---
title: List Access identity providers
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Zero Trust](https://developers.cloudflare.com/api/go/resources/zero_trust)

[Identity Providers](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/identity_providers)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List Access identity providers

client.ZeroTrust.IdentityProviders.List(ctx, params) (\*V4PagePaginationArray\[[IdentityProviderListResponse](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)>)], error)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers

Lists all configured identity providers.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Access: Organizations, Identity Providers, and Groups Write``Access: Organizations, Identity Providers, and Groups Read`

##### ParametersExpand Collapse

<details>

<summary>

params IdentityProviderListParams

</summary>

AccountID param.Field\[string]Optional

Path param: The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

ZoneID param.Field\[string]Optional

Path param: The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone_id">Link to this property</a>

Page param.Field\[int64]Optional

Query param: Page number of results.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page">Link to this property</a>

PerPage param.Field\[int64]Optional

Query param: Number of results per page.

maximum1000

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page">Link to this property</a>

SCIMEnabled param.Field\[string]Optional

Query param: Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20scim_enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type IdentityProviderListResponse interface{…}

</summary>

One of the following:

<details>

<summary>

type AzureAD struct{…}

</summary>

<details>

<summary>

Config AzureADConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

ConditionalAccessEnabled boolOptional

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20conditional_access_enabled">Link to this property</a>

DirectoryID stringOptional

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20directory_id">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

Prompt AzureADConfigPromptOptional

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

</summary>

One of the following:

const AzureADConfigPromptLogin AzureADConfigPrompt = "login"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

const AzureADConfigPromptSelectAccount AzureADConfigPrompt = "select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

const AzureADConfigPromptNone AzureADConfigPrompt = "none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

SupportGroups boolOptional

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20support_groups">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet AzureADSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate AzureADSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessCentrify struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessCentrifyConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

CentrifyAccount stringOptional

Your centrify account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20centrify_account">Link to this property</a>

CentrifyAppID stringOptional

Your centrify app id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20centrify_app_id">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessCentrifySAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessCentrifySAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessFacebook struct{…}

</summary>

<details>

<summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessFacebookSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessFacebookSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessGitHub struct{…}

</summary>

<details>

<summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessGitHubSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessGitHubSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessGoogle struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessGoogleConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessGoogleSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessGoogleSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessGoogleApps struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessGoogleAppsConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

AppsDomain stringOptional

Your companies TLD

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20apps_domain">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

Prompt IdentityProviderListResponseAccessGoogleAppsConfigPromptOptional

Configures the prompt behavior for Google authentication.

</summary>

One of the following:

const IdentityProviderListResponseAccessGoogleAppsConfigPromptNone IdentityProviderListResponseAccessGoogleAppsConfigPrompt = "none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderListResponseAccessGoogleAppsConfigPromptConsent IdentityProviderListResponseAccessGoogleAppsConfigPrompt = "consent"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderListResponseAccessGoogleAppsConfigPromptSelectAccount IdentityProviderListResponseAccessGoogleAppsConfigPrompt = "select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

UseLoginHint boolOptional

Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20use_login_hint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessGoogleAppsSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessGoogleAppsSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessLinkedin struct{…}

</summary>

<details>

<summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessLinkedinSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessLinkedinSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessOIDC struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessOIDCConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

AuthURL stringOptional

The authorization\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20auth_url">Link to this property</a>

CERTsURL stringOptional

The jwks\_uri endpoint of your IdP to allow the IdP keys to sign the tokens

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20certs_url">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

PKCEEnabled boolOptional

Enable Proof Key for Code Exchange (PKCE)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20pkce_enabled">Link to this property</a>

Scopes \[]stringOptional

OAuth scopes

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20scopes">Link to this property</a>

TokenURL stringOptional

The token\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20token_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessOIDCSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessOIDCSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessOkta struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessOktaConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

AuthorizationServerID stringOptional

Your okta authorization server id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20authorization_server_id">Link to this property</a>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

OktaAccount stringOptional

Your okta account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20okta_account">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessOktaSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessOktaSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%208">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessOnelogin struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessOneloginConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

OneloginAccount stringOptional

Your OneLogin account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20onelogin_account">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessOneloginSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessOneloginSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%209">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessPingone struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessPingoneConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Claims \[]stringOptional

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

EmailClaimName stringOptional

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

PingEnvID stringOptional

Your PingOne environment identifier

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20ping_env_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessPingoneSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessPingoneSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2010">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessSAML struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessSAMLConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

Attributes \[]stringOptional

A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20attributes">Link to this property</a>

EmailAttributeName stringOptional

The attribute name for email in the SAML response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20email_attribute_name">Link to this property</a>

EnableEncryption boolOptional

Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set.

