain stringOptional

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20domain">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBrowserIsolationPermissionsApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplication

</summary>

Domain string

The URL or domain of the bookmark.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20domain">Link to this property</a>

Type string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

AppLauncherVisible boolOptional

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

AUD stringOptional

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20aud">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20created_at">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

SCIMConfig ApplicationBookmarkApplicationSCIMConfigOptional

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

IdPUID string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

RemoteURI string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

Authentication ApplicationBookmarkApplicationSCIMConfigAuthenticationUnionOptional

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2

</summary>

One of the following:

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken

</summary>

ClientID string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme ApplicationBookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

DeactivateOnDelete boolOptional

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

Enabled boolOptional

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

Mappings \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>Optional

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)>)

<details>

<summary>

type ApplicationPolicy struct{…}

</summary>

ID stringOptional

The UUID of the policy

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

ApprovalGroups \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a>Optional

Administrators who can approve a temporary authentication request.

</summary>

ApprovalsNeeded float64

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

EmailAddresses \[]stringOptional

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

EmailListUUID stringOptional

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_groups">Link to this property</a>

ApprovalRequired boolOptional

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_required">Link to this property</a>

<details>

<summary>

ConnectionRules ApplicationPolicyConnectionRulesOptional

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

RDP ApplicationPolicyConnectionRulesRDPOptional

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

<details>

<summary>

AllowedClipboardLocalToRemoteFormats \[]ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormatOptional

Clipboard formats allowed when copying from local machine to remote RDP session.

</summary>

One of the following:

const ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormatText ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormat = "text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormatFile ApplicationPolicyConnectionRulesRDPAllowedClipboardLocalToRemoteFormat = "file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

<details>

<summary>

AllowedClipboardRemoteToLocalFormats \[]ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormatOptional

Clipboard formats allowed when copying from remote RDP session to local machine.

</summary>

One of the following:

const ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormatText ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormat = "text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormatFile ApplicationPolicyConnectionRulesRDPAllowedClipboardRemoteToLocalFormat = "file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

Decision <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a>Optional

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

Exclude \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

Include \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20include">Link to this property</a>

IsolationRequired boolOptional

Require this application to be served in an isolated browser for users matching this policy. ‘Client Web Isolation’ must be on for the account in order to use this feature.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20isolation_required">Link to this property</a>

<details>

<summary>

MfaConfig ApplicationPolicyMfaConfigOptional

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

AllowedAuthenticators \[]ApplicationPolicyMfaConfigAllowedAuthenticatorOptional

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

const ApplicationPolicyMfaConfigAllowedAuthenticatorTotp ApplicationPolicyMfaConfigAllowedAuthenticator = "totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const ApplicationPolicyMfaConfigAllowedAuthenticatorBiometrics ApplicationPolicyMfaConfigAllowedAuthenticator = "biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const ApplicationPolicyMfaConfigAllowedAuthenticatorSecurityKey ApplicationPolicyMfaConfigAllowedAuthenticator = "security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

MfaDisabled boolOptional

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

SessionDuration stringOptional

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

Name stringOptional

The name of the Access policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

PurposeJustificationPrompt stringOptional

A custom message that will appear on the purpose justification screen.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_prompt">Link to this property</a>

PurposeJustificationRequired boolOptional

Require users to enter a justification when they log in to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_required">Link to this property</a>

<details>

<summary>

Require \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20require">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for the application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)>)

<details>

<summary>

type ApplicationType string

The application type.

</summary>

One of the following:

const ApplicationTypeSelfHosted <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const ApplicationTypeEndUser <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "end\_user"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const ApplicationTypeSaaS <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const ApplicationTypeSSH <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const ApplicationTypeVNC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const ApplicationTypeAppLauncher <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const ApplicationTypeWARP <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const ApplicationTypeBISO <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const ApplicationTypeBookmark <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const ApplicationTypeDashSSO <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const ApplicationTypeInfrastructure <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "infrastructure"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const ApplicationTypeRDP <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "rdp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const ApplicationTypeMcp <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "mcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const ApplicationTypeMcpPortal <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "mcp\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const ApplicationTypeProxyEndpoint <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a> = "proxy\_endpoint"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)>)

<details>

<summary>

type CORSHeaders struct{…}

</summary>

AllowAllHeaders boolOptional

Allows all HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_headers">Link to this property</a>

AllowAllMethods boolOptional

Allows all HTTP request methods.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_methods">Link to this property</a>

AllowAllOrigins boolOptional

Allows all origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_origins">Link to this property</a>

AllowCredentials boolOptional

When set to <code>true</code>, includes credentials (cookies, authorization headers, or TLS client certificates) with requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_credentials">Link to this property</a>

AllowedHeaders \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)">AllowedHeaders</a>Optional

Allowed HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_headers">Link to this property</a>

<details>

<summary>

AllowedMethods \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a>Optional

Allowed HTTP request methods.

</summary>

One of the following:

const AllowedMethodsGet <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const AllowedMethodsPost <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const AllowedMethodsHead <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const AllowedMethodsPut <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const AllowedMethodsDelete <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const AllowedMethodsConnect <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const AllowedMethodsOptions <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const AllowedMethodsTrace <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const AllowedMethodsPatch <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a> = "PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_methods">Link to this property</a>

AllowedOrigins \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)">AllowedOrigins</a>Optional

Allowed origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_origins">Link to this property</a>

MaxAge float64Optional

The maximum number of seconds the results of a preflight request can be cached.

maximum86400

minimum-1

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20max_age">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)>)

<details>

<summary>

type Decision string

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

</summary>

One of the following:

const DecisionAllow <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "allow"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const DecisionDeny <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "deny"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const DecisionNonIdentity <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "non\_identity"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const DecisionBypass <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a> = "bypass"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)>)

<details>

<summary>

type OIDCSaaSApp struct{…}

</summary>

AccessTokenLifetime stringOptional

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

AllowPKCEWithoutClientSecret boolOptional

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

AppLauncherURL stringOptional

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

AuthType OIDCSaaSAppAuthTypeOptional

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

const OIDCSaaSAppAuthTypeSAML OIDCSaaSAppAuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppAuthTypeOIDC OIDCSaaSAppAuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

ClientID stringOptional

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

<details>

<summary>

CustomClaims \[]OIDCSaaSAppCustomClaimOptional

</summary>

Name stringOptional

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

Required boolOptional

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Scope OIDCSaaSAppCustomClaimsScopeOptional

The scope of the claim.

