---
title: Create your Zero Trust organization
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Zero Trust](https://developers.cloudflare.com/api/go/resources/zero_trust)

[Organizations](https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Create your Zero Trust organization

client.ZeroTrust.Organizations.New(ctx, params) (\*[Organization](<https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>), error)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

Sets up a Zero Trust organization for your account or zone.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Access: Organizations, Identity Providers, and Groups Write`

##### ParametersExpand Collapse

<details>

<summary>

params OrganizationNewParams

</summary>

AccountID param.Field\[string]Optional

Path param: The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

ZoneID param.Field\[string]Optional

Path param: The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zone_id">Link to this property</a>

AllowAuthenticateViaWARP param.Field\[bool]Optional

Body param: When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20allow_authenticate_via_warp">Link to this property</a>

AuthDomain param.Field\[string]Optional

Body param: The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format <code>adjective-noun-hex4</code> (e.g. <code>frosty-moon-7a3b.cloudflareaccess.com</code>).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20auth_domain">Link to this property</a>

AutoRedirectToIdentity param.Field\[bool]Optional

Body param: When set to <code>true</code>, users skip the identity provider selection step during login.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20auto_redirect_to_identity">Link to this property</a>

DenyUnmatchedRequests param.Field\[bool]Optional

Body param: Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the <code>deny_unmatched_requests_exempted_zone_names</code> array.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20deny_unmatched_requests">Link to this property</a>

DenyUnmatchedRequestsExemptedZoneNames param.Field\[\[]string]Optional

Body param: Contains zone names to exempt from the <code>deny_unmatched_requests</code> feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20deny_unmatched_requests_exempted_zone_names">Link to this property</a>

IsUIReadOnly param.Field\[bool]Optional

Body param: Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20is_ui_read_only">Link to this property</a>

LoginDesign param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)">LoginDesign</a>]Optional

Body param

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20login_design">Link to this property</a>

<details>

<summary>

MfaConfig param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/create#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)">OrganizationNewParamsMfaConfig</a>]Optional

Body param: Configures multi-factor authentication (MFA) settings for an organization.

</summary>

<details>

<summary>

AllowedAuthenticators \[]OrganizationNewParamsMfaConfigAllowedAuthenticatorOptional

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

</summary>

One of the following:

const OrganizationNewParamsMfaConfigAllowedAuthenticatorTotp OrganizationNewParamsMfaConfigAllowedAuthenticator = "totp"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationNewParamsMfaConfigAllowedAuthenticatorBiometrics OrganizationNewParamsMfaConfigAllowedAuthenticator = "biometrics"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationNewParamsMfaConfigAllowedAuthenticatorSecurityKey OrganizationNewParamsMfaConfigAllowedAuthenticator = "security\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OrganizationNewParamsMfaConfigAllowedAuthenticatorPivKey OrganizationNewParamsMfaConfigAllowedAuthenticator = "piv\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OrganizationNewParamsMfaConfigAllowedAuthenticatorSSHFido2Key OrganizationNewParamsMfaConfigAllowedAuthenticator = "ssh\_fido2\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

AmrMatchingSessionDuration stringOptional

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20amr_matching_session_duration">Link to this property</a>

RequiredAaguids stringOptional

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

formatuuid

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20required_aaguids">Link to this property</a>

SessionDuration stringOptional

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_config">Link to this property</a>

<details>

<summary>

MfaPivKeyRequirements param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/create#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)">OrganizationNewParamsMfaPivKeyRequirements</a>]Optional

Body param: Configures PIV key requirements for MFA using hardware security keys.

