---
title: Access
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Zero Trust](https://developers.cloudflare.com/api/python/resources/zero_trust)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Access

#### AccessAI Controls

#### AccessAI ControlsMcp

#### AccessAI ControlsMcpPortals

##### [List MCP Portals](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/list)

zero\_trust.access.ai\_controls.mcp.portals.list(PortalListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[PortalListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Create a new MCP Portal](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/create)

zero\_trust.access.ai\_controls.mcp.portals.create(PortalCreateParams\*\*kwargs) -> [PortalCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Read details of an MCP Portal](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/read)

zero\_trust.access.ai\_controls.mcp.portals.read(strid, PortalReadParams\*\*kwargs) -> [PortalReadResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Update an MCP Portal](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/update)

zero\_trust.access.ai\_controls.mcp.portals.update(strid, PortalUpdateParams\*\*kwargs) -> [PortalUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Delete an MCP Portal](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/delete)

zero\_trust.access.ai\_controls.mcp.portals.delete(strid, PortalDeleteParams\*\*kwargs) -> [PortalDeleteResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### ModelsExpand Collapse

<details>

<summary>

class PortalListResponse: …

</summary>

id: str

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: str

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: List\[Server]

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[ServerAuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[ServerAuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[ServerAuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled: Optional\[bool]

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ServerErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[ServerUpdatedPrompt]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[ServerUpdatedTool]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode: Optional\[bool]

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode: Optional\[Literal\["off", "opt\_in", "default\_on", "enforced"]]

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)>)

<details>

<summary>

class PortalCreateResponse: …

</summary>

id: str

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: str

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: List\[Server]

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[ServerAuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[ServerAuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[ServerAuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled: Optional\[bool]

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ServerErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[ServerUpdatedPrompt]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[ServerUpdatedTool]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode: Optional\[bool]

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode: Optional\[Literal\["off", "opt\_in", "default\_on", "enforced"]]

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)>)

<details>

<summary>

class PortalReadResponse: …

</summary>

id: str

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: str

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: List\[Server]

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[ServerAuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[ServerAuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[ServerAuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled: Optional\[bool]

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ServerErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[ServerUpdatedPrompt]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[ServerUpdatedTool]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode: Optional\[bool]

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode: Optional\[Literal\["off", "opt\_in", "default\_on", "enforced"]]

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)>)

<details>

<summary>

class PortalUpdateResponse: …

</summary>

id: str

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: str

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: List\[Server]

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[ServerAuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[ServerAuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[ServerAuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled: Optional\[bool]

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ServerErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[ServerUpdatedPrompt]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[ServerUpdatedTool]]

</summary>

name: str

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode: Optional\[bool]

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode: Optional\[Literal\["off", "opt\_in", "default\_on", "enforced"]]

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)>)

<details>

<summary>

class PortalDeleteResponse: …

</summary>

id: str

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: str

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Deprecatedallow\_code\_mode: Optional\[bool]

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode: Optional\[Literal\["off", "opt\_in", "default\_on", "enforced"]]

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)>)

#### AccessAI ControlsMcpServers

##### [List MCP Servers](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/list)

zero\_trust.access.ai\_controls.mcp.servers.list(ServerListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[ServerListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Create a new MCP Server](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/create)

zero\_trust.access.ai\_controls.mcp.servers.create(ServerCreateParams\*\*kwargs) -> [ServerCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Read the details of an MCP Server](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/read)

zero\_trust.access.ai\_controls.mcp.servers.read(strid, ServerReadParams\*\*kwargs) -> [ServerReadResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Update an MCP Server](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/update)

zero\_trust.access.ai\_controls.mcp.servers.update(strid, ServerUpdateParams\*\*kwargs) -> [ServerUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Delete an MCP Server](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/delete)

zero\_trust.access.ai\_controls.mcp.servers.delete(strid, ServerDeleteParams\*\*kwargs) -> [ServerDeleteResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Sync MCP Server Capabilities](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/sync)

zero\_trust.access.ai\_controls.mcp.servers.sync(strid, ServerSyncParams\*\*kwargs) -> [ServerSyncResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}/sync

##### ModelsExpand Collapse

<details>

<summary>

class ServerListResponse: …

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[AuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[AuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[AuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[UpdatedPrompt]]

Server-wide prompt capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[UpdatedTool]]

Server-wide tool capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)>)

<details>

<summary>

class ServerCreateResponse: …

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[AuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[AuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[AuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[UpdatedPrompt]]

Server-wide prompt capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[UpdatedTool]]

Server-wide tool capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)>)

<details>

<summary>

class ServerReadResponse: …

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[AuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[AuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[AuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[UpdatedPrompt]]

Server-wide prompt capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[UpdatedTool]]

Server-wide tool capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)>)

<details>

<summary>

class ServerUpdateResponse: …

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[AuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[AuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[AuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[UpdatedPrompt]]

Server-wide prompt capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[UpdatedTool]]

Server-wide tool capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)>)

<details>

<summary>

class ServerDeleteResponse: …

</summary>

id: str

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: Literal\["oauth", "bearer", "unauthenticated"]

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: str

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: str

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: List\[Dict\[str, object]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Optional\[AuthConfigSummary]

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode: Optional\[Literal\["dcr", "manual"]]

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version: Optional\[float]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Optional\[AuthConfigSummaryConfig]

</summary>

authorization\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret: Optional\[bool]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Optional\[AuthConfigSummaryRegistrationInfo]

</summary>

client\_id: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status: Optional\[Literal\["not\_required", "required", "connected", 2 more]]

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description: Optional\[str]

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Optional\[bool]

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway: Optional\[bool]

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: Optional\[List\[UpdatedPrompt]]

Server-wide prompt capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: Optional\[List\[UpdatedTool]]

Server-wide tool capability overrides.

</summary>

name: str

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias: Optional\[str]

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description: Optional\[str]

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled: Optional\[bool]

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)>)

<details>

<summary>

class ServerSyncResponse: …

</summary>

error: Optional\[str]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details: Optional\[ErrorDetails]

</summary>

cause: Optional\[str]

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream: Optional\[bool]

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code: Optional\[float]

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable: Optional\[bool]

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code: Optional\[float]

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["waiting", "ready", "stale", "error"]]

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)>)

#### AccessGateway CA

##### [List SSH Certificate Authorities (CA)](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/list)

zero\_trust.access.gateway\_ca.list(GatewayCAListParams\*\*kwargs) -> SyncSinglePage\[[GatewayCAListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/access/gateway\_ca

##### [Add a new SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/create)

zero\_trust.access.gateway\_ca.create(GatewayCACreateParams\*\*kwargs) -> [GatewayCACreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/access/gateway\_ca

##### [Delete an SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/delete)

zero\_trust.access.gateway\_ca.delete(strcertificate\_id, GatewayCADeleteParams\*\*kwargs) -> [GatewayCADeleteResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/access/gateway\_ca/{certificate\_id}

##### ModelsExpand Collapse

<details>

<summary>

class GatewayCAListResponse: …

</summary>

id: Optional\[str]

The key ID of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

public\_key: Optional\[str]

The public key of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)>)

<details>

<summary>

class GatewayCACreateResponse: …

</summary>

id: Optional\[str]

The key ID of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

public\_key: Optional\[str]

The public key of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)>)

<details>

<summary>

class GatewayCADeleteResponse: …

</summary>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_delete_response%20%3E%20(schema)>)

