---
title: Change Image Transformations Allowed Origins setting
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Zones](https://developers.cloudflare.com/api/go/resources/zones)

[Transformations Allowed Origins](https://developers.cloudflare.com/api/go/resources/zones/subresources/transformations_allowed_origins)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Change Image Transformations Allowed Origins setting

client.Zones.TransformationsAllowedOrigins.Edit(ctx, params) (\*[TransformationsAllowedOrigins](<https://developers.cloudflare.com/api/go/resources/zones#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)>), error)

PATCH/zones/{zone\_id}/settings/transformations\_allowed\_origins

Media Transformations Allowed Origins restricts transformations for images and video served through Cloudflare’s network to requests originating from specified domains. Refer to the Image Transformations and Video Transformations documentation for more information.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Zone Settings Write`

##### ParametersExpand Collapse

<details>

<summary>

params TransformationsAllowedOriginEditParams

</summary>

ZoneID param.Field\[string]

Path param: Identifier.

maxLength32

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(method)%20edit%20%3E%20(params)%20default%20%3E%20(param)%20zone_id">Link to this property</a>

Value param.Field\[string]

Body param: Comma-separated list of allowed origin domains for image and video transformations. Use ”\*” to allow all origins (default).

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(method)%20edit%20%3E%20(params)%20default%20%3E%20(param)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zones.transformations_allowed_origins%20%3E%20(method)%20edit%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type TransformationsAllowedOrigins struct{…}

Controls which origins are allowed to request image and video transformations.

</summary>

ID TransformationsAllowedOriginsIDOptional

ID of the zone setting.

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Editable TransformationsAllowedOriginsEditableOptional

Whether or not this setting can be modified for this zone (based on your Cloudflare plan level).

</summary>

One of the following:

const TransformationsAllowedOriginsEditableTrue TransformationsAllowedOriginsEditable = true

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20editable%20%3E%20(member)%200">Link to this property</a>

const TransformationsAllowedOriginsEditableFalse TransformationsAllowedOriginsEditable = false

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20editable%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20editable">Link to this property</a>

ModifiedOn TimeOptional

last time this setting was modified.

formatdate-time

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

<details>

<summary>

Value TransformationsAllowedOriginsValueOptional

Comma-separated list of allowed origin domains for image and video transformations. Use ”\*” to allow all origins (default).

</summary>

One of the following:

const TransformationsAllowedOriginsValueOn TransformationsAllowedOriginsValue = "on"

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20value%20%3E%20(member)%200">Link to this property</a>

const TransformationsAllowedOriginsValueOff TransformationsAllowedOriginsValue = "off"

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20value%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zones.transformations_allowed_origins%20%3E%20(model)%20transformations_allowed_origins%20%3E%20(schema)>)

### Change Image Transformations Allowed Origins setting

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/zones"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  transformationsAllowedOrigins, err := client.Zones.TransformationsAllowedOrigins.Edit(context.TODO(), zones.TransformationsAllowedOriginEditParams{
    ZoneID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
    Value: cloudflare.F("example.com,cdn.example.com"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", transformationsAllowedOrigins.ID)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "image_resizing_allowed_origins",
    "editable": true,
    "modified_on": "2014-01-01T05:20:00.12345Z",
    "value": "on"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "image_resizing_allowed_origins",
    "editable": true,
    "modified_on": "2014-01-01T05:20:00.12345Z",
    "value": "on"
  }
}
```