</summary>

One of the following:

const OIDCSaaSAppCustomClaimsScopeGroups OIDCSaaSAppCustomClaimsScope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppCustomClaimsScopeProfile OIDCSaaSAppCustomClaimsScope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

const OIDCSaaSAppCustomClaimsScopeEmail OIDCSaaSAppCustomClaimsScope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

const OIDCSaaSAppCustomClaimsScopeOpenid OIDCSaaSAppCustomClaimsScope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

Source OIDCSaaSAppCustomClaimsSourceOptional

</summary>

Name stringOptional

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

NameByIdP map\[string, string]Optional

A mapping from IdP ID to claim name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

GrantTypes \[]OIDCSaaSAppGrantTypeOptional

The OIDC flows supported by this application

</summary>

One of the following:

const OIDCSaaSAppGrantTypeAuthorizationCode OIDCSaaSAppGrantType = "authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppGrantTypeAuthorizationCodeWithPKCE OIDCSaaSAppGrantType = "authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OIDCSaaSAppGrantTypeRefreshTokens OIDCSaaSAppGrantType = "refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OIDCSaaSAppGrantTypeHybrid OIDCSaaSAppGrantType = "hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OIDCSaaSAppGrantTypeImplicit OIDCSaaSAppGrantType = "implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types">Link to this property</a>

GroupFilterRegex stringOptional

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

HybridAndImplicitOptions OIDCSaaSAppHybridAndImplicitOptionsOptional

</summary>

ReturnAccessTokenFromAuthorizationEndpoint boolOptional

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

ReturnIDTokenFromAuthorizationEndpoint boolOptional

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

RedirectURIs \[]stringOptional

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

RefreshTokenOptions OIDCSaaSAppRefreshTokenOptionsOptional

</summary>

Lifetime stringOptional

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

Scopes \[]OIDCSaaSAppScopeOptional

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

const OIDCSaaSAppScopeOpenid OIDCSaaSAppScope = "openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OIDCSaaSAppScopeGroups OIDCSaaSAppScope = "groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OIDCSaaSAppScopeEmail OIDCSaaSAppScope = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OIDCSaaSAppScopeProfile OIDCSaaSAppScope = "profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)>)

<details>

<summary>

type SaaSAppNameIDFormat string

The format of the name identifier sent to the SaaS application.

</summary>

One of the following:

const SaaSAppNameIDFormatID <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a> = "id"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const SaaSAppNameIDFormatEmail <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a> = "email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)>)

<details>

<summary>

type SAMLSaaSApp struct{…}

</summary>

<details>

<summary>

AuthType SAMLSaaSAppAuthTypeOptional

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

const SAMLSaaSAppAuthTypeSAML SAMLSaaSAppAuthType = "saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

const SAMLSaaSAppAuthTypeOIDC SAMLSaaSAppAuthType = "oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

ConsumerServiceURL stringOptional

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20consumer_service_url">Link to this property</a>

<details>

<summary>

CustomAttributes \[]SAMLSaaSAppCustomAttributeOptional

</summary>

FriendlyName stringOptional

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

Name stringOptional

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameFormat SAMLSaaSAppCustomAttributesNameFormatOptional

A globally unique name for an identity or service provider.

</summary>

One of the following:

const SAMLSaaSAppCustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatUnspecified SAMLSaaSAppCustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

const SAMLSaaSAppCustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatBasic SAMLSaaSAppCustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

const SAMLSaaSAppCustomAttributesNameFormatUrnOasisNamesTcSAML2\_0AttrnameFormatURI SAMLSaaSAppCustomAttributesNameFormat = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

Required boolOptional

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

Source SAMLSaaSAppCustomAttributesSourceOptional

</summary>

Name stringOptional

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

NameByIdP \[]SAMLSaaSAppCustomAttributesSourceNameByIdPOptional

A mapping from IdP ID to attribute name.

</summary>

IdPID stringOptional

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

SourceName stringOptional

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes">Link to this property</a>

DefaultRelayState stringOptional

The URL that the user will be redirected to after a successful login for IDP initiated logins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20default_relay_state">Link to this property</a>

IdPEntityID stringOptional

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20idp_entity_id">Link to this property</a>

NameIDFormat <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a>Optional

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_format">Link to this property</a>

NameIDTransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

PublicKey stringOptional

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

SAMLAttributeTransformJsonata stringOptional

A \[JSONata] (<a href="https://jsonata.org/">https://jsonata.org/</a>) expression that transforms an application’s user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml\_attributes or oidc\_fields of the identity provider used to authenticate. The output of this expression must be a JSON object.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20saml_attribute_transform_jsonata">Link to this property</a>

SPEntityID stringOptional

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sp_entity_id">Link to this property</a>

SSOEndpoint stringOptional

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sso_endpoint">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigAuthenticationHTTPBasic struct{…}

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

Password string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

Scheme SCIMConfigAuthenticationHTTPBasicScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

User string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigAuthenticationOAuthBearerToken struct{…}

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

Token string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20token">Link to this property</a>

Scheme SCIMConfigAuthenticationOAuthBearerTokenScheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigAuthenticationOauth2 struct{…}

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

AuthorizationURL string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

ClientID string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

Scheme SCIMConfigAuthenticationOauth2Scheme

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

TokenURL string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

Scopes \[]stringOptional

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)>)

<details>

<summary>

type SCIMConfigMapping struct{…}

Transformations and filters applied to resources before they are provisioned in the remote SCIM service.