#### AccessIdP Federation Grants

##### [List IdP federation grants](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/list)

zero\_trust.access.idp\_federation\_grants.list(IdPFederationGrantListParams\*\*kwargs) -> [IdPFederationGrantListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/access/idp\_federation\_grants

##### [Create an IdP federation grant](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/create)

zero\_trust.access.idp\_federation\_grants.create(IdPFederationGrantCreateParams\*\*kwargs) -> [IdPFederationGrant](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>)

POST/accounts/{account\_id}/access/idp\_federation\_grants

##### [Get an IdP federation grant](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/get)

zero\_trust.access.idp\_federation\_grants.get(strgrant\_id, IdPFederationGrantGetParams\*\*kwargs) -> [IdPFederationGrant](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>)

GET/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### [Delete an IdP federation grant](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/delete)

zero\_trust.access.idp\_federation\_grants.delete(strgrant\_id, IdPFederationGrantDeleteParams\*\*kwargs) -> [IdPFederationGrantDeleteResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### ModelsExpand Collapse

<details>

<summary>

class IdPFederationGrant: …

</summary>

id: str

UID of the IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

idp\_id: str

UID of the identity provider being federated.

formatuuid

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20idp_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>)

<details>

<summary>

List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)">IdPFederationGrant</a>]

</summary>

id: str

UID of the IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

idp\_id: str

UID of the identity provider being federated.

formatuuid

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20idp_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_list_response%20%3E%20(schema)>)

<details>

<summary>

class IdPFederationGrantDeleteResponse: …

</summary>

id: Optional\[str]

UID of the deleted IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_delete_response%20%3E%20(schema)>)

#### AccessSAML Certificates

##### [List SAML certificate sets](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/list)

zero\_trust.access.saml\_certificates.list(SAMLCertificateListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[SAMLCertificateListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/access/saml\_certificates

##### [Get SAML certificate set](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get)

zero\_trust.access.saml\_certificates.get(strsaml\_cert\_set\_id, SAMLCertificateGetParams\*\*kwargs) -> [SAMLCertificateGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}

##### [Rotate SAML certificate](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/rotate)

zero\_trust.access.saml\_certificates.rotate(strsaml\_cert\_set\_id, SAMLCertificateRotateParams\*\*kwargs) -> [SAMLCertificateRotateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/rotate

##### [Download current certificate in PEM format](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get_pem)

zero\_trust.access.saml\_certificates.get\_pem(strsaml\_cert\_set\_id, SAMLCertificateGetPemParams\*\*kwargs) -> BinaryResponseContent

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/pem

##### ModelsExpand Collapse

<details>

<summary>

class SAMLCertificateListResponse: …

</summary>

created\_at: datetime

When the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

When the certificate set was last updated

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[CurrentCertificate]

The current active certificate

</summary>

is\_current: bool

Indicates whether the certificate can be used for IdP configuration.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

The public certificate in PEM format

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate (maintained during rotation period). May be null when no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)>)

<details>

<summary>

class SAMLCertificateGetResponse: …

</summary>

created\_at: datetime

When the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

When the certificate set was last updated

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[CurrentCertificate]

The current active certificate

</summary>

is\_current: bool

Indicates whether the certificate can be used for IdP configuration.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

The public certificate in PEM format

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate (maintained during rotation period). May be null when no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)>)

<details>

<summary>

class SAMLCertificateRotateResponse: …

</summary>

created\_at: datetime

When the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

When the certificate set was last updated

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[CurrentCertificate]

The current active certificate

</summary>

is\_current: bool

Indicates whether the certificate can be used for IdP configuration.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

The public certificate in PEM format

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate (maintained during rotation period). May be null when no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)>)

#### AccessInfrastructure

#### AccessInfrastructureTargets

##### [List all targets](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/list)

zero\_trust.access.infrastructure.targets.list(TargetListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[TargetListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/infrastructure/targets

##### [Get target](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/get)

zero\_trust.access.infrastructure.targets.get(strtarget\_id, TargetGetParams\*\*kwargs) -> [TargetGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new target](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/create)

zero\_trust.access.infrastructure.targets.create(TargetCreateParams\*\*kwargs) -> [TargetCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/infrastructure/targets

##### [Update target](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/update)

zero\_trust.access.infrastructure.targets.update(strtarget\_id, TargetUpdateParams\*\*kwargs) -> [TargetUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Delete target](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/delete)

zero\_trust.access.infrastructure.targets.delete(strtarget\_id, TargetDeleteParams\*\*kwargs)

DELETE/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new targets](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_update)

zero\_trust.access.infrastructure.targets.bulk\_update(TargetBulkUpdateParams\*\*kwargs) -> SyncSinglePage\[[TargetBulkUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)>)]

PUT/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets (Deprecated)](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete)

Deprecated

zero\_trust.access.infrastructure.targets.bulk\_delete(TargetBulkDeleteParams\*\*kwargs)

DELETE/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete_v2)

zero\_trust.access.infrastructure.targets.bulk\_delete\_v2(TargetBulkDeleteV2Params\*\*kwargs)

POST/accounts/{account\_id}/infrastructure/targets/batch\_delete

##### ModelsExpand Collapse

<details>

<summary>

class TargetListResponse: …

</summary>

id: str

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: datetime

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: str

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Optional\[IPIPV4]

The target’s IPv4 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Optional\[IPIPV6]

The target’s IPv6 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: datetime

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags: Optional\[Dict\[str, str]]

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)>)

<details>

<summary>

class TargetGetResponse: …

</summary>

id: str

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: datetime

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: str

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Optional\[IPIPV4]

The target’s IPv4 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Optional\[IPIPV6]

The target’s IPv6 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: datetime

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags: Optional\[Dict\[str, str]]

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)>)

<details>

<summary>

class TargetCreateResponse: …

</summary>

id: str

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: datetime

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: str

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Optional\[IPIPV4]

The target’s IPv4 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Optional\[IPIPV6]

The target’s IPv6 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: datetime

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags: Optional\[Dict\[str, str]]

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)>)

<details>

<summary>

class TargetUpdateResponse: …

</summary>

id: str

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: datetime

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: str

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Optional\[IPIPV4]

The target’s IPv4 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Optional\[IPIPV6]

The target’s IPv6 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: datetime

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags: Optional\[Dict\[str, str]]

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)>)

<details>

<summary>

class TargetBulkUpdateResponse: …

</summary>

id: str

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: datetime

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: str

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Optional\[IPIPV4]

The target’s IPv4 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Optional\[IPIPV6]

The target’s IPv6 address

</summary>

ip\_addr: Optional\[str]

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id: Optional\[str]

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: datetime

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags: Optional\[Dict\[str, str]]

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)>)

#### AccessApplications

##### [List Access applications](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/applications/methods/list)

zero\_trust.access.applications.list(ApplicationListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[ApplicationListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)>)]

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Get an Access application](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/applications/methods/get)

zero\_trust.access.applications.get([AppID](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)app\_id, ApplicationGetParams\*\*kwargs) -> [ApplicationGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_get_response%20%3E%20(schema)>)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Add an Access application](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/applications/methods/create)

zero\_trust.access.applications.create(ApplicationCreateParams\*\*kwargs) -> [ApplicationCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_create_response%20%3E%20(schema)>)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Update an Access application](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/applications/methods/update)

zero\_trust.access.applications.update([AppID](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)app\_id, ApplicationUpdateParams\*\*kwargs) -> [ApplicationUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_update_response%20%3E%20(schema)>)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Delete an Access application](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/applications/methods/delete)

zero\_trust.access.applications.delete([AppID](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)app\_id, ApplicationDeleteParams\*\*kwargs) -> [ApplicationDeleteResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_delete_response%20%3E%20(schema)>)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Revoke application tokens](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/access/subresources/applications/methods/revoke_tokens)

zero\_trust.access.applications.revoke\_tokens([AppID](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)app\_id, ApplicationRevokeTokensParams\*\*kwargs) -> object