To enable encryption:

1. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>
2. Set this field to <code>true</code> and include <code>saml_certificate_set_id</code> in the PUT request
3. Configure the public certificate in your external Identity Provider

Note: Requires <code>saml_certificate_set_id</code> to be set when <code>true</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20enable_encryption">Link to this property</a>

ForceAuthn boolOptional

Asks the IdP to reauthenticate the user for each SAML authentication request.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20force_authn">Link to this property</a>

<details>

<summary>

HeaderAttributes \[]IdentityProviderListResponseAccessSAMLConfigHeaderAttributeOptional

Add a list of attribute names that will be returned in the response header from the Access callback.

</summary>

AttributeName stringOptional

attribute name from the IDP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes%20%3E%20(items)%20%3E%20(property)%20attribute_name">Link to this property</a>

HeaderName stringOptional

header that will be added on the request to the origin

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes%20%3E%20(items)%20%3E%20(property)%20header_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes">Link to this property</a>

IdPPublicCERTs \[]stringOptional

X509 certificate to verify the signature in the SAML authentication response

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20idp_public_certs">Link to this property</a>

IssuerURL stringOptional

IdP Entity ID or Issuer URL

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20issuer_url">Link to this property</a>

MaxSSOURLLength int64Optional

The maximum URL length the IdP accepts for the SSO redirect URL. When the constructed SSO URL would exceed this length, the RelayState is stored server-side and a short nonce is passed to the IdP instead. Set this if your IdP enforces a URL length limit.

maximum100000

minimum512

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20max_sso_url_length">Link to this property</a>

SignRequest boolOptional

Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20sign_request">Link to this property</a>

SSOTargetURL stringOptional

URL to send the SAML authentication requests to

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20sso_target_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessSAMLSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessSAMLSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2011">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessYandex struct{…}

</summary>

<details>

<summary>

Config <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

ClientID stringOptional

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

ClientSecret stringOptional

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessYandexSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessYandexSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2012">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessOnetimepin struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessOnetimepinConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

RedirectURL stringOptional

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessOnetimepinSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessOnetimepinSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2013">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessCloudflare struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessCloudflareConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

RedirectURL stringOptional

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

RestrictToAccountMembers boolOptional

When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config%20%3E%20(property)%20restrict_to_account_members">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessCloudflareSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessCloudflareSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2014">Link to this property</a>

<details>

<summary>

type IdentityProviderListResponseAccessPasskeys struct{…}

</summary>

<details>

<summary>

Config IdentityProviderListResponseAccessPasskeysConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

LoginPageAutoPrompt boolOptional

When enabled, the Access login page automatically prompts the user to authenticate with a passkey.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config%20%3E%20(property)%20login_page_auto_prompt">Link to this property</a>

RedirectURL stringOptional

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config">Link to this property</a>

Name string

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

Type <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

const IdentityProviderTypeOnetimepin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderTypeAzureAD <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderTypeSAML <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const IdentityProviderTypeCentrify <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const IdentityProviderTypeFacebook <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const IdentityProviderTypeGitHub <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const IdentityProviderTypeGoogleApps <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

const IdentityProviderTypeGoogle <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

const IdentityProviderTypeLinkedin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

const IdentityProviderTypeOIDC <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

const IdentityProviderTypeOkta <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

const IdentityProviderTypeOnelogin <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

const IdentityProviderTypePingone <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

const IdentityProviderTypeYandex <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

const IdentityProviderTypeCloudflare <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

const IdentityProviderTypePasskeys <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a> = "passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type">Link to this property</a>

ID stringOptional

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20id">Link to this property</a>

ReadOnly boolOptional

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

SAMLCertificateSet IdentityProviderListResponseAccessPasskeysSAMLCertificateSetOptional

