---
title: Get indicator feed metadata
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Intel](https://developers.cloudflare.com/api/python/resources/intel)

[Indicator Feeds](https://developers.cloudflare.com/api/python/resources/intel/subresources/indicator_feeds)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Get indicator feed metadata

intel.indicator\_feeds.get(intfeed\_id, IndicatorFeedGetParams\*\*kwargs) -> [IndicatorFeedGetResponse](<https://developers.cloudflare.com/api/python/resources/intel#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/intel/indicator-feeds/{feed\_id}

Retrieves details for a specific custom threat indicator feed.

##### Security

API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**`X-Auth-Email: user@example.com`

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**`X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194`

##### Accepted Permissions (at least one required)

`Intel Write``Intel Read`

##### ParametersExpand Collapse

account\_id: str

Identifier

maxLength32

[Link to this property](<#(resource)%20intel.indicator_feeds%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

feed\_id: int

Indicator feed ID

[Link to this property](<#(resource)%20intel.indicator_feeds%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20feed_id%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class IndicatorFeedGetResponse: …

</summary>

id: Optional\[int]

The unique identifier for the indicator feed

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_on: Optional\[datetime]

The date and time when the data entry was created

formatdate-time

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20created_on">Link to this property</a>

description: Optional\[str]

The description of the example test

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

is\_attributable: Optional\[bool]

Whether the indicator feed can be attributed to a provider

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20is_attributable">Link to this property</a>

is\_downloadable: Optional\[bool]

Whether the indicator feed can be downloaded

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20is_downloadable">Link to this property</a>

is\_public: Optional\[bool]

Whether the indicator feed is exposed to customers

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20is_public">Link to this property</a>

<details>

<summary>

last\_upload\_summary: Optional\[LastUploadSummary]

Summary of indicator counts from the last successful upload to this feed. Populated by the custom-threat-feeds loader at the end of each successful load. Absent (omitted) when no upload has completed successfully or the upload errored before the summary write. Surfaces silent-failure paths so operators can see when their indicators were dropped (popularity allowlist, expired valid\_until, etc.) without reading loader logs.

</summary>

<details>

<summary>

persisted: Optional\[LastUploadSummaryPersisted]

Net delta applied to feed indicators by this upload. Snapshot uploads emit both \*\_added and \*\_removed; delta-add emits only \*\_added; delta-remove emits only \*\_removed.

</summary>

domains\_added: Optional\[int]

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted%20%3E%20(property)%20domains_added">Link to this property</a>

domains\_removed: Optional\[int]

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted%20%3E%20(property)%20domains_removed">Link to this property</a>

ips\_added: Optional\[int]

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted%20%3E%20(property)%20ips_added">Link to this property</a>

ips\_removed: Optional\[int]

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted%20%3E%20(property)%20ips_removed">Link to this property</a>

urls\_added: Optional\[int]

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted%20%3E%20(property)%20urls_added">Link to this property</a>

urls\_removed: Optional\[int]

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted%20%3E%20(property)%20urls_removed">Link to this property</a>

</details>

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20persisted">Link to this property</a>

<details>

<summary>

skipped: Optional\[LastUploadSummarySkipped]

Counts of indicators that were uploaded but did not reach QuickSilver, broken down by reason.

</summary>

allowlisted\_domains: Optional\[int]

Domains filtered by the global popularity allowlist at QS provisioning time. Popular domains (bing.com, naver.com, etc.) are protected from custom-threat-feed enforcement.

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20skipped%20%3E%20(property)%20allowlisted_domains">Link to this property</a>

expired\_indicators: Optional\[int]

Indicators in the upload whose valid\_until is already in the past. These are not added to QS; the expiration cron handles cleanup.

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20skipped%20%3E%20(property)%20expired_indicators">Link to this property</a>

invalid\_indicators: Optional\[int]

Reserved for future use. Currently always 0 — the unifier aborts the entire upload on a single bad indicator.

