---
title: List IP Access rules
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Firewall](https://developers.cloudflare.com/api/python/resources/firewall)

[Access Rules](https://developers.cloudflare.com/api/python/resources/firewall/subresources/access_rules)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List IP Access rules

firewall.access\_rules.list(AccessRuleListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[AccessRuleListResponse](<https://developers.cloudflare.com/api/python/resources/firewall#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)>)]

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/firewall/access\_rules/rules

Fetches IP Access rules of an account or zone. These rules apply to all the zones in the account or zone. You can filter the results using several optional parameters.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Account Firewall Access Rules Write``Account Firewall Access Rules Read`

##### ParametersExpand Collapse

account\_id: Optional\[str]

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

zone\_id: Optional\[str]

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone_id%20%3E%20(schema)>)

<details>

<summary>

configuration: Optional\[<a href="https://developers.cloudflare.com/api/python/resources/firewall/subresources/access_rules/methods/list#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)">Configuration</a>]

</summary>

<details>

<summary>

target: Optional\[Literal\["ip", "ip\_range", "asn", "country"]]

Defines the target to search in existing rules.

</summary>

One of the following:

"ip"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)%20%3E%20(property)%20target%20%3E%20(member)%200">Link to this property</a>

"ip\_range"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)%20%3E%20(property)%20target%20%3E%20(member)%201">Link to this property</a>

"asn"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)%20%3E%20(property)%20target%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)%20%3E%20(property)%20target%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)%20%3E%20(property)%20target">Link to this property</a>

value: Optional\[str]

Defines the target value to search for in existing rules: an IP address, an IP address range, or a country code, depending on the provided <code>configuration.target</code>. Notes: You can search for a single IPv4 address, an IP address range with a subnet of ‘/16’ or ‘/24’, or a two-letter ISO-3166-1 alpha-2 country code.

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20configuration%20%3E%20(schema)>)

<details>

<summary>

direction: Optional\[Literal\["asc", "desc"]]

Defines the direction used to sort returned rules.

</summary>

One of the following:

"asc"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"desc"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)>)

<details>

<summary>

match: Optional\[Literal\["any", "all"]]

Defines the search requirements. When set to <code>all</code>, all the search requirements must match. When set to <code>any</code>, only one of the search requirements has to match.

</summary>

One of the following:

"any"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20match%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"all"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20match%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20match%20%3E%20(schema)>)

<details>

<summary>

mode: Optional\[Literal\["block", "challenge", "whitelist", 2 more]]

The action to apply to a matched request.

</summary>

One of the following:

"block"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20mode%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20mode%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"whitelist"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20mode%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"js\_challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20mode%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"managed\_challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20mode%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20mode%20%3E%20(schema)>)

notes: Optional\[str]

Defines the string to search for in the notes of existing IP Access rules. Notes: For example, the string ‘attack’ would match IP Access rules with notes ‘Attack 26/02’ and ‘Attack 27/02’. The search is case insensitive.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20notes%20%3E%20(schema)>)

<details>

<summary>

order: Optional\[Literal\["configuration.target", "configuration.value", "mode"]]

Defines the field used to sort returned rules.

</summary>

One of the following:

"configuration.target"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"configuration.value"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"mode"

<a href="#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order%20%3E%20(schema)>)

page: Optional\[float]

Defines the requested page within paginated list of results.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page%20%3E%20(schema)>)

per\_page: Optional\[float]

Defines the maximum number of results requested.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class AccessRuleListResponse: …

</summary>

id: str

The unique identifier of the IP Access rule.

maxLength32

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

allowed\_modes: List\[Literal\["block", "challenge", "whitelist", 2 more]]

The available actions that a rule can apply to a matched request.

</summary>

One of the following:

"block"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"whitelist"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"js\_challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"managed\_challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_modes%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20allowed_modes">Link to this property</a>

<details>

<summary>

configuration: Configuration

The rule configuration.