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/revoke\_tokens

##### ModelsExpand Collapse

str

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)>)

str

The identity providers selected for application.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)>)

<details>

<summary>

Literal\["GET", "POST", "HEAD", 6 more]

</summary>

One of the following:

"GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)>)

str

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)>)

str

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)

<details>

<summary>

<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)">Application</a>

</summary>

One of the following:

<details>

<summary>

class SelfHostedApplication: …

</summary>

domain: str

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20domain">Link to this property</a>

type: str

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

allow\_iframe: Optional\[bool]

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible: Optional\[bool]

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers: Optional\[CORSHeaders]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20cors_headers">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

custom\_deny\_message: Optional\[str]

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url: Optional\[str]

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_url">Link to this property</a>

eager\_redirect\_cookie\_setting: Optional\[bool]

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie: Optional\[bool]

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute: Optional\[bool]

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url: Optional\[str]

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20logo_url">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

options\_preflight\_bypass: Optional\[bool]

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

same\_site\_cookie\_attribute: Optional\[str]

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[SelfHostedApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[SelfHostedApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[SelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config">Link to this property</a>

service\_auth\_401\_redirect: Optional\[bool]

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20session_duration">Link to this property</a>

skip\_interstitial: Optional\[bool]

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20skip_interstitial">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

use\_clientless\_isolation\_app\_launcher\_url: Optional\[bool]

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class SaaSApplication: …

</summary>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible: Optional\[bool]

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

logo\_url: Optional\[str]

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20logo_url">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

saas\_app: Optional\[SaaSApplicationSaaSApp]

</summary>

One of the following:

<details>

<summary>

class SaaSApplicationSaaSAppAccessSAMLSaaSApp2: …

</summary>

<details>

<summary>

auth\_type: Optional\[Literal\["saml", "oidc"]]

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type">Link to this property</a>

consumer\_service\_url: Optional\[str]

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20consumer_service_url">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

custom\_attributes: Optional\[List\[SaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttribute]]

</summary>

friendly\_name: Optional\[str]

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

name: Optional\[str]

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_format: Optional\[Literal\["urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified", "urn:oasis:names:tc:SAML:2.0:attrname-format:basic", "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"]]

A globally unique name for an identity or service provider.

</summary>

One of the following:

"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

required: Optional\[bool]

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

source: Optional\[SaaSApplicationSaaSAppAccessSAMLSaaSApp2CustomAttributeSource]

</summary>

name: Optional\[str]

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

name\_by\_idp: Optional\[Dict\[str, str]]

A mapping from IdP ID to attribute name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes">Link to this property</a>

idp\_entity\_id: Optional\[str]

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20idp_entity_id">Link to this property</a>

name\_id\_format: Optional\[SaaSAppNameIDFormat]

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_format">Link to this property</a>

name\_id\_transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

public\_key: Optional\[str]

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20public_key">Link to this property</a>

sp\_entity\_id: Optional\[str]

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sp_entity_id">Link to this property</a>

sso\_endpoint: Optional\[str]

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sso_endpoint">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class SaaSApplicationSaaSAppAccessOIDCSaaSApp2: …

</summary>

access\_token\_lifetime: Optional\[str]

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

allow\_pkce\_without\_client\_secret: Optional\[bool]

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

app\_launcher\_url: Optional\[str]

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

auth\_type: Optional\[Literal\["saml", "oidc"]]

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type">Link to this property</a>

client\_id: Optional\[str]

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_secret">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

custom\_claims: Optional\[List\[SaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaim]]

</summary>

name: Optional\[str]

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

required: Optional\[bool]

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

scope: Optional\[Literal\["groups", "profile", "email", "openid"]]

The scope of the claim.

</summary>

One of the following:

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

source: Optional\[SaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimSource]

</summary>

name: Optional\[str]

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_by\_idp: Optional\[List\[SaaSApplicationSaaSAppAccessOIDCSaaSApp2CustomClaimSourceNameByIdP]]

A mapping from IdP ID to attribute name.

</summary>

idp\_id: Optional\[str]

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

source\_name: Optional\[str]

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

grant\_types: Optional\[List\[Literal\["authorization\_code", "authorization\_code\_with\_pkce", "refresh\_tokens", 2 more]]]

The OIDC flows supported by this application

</summary>

One of the following:

"authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types">Link to this property</a>

group\_filter\_regex: Optional\[str]

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

hybrid\_and\_implicit\_options: Optional\[SaaSApplicationSaaSAppAccessOIDCSaaSApp2HybridAndImplicitOptions]

</summary>

return\_access\_token\_from\_authorization\_endpoint: Optional\[bool]

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

return\_id\_token\_from\_authorization\_endpoint: Optional\[bool]

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

public\_key: Optional\[str]

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20public_key">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

refresh\_token\_options: Optional\[SaaSApplicationSaaSAppAccessOIDCSaaSApp2RefreshTokenOptions]

</summary>

lifetime: Optional\[str]

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

scopes: Optional\[List\[Literal\["openid", "groups", "email", "profile"]]]

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[SaaSApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[SaaSApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[SaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SaaSApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

type: Optional\[str]

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class BrowserSSHApplication: …

</summary>

domain: str

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20domain">Link to this property</a>

type: str

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

allow\_iframe: Optional\[bool]

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible: Optional\[bool]

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers: Optional\[CORSHeaders]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20cors_headers">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20created_at">Link to this property</a>

custom\_deny\_message: Optional\[str]

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url: Optional\[str]

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_url">Link to this property</a>

eager\_redirect\_cookie\_setting: Optional\[bool]

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie: Optional\[bool]

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute: Optional\[bool]

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url: Optional\[str]

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20logo_url">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

options\_preflight\_bypass: Optional\[bool]

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

same\_site\_cookie\_attribute: Optional\[str]

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[BrowserSSHApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[BrowserSSHApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[BrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserSSHApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

service\_auth\_401\_redirect: Optional\[bool]

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20session_duration">Link to this property</a>

skip\_interstitial: Optional\[bool]

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20skip_interstitial">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20updated_at">Link to this property</a>

use\_clientless\_isolation\_app\_launcher\_url: Optional\[bool]

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class BrowserVNCApplication: …

</summary>

domain: str

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20domain">Link to this property</a>

type: str

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

allow\_iframe: Optional\[bool]

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible: Optional\[bool]

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers: Optional\[CORSHeaders]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20cors_headers">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20created_at">Link to this property</a>

custom\_deny\_message: Optional\[str]

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url: Optional\[str]

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_url">Link to this property</a>

eager\_redirect\_cookie\_setting: Optional\[bool]

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie: Optional\[bool]

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute: Optional\[bool]

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url: Optional\[str]

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20logo_url">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

options\_preflight\_bypass: Optional\[bool]

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

same\_site\_cookie\_attribute: Optional\[str]

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[BrowserVNCApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[BrowserVNCApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[BrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserVNCApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

service\_auth\_401\_redirect: Optional\[bool]

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20session_duration">Link to this property</a>

skip\_interstitial: Optional\[bool]

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20skip_interstitial">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20updated_at">Link to this property</a>

use\_clientless\_isolation\_app\_launcher\_url: Optional\[bool]