</summary>

Schema string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

Enabled boolOptional

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

Filter stringOptional

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

Operations SCIMConfigMappingOperationsOptional

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

Create boolOptional

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

Delete boolOptional

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

Update boolOptional

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

Strictness SCIMConfigMappingStrictnessOptional

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

const SCIMConfigMappingStrictnessStrict SCIMConfigMappingStrictness = "strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

const SCIMConfigMappingStrictnessPassthrough SCIMConfigMappingStrictness = "passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

TransformJsonata stringOptional

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)>)

type SelfHostedDomains string

A domain that Access will secure.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20self_hosted_domains%20%3E%20(schema)>)

#### AccessApplicationsCAs

##### [List short-lived certificate CAs](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/list)

client.ZeroTrust.Access.Applications.CAs.List(ctx, params) (\*V4PagePaginationArray\[[CA](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/ca

##### [Get a short-lived certificate CA](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/get)

client.ZeroTrust.Access.Applications.CAs.Get(ctx, appID, query) (\*[CA](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### [Create a short-lived certificate CA](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/create)

client.ZeroTrust.Access.Applications.CAs.New(ctx, appID, body) (\*[CA](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### [Delete a short-lived certificate CA](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/delete)

client.ZeroTrust.Access.Applications.CAs.Delete(ctx, appID, body) (\*[AccessApplicationCADeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20AccessApplicationCADeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### ModelsExpand Collapse

<details>

<summary>

type CA struct{…}

</summary>

ID stringOptional

The ID of the CA.

maxLength48

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

AUD stringOptional

The Application Audience (AUD) tag. Identifies the application associated with the CA.

maxLength64

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)%20%3E%20(property)%20aud">Link to this property</a>

PublicKey stringOptional

The public key to add to your SSH server configuration.

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(model)%20ca%20%3E%20(schema)>)

#### AccessApplicationsUser Policy Checks

##### [Test Access policies](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/user_policy_checks/methods/list)

client.ZeroTrust.Access.Applications.UserPolicyChecks.List(ctx, appID, query) (\*[AccessApplicationUserPolicyCheckListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.user_policy_checks%20%3E%20(model)%20AccessApplicationUserPolicyCheckListResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/user\_policy\_checks

#### AccessApplicationsPolicies

##### [List Access application policies](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/list)

client.ZeroTrust.Access.Applications.Policies.List(ctx, appID, params) (\*V4PagePaginationArray\[[AccessApplicationPolicyListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies

##### [Get an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/get)

client.ZeroTrust.Access.Applications.Policies.Get(ctx, appID, policyID, query) (\*[AccessApplicationPolicyGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyGetResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### [Create an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/create)

client.ZeroTrust.Access.Applications.Policies.New(ctx, appID, params) (\*[AccessApplicationPolicyNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyNewResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies

##### [Update an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/update)

client.ZeroTrust.Access.Applications.Policies.Update(ctx, appID, policyID, params) (\*[AccessApplicationPolicyUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyUpdateResponse%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### [Delete an Access application policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/delete)

client.ZeroTrust.Access.Applications.Policies.Delete(ctx, appID, policyID, body) (\*[AccessApplicationPolicyDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20AccessApplicationPolicyDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### ModelsExpand Collapse

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)>)

<details>

<summary>

type AccessRule interface{…}

Matches an Access group.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)>)

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)>)

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)>)

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)>)

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)>)

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)>)

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)>)

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)>)

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)>)

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)>)

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)>)

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)>)

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)>)

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)>)

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)>)

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)>)

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)>)

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)>)

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)>)

#### AccessApplicationsPolicy Tests

##### [Get the current status of a given Access policy test](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/methods/get)

client.ZeroTrust.Access.Applications.PolicyTests.Get(ctx, policyTestID, query) (\*[AccessApplicationPolicyTestGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policy_tests%20%3E%20(model)%20AccessApplicationPolicyTestGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/policy-tests/{policy\_test\_id}

##### [Start Access policy test](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/methods/create)

client.ZeroTrust.Access.Applications.PolicyTests.New(ctx, params) (\*[AccessApplicationPolicyTestNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policy_tests%20%3E%20(model)%20AccessApplicationPolicyTestNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/policy-tests

#### AccessApplicationsPolicy TestsUsers

##### [Get an Access policy test users page](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/subresources/users/methods/list)

client.ZeroTrust.Access.Applications.PolicyTests.Users.List(ctx, policyTestID, params) (\*V4PagePaginationArray\[[AccessApplicationPolicyTestUserListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policy_tests.users%20%3E%20(model)%20AccessApplicationPolicyTestUserListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/policy-tests/{policy\_test\_id}/users

#### AccessApplicationsSettings

##### [Update Access application settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/settings/methods/update)

client.ZeroTrust.Access.Applications.Settings.Update(ctx, appID, params) (\*[AccessApplicationSettingUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.settings%20%3E%20(model)%20AccessApplicationSettingUpdateResponse%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/settings

##### [Update Access application settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/applications/subresources/settings/methods/edit)

client.ZeroTrust.Access.Applications.Settings.Edit(ctx, appID, params) (\*[AccessApplicationSettingEditResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.settings%20%3E%20(model)%20AccessApplicationSettingEditResponse%20%3E%20(schema)>), error)

PATCH/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/settings

#### AccessCertificates

##### [List mTLS certificates](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/methods/list)

client.ZeroTrust.Access.Certificates.List(ctx, params) (\*V4PagePaginationArray\[[Certificate](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates

##### [Get an mTLS certificate](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/methods/get)

client.ZeroTrust.Access.Certificates.Get(ctx, certificateID, query) (\*[Certificate](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/{certificate\_id}

##### [Add an mTLS certificate](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/methods/create)

client.ZeroTrust.Access.Certificates.New(ctx, params) (\*[Certificate](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates

##### [Update an mTLS certificate](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/methods/update)

client.ZeroTrust.Access.Certificates.Update(ctx, certificateID, params) (\*[Certificate](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/{certificate\_id}

##### [Delete an mTLS certificate](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/methods/delete)

client.ZeroTrust.Access.Certificates.Delete(ctx, certificateID, body) (\*[AccessCertificateDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20AccessCertificateDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/{certificate\_id}

##### ModelsExpand Collapse

type AssociatedHostnames string

A fully-qualified domain name (FQDN).