</summary>

One of the following:

<details>

<summary>

class AccessRuleIPConfiguration: …

</summary>

target: Optional\[Literal\["ip"]]

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_ip_configuration%20%3E%20(schema)%20%3E%20(property)%20target">Link to this property</a>

value: Optional\[str]

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_ip_configuration%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_ip_configuration%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class IPV6Configuration: …

</summary>

target: Optional\[Literal\["ip6"]]

The configuration target. You must set the target to <code>ip6</code> when specifying an IPv6 address in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20ipv6_configuration%20%3E%20(schema)%20%3E%20(property)%20target">Link to this property</a>

value: Optional\[str]

The IPv6 address to match.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20ipv6_configuration%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20ipv6_configuration%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessRuleCIDRConfiguration: …

</summary>

target: Optional\[Literal\["ip\_range"]]

The configuration target. You must set the target to <code>ip_range</code> when specifying an IP address range in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_cidr_configuration%20%3E%20(schema)%20%3E%20(property)%20target">Link to this property</a>

value: Optional\[str]

The IP address range to match. You can only use prefix lengths <code>/16</code> and <code>/24</code> for IPv4 ranges, and prefix lengths <code>/32</code>, <code>/48</code>, and <code>/64</code> for IPv6 ranges.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_cidr_configuration%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_cidr_configuration%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ASNConfiguration: …

</summary>

target: Optional\[Literal\["asn"]]

The configuration target. You must set the target to <code>asn</code> when specifying an Autonomous System Number (ASN) in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20asn_configuration%20%3E%20(schema)%20%3E%20(property)%20target">Link to this property</a>

value: Optional\[str]

The AS number to match.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20asn_configuration%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20asn_configuration%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CountryConfiguration: …

</summary>

target: Optional\[Literal\["country"]]

The configuration target. You must set the target to <code>country</code> when specifying a country code in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20country_configuration%20%3E%20(schema)%20%3E%20(property)%20target">Link to this property</a>

value: Optional\[str]

The two-letter ISO-3166-1 alpha-2 code to match. For more information, refer to <a href="https://developers.cloudflare.com/waf/tools/ip-access-rules/parameters/#country">IP Access rules: Parameters</a>.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20country_configuration%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20country_configuration%20%3E%20(schema)">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20configuration">Link to this property</a>

<details>

<summary>

mode: Literal\["block", "challenge", "whitelist", 2 more]

The action to apply to a matched request.

</summary>

One of the following:

"block"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

"challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

"whitelist"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%202">Link to this property</a>

"js\_challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%203">Link to this property</a>

"managed\_challenge"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20mode">Link to this property</a>

created\_on: Optional\[datetime]

The timestamp of when the rule was created.

formatdate-time

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20created_on">Link to this property</a>

modified\_on: Optional\[datetime]

The timestamp of when the rule was last modified.

formatdate-time

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

notes: Optional\[str]

An informative summary of the rule, typically used as a reminder or explanation.

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20notes">Link to this property</a>

<details>

<summary>

scope: Optional\[Scope]

All zones owned by the user will have the rule applied.

</summary>

id: Optional\[str]

Defines an identifier.

maxLength32

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20scope%20%3E%20(property)%20id">Link to this property</a>

email: Optional\[str]

The contact email address of the user.

maxLength90

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20scope%20%3E%20(property)%20email">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["user", "organization"]]

Defines the scope of the rule.

</summary>

One of the following:

"user"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20scope%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"organization"

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20scope%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20scope%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)%20%3E%20(property)%20scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(model)%20access_rule_list_response%20%3E%20(schema)>)

### List IP Access rules

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
page = client.firewall.access_rules.list(
    account_id="account_id",
)
page = page.result[0]
print(page.id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "92f17202ed8bd63d69a66b86a49a8f6b",
      "allowed_modes": [
        "whitelist",
        "block",
        "challenge",
        "js_challenge",
        "managed_challenge"
      ],
      "configuration": {
        "target": "ip",
        "value": "198.51.100.4"
      },
      "mode": "challenge",
      "created_on": "2014-01-01T05:20:00.12345Z",
      "modified_on": "2014-01-01T05:20:00.12345Z",
      "notes": "This rule is enabled because of an event that occurred on date X.",
      "scope": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "email": "user@example.com",
        "type": "user"
      }
    }
  ],
  "success": true,
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "92f17202ed8bd63d69a66b86a49a8f6b",
      "allowed_modes": [
        "whitelist",
        "block",
        "challenge",
        "js_challenge",
        "managed_challenge"
      ],
      "configuration": {
        "target": "ip",
        "value": "198.51.100.4"
      },
      "mode": "challenge",
      "created_on": "2014-01-01T05:20:00.12345Z",
      "modified_on": "2014-01-01T05:20:00.12345Z",
      "notes": "This rule is enabled because of an event that occurred on date X.",
      "scope": {
        "id": "023e105f4ecef8ad9ca31a8372d0c353",
        "email": "user@example.com",
        "type": "user"
      }
    }
  ],
  "success": true,
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```