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

class AppLauncherApplication: …

</summary>

<details>

<summary>

type: Literal\["self\_hosted", "saas", "ssh", 6 more]

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20created_at">Link to this property</a>

domain: Optional\[str]

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20domain">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[AppLauncherApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[AppLauncherApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[AppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AppLauncherApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

class DeviceEnrollmentPermissionsApplication: …

</summary>

<details>

<summary>

type: Literal\["self\_hosted", "saas", "ssh", 6 more]

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20created_at">Link to this property</a>

domain: Optional\[str]

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20domain">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[DeviceEnrollmentPermissionsApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[DeviceEnrollmentPermissionsApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[DeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DeviceEnrollmentPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

class BrowserIsolationPermissionsApplication: …

</summary>

<details>

<summary>

type: Literal\["self\_hosted", "saas", "ssh", 6 more]

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20created_at">Link to this property</a>

domain: Optional\[str]

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20domain">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[BrowserIsolationPermissionsApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[BrowserIsolationPermissionsApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[BrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BrowserIsolationPermissionsApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class BookmarkApplication: …

</summary>

domain: str

The URL or domain of the bookmark.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20domain">Link to this property</a>

type: str

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

app\_launcher\_visible: Optional\[bool]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20aud">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20created_at">Link to this property</a>

logo\_url: Optional\[str]

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20logo_url">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[BookmarkApplicationSCIMConfig]

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: str

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: str

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication: Optional\[BookmarkApplicationSCIMConfigAuthentication]

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

List\[BookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2]

Multiple authentication schemes

</summary>

One of the following:

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationOAuthBearerToken2: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class BookmarkApplicationSCIMConfigAuthenticationAccessSCIMConfigMultiAuthentication2AccessSCIMConfigAuthenticationAccessServiceToken: …

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: str

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["access\_service\_token"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete: Optional\[bool]

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled: Optional\[bool]

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a>]]

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)>)

<details>

<summary>

class ApplicationPolicy: …

</summary>

id: Optional\[str]

The UUID of the policy

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

approval\_groups: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a>]]

Administrators who can approve a temporary authentication request.

</summary>

approvals\_needed: float

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

email\_addresses: Optional\[List\[str]]

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

email\_list\_uuid: Optional\[str]

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_groups">Link to this property</a>

approval\_required: Optional\[bool]

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_required">Link to this property</a>

<details>

<summary>

connection\_rules: Optional\[ConnectionRules]

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

rdp: Optional\[ConnectionRulesRDP]

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

<details>

<summary>

allowed\_clipboard\_local\_to\_remote\_formats: Optional\[List\[Literal\["text", "file"]]]

Clipboard formats allowed when copying from local machine to remote RDP session.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

<details>

<summary>

allowed\_clipboard\_remote\_to\_local\_formats: Optional\[List\[Literal\["text", "file"]]]

Clipboard formats allowed when copying from remote RDP session to local machine.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

decision: Optional\[Decision]

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

exclude: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>]]

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

class GroupRule: …

Matches an Access group.

</summary>

<details>

<summary>

group: Group

</summary>

id: str

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AnyValidServiceTokenRule: …

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessAuthContextRule: …

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AccessAuthContextRuleAuthContext

</summary>

id: str

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: str

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AuthenticationMethodRule: …

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod

</summary>

auth\_method: str

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AzureGroupRule: …

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azure\_ad: AzureAD

</summary>

id: str

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CertificateRule: …

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCommonNameRule: …

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: AccessCommonNameRuleCommonName

</summary>

common\_name: str

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class CountryRule: …

Matches a specific country

</summary>

<details>

<summary>

geo: Geo

</summary>

country\_code: str

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessDevicePostureRule: …

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture

</summary>

integration\_uid: str

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id: Optional\[str]

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DomainRule: …

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain

</summary>

domain: str

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailListRule: …

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList

</summary>

id: str

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailRule: …

Matches a specific email.

</summary>

<details>

<summary>

email: Email

</summary>

email: str

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EveryoneRule: …

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ExternalEvaluationRule: …

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation

</summary>

evaluate\_url: str

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: str

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GitHubOrganizationRule: …

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

github\_organization: GitHubOrganization

</summary>

identity\_provider\_id: str

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team: Optional\[str]

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GSuiteGroupRule: …

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite

</summary>

email: str

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: str

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLoginMethodRule: …

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: AccessLoginMethodRuleLoginMethod

</summary>

id: str

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

class IPListRule: …

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList

</summary>

id: str

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class IPRule: …

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP

</summary>

ip: str

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class OktaGroupRule: …

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta

</summary>

identity\_provider\_id: str

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SAMLGroupRule: …

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML

</summary>

attribute\_name: str

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: str

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: str

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessOIDCClaimRule: …

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: AccessOIDCClaimRuleOIDC

</summary>

claim\_name: str

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: str

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: str

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

class ServiceTokenRule: …

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken

</summary>

token\_id: str

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLinkedAppTokenRule: …

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: AccessLinkedAppTokenRuleLinkedAppToken

</summary>

app\_uid: str

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

class AccessUserRiskScoreRule: …

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: AccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

user\_risk\_score: List\[Literal\["low", "medium", "high", "unscored"]]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

class AccessCloudflareAccountMemberRule: …

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: AccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

account\_id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

include: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>]]

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

class GroupRule: …

Matches an Access group.

</summary>

<details>

<summary>

group: Group

</summary>

id: str

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AnyValidServiceTokenRule: …

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessAuthContextRule: …

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AccessAuthContextRuleAuthContext

</summary>

id: str

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: str

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AuthenticationMethodRule: …

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod

</summary>

auth\_method: str

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AzureGroupRule: …

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azure\_ad: AzureAD

</summary>

id: str

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CertificateRule: …

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCommonNameRule: …

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: AccessCommonNameRuleCommonName

</summary>

common\_name: str

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class CountryRule: …

Matches a specific country

</summary>

<details>

<summary>

geo: Geo

</summary>

country\_code: str

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessDevicePostureRule: …

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture

</summary>

integration\_uid: str

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id: Optional\[str]

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DomainRule: …

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain

</summary>

domain: str

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailListRule: …

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList

</summary>

id: str

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailRule: …

Matches a specific email.

</summary>

<details>

<summary>

email: Email

</summary>

email: str

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EveryoneRule: …

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ExternalEvaluationRule: …

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation

</summary>

evaluate\_url: str

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: str

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GitHubOrganizationRule: …

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

github\_organization: GitHubOrganization

</summary>

identity\_provider\_id: str

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team: Optional\[str]

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GSuiteGroupRule: …

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite

</summary>

email: str

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: str

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLoginMethodRule: …

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: AccessLoginMethodRuleLoginMethod

</summary>

id: str

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

class IPListRule: …

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList

</summary>

id: str

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class IPRule: …

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP

</summary>

ip: str

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class OktaGroupRule: …

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta

</summary>

identity\_provider\_id: str

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SAMLGroupRule: …

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML

</summary>

attribute\_name: str

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: str

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: str

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessOIDCClaimRule: …

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: AccessOIDCClaimRuleOIDC

</summary>

claim\_name: str

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: str

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: str

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

class ServiceTokenRule: …

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken

</summary>

token\_id: str

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLinkedAppTokenRule: …

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: AccessLinkedAppTokenRuleLinkedAppToken

</summary>

app\_uid: str

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

class AccessUserRiskScoreRule: …

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: AccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

user\_risk\_score: List\[Literal\["low", "medium", "high", "unscored"]]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

class AccessCloudflareAccountMemberRule: …

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: AccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

account\_id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20include">Link to this property</a>

isolation\_required: Optional\[bool]

Require this application to be served in an isolated browser for users matching this policy. ‘Client Web Isolation’ must be on for the account in order to use this feature.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20isolation_required">Link to this property</a>

<details>

<summary>

mfa\_config: Optional\[MfaConfig]

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

allowed\_authenticators: Optional\[List\[Literal\["totp", "biometrics", "security\_key"]]]

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

mfa\_disabled: Optional\[bool]

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

session\_duration: Optional\[str]

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

name: Optional\[str]

The name of the Access policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

purpose\_justification\_prompt: Optional\[str]

A custom message that will appear on the purpose justification screen.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_prompt">Link to this property</a>

purpose\_justification\_required: Optional\[bool]

Require users to enter a justification when they log in to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_required">Link to this property</a>

<details>

<summary>

require: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>]]

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

One of the following:

<details>

<summary>

class GroupRule: …

Matches an Access group.