</summary>

<details>

<summary>

PinPolicy OrganizationNewParamsMfaPivKeyRequirementsPinPolicyOptional

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

</summary>

One of the following:

const OrganizationNewParamsMfaPivKeyRequirementsPinPolicyNever OrganizationNewParamsMfaPivKeyRequirementsPinPolicy = "never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20pin_policy%20%3E%20(member)%200">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsPinPolicyOnce OrganizationNewParamsMfaPivKeyRequirementsPinPolicy = "once"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20pin_policy%20%3E%20(member)%201">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsPinPolicyAlways OrganizationNewParamsMfaPivKeyRequirementsPinPolicy = "always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20pin_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20pin_policy">Link to this property</a>

RequireFipsDevice boolOptional

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20require_fips_device">Link to this property</a>

<details>

<summary>

SSHKeySize \[]OrganizationNewParamsMfaPivKeyRequirementsSSHKeySizeOptional

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

</summary>

One of the following:

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize256 OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize = 256

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize384 OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize = 384

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize521 OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize = 521

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize2048 OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize = 2048

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize3072 OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize = 3072

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize4096 OrganizationNewParamsMfaPivKeyRequirementsSSHKeySize = 4096

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_size">Link to this property</a>

<details>

<summary>

SSHKeyType \[]OrganizationNewParamsMfaPivKeyRequirementsSSHKeyTypeOptional

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

</summary>

One of the following:

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeyTypeEcdsa OrganizationNewParamsMfaPivKeyRequirementsSSHKeyType = "ecdsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeyTypeEd25519 OrganizationNewParamsMfaPivKeyRequirementsSSHKeyType = "ed25519"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsSSHKeyTypeRSA OrganizationNewParamsMfaPivKeyRequirementsSSHKeyType = "rsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20ssh_key_type">Link to this property</a>

<details>

<summary>

TouchPolicy OrganizationNewParamsMfaPivKeyRequirementsTouchPolicyOptional

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

</summary>

One of the following:

const OrganizationNewParamsMfaPivKeyRequirementsTouchPolicyNever OrganizationNewParamsMfaPivKeyRequirementsTouchPolicy = "never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20touch_policy%20%3E%20(member)%200">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsTouchPolicyAlways OrganizationNewParamsMfaPivKeyRequirementsTouchPolicy = "always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20touch_policy%20%3E%20(member)%201">Link to this property</a>

const OrganizationNewParamsMfaPivKeyRequirementsTouchPolicyCached OrganizationNewParamsMfaPivKeyRequirementsTouchPolicy = "cached"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20touch_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements%20%3E%20(schema)%20%3E%20(property)%20touch_policy">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_piv_key_requirements">Link to this property</a>

MfaRequiredForAllApps param.Field\[bool]Optional

Body param: Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20mfa_required_for_all_apps">Link to this property</a>

Name param.Field\[string]Optional

Body param: The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20name">Link to this property</a>

<details>

<summary>

ServiceTokenInactivity param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/zero_trust/subresources/organizations/methods/create#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity%20%3E%20(schema)">OrganizationNewParamsServiceTokenInactivity</a>]Optional

Body param: Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

<details>

<summary>

Action OrganizationNewParamsServiceTokenInactivityAction

The action applied to an inactive service token.

</summary>

One of the following:

const OrganizationNewParamsServiceTokenInactivityActionDisable OrganizationNewParamsServiceTokenInactivityAction = "disable"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

const OrganizationNewParamsServiceTokenInactivityActionDelete OrganizationNewParamsServiceTokenInactivityAction = "delete"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

Enabled bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

InactivityThresholdDays int64

The number of days a service token must be inactive before the configured action is applied.

maximum365

minimum30

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity%20%3E%20(schema)%20%3E%20(property)%20inactivity_threshold_days">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20service_token_inactivity">Link to this property</a>

SessionDuration param.Field\[string]Optional

Body param: The amount of time that tokens issued for applications will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20session_duration">Link to this property</a>

StrictServiceTokenAuth param.Field\[bool]Optional

Body param: Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20strict_service_token_auth">Link to this property</a>

UIReadOnlyToggleReason param.Field\[string]Optional

Body param: A description of the reason why the UI read only field is being toggled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20ui_read_only_toggle_reason">Link to this property</a>

UserSeatExpirationInactiveTime param.Field\[string]Optional

Body param: The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: <code>ns</code>, <code>us</code> (or <code>µs</code>), <code>ms</code>, <code>s</code>, <code>m</code>, <code>h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20user_seat_expiration_inactive_time">Link to this property</a>