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20associated_hostnames%20%3E%20(schema)>)

<details>

<summary>

type Certificate struct{…}

</summary>

ID stringOptional

The ID of the application that will use this certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

AssociatedHostnames \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20associated_hostnames%20%3E%20(schema)">AssociatedHostnames</a>Optional

The hostnames of the applications that will use this certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)%20%3E%20(property)%20associated_hostnames">Link to this property</a>

ExpiresOn TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

Fingerprint stringOptional

The MD5 fingerprint of the certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

Name stringOptional

The name of the certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(model)%20certificate%20%3E%20(schema)>)

#### AccessCertificatesSettings

##### [List all mTLS hostname settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/subresources/settings/methods/get)

client.ZeroTrust.Access.Certificates.Settings.Get(ctx, query) (\*SinglePage\[[CertificateSettings](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates.settings%20%3E%20(model)%20certificate_settings%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/settings

##### [Update an mTLS certificate's hostname settings](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/certificates/subresources/settings/methods/update)

client.ZeroTrust.Access.Certificates.Settings.Update(ctx, params) (\*SinglePage\[[CertificateSettings](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.certificates.settings%20%3E%20(model)%20certificate_settings%20%3E%20(schema)>)], error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/settings

##### ModelsExpand Collapse

<details>

<summary>

type CertificateSettings struct{…}

</summary>

ChinaNetwork bool

Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled.

<a href="#(resource)%20zero_trust.access.certificates.settings%20%3E%20(model)%20certificate_settings%20%3E%20(schema)%20%3E%20(property)%20china_network">Link to this property</a>

ClientCertificateForwarding bool

Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin.

<a href="#(resource)%20zero_trust.access.certificates.settings%20%3E%20(model)%20certificate_settings%20%3E%20(schema)%20%3E%20(property)%20client_certificate_forwarding">Link to this property</a>

Hostname string

The hostname that these settings apply to.

<a href="#(resource)%20zero_trust.access.certificates.settings%20%3E%20(model)%20certificate_settings%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(model)%20certificate_settings%20%3E%20(schema)>)

#### AccessGroups

##### [List Access groups](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/groups/methods/list)

client.ZeroTrust.Access.Groups.List(ctx, params) (\*V4PagePaginationArray\[[AccessGroupListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.groups%20%3E%20(model)%20AccessGroupListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups

##### [Get an Access group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/groups/methods/get)

client.ZeroTrust.Access.Groups.Get(ctx, groupID, query) (\*[AccessGroupGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.groups%20%3E%20(model)%20AccessGroupGetResponse%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups/{group\_id}

##### [Create an Access group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/groups/methods/create)

client.ZeroTrust.Access.Groups.New(ctx, params) (\*[AccessGroupNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.groups%20%3E%20(model)%20AccessGroupNewResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups

##### [Update an Access group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/groups/methods/update)

client.ZeroTrust.Access.Groups.Update(ctx, groupID, params) (\*[AccessGroupUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.groups%20%3E%20(model)%20AccessGroupUpdateResponse%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups/{group\_id}

##### [Delete an Access group](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/groups/methods/delete)

client.ZeroTrust.Access.Groups.Delete(ctx, groupID, body) (\*[AccessGroupDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.groups%20%3E%20(model)%20AccessGroupDeleteResponse%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups/{group\_id}

##### ModelsExpand Collapse

<details>

<summary>

type ZeroTrustGroup struct{…}

</summary>

ID stringOptional

The unique Cloudflare-generated Id of the SCIM resource.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

DisplayName stringOptional

The display name of the SCIM Group resource.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20displayName">Link to this property</a>

ExternalID stringOptional

The IdP-generated Id of the SCIM resource.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20externalId">Link to this property</a>

<details>

<summary>

Meta ZeroTrustGroupMetaOptional

The metadata of the SCIM resource.

</summary>

Created TimeOptional

The timestamp of when the SCIM resource was created.

formatdate-time

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20meta%20%3E%20(property)%20created">Link to this property</a>

LastModified TimeOptional

The timestamp of when the SCIM resource was last modified.

formatdate-time

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20meta%20%3E%20(property)%20lastModified">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20meta">Link to this property</a>

Schemas \[]stringOptional

The list of URIs which indicate the attributes contained within a SCIM resource.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)%20%3E%20(property)%20schemas">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(model)%20zero_trust_group%20%3E%20(schema)>)

#### AccessService Tokens

##### [List service tokens](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/list)

client.ZeroTrust.Access.ServiceTokens.List(ctx, params) (\*V4PagePaginationArray\[[ServiceToken](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens

##### [Get a service token](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/get)

client.ZeroTrust.Access.ServiceTokens.Get(ctx, serviceTokenID, query) (\*[ServiceToken](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)>), error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens/{service\_token\_id}

##### [Create a service token](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/create)

client.ZeroTrust.Access.ServiceTokens.New(ctx, params) (\*[AccessServiceTokenNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20AccessServiceTokenNewResponse%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens

##### [Update a service token](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/update)

client.ZeroTrust.Access.ServiceTokens.Update(ctx, serviceTokenID, params) (\*[ServiceToken](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)>), error)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens/{service\_token\_id}

##### [Delete a service token](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/delete)

client.ZeroTrust.Access.ServiceTokens.Delete(ctx, serviceTokenID, body) (\*[ServiceToken](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)>), error)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens/{service\_token\_id}

##### [Refresh a service token](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/refresh)

client.ZeroTrust.Access.ServiceTokens.Refresh(ctx, serviceTokenID, body) (\*[ServiceToken](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/service\_tokens/{service\_token\_id}/refresh

##### [Rotate a service token](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/service_tokens/methods/rotate)

client.ZeroTrust.Access.ServiceTokens.Rotate(ctx, serviceTokenID, params) (\*[AccessServiceTokenRotateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20AccessServiceTokenRotateResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/service\_tokens/{service\_token\_id}/rotate

##### ModelsExpand Collapse

<details>

<summary>

type ServiceToken struct{…}

</summary>

ID stringOptional

The ID of the service token.

maxLength36

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

ClientID stringOptional

The Client ID for the service token. Access will check for this value in the <code>CF-Access-Client-ID</code> request header.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

Duration stringOptional

The duration for how long the service token will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>, or the special value <code>forever</code> for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h).