</summary>

<details>

<summary>

group: Group

</summary>

id: str

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AnyValidServiceTokenRule: …

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessAuthContextRule: …

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AccessAuthContextRuleAuthContext

</summary>

id: str

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: str

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AuthenticationMethodRule: …

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod

</summary>

auth\_method: str

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AzureGroupRule: …

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azure\_ad: AzureAD

</summary>

id: str

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CertificateRule: …

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCommonNameRule: …

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: AccessCommonNameRuleCommonName

</summary>

common\_name: str

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class CountryRule: …

Matches a specific country

</summary>

<details>

<summary>

geo: Geo

</summary>

country\_code: str

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessDevicePostureRule: …

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture

</summary>

integration\_uid: str

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id: Optional\[str]

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DomainRule: …

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain

</summary>

domain: str

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailListRule: …

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList

</summary>

id: str

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailRule: …

Matches a specific email.

</summary>

<details>

<summary>

email: Email

</summary>

email: str

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EveryoneRule: …

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ExternalEvaluationRule: …

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation

</summary>

evaluate\_url: str

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: str

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GitHubOrganizationRule: …

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

github\_organization: GitHubOrganization

</summary>

identity\_provider\_id: str

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team: Optional\[str]

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GSuiteGroupRule: …

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite

</summary>

email: str

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: str

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLoginMethodRule: …

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: AccessLoginMethodRuleLoginMethod

</summary>

id: str

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

class IPListRule: …

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList

</summary>

id: str

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class IPRule: …

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP

</summary>

ip: str

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class OktaGroupRule: …

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta

</summary>

identity\_provider\_id: str

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SAMLGroupRule: …

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML

</summary>

attribute\_name: str

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: str

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: str

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessOIDCClaimRule: …

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: AccessOIDCClaimRuleOIDC

</summary>

claim\_name: str

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: str

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: str

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

class ServiceTokenRule: …

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken

</summary>

token\_id: str

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLinkedAppTokenRule: …

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: AccessLinkedAppTokenRuleLinkedAppToken

</summary>

app\_uid: str

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

class AccessUserRiskScoreRule: …

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: AccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

user\_risk\_score: List\[Literal\["low", "medium", "high", "unscored"]]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

class AccessCloudflareAccountMemberRule: …

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: AccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

account\_id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20require">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for the application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)>)

<details>

<summary>

Literal\["self\_hosted", "end\_user", "saas", 12 more]

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"end\_user"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"infrastructure"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"rdp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"mcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"mcp\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"proxy\_endpoint"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)>)

<details>

<summary>

class CORSHeaders: …

</summary>

allow\_all\_headers: Optional\[bool]

Allows all HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_headers">Link to this property</a>

allow\_all\_methods: Optional\[bool]

Allows all HTTP request methods.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_methods">Link to this property</a>

allow\_all\_origins: Optional\[bool]

Allows all origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_origins">Link to this property</a>

allow\_credentials: Optional\[bool]

When set to <code>true</code>, includes credentials (cookies, authorization headers, or TLS client certificates) with requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_credentials">Link to this property</a>

allowed\_headers: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)">AllowedHeaders</a>]]

Allowed HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_headers">Link to this property</a>

<details>

<summary>

allowed\_methods: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a>]]

Allowed HTTP request methods.

</summary>

One of the following:

"GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_methods">Link to this property</a>

allowed\_origins: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)">AllowedOrigins</a>]]

Allowed origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_origins">Link to this property</a>

max\_age: Optional\[float]

The maximum number of seconds the results of a preflight request can be cached.

maximum86400

minimum-1

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20max_age">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)>)

<details>

<summary>

Literal\["allow", "deny", "non\_identity", "bypass"]

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

</summary>

One of the following:

"allow"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"deny"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"non\_identity"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"bypass"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)>)

<details>

<summary>

class OIDCSaaSApp: …

</summary>

access\_token\_lifetime: Optional\[str]

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

allow\_pkce\_without\_client\_secret: Optional\[bool]

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

app\_launcher\_url: Optional\[str]

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

auth\_type: Optional\[Literal\["saml", "oidc"]]

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

client\_id: Optional\[str]

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

<details>

<summary>

custom\_claims: Optional\[List\[CustomClaim]]

</summary>

name: Optional\[str]

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

required: Optional\[bool]

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

scope: Optional\[Literal\["groups", "profile", "email", "openid"]]

The scope of the claim.

</summary>

One of the following:

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

source: Optional\[CustomClaimSource]

</summary>

name: Optional\[str]

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

name\_by\_idp: Optional\[Dict\[str, str]]

A mapping from IdP ID to claim name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

grant\_types: Optional\[List\[Literal\["authorization\_code", "authorization\_code\_with\_pkce", "refresh\_tokens", 2 more]]]

The OIDC flows supported by this application

</summary>

One of the following:

"authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types">Link to this property</a>

group\_filter\_regex: Optional\[str]

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

hybrid\_and\_implicit\_options: Optional\[HybridAndImplicitOptions]

</summary>

return\_access\_token\_from\_authorization\_endpoint: Optional\[bool]

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

return\_id\_token\_from\_authorization\_endpoint: Optional\[bool]

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

public\_key: Optional\[str]

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

redirect\_uris: Optional\[List\[str]]

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

refresh\_token\_options: Optional\[RefreshTokenOptions]

</summary>

lifetime: Optional\[str]

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

scopes: Optional\[List\[Literal\["openid", "groups", "email", "profile"]]]

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)>)

<details>

<summary>

Literal\["id", "email"]

The format of the name identifier sent to the SaaS application.

</summary>

One of the following:

"id"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)>)

<details>

<summary>

class SAMLSaaSApp: …

</summary>

<details>

<summary>

auth\_type: Optional\[Literal\["saml", "oidc"]]

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

consumer\_service\_url: Optional\[str]

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20consumer_service_url">Link to this property</a>

<details>

<summary>

custom\_attributes: Optional\[List\[CustomAttribute]]

</summary>

friendly\_name: Optional\[str]

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

name: Optional\[str]

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_format: Optional\[Literal\["urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified", "urn:oasis:names:tc:SAML:2.0:attrname-format:basic", "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"]]

A globally unique name for an identity or service provider.

</summary>

One of the following:

"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

required: Optional\[bool]

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

source: Optional\[CustomAttributeSource]

</summary>

name: Optional\[str]

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_by\_idp: Optional\[List\[CustomAttributeSourceNameByIdP]]

A mapping from IdP ID to attribute name.