WARPAuthNonBrowser401 param.Field\[bool]Optional

Body param: When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20warp_auth_non_browser_401">Link to this property</a>

WARPAuthSessionDuration param.Field\[string]Optional

Body param: The amount of time that tokens issued for applications will be valid. Must be in the format <code>30m</code> or <code>2h45m</code>. Valid time units are: m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20warp_auth_session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(method)%20create%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type Organization struct{…}

</summary>

AllowAuthenticateViaWARP boolOptional

When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20allow_authenticate_via_warp">Link to this property</a>

AuthDomain stringOptional

The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format <code>adjective-noun-hex4</code> (e.g. <code>frosty-moon-7a3b.cloudflareaccess.com</code>).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20auth_domain">Link to this property</a>

AutoRedirectToIdentity boolOptional

When set to <code>true</code>, users skip the identity provider selection step during login.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

<details>

<summary>

CustomPages OrganizationCustomPagesOptional

</summary>

Forbidden stringOptional

The uid of the custom page to use when a user is denied access after failing a non-identity rule.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20forbidden">Link to this property</a>

IdentityDenied stringOptional

The uid of the custom page to use when a user is denied access.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20identity_denied">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages">Link to this property</a>

DenyUnmatchedRequests boolOptional

Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the <code>deny_unmatched_requests_exempted_zone_names</code> array.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests">Link to this property</a>

DenyUnmatchedRequestsExemptedZoneNames \[]stringOptional

Contains zone names to exempt from the <code>deny_unmatched_requests</code> feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests_exempted_zone_names">Link to this property</a>

IsUIReadOnly boolOptional

Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20is_ui_read_only">Link to this property</a>

<details>

<summary>

LoginDesign <a href="https://developers.cloudflare.com/api/go/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)">LoginDesign</a>Optional

</summary>

BackgroundColor stringOptional

The background color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design%20%2B%20(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20background_color">Link to this property</a>

FooterText stringOptional

The text at the bottom of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design%20%2B%20(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20footer_text">Link to this property</a>

HeaderText stringOptional

The text at the top of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design%20%2B%20(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20header_text">Link to this property</a>

LogoPath stringOptional

The URL of the logo on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design%20%2B%20(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20logo_path">Link to this property</a>

TextColor stringOptional

The text color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design%20%2B%20(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20text_color">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design">Link to this property</a>

<details>

<summary>

MfaConfig OrganizationMfaConfigOptional

Configures multi-factor authentication (MFA) settings for an organization.

</summary>

<details>

<summary>

AllowedAuthenticators \[]OrganizationMfaConfigAllowedAuthenticatorOptional

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

</summary>

One of the following:

const OrganizationMfaConfigAllowedAuthenticatorTotp OrganizationMfaConfigAllowedAuthenticator = "totp"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorBiometrics OrganizationMfaConfigAllowedAuthenticator = "biometrics"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorSecurityKey OrganizationMfaConfigAllowedAuthenticator = "security\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorPivKey OrganizationMfaConfigAllowedAuthenticator = "piv\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OrganizationMfaConfigAllowedAuthenticatorSSHFido2Key OrganizationMfaConfigAllowedAuthenticator = "ssh\_fido2\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

AmrMatchingSessionDuration stringOptional

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20amr_matching_session_duration">Link to this property</a>

RequiredAaguids stringOptional

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

formatuuid

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20required_aaguids">Link to this property</a>

SessionDuration stringOptional

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

<details>

<summary>

MfaPivKeyRequirements OrganizationMfaPivKeyRequirementsOptional

Configures PIV key requirements for MFA using hardware security keys.