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)%20%3E%20(property)%20duration">Link to this property</a>

Enabled boolOptional

Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous <code>client_secret</code> stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

ExpiresAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)%20%3E%20(property)%20expires_at">Link to this property</a>

Name stringOptional

The name of the service token.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(model)%20service_token%20%3E%20(schema)>)

#### AccessBookmarks

##### [List Bookmark applications](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/bookmarks/methods/list)

Deprecated

client.ZeroTrust.Access.Bookmarks.List(ctx, query) (\*SinglePage\[[Bookmark](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/bookmarks

##### [Get a Bookmark application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/bookmarks/methods/get)

Deprecated

client.ZeroTrust.Access.Bookmarks.Get(ctx, bookmarkID, query) (\*[Bookmark](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### [Create a Bookmark application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/bookmarks/methods/create)

Deprecated

client.ZeroTrust.Access.Bookmarks.New(ctx, bookmarkID, body) (\*[Bookmark](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### [Update a Bookmark application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/bookmarks/methods/update)

Deprecated

client.ZeroTrust.Access.Bookmarks.Update(ctx, bookmarkID, body) (\*[Bookmark](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### [Delete a Bookmark application](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/bookmarks/methods/delete)

Deprecated

client.ZeroTrust.Access.Bookmarks.Delete(ctx, bookmarkID, body) (\*[AccessBookmarkDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20AccessBookmarkDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### ModelsExpand Collapse

<details>

<summary>

type Bookmark struct{…}

</summary>

ID stringOptional

The unique identifier for the Bookmark application.

<a href="#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

AppLauncherVisible boolOptional

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

Domain stringOptional

The domain of the Bookmark application.

<a href="#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)%20%3E%20(property)%20domain">Link to this property</a>

LogoURL stringOptional

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)%20%3E%20(property)%20logo_url">Link to this property</a>

Name stringOptional

The name of the Bookmark application.

<a href="#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.bookmarks%20%3E%20(model)%20bookmark%20%3E%20(schema)>)

#### AccessKeys

##### [Get the Access key configuration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/keys/methods/get)

client.ZeroTrust.Access.Keys.Get(ctx, query) (\*[AccessKeyGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.keys%20%3E%20(model)%20AccessKeyGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/keys

##### [Update the Access key configuration](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/keys/methods/update)

client.ZeroTrust.Access.Keys.Update(ctx, params) (\*[AccessKeyUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.keys%20%3E%20(model)%20AccessKeyUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/keys

##### [Rotate Access keys](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/keys/methods/rotate)

client.ZeroTrust.Access.Keys.Rotate(ctx, body) (\*[AccessKeyRotateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.keys%20%3E%20(model)%20AccessKeyRotateResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/keys/rotate

#### AccessLogs

#### AccessLogsAccess Requests

##### [Get Access authentication logs](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/logs/subresources/access_requests/methods/list)

client.ZeroTrust.Access.Logs.AccessRequests.List(ctx, params) (\*\[] [AccessRequest](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/logs/access\_requests

#### AccessLogsSCIM

##### ModelsExpand Collapse

<details>

<summary>

type AccessRequest struct{…}

</summary>

Action stringOptional

The event that occurred, such as a login attempt.

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

Allowed boolOptional

The result of the authentication event.

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20allowed">Link to this property</a>

AppDomain stringOptional

The URL of the Access application.

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20app_domain">Link to this property</a>

AppUID stringOptional

The unique identifier for the Access application.

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20app_uid">Link to this property</a>

Connection stringOptional

The IdP used to authenticate.

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20connection">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

IPAddress stringOptional

The IP address of the authenticating user.

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20ip_address">Link to this property</a>

RayID stringOptional

The unique identifier for the request to Cloudflare.

maxLength16

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20ray_id">Link to this property</a>

UserEmail stringOptional

The email address of the authenticating user.

formatemail

<a href="#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.logs.scim%20%3E%20(model)%20access_request%20%3E%20(schema)>)

#### AccessLogsSCIMUpdates

##### [List Access SCIM update logs](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/logs/subresources/scim/subresources/updates/methods/list)

client.ZeroTrust.Access.Logs.SCIM.Updates.List(ctx, params) (\*V4PagePaginationArray\[[AccessLogSCIMUpdateListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.logs.scim.updates%20%3E%20(model)%20AccessLogSCIMUpdateListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/logs/scim/updates

#### AccessUsers

##### [Get users](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/methods/list)

client.ZeroTrust.Access.Users.List(ctx, params) (\*V4PagePaginationArray\[[AccessUserListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users%20%3E%20(model)%20AccessUserListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/users

##### [Get a user](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/methods/get)

client.ZeroTrust.Access.Users.Get(ctx, userID, query) (\*[AccessUserGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users%20%3E%20(model)%20AccessUserGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/users/{user\_id}

##### [Create a user](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/methods/create)

client.ZeroTrust.Access.Users.New(ctx, params) (\*[AccessUserNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users%20%3E%20(model)%20AccessUserNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/users

##### [Update a user](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/methods/update)

client.ZeroTrust.Access.Users.Update(ctx, userID, params) (\*[AccessUserUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users%20%3E%20(model)%20AccessUserUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/users/{user\_id}

##### [Delete a user](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/methods/delete)

client.ZeroTrust.Access.Users.Delete(ctx, userID, body) (\*[AccessUserDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users%20%3E%20(model)%20AccessUserDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/users/{user\_id}

##### ModelsExpand Collapse

<details>

<summary>

type AccessUser struct{…}

</summary>

ID stringOptional

The unique Cloudflare-generated Id of the SCIM resource.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Active boolOptional

Determines the status of the SCIM User resource.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20active">Link to this property</a>

DisplayName stringOptional

The name of the SCIM User resource.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20displayName">Link to this property</a>

<details>

<summary>

Emails \[]AccessUserEmailOptional

</summary>

Primary boolOptional

Indicates if the email address is the primary email belonging to the SCIM User resource.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20emails%20%3E%20(items)%20%3E%20(property)%20primary">Link to this property</a>

Type stringOptional

Indicates the type of the email address.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20emails%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

Value stringOptional

The email address of the SCIM User resource.

formatemail

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20emails%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20emails">Link to this property</a>

ExternalID stringOptional

The IdP-generated Id of the SCIM resource.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20externalId">Link to this property</a>

<details>

<summary>

Meta AccessUserMetaOptional

The metadata of the SCIM resource.