</summary>

idp\_id: Optional\[str]

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

source\_name: Optional\[str]

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes">Link to this property</a>

default\_relay\_state: Optional\[str]

The URL that the user will be redirected to after a successful login for IDP initiated logins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20default_relay_state">Link to this property</a>

idp\_entity\_id: Optional\[str]

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20idp_entity_id">Link to this property</a>

name\_id\_format: Optional\[SaaSAppNameIDFormat]

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_format">Link to this property</a>

name\_id\_transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

public\_key: Optional\[str]

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

saml\_attribute\_transform\_jsonata: Optional\[str]

A \[JSONata] (<a href="https://jsonata.org/">https://jsonata.org/</a>) expression that transforms an application’s user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml\_attributes or oidc\_fields of the identity provider used to authenticate. The output of this expression must be a JSON object.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20saml_attribute_transform_jsonata">Link to this property</a>

sp\_entity\_id: Optional\[str]

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sp_entity_id">Link to this property</a>

sso\_endpoint: Optional\[str]

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sso_endpoint">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)>)

<details>

<summary>

class SCIMConfigAuthenticationHTTPBasic: …

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: str

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: Literal\["httpbasic"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: str

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)>)

<details>

<summary>

class SCIMConfigAuthenticationOAuthBearerToken: …

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: str

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20token">Link to this property</a>

scheme: Literal\["oauthbearertoken"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)>)

<details>

<summary>

class SCIMConfigAuthenticationOauth2: …

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: str

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: str

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: str

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: Literal\["oauth2"]

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: str

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes: Optional\[List\[str]]

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)>)

<details>

<summary>

class SCIMConfigMapping: …

Transformations and filters applied to resources before they are provisioned in the remote SCIM service.

</summary>

schema: str

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled: Optional\[bool]

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter: Optional\[str]

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations: Optional\[Operations]

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create: Optional\[bool]

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete: Optional\[bool]

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update: Optional\[bool]

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness: Optional\[Literal\["strict", "passthrough"]]

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata: Optional\[str]

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)>)

str

A domain that Access will secure.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20self_hosted_domains%20%3E%20(schema)>)

<details>

<summary>

<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)">ApplicationListResponse</a>

</summary>

One of the following:

<details>

<summary>

class EndUserApplication: …

</summary>

<details>

<summary>

oauth\_configuration: EndUserApplicationOAuthConfiguration

**Beta:** Optional configuration for managing an OAuth authorization flow controlled by Access. When set, Access will act as the OAuth authorization server for this application. Only compatible with OAuth clients that support <a href="https://datatracker.ietf.org/doc/html/rfc8707">RFC 8707</a> (Resource Indicators for OAuth 2.0). This feature is currently in beta.

</summary>

<details>

<summary>

dynamic\_client\_registration: Optional\[EndUserApplicationOAuthConfigurationDynamicClientRegistration]

Settings for OAuth dynamic client registration.

</summary>

allow\_any\_on\_localhost: Optional\[bool]

Allows any client with redirect URIs on localhost.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_localhost">Link to this property</a>

allow\_any\_on\_loopback: Optional\[bool]

Allows any client with redirect URIs on 127.0.0.1.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_loopback">Link to this property</a>

allowed\_uris: Optional\[List\[str]]

The URIs that are allowed as redirect URIs for dynamically registered clients. HTTP and HTTPS paths may end in <code>/*</code> to match all sub-paths. Custom-scheme URIs must be explicitly configured and match exactly.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allowed_uris">Link to this property</a>

enabled: Optional\[bool]

Whether dynamic client registration is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration">Link to this property</a>

enabled: Optional\[Literal\[true]]

Managed OAuth is required for end user applications and cannot be disabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

grant: Optional\[EndUserApplicationOAuthConfigurationGrant]

Settings for OAuth grant behavior.

</summary>

access\_token\_lifetime: Optional\[str]

The lifetime of the access token. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

session\_duration: Optional\[str]

The duration of the OAuth session. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration">Link to this property</a>

<details>

<summary>

type: Literal\["self\_hosted", "end\_user", "saas", 12 more]

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"end\_user"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%209">Link to this property</a>

"infrastructure"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2010">Link to this property</a>

"rdp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2011">Link to this property</a>

"mcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2012">Link to this property</a>

"mcp\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2013">Link to this property</a>

"proxy\_endpoint"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2014">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

user\_populations: List\[str]

The single user population associated with this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20user_populations">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20aud">Link to this property</a>

<details>

<summary>

destinations: Optional\[List\[EndUserApplicationDestination]]

Public hostname and Workers destinations secured by Access.

</summary>

One of the following:

<details>

<summary>

class EndUserApplicationDestinationAccessEndUserPublicDestination: …

</summary>

uri: str

The public hostname and optional path to secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20uri">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[EndUserApplicationDestinationAccessEndUserPublicDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides">Link to this property</a>

type: Optional\[Literal\["public"]]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class EndUserApplicationDestinationAccessEndUserWorkerDestination: …

</summary>

type: Literal\["worker"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

worker\_id: str

The ID of the Cloudflare Worker to secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[EndUserApplicationDestinationAccessEndUserWorkerDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class EndUserApplicationDestinationAccessEndUserPreviewWorkerDestination: …

</summary>

type: Literal\["preview\_worker"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

worker\_id: str

The ID of the Cloudflare Worker whose previews to secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[EndUserApplicationDestinationAccessEndUserPreviewWorkerDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class EndUserApplicationDestinationAccessEndUserAllWorkersDestination: …

</summary>

type: Literal\["all\_workers"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[EndUserApplicationDestinationAccessEndUserAllWorkersDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

class EndUserApplicationDestinationAccessEndUserAllPreviewWorkersDestination: …

</summary>

type: Literal\["all\_preview\_workers"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[EndUserApplicationDestinationAccessEndUserAllPreviewWorkersDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations">Link to this property</a>

domain: Optional\[str]

The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20domain">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

Deprecatedself\_hosted\_domains: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20self_hosted_domains%20%3E%20(schema)">SelfHostedDomains</a>]]

List of public domains that Access will secure. This field is deprecated in favor of <code>destinations</code> and will be supported until **November 21, 2025.** If <code>destinations</code> are provided, then <code>self_hosted_domains</code> will be ignored.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20self_hosted_domains">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class SelfHostedApplication: …

</summary>

domain: str

The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20domain">Link to this property</a>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a>

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

allow\_authenticate\_via\_warp: Optional\[bool]

When set to true, users can authenticate to this application using their WARP session. When set to false this application will always require direct IdP authentication. This setting always overrides the organization setting for WARP authentication.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allow_authenticate_via_warp">Link to this property</a>

allow\_iframe: Optional\[bool]

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>]]

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible: Optional\[bool]

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud: Optional\[str]

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers: Optional\[CORSHeaders]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20cors_headers">Link to this property</a>

custom\_deny\_message: Optional\[str]

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url: Optional\[str]

The custom URL a user is redirected to when they are denied access to the application when failing identity-based rules.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_deny_url">Link to this property</a>

custom\_non\_identity\_deny\_url: Optional\[str]

The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_non_identity_deny_url">Link to this property</a>

custom\_pages: Optional\[List\[str]]

The custom pages that will be displayed when applicable for this application

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_pages">Link to this property</a>

<details>

<summary>

destinations: Optional\[List\[SelfHostedApplicationDestination]]

List of destinations secured by Access. This supersedes <code>self_hosted_domains</code> to allow for more flexibility in defining different types of domains. If <code>destinations</code> are provided, then <code>self_hosted_domains</code> will be ignored.