</summary>

<details>

<summary>

PinPolicy OrganizationMfaPivKeyRequirementsPinPolicyOptional

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsPinPolicyNever OrganizationMfaPivKeyRequirementsPinPolicy = "never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsPinPolicyOnce OrganizationMfaPivKeyRequirementsPinPolicy = "once"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsPinPolicyAlways OrganizationMfaPivKeyRequirementsPinPolicy = "always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy">Link to this property</a>

RequireFipsDevice boolOptional

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20require_fips_device">Link to this property</a>

<details>

<summary>

SSHKeySize \[]OrganizationMfaPivKeyRequirementsSSHKeySizeOptional

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsSSHKeySize256 OrganizationMfaPivKeyRequirementsSSHKeySize = 256

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize384 OrganizationMfaPivKeyRequirementsSSHKeySize = 384

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize521 OrganizationMfaPivKeyRequirementsSSHKeySize = 521

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize2048 OrganizationMfaPivKeyRequirementsSSHKeySize = 2048

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize3072 OrganizationMfaPivKeyRequirementsSSHKeySize = 3072

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeySize4096 OrganizationMfaPivKeyRequirementsSSHKeySize = 4096

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size">Link to this property</a>

<details>

<summary>

SSHKeyType \[]OrganizationMfaPivKeyRequirementsSSHKeyTypeOptional

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsSSHKeyTypeEcdsa OrganizationMfaPivKeyRequirementsSSHKeyType = "ecdsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeyTypeEd25519 OrganizationMfaPivKeyRequirementsSSHKeyType = "ed25519"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsSSHKeyTypeRSA OrganizationMfaPivKeyRequirementsSSHKeyType = "rsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type">Link to this property</a>

<details>

<summary>

TouchPolicy OrganizationMfaPivKeyRequirementsTouchPolicyOptional

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

</summary>

One of the following:

const OrganizationMfaPivKeyRequirementsTouchPolicyNever OrganizationMfaPivKeyRequirementsTouchPolicy = "never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%200">Link to this property</a>

const OrganizationMfaPivKeyRequirementsTouchPolicyAlways OrganizationMfaPivKeyRequirementsTouchPolicy = "always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%201">Link to this property</a>

const OrganizationMfaPivKeyRequirementsTouchPolicyCached OrganizationMfaPivKeyRequirementsTouchPolicy = "cached"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements">Link to this property</a>

MfaRequiredForAllApps boolOptional

Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_required_for_all_apps">Link to this property</a>

Name stringOptional

The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

ServiceTokenInactivity OrganizationServiceTokenInactivityOptional

Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

<details>

<summary>

Action OrganizationServiceTokenInactivityAction

The action applied to an inactive service token.

</summary>

One of the following:

const OrganizationServiceTokenInactivityActionDisable OrganizationServiceTokenInactivityAction = "disable"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

const OrganizationServiceTokenInactivityActionDelete OrganizationServiceTokenInactivityAction = "delete"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action">Link to this property</a>

Enabled bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20enabled">Link to this property</a>

InactivityThresholdDays int64

The number of days a service token must be inactive before the configured action is applied.

maximum365

minimum30

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20inactivity_threshold_days">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity">Link to this property</a>

SessionDuration stringOptional

The amount of time that tokens issued for applications will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

StrictServiceTokenAuth boolOptional

Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20strict_service_token_auth">Link to this property</a>

UIReadOnlyToggleReason stringOptional

A description of the reason why the UI read only field is being toggled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20ui_read_only_toggle_reason">Link to this property</a>

UserSeatExpirationInactiveTime stringOptional

The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: <code>ns</code>, <code>us</code> (or <code>µs</code>), <code>ms</code>, <code>s</code>, <code>m</code>, <code>h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20user_seat_expiration_inactive_time">Link to this property</a>

WARPAuthNonBrowser401 boolOptional

When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20warp_auth_non_browser_401">Link to this property</a>

WARPAuthSessionDuration stringOptional

The amount of time that tokens issued for applications will be valid. Must be in the format <code>30m</code> or <code>2h45m</code>. Valid time units are: m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20warp_auth_session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>)

### Create your Zero Trust organization

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/zero_trust"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  organization, err := client.ZeroTrust.Organizations.New(context.TODO(), zero_trust.OrganizationNewParams{