</summary>

Created TimeOptional

The timestamp of when the SCIM resource was created.

formatdate-time

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20meta%20%3E%20(property)%20created">Link to this property</a>

LastModified TimeOptional

The timestamp of when the SCIM resource was last modified.

formatdate-time

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20meta%20%3E%20(property)%20lastModified">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20meta">Link to this property</a>

Schemas \[]stringOptional

The list of URIs which indicate the attributes contained within a SCIM resource.

<a href="#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)%20%3E%20(property)%20schemas">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.users%20%3E%20(model)%20access_user%20%3E%20(schema)>)

#### AccessUsersActive Sessions

##### [Get active sessions](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/subresources/active_sessions/methods/list)

client.ZeroTrust.Access.Users.ActiveSessions.List(ctx, userID, query) (\*SinglePage\[[AccessUserActiveSessionListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users.active_sessions%20%3E%20(model)%20AccessUserActiveSessionListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/users/{user\_id}/active\_sessions

##### [Get single active session](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/subresources/active_sessions/methods/get)

client.ZeroTrust.Access.Users.ActiveSessions.Get(ctx, userID, nonce, query) (\*[AccessUserActiveSessionGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users.active_sessions%20%3E%20(model)%20AccessUserActiveSessionGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/users/{user\_id}/active\_sessions/{nonce}

#### AccessUsersLast Seen Identity

##### [Get last seen identity](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/subresources/last_seen_identity/methods/get)

client.ZeroTrust.Access.Users.LastSeenIdentity.Get(ctx, userID, query) (\*[AccessUserLastSeenIdentityGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20AccessUserLastSeenIdentityGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/users/{user\_id}/last\_seen\_identity

##### ModelsExpand Collapse

<details>

<summary>

type Identity struct{…}

</summary>

AccountID stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

AuthStatus stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20auth_status">Link to this property</a>

CommonName stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20common_name">Link to this property</a>

DeviceID stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20device_id">Link to this property</a>

<details>

<summary>

DeviceSessions map\[string, IdentityDeviceSession]Optional

</summary>

LastAuthenticated float64Optional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20device_sessions%20%3E%20(items)%20%3E%20(property)%20last_authenticated">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20device_sessions">Link to this property</a>

<details>

<summary>

DevicePosture map\[string, IdentityDevicePosture]Optional

</summary>

ID stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Check IdentityDevicePostureCheckOptional

</summary>

Exists boolOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20check%20%3E%20(property)%20exists">Link to this property</a>

Path stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20check%20%3E%20(property)%20path">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20check">Link to this property</a>

Data unknownOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20data">Link to this property</a>

Description stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

Error stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

RuleName stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20rule_name">Link to this property</a>

Success boolOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20success">Link to this property</a>

Timestamp stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20timestamp">Link to this property</a>

Type stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20devicePosture">Link to this property</a>

Email stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

<details>

<summary>

Geo IdentityGeoOptional

</summary>

Country stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

Iat float64Optional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20iat">Link to this property</a>

<details>

<summary>

IdP IdentityIdPOptional

</summary>

ID stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20idp%20%3E%20(property)%20id">Link to this property</a>

Type stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20idp%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20idp">Link to this property</a>

IP stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

IsGateway boolOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20is_gateway">Link to this property</a>

IsWARP boolOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20is_warp">Link to this property</a>

<details>

<summary>

MTLSAuth IdentityMTLSAuthOptional

</summary>

AuthStatus stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20mtls_auth%20%3E%20(property)%20auth_status">Link to this property</a>

CERTIssuerDn stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20mtls_auth%20%3E%20(property)%20cert_issuer_dn">Link to this property</a>

CERTIssuerSki stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20mtls_auth%20%3E%20(property)%20cert_issuer_ski">Link to this property</a>

CERTPresented boolOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20mtls_auth%20%3E%20(property)%20cert_presented">Link to this property</a>

CERTSerial stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20mtls_auth%20%3E%20(property)%20cert_serial">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20mtls_auth">Link to this property</a>

ServiceTokenID stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20service_token_id">Link to this property</a>

ServiceTokenStatus boolOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20service_token_status">Link to this property</a>

UserUUID stringOptional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20user_uuid">Link to this property</a>

Version float64Optional

<a href="#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.users.last_seen_identity%20%3E%20(model)%20identity%20%3E%20(schema)>)

#### AccessUsersFailed Logins

##### [Get failed logins](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/users/subresources/failed_logins/methods/list)

client.ZeroTrust.Access.Users.FailedLogins.List(ctx, userID, query) (\*SinglePage\[[AccessUserFailedLoginListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.users.failed_logins%20%3E%20(model)%20AccessUserFailedLoginListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/users/{user\_id}/failed\_logins

#### AccessCustom Pages

##### [List custom pages](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/custom_pages/methods/list)

client.ZeroTrust.Access.CustomPages.List(ctx, params) (\*V4PagePaginationArray\[[CustomPageWithoutHTML](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/custom\_pages

##### [Get a custom page](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/custom_pages/methods/get)

client.ZeroTrust.Access.CustomPages.Get(ctx, customPageID, query) (\*[CustomPage](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/custom\_pages/{custom\_page\_id}