</summary>

One of the following:

<details>

<summary>

class SelfHostedApplicationDestinationPublicDestination: …

A public hostname that Access will secure. Public destinations support sub-domain and path. Wildcard ’\*’ can be used in the definition.

</summary>

<details>

<summary>

overrides: Optional\[List\[SelfHostedApplicationDestinationPublicDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides">Link to this property</a>

type: Optional\[Literal\["public"]]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

uri: Optional\[str]

The URI of the destination. Public destinations’ URIs can include a domain and path with <a href="https://developers.cloudflare.com/cloudflare-one/policies/access/app-paths/">wildcards</a>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20uri">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationDestinationPrivateDestination: …

</summary>

cidr: Optional\[str]

The CIDR range of the destination. Single IPs will be computed as /32.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20cidr">Link to this property</a>

hostname: Optional\[str]

The hostname of the destination. Matches a valid SNI served by an HTTPS origin.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

l4\_protocol: Optional\[Literal\["tcp", "udp"]]

The L4 protocol of the destination. When omitted, both UDP and TCP traffic will match.

</summary>

One of the following:

"tcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20l4_protocol%20%3E%20(member)%200">Link to this property</a>

"udp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20l4_protocol%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20l4_protocol">Link to this property</a>

port\_range: Optional\[str]

The port range of the destination. Can be a single port or a range of ports. When omitted, all ports will match.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20port_range">Link to this property</a>

type: Optional\[Literal\["private"]]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

vnet\_id: Optional\[str]

The VNET ID to match the destination. When omitted, all VNETs will match.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationDestinationViaMcpServerPortalDestination: …

A MCP server id configured in ai-controls. Access will secure the MCP server if accessed through a MCP portal.

</summary>

mcp\_server\_id: Optional\[str]

The MCP server id configured in ai-controls.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20mcp_server_id">Link to this property</a>

type: Optional\[Literal\["via\_mcp\_server\_portal"]]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationDestinationWorkerDestination: …

A specific Cloudflare Worker that Access will secure. All requests routed to the specified Worker, including its preview deployments, will be protected. The <code>preview_worker</code> and <code>public</code> destination types takes precedence, so you can create separate applications to override the policies for the Worker’s previews or specific paths.

</summary>

type: Literal\["worker"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

worker\_id: str

The ID of the Cloudflare Worker to protect with Access.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[SelfHostedApplicationDestinationWorkerDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationDestinationPreviewWorkerDestination: …

A specific Cloudflare Worker whose preview deployments Access will secure. Only requests routed to the preview deployments of the specified Worker will be protected. The <code>public</code> destination type takes precedence, so you can create separate applications to override the policies for specific paths.

</summary>

type: Literal\["preview\_worker"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

worker\_id: str

The ID of the Cloudflare Worker whose preview deployments to protect with Access.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[SelfHostedApplicationDestinationPreviewWorkerDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationDestinationAllWorkersDestination: …

Protects all Cloudflare Workers on the account with Access, including their preview deployments. At most one destination of this type can exist per account. The <code>worker</code>, <code>preview_worker</code>, <code>all_preview_workers</code>, and <code>public</code> destination types take precedence, so you can create separate applications to override the policies for specific Workers, their previews, or specific paths.

</summary>

type: Literal\["all\_workers"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[SelfHostedApplicationDestinationAllWorkersDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

class SelfHostedApplicationDestinationAllPreviewWorkersDestination: …

Protects the preview deployments of all Cloudflare Workers on the account with Access. At most one destination of this type can exist per account. The <code>worker</code>, <code>preview_worker</code>, and <code>public</code> destination types take precedence, so you can create separate applications to override the policies for specific Workers, their previews, or specific paths.

</summary>

type: Literal\["all\_preview\_workers"]

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides: Optional\[List\[SelfHostedApplicationDestinationAllPreviewWorkersDestinationOverride]]

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: Literal\["public"]

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: str

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations">Link to this property</a>

eager\_redirect\_cookie\_setting: Optional\[bool]

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie: Optional\[bool]

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute: Optional\[bool]

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url: Optional\[str]

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20logo_url">Link to this property</a>

<details>

<summary>

mfa\_config: Optional\[SelfHostedApplicationMfaConfig]

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

allowed\_authenticators: Optional\[List\[Literal\["totp", "biometrics", "security\_key"]]]

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

mfa\_disabled: Optional\[bool]

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

session\_duration: Optional\[str]

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config">Link to this property</a>

name: Optional\[str]

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

oauth\_configuration: Optional\[SelfHostedApplicationOAuthConfiguration]

**Beta:** Optional configuration for managing an OAuth authorization flow controlled by Access. When set, Access will act as the OAuth authorization server for this application. Only compatible with OAuth clients that support <a href="https://datatracker.ietf.org/doc/html/rfc8707">RFC 8707</a> (Resource Indicators for OAuth 2.0). This feature is currently in beta.

</summary>

<details>

<summary>

dynamic\_client\_registration: Optional\[SelfHostedApplicationOAuthConfigurationDynamicClientRegistration]

Settings for OAuth dynamic client registration.

</summary>

allow\_any\_on\_localhost: Optional\[bool]

Allows any client with redirect URIs on localhost.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_localhost">Link to this property</a>

allow\_any\_on\_loopback: Optional\[bool]

Allows any client with redirect URIs on 127.0.0.1.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_loopback">Link to this property</a>

allowed\_uris: Optional\[List\[str]]

The URIs that are allowed as redirect URIs for dynamically registered clients. HTTP and HTTPS paths may end in <code>/*</code> to match all sub-paths. Custom-scheme URIs must be explicitly configured and match exactly.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allowed_uris">Link to this property</a>

enabled: Optional\[bool]

Whether dynamic client registration is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration">Link to this property</a>

enabled: Optional\[bool]

Whether the OAuth configuration is enabled for this application. When set to <code>false</code>, Access will not handle OAuth for this application. Defaults to <code>true</code> if omitted.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

grant: Optional\[SelfHostedApplicationOAuthConfigurationGrant]

Settings for OAuth grant behavior.

</summary>

access\_token\_lifetime: Optional\[str]

The lifetime of the access token. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

session\_duration: Optional\[str]

The duration of the OAuth session. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration">Link to this property</a>

options\_preflight\_bypass: Optional\[bool]

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

path\_cookie\_attribute: Optional\[bool]

Enables cookie paths to scope an application’s JWT to the application path. If disabled, the JWT will scope to the hostname by default

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20path_cookie_attribute">Link to this property</a>

<details>

<summary>

policies: Optional\[List\[SelfHostedApplicationPolicy]]

</summary>

id: Optional\[str]

The UUID of the policy

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

account\_id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20account_id">Link to this property</a>

<details>

<summary>

approval\_groups: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a>]]

Administrators who can approve a temporary authentication request.

</summary>

approvals\_needed: float

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

email\_addresses: Optional\[List\[str]]

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

email\_list\_uuid: Optional\[str]

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20approval_groups">Link to this property</a>

approval\_required: Optional\[bool]

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20approval_required">Link to this property</a>

<details>

<summary>

connection\_rules: Optional\[SelfHostedApplicationPolicyConnectionRules]

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

rdp: Optional\[SelfHostedApplicationPolicyConnectionRulesRDP]

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

<details>

<summary>

allowed\_clipboard\_local\_to\_remote\_formats: Optional\[List\[Literal\["text", "file"]]]

Clipboard formats allowed when copying from local machine to remote RDP session.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

<details>

<summary>

allowed\_clipboard\_remote\_to\_local\_formats: Optional\[List\[Literal\["text", "file"]]]

Clipboard formats allowed when copying from remote RDP session to local machine.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

decision: Optional\[Decision]

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

exclude: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>]]

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

class GroupRule: …

Matches an Access group.