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

CreatedAt Time

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

UID string

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

UpdatedAt Time

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

CurrentCertificate IdentityProviderListResponseAccessPasskeysSAMLCertificateSetCurrentCertificateOptional

The currently active certificate used for encrypting SAML assertions

</summary>

IsCurrent bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

NotAfter Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

PublicCertificate string

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

UID string

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

PreviousCertificate unknownOptional

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

SAMLCertificateSetID stringOptional

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

SCIMConfig <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)">IdentityProviderSCIMConfig</a>Optional

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

Enabled boolOptional

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

IdentityUpdateBehavior IdentityProviderSCIMConfigIdentityUpdateBehaviorOptional

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

const IdentityProviderSCIMConfigIdentityUpdateBehaviorAutomatic IdentityProviderSCIMConfigIdentityUpdateBehavior = "automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorReauth IdentityProviderSCIMConfigIdentityUpdateBehavior = "reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

const IdentityProviderSCIMConfigIdentityUpdateBehaviorNoAction IdentityProviderSCIMConfigIdentityUpdateBehavior = "no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

SCIMBaseURL stringOptional

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

SeatDeprovision boolOptional

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

Secret stringOptional

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

UserDeprovision boolOptional

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)%20%3E%20(variant)%2015">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20IdentityProviderListResponse%20%3E%20(schema)>)

### List Access identity providers

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/zero_trust"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  page, err := client.ZeroTrust.IdentityProviders.List(context.TODO(), zero_trust.IdentityProviderListParams{

  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", page)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "config": {
        "claims": [
          "email_verified",
          "preferred_username",
          "custom_claim_name"
        ],
        "client_id": "<your client id>",
        "client_secret": "<your client secret>",
        "conditional_access_enabled": true,
        "directory_id": "<your azure directory uuid>",
        "email_claim_name": "custom_claim_name",
        "prompt": "login",
        "support_groups": true
      },
      "name": "Widget Corps IDP",
      "type": "onetimepin",
      "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
      "read_only": true,
      "saml_certificate_set": {
        "created_at": "2026-05-07T19:16:19.821162Z",
        "uid": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
        "updated_at": "2026-05-07T19:16:19.821162Z",
        "current_certificate": {
          "is_current": true,
          "not_after": "2027-05-07T19:11:00Z",
          "public_certificate": "-----BEGIN CERTIFICATE-----\nMIIEpzCCA4+gAwIBAgIUTh2VSDDJ0oB/gabio6j1L9QwWoUwDQYJKoZIhvcNAQEL\n...\n-----END CERTIFICATE-----\n",
          "uid": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
        },
        "previous_certificate": {}
      },
      "saml_certificate_set_id": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
      "scim_config": {
        "enabled": true,
        "identity_update_behavior": "automatic",
        "scim_base_url": "scim_base_url",
        "seat_deprovision": true,
        "secret": "secret",
        "user_deprovision": true
      }
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "config": {
        "claims": [
          "email_verified",
          "preferred_username",
          "custom_claim_name"
        ],
        "client_id": "<your client id>",
        "client_secret": "<your client secret>",
        "conditional_access_enabled": true,
        "directory_id": "<your azure directory uuid>",
        "email_claim_name": "custom_claim_name",
        "prompt": "login",
        "support_groups": true
      },
      "name": "Widget Corps IDP",
      "type": "onetimepin",
      "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
      "read_only": true,
      "saml_certificate_set": {
        "created_at": "2026-05-07T19:16:19.821162Z",
        "uid": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
        "updated_at": "2026-05-07T19:16:19.821162Z",
        "current_certificate": {
          "is_current": true,
          "not_after": "2027-05-07T19:11:00Z",
          "public_certificate": "-----BEGIN CERTIFICATE-----\nMIIEpzCCA4+gAwIBAgIUTh2VSDDJ0oB/gabio6j1L9QwWoUwDQYJKoZIhvcNAQEL\n...\n-----END CERTIFICATE-----\n",
          "uid": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
        },
        "previous_certificate": {}
      },
      "saml_certificate_set_id": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
      "scim_config": {
        "enabled": true,
        "identity_update_behavior": "automatic",
        "scim_base_url": "scim_base_url",
        "seat_deprovision": true,
        "secret": "secret",
        "user_deprovision": true
      }
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```