##### [Create a custom page](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/custom_pages/methods/create)

client.ZeroTrust.Access.CustomPages.New(ctx, params) (\*[CustomPageWithoutHTML](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/custom\_pages

##### [Update a custom page](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/custom_pages/methods/update)

client.ZeroTrust.Access.CustomPages.Update(ctx, customPageID, params) (\*[CustomPageWithoutHTML](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/custom\_pages/{custom\_page\_id}

##### [Delete a custom page](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/custom_pages/methods/delete)

client.ZeroTrust.Access.CustomPages.Delete(ctx, customPageID, body) (\*[AccessCustomPageDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20AccessCustomPageDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/custom\_pages/{custom\_page\_id}

##### ModelsExpand Collapse

<details>

<summary>

type CustomPage struct{…}

</summary>

CustomHTML string

Custom page HTML.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20custom_html">Link to this property</a>

Name string

Custom page name.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type CustomPageType

Custom page type.

</summary>

One of the following:

const CustomPageTypeIdentityDenied CustomPageType = "identity\_denied"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const CustomPageTypeForbidden CustomPageType = "forbidden"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const CustomPageTypeLogin CustomPageType = "login"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const CustomPageTypeInterstitial CustomPageType = "interstitial"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

ContractVersion int64Optional

Contract version of the page’s Liquid template. Present (&gt;= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20contract_version">Link to this property</a>

UID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page%20%3E%20(schema)>)

<details>

<summary>

type CustomPageWithoutHTML struct{…}

</summary>

Name string

Custom page name.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type CustomPageWithoutHTMLType

Custom page type.

</summary>

One of the following:

const CustomPageWithoutHTMLTypeIdentityDenied CustomPageWithoutHTMLType = "identity\_denied"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const CustomPageWithoutHTMLTypeForbidden CustomPageWithoutHTMLType = "forbidden"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

const CustomPageWithoutHTMLTypeLogin CustomPageWithoutHTMLType = "login"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

const CustomPageWithoutHTMLTypeInterstitial CustomPageWithoutHTMLType = "interstitial"

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

ContractVersion int64Optional

Contract version of the page’s Liquid template. Present (&gt;= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20contract_version">Link to this property</a>

UID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

<details>

<summary>

Warnings \[]CustomPageWithoutHTMLWarningOptional

Advisory validation findings returned when creating or updating a template. Omitted when empty.

</summary>

Message string

Human-readable description of the finding.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20warnings%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

Tier string

The validation tier that produced the finding (e.g. html, liquid).

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20warnings%20%3E%20(items)%20%3E%20(property)%20tier">Link to this property</a>

Ref stringOptional

Optional pointer to the part of the template the finding refers to.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20warnings%20%3E%20(items)%20%3E%20(property)%20ref">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)%20%3E%20(property)%20warnings">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(model)%20custom_page_without_html%20%3E%20(schema)>)

#### AccessTags

##### [List tags](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/tags/methods/list)

client.ZeroTrust.Access.Tags.List(ctx, params) (\*V4PagePaginationArray\[[Tag](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.tags%20%3E%20(model)%20tag%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/tags

##### [Get a tag](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/tags/methods/get)

client.ZeroTrust.Access.Tags.Get(ctx, tagName, query) (\*[Tag](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.tags%20%3E%20(model)%20tag%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/tags/{tag\_name}

##### [Create a tag](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/tags/methods/create)

client.ZeroTrust.Access.Tags.New(ctx, params) (\*[Tag](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.tags%20%3E%20(model)%20tag%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/tags

##### [Update a tag](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/tags/methods/update)

client.ZeroTrust.Access.Tags.Update(ctx, tagName, params) (\*[Tag](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.tags%20%3E%20(model)%20tag%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/tags/{tag\_name}

##### [Delete a tag](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/tags/methods/delete)

client.ZeroTrust.Access.Tags.Delete(ctx, tagName, body) (\*[AccessTagDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.tags%20%3E%20(model)%20AccessTagDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/tags/{tag\_name}

##### ModelsExpand Collapse

<details>

<summary>

type Tag struct{…}

A tag

</summary>

Name string

The name of the tag

<a href="#(resource)%20zero_trust.access.tags%20%3E%20(model)%20tag%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(model)%20tag%20%3E%20(schema)>)

#### AccessPolicies

##### [List Access reusable policies](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/policies/methods/list)

client.ZeroTrust.Access.Policies.List(ctx, params) (\*V4PagePaginationArray\[[AccessPolicyListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20AccessPolicyListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/access/policies

##### [Get an Access reusable policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/policies/methods/get)

client.ZeroTrust.Access.Policies.Get(ctx, policyID, query) (\*[AccessPolicyGetResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20AccessPolicyGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/access/policies/{policy\_id}

##### [Create an Access reusable policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/policies/methods/create)

client.ZeroTrust.Access.Policies.New(ctx, params) (\*[AccessPolicyNewResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20AccessPolicyNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/access/policies

##### [Update an Access reusable policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/policies/methods/update)

client.ZeroTrust.Access.Policies.Update(ctx, policyID, params) (\*[AccessPolicyUpdateResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20AccessPolicyUpdateResponse%20%3E%20(schema)>), error)

PUT/accounts/{account\_id}/access/policies/{policy\_id}

##### [Delete an Access reusable policy](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/access/subresources/policies/methods/delete)

client.ZeroTrust.Access.Policies.Delete(ctx, policyID, body) (\*[AccessPolicyDeleteResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20AccessPolicyDeleteResponse%20%3E%20(schema)>), error)

DELETE/accounts/{account\_id}/access/policies/{policy\_id}

##### ModelsExpand Collapse

<details>

<summary>

type ApprovalGroup struct{…}

A group of email addresses that can approve a temporary authentication request.

</summary>

ApprovalsNeeded float64

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

EmailAddresses \[]stringOptional

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

EmailListUUID stringOptional

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)>)

<details>

<summary>

type Policy struct{…}

</summary>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

ApprovalGroups \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a>Optional

Administrators who can approve a temporary authentication request.