</summary>

<details>

<summary>

group: Group

</summary>

id: str

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AnyValidServiceTokenRule: …

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessAuthContextRule: …

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AccessAuthContextRuleAuthContext

</summary>

id: str

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: str

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AuthenticationMethodRule: …

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod

</summary>

auth\_method: str

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AzureGroupRule: …

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azure\_ad: AzureAD

</summary>

id: str

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CertificateRule: …

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCommonNameRule: …

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: AccessCommonNameRuleCommonName

</summary>

common\_name: str

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class CountryRule: …

Matches a specific country

</summary>

<details>

<summary>

geo: Geo

</summary>

country\_code: str

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessDevicePostureRule: …

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture

</summary>

integration\_uid: str

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id: Optional\[str]

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DomainRule: …

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain

</summary>

domain: str

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailListRule: …

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList

</summary>

id: str

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailRule: …

Matches a specific email.

</summary>

<details>

<summary>

email: Email

</summary>

email: str

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EveryoneRule: …

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ExternalEvaluationRule: …

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation

</summary>

evaluate\_url: str

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: str

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GitHubOrganizationRule: …

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

github\_organization: GitHubOrganization

</summary>

identity\_provider\_id: str

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team: Optional\[str]

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GSuiteGroupRule: …

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite

</summary>

email: str

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: str

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLoginMethodRule: …

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: AccessLoginMethodRuleLoginMethod

</summary>

id: str

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

class IPListRule: …

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList

</summary>

id: str

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class IPRule: …

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP

</summary>

ip: str

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class OktaGroupRule: …

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta

</summary>

identity\_provider\_id: str

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SAMLGroupRule: …

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML

</summary>

attribute\_name: str

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: str

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: str

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessOIDCClaimRule: …

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: AccessOIDCClaimRuleOIDC

</summary>

claim\_name: str

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: str

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: str

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

class ServiceTokenRule: …

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken

</summary>

token\_id: str

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLinkedAppTokenRule: …

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: AccessLinkedAppTokenRuleLinkedAppToken

</summary>

app\_uid: str

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

class AccessUserRiskScoreRule: …

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: AccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

user\_risk\_score: List\[Literal\["low", "medium", "high", "unscored"]]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

class AccessCloudflareAccountMemberRule: …

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: AccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

account\_id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

include: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>]]

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

class GroupRule: …

Matches an Access group.

</summary>

<details>

<summary>

group: Group

</summary>

id: str

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AnyValidServiceTokenRule: …

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessAuthContextRule: …

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AccessAuthContextRuleAuthContext

</summary>

id: str

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: str

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AuthenticationMethodRule: …

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod

</summary>

auth\_method: str

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AzureGroupRule: …

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azure\_ad: AzureAD

</summary>

id: str

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CertificateRule: …

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCommonNameRule: …

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: AccessCommonNameRuleCommonName

</summary>

common\_name: str

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class CountryRule: …

Matches a specific country

</summary>

<details>

<summary>

geo: Geo

</summary>

country\_code: str

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessDevicePostureRule: …

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture

</summary>

integration\_uid: str

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id: Optional\[str]

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DomainRule: …

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain

</summary>

domain: str

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailListRule: …

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList

</summary>

id: str

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailRule: …

Matches a specific email.

</summary>

<details>

<summary>

email: Email

</summary>

email: str

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EveryoneRule: …

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ExternalEvaluationRule: …

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation

</summary>

evaluate\_url: str

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: str

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GitHubOrganizationRule: …

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

github\_organization: GitHubOrganization

</summary>

identity\_provider\_id: str

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team: Optional\[str]

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class GSuiteGroupRule: …

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite

</summary>

email: str

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: str

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLoginMethodRule: …

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: AccessLoginMethodRuleLoginMethod

</summary>

id: str

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

class IPListRule: …

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList

</summary>

id: str

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class IPRule: …

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP

</summary>

ip: str

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class OktaGroupRule: …

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta

</summary>

identity\_provider\_id: str

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: str

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class SAMLGroupRule: …

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML

</summary>

attribute\_name: str

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: str

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: str

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessOIDCClaimRule: …

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: AccessOIDCClaimRuleOIDC

</summary>

claim\_name: str

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: str

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: str

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

class ServiceTokenRule: …

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken

</summary>

token\_id: str

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessLinkedAppTokenRule: …

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: AccessLinkedAppTokenRuleLinkedAppToken

</summary>

app\_uid: str

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

class AccessUserRiskScoreRule: …

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: AccessUserRiskScoreRuleUserRiskScore

</summary>

<details>

<summary>

user\_risk\_score: List\[Literal\["low", "medium", "high", "unscored"]]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

class AccessCloudflareAccountMemberRule: …

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: AccessCloudflareAccountMemberRuleCloudflareAccountMember

</summary>

account\_id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20include">Link to this property</a>

isolation\_required: Optional\[bool]

Require this application to be served in an isolated browser for users matching this policy. ‘Client Web Isolation’ must be on for the account in order to use this feature.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20isolation_required">Link to this property</a>

<details>

<summary>

mfa\_config: Optional\[SelfHostedApplicationPolicyMfaConfig]

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

allowed\_authenticators: Optional\[List\[Literal\["totp", "biometrics", "security\_key"]]]

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

mfa\_disabled: Optional\[bool]

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

session\_duration: Optional\[str]

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20mfa_config">Link to this property</a>

name: Optional\[str]

The name of the Access policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

precedence: Optional\[int]

The order of execution for this policy. Must be unique for each policy within an app.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20precedence">Link to this property</a>

purpose\_justification\_prompt: Optional\[str]

A custom message that will appear on the purpose justification screen.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20purpose_justification_prompt">Link to this property</a>

purpose\_justification\_required: Optional\[bool]

Require users to enter a justification when they log in to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20purpose_justification_required">Link to this property</a>

<details>

<summary>

require: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>]]

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

One of the following:

<details>

<summary>

class GroupRule: …

Matches an Access group.

</summary>

<details>

<summary>

group: Group

</summary>

id: str

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AnyValidServiceTokenRule: …

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessAuthContextRule: …

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AccessAuthContextRuleAuthContext

</summary>

id: str

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: str

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AuthenticationMethodRule: …

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod

</summary>

auth\_method: str

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AzureGroupRule: …

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azure\_ad: AzureAD

</summary>

id: str

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: str

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class CertificateRule: …

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCommonNameRule: …

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: AccessCommonNameRuleCommonName

</summary>

common\_name: str

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class CountryRule: …

Matches a specific country

</summary>

<details>

<summary>

geo: Geo

</summary>

country\_code: str

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessDevicePostureRule: …

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture

</summary>

integration\_uid: str

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id: Optional\[str]

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DomainRule: …

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain

</summary>

domain: str

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailListRule: …

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList

</summary>

id: str

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EmailRule: …

Matches a specific email.

</summary>

<details>

<summary>

email: Email

</summary>

email: str

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class EveryoneRule: …

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class ExternalEvaluationRule: …

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

</summary>

</details>

</details>

</details>

</details>

</details>

</details>

<!-- Cloudflare Markdown for Agents: incomplete conversion; source HTML truncated at the conversion size limit -->