  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", organization.AutoRedirectToIdentity)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "allow_authenticate_via_warp": true,
    "auth_domain": "test.cloudflareaccess.com",
    "auto_redirect_to_identity": true,
    "created_at": "2014-01-01T05:20:00.12345Z",
    "custom_pages": {
      "forbidden": "699d98642c564d2e855e9661899b7252",
      "identity_denied": "699d98642c564d2e855e9661899b7252"
    },
    "deny_unmatched_requests": true,
    "deny_unmatched_requests_exempted_zone_names": [
      "example.com"
    ],
    "is_ui_read_only": true,
    "login_design": {
      "background_color": "#c5ed1b",
      "footer_text": "This is an example description.",
      "header_text": "This is an example description.",
      "logo_path": "https://example.com/logo.png",
      "text_color": "#c5ed1b"
    },
    "mfa_config": {
      "allowed_authenticators": [
        "totp",
        "biometrics",
        "security_key"
      ],
      "amr_matching_session_duration": "12h",
      "required_aaguids": "2fc0579f-8113-47ea-b116-bb5a8db9202a",
      "session_duration": "24h"
    },
    "mfa_piv_key_requirements": {
      "pin_policy": "always",
      "require_fips_device": true,
      "ssh_key_size": [
        256,
        2048
      ],
      "ssh_key_type": [
        "ecdsa",
        "rsa"
      ],
      "touch_policy": "always"
    },
    "mfa_required_for_all_apps": false,
    "name": "Widget Corps Internal Applications",
    "service_token_inactivity": {
      "action": "disable",
      "enabled": true,
      "inactivity_threshold_days": 30
    },
    "session_duration": "24h",
    "strict_service_token_auth": true,
    "ui_read_only_toggle_reason": "Temporarily turn off the UI read only lock to make a change via the UI",
    "updated_at": "2014-01-01T05:20:00.12345Z",
    "user_seat_expiration_inactive_time": "730h",
    "warp_auth_non_browser_401": false,
    "warp_auth_session_duration": "24h"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "allow_authenticate_via_warp": true,
    "auth_domain": "test.cloudflareaccess.com",
    "auto_redirect_to_identity": true,
    "created_at": "2014-01-01T05:20:00.12345Z",
    "custom_pages": {
      "forbidden": "699d98642c564d2e855e9661899b7252",
      "identity_denied": "699d98642c564d2e855e9661899b7252"
    },
    "deny_unmatched_requests": true,
    "deny_unmatched_requests_exempted_zone_names": [
      "example.com"
    ],
    "is_ui_read_only": true,
    "login_design": {
      "background_color": "#c5ed1b",
      "footer_text": "This is an example description.",
      "header_text": "This is an example description.",
      "logo_path": "https://example.com/logo.png",
      "text_color": "#c5ed1b"
    },
    "mfa_config": {
      "allowed_authenticators": [
        "totp",
        "biometrics",
        "security_key"
      ],
      "amr_matching_session_duration": "12h",
      "required_aaguids": "2fc0579f-8113-47ea-b116-bb5a8db9202a",
      "session_duration": "24h"
    },
    "mfa_piv_key_requirements": {
      "pin_policy": "always",
      "require_fips_device": true,
      "ssh_key_size": [
        256,
        2048
      ],
      "ssh_key_type": [
        "ecdsa",
        "rsa"
      ],
      "touch_policy": "always"
    },
    "mfa_required_for_all_apps": false,
    "name": "Widget Corps Internal Applications",
    "service_token_inactivity": {
      "action": "disable",
      "enabled": true,
      "inactivity_threshold_days": 30
    },
    "session_duration": "24h",
    "strict_service_token_auth": true,
    "ui_read_only_toggle_reason": "Temporarily turn off the UI read only lock to make a change via the UI",
    "updated_at": "2014-01-01T05:20:00.12345Z",
    "user_seat_expiration_inactive_time": "730h",
    "warp_auth_non_browser_401": false,
    "warp_auth_session_duration": "24h"
  }
}
```