</summary>

ApprovalsNeeded float64

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

EmailAddresses \[]stringOptional

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

EmailListUUID stringOptional

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20approval_groups">Link to this property</a>

ApprovalRequired boolOptional

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20approval_required">Link to this property</a>

CreatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

Decision PolicyDecisionOptional

The action Access will take if a user matches this policy.

</summary>

One of the following:

const PolicyDecisionAllow PolicyDecision = "allow"

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20decision%20%3E%20(member)%200">Link to this property</a>

const PolicyDecisionDeny PolicyDecision = "deny"

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20decision%20%3E%20(member)%201">Link to this property</a>

const PolicyDecisionNonIdentity PolicyDecision = "non\_identity"

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20decision%20%3E%20(member)%202">Link to this property</a>

const PolicyDecisionBypass PolicyDecision = "bypass"

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20decision%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

Exclude \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

Include \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20include">Link to this property</a>

IsolationRequired boolOptional

Require this application to be served in an isolated browser for users matching this policy.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20isolation_required">Link to this property</a>

Name stringOptional

The name of the Access policy.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Precedence int64Optional

The order of execution for this policy. Must be unique for each policy.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20precedence">Link to this property</a>

PurposeJustificationPrompt stringOptional

A custom message that will appear on the purpose justification screen.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_prompt">Link to this property</a>

PurposeJustificationRequired boolOptional

Require users to enter a justification when they log in to the application.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_required">Link to this property</a>

<details>

<summary>

Require \[]<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>Optional

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

One of the following:

<details>

<summary>

type GroupRule struct{…}

Matches an Access group.

</summary>

<details>

<summary>

Group GroupRuleGroup

</summary>

ID string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AnyValidServiceTokenRule struct{…}

Matches any valid Access Service Token

</summary>

AnyValidServiceToken AnyValidServiceTokenRuleAnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessAuthContextRule struct{…}

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

AuthContext AccessRuleAccessAuthContextRuleAuthContext

</summary>

ID string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

AcID string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type AuthenticationMethodRule struct{…}

Enforce different MFA options

</summary>

<details>

<summary>

AuthMethod AuthenticationMethodRuleAuthMethod

</summary>

AuthMethod string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AzureGroupRule struct{…}

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

AzureAD AzureGroupRuleAzureAD

</summary>

ID string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

IdentityProviderID string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type CertificateRule struct{…}

Matches any valid client certificate.

</summary>

Certificate CertificateRuleCertificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCommonNameRule struct{…}

Matches a specific common name.

</summary>

<details>

<summary>

CommonName AccessRuleAccessCommonNameRuleCommonName

</summary>

CommonName string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type CountryRule struct{…}

Matches a specific country

</summary>

<details>

<summary>

Geo CountryRuleGeo

</summary>

CountryCode string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessDevicePostureRule struct{…}

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

DevicePosture AccessDevicePostureRuleDevicePosture

</summary>

IntegrationUID string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

AccountID stringOptional

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DomainRule struct{…}

Match an entire email domain.

</summary>

<details>

<summary>

EmailDomain DomainRuleEmailDomain

</summary>

Domain string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailListRule struct{…}

Matches an email address from a list.

</summary>

<details>

<summary>

EmailList EmailListRuleEmailList

</summary>

ID string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EmailRule struct{…}

Matches a specific email.

</summary>

<details>

<summary>

Email EmailRuleEmail

</summary>

Email string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type EveryoneRule struct{…}

Matches everyone.

</summary>

Everyone EveryoneRuleEveryone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type ExternalEvaluationRule struct{…}

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

ExternalEvaluation ExternalEvaluationRuleExternalEvaluation

</summary>

EvaluateURL string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

KeysURL string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GitHubOrganizationRule struct{…}

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

GitHubOrganization GitHubOrganizationRuleGitHubOrganization

</summary>

IdentityProviderID string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

Team stringOptional

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type GSuiteGroupRule struct{…}

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

GSuite GSuiteGroupRuleGSuite

</summary>

Email string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

IdentityProviderID string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLoginMethodRule struct{…}

Matches a specific identity provider id.

</summary>

<details>

<summary>

LoginMethod AccessRuleAccessLoginMethodRuleLoginMethod

</summary>

ID string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

type IPListRule struct{…}

Matches an IP address from a list.

</summary>

<details>

<summary>

IPList IPListRuleIPList

</summary>

ID string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IPRule struct{…}

Matches an IP address block.

</summary>

<details>

<summary>

IP IPRuleIP

</summary>

IP string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type OktaGroupRule struct{…}

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

Okta OktaGroupRuleOkta

</summary>

IdentityProviderID string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

Name string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type SAMLGroupRule struct{…}

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

SAML SAMLGroupRuleSAML

</summary>

AttributeName string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

AttributeValue string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

IdentityProviderID string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessOIDCClaimRule struct{…}

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

OIDC AccessRuleAccessOIDCClaimRuleOIDC

</summary>

ClaimName string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

ClaimValue string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

IdentityProviderID string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

type ServiceTokenRule struct{…}

Matches a specific Access Service Token

</summary>

<details>

<summary>

ServiceToken ServiceTokenRuleServiceToken

</summary>

TokenID string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type AccessRuleAccessLinkedAppTokenRule struct{…}

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

LinkedAppToken AccessRuleAccessLinkedAppTokenRuleLinkedAppToken

</summary>

AppUID string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

type AccessRuleAccessUserRiskScoreRule struct{…}

Matches a user’s risk score.

</summary>

<details>

<summary>

UserRiskScore AccessRuleAccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

UserRiskScore \[]AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreLow AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreMedium AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreHigh AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScoreUnscored AccessRuleAccessUserRiskScoreRuleUserRiskScoreUserRiskScore = "unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

type AccessRuleAccessCloudflareAccountMemberRule struct{…}

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

CloudflareAccountMember AccessRuleAccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

AccountID stringOptional

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20require">Link to this property</a>

UpdatedAt TimeOptional

formatdate-time

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(model)%20policy%20%3E%20(schema)>)