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20skipped%20%3E%20(property)%20invalid_indicators">Link to this property</a>

</details>

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20skipped">Link to this property</a>

<details>

<summary>

uploaded: Optional\[LastUploadSummaryUploaded]

Indicator counts from the unified file the loader received

</summary>

domains: Optional\[int]

Number of domain indicators in the upload

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20uploaded%20%3E%20(property)%20domains">Link to this property</a>

ips: Optional\[int]

Number of IP indicators in the upload

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20uploaded%20%3E%20(property)%20ips">Link to this property</a>

urls: Optional\[int]

Number of URL indicators in the upload

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20uploaded%20%3E%20(property)%20urls">Link to this property</a>

</details>

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary%20%3E%20(property)%20uploaded">Link to this property</a>

</details>

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20last_upload_summary">Link to this property</a>

latest\_upload\_error: Optional\[str]

Human-readable error message describing why the latest upload failed. Populated only when <code>latest_upload_status</code> is <code>Error</code>. Returns one of a small fixed set of category-level messages (invalid domain / IP / URL entries, malformed row or header, invalid valid\_until timestamp, etc.) or the generic <code>Upload failed</code> for unknown or infrastructure-level errors. Never echoes raw error text from the underlying loader. Intel accounts receive the verbatim loader/API error text (including specific offending values) instead of these category-level messages.

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_error">Link to this property</a>

<details>

<summary>

latest\_upload\_status: Optional\[Literal\["Mirroring", "Unifying", "Loading", 3 more]]

Status of the latest snapshot uploaded

</summary>

One of the following:

"Mirroring"

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status%20%3E%20(member)%200">Link to this property</a>

"Unifying"

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status%20%3E%20(member)%201">Link to this property</a>

"Loading"

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status%20%3E%20(member)%202">Link to this property</a>

"Provisioning"

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status%20%3E%20(member)%203">Link to this property</a>

"Complete"

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status%20%3E%20(member)%204">Link to this property</a>

"Error"

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20latest_upload_status">Link to this property</a>

modified\_on: Optional\[datetime]

The date and time when the data entry was last modified

formatdate-time

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

name: Optional\[str]

The name of the indicator feed

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

provider\_id: Optional\[int]

The unique identifier for the provider

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20provider_id">Link to this property</a>

provider\_name: Optional\[str]

The provider of the indicator feed

<a href="#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)%20%3E%20(property)%20provider_name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_get_response%20%3E%20(schema)>)

### Get indicator feed metadata

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_email=os.environ.get("CLOUDFLARE_EMAIL"),  # This is the default and can be omitted
    api_key=os.environ.get("CLOUDFLARE_API_KEY"),  # This is the default and can be omitted
)
indicator_feed = client.intel.indicator_feeds.get(
    feed_id=12,
    account_id="023e105f4ecef8ad9ca31a8372d0c353",
)
print(indicator_feed.id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": 1,
    "created_on": "2023-05-12T12:21:56.777653Z",
    "description": "example feed description",
    "is_attributable": false,
    "is_downloadable": false,
    "is_public": false,
    "last_upload_summary": {
      "persisted": {
        "domains_added": 2,
        "domains_removed": 1,
        "ips_added": 0,
        "ips_removed": 0,
        "urls_added": 0,
        "urls_removed": 0
      },
      "skipped": {
        "allowlisted_domains": 1,
        "expired_indicators": 0,
        "invalid_indicators": 0
      },
      "uploaded": {
        "domains": 3,
        "ips": 0,
        "urls": 0
      }
    },
    "latest_upload_error": "Feed contains one or more invalid domain entries. Check your feed for wildcards or other values that are not valid DNS names.",
    "latest_upload_status": "Complete",
    "modified_on": "2023-06-18T03:13:34.123321Z",
    "name": "example_feed_1",
    "provider_id": 1,
    "provider_name": "provider_name"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": 1,
    "created_on": "2023-05-12T12:21:56.777653Z",
    "description": "example feed description",
    "is_attributable": false,
    "is_downloadable": false,
    "is_public": false,
    "last_upload_summary": {
      "persisted": {
        "domains_added": 2,
        "domains_removed": 1,
        "ips_added": 0,
        "ips_removed": 0,
        "urls_added": 0,
        "urls_removed": 0
      },
      "skipped": {
        "allowlisted_domains": 1,
        "expired_indicators": 0,
        "invalid_indicators": 0
      },
      "uploaded": {
        "domains": 3,
        "ips": 0,
        "urls": 0
      }
    },
    "latest_upload_error": "Feed contains one or more invalid domain entries. Check your feed for wildcards or other values that are not valid DNS names.",
    "latest_upload_status": "Complete",
    "modified_on": "2023-06-18T03:13:34.123321Z",
    "name": "example_feed_1",
    "provider_id": 1,
    "provider_name": "provider_name"
  }
}
```