---
title: Gateway
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Zero Trust](https://developers.cloudflare.com/api/python/resources/zero_trust)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Gateway

##### [Get Zero Trust account information](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/methods/list)

zero\_trust.gateway.list(GatewayListParams\*\*kwargs) -> [GatewayListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway

##### [Create Zero Trust account](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/methods/create)

zero\_trust.gateway.create(GatewayCreateParams\*\*kwargs) -> [GatewayCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway

##### ModelsExpand Collapse

<details>

<summary>

class GatewayListResponse: …

</summary>

id: Optional\[str]

Specify the Cloudflare account ID.

maxLength32

<a href="#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

gateway\_tag: Optional\[str]

Specify the gateway internal ID.

maxLength32

<a href="#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_list_response%20%3E%20(schema)%20%3E%20(property)%20gateway_tag">Link to this property</a>

provider\_name: Optional\[str]

Specify the provider name (usually Cloudflare).

<a href="#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_list_response%20%3E%20(schema)%20%3E%20(property)%20provider_name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_list_response%20%3E%20(schema)>)

<details>

<summary>

class GatewayCreateResponse: …

</summary>

id: Optional\[str]

Specify the Cloudflare account ID.

maxLength32

<a href="#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

gateway\_tag: Optional\[str]

Specify the gateway internal ID.

maxLength32

<a href="#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_create_response%20%3E%20(schema)%20%3E%20(property)%20gateway_tag">Link to this property</a>

provider\_name: Optional\[str]

Specify the provider name (usually Cloudflare).

<a href="#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_create_response%20%3E%20(schema)%20%3E%20(property)%20provider_name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway%20%3E%20(model)%20gateway_create_response%20%3E%20(schema)>)

#### GatewayAudit SSH Settings

##### [Get Zero Trust SSH settings](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/audit_ssh_settings/methods/get)

zero\_trust.gateway.audit\_ssh\_settings.get(AuditSSHSettingGetParams\*\*kwargs) -> [GatewaySettings](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/audit\_ssh\_settings

##### [Update Zero Trust SSH settings](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/audit_ssh_settings/methods/update)

zero\_trust.gateway.audit\_ssh\_settings.update(AuditSSHSettingUpdateParams\*\*kwargs) -> [GatewaySettings](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/audit\_ssh\_settings

##### [Rotate Zero Trust SSH account seed](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/audit_ssh_settings/methods/rotate_seed)

zero\_trust.gateway.audit\_ssh\_settings.rotate\_seed(AuditSSHSettingRotateSeedParams\*\*kwargs) -> [GatewaySettings](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/audit\_ssh\_settings/rotate\_seed

##### ModelsExpand Collapse

<details>

<summary>

class GatewaySettings: …

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

public\_key: Optional\[str]

Provide the Base64-encoded HPKE public key that encrypts SSH session logs. See <a href="https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/#enable-ssh-command-logging">https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/#enable-ssh-command-logging</a>.

<a href="#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

seed\_id: Optional\[str]

Identify the seed ID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)%20%3E%20(property)%20seed_id">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.audit_ssh_settings%20%3E%20(model)%20gateway_settings%20%3E%20(schema)>)

#### GatewayCategories

##### [List categories](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/categories/methods/list)

zero\_trust.gateway.categories.list(CategoryListParams\*\*kwargs) -> SyncSinglePage\[[Category](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/categories

##### ModelsExpand Collapse

<details>

<summary>

class Category: …

</summary>

id: Optional\[int]

Identify this category. Only one category per ID.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

beta: Optional\[bool]

Indicate whether the category is in beta and subject to change.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20beta">Link to this property</a>

<details>

<summary>

class\_: Optional\[Literal\["free", "premium", "blocked", 2 more]]

Specify which account types can create policies for this category. <code>blocked</code> Blocks unconditionally for all accounts. <code>removalPending</code> Allows removal from policies but disables addition. <code>noBlock</code> Prevents blocking.

</summary>

One of the following:

"free"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20class%20%3E%20(member)%200">Link to this property</a>

"premium"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20class%20%3E%20(member)%201">Link to this property</a>

"blocked"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20class%20%3E%20(member)%202">Link to this property</a>

"removalPending"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20class%20%3E%20(member)%203">Link to this property</a>

"noBlock"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20class%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20class">Link to this property</a>

description: Optional\[str]

Provide a short summary of domains in the category.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Specify the category name.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

subcategories: Optional\[List\[Subcategory]]

Provide all subcategories for this category.

</summary>

id: Optional\[int]

Identify this category. Only one category per ID.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

beta: Optional\[bool]

Indicate whether the category is in beta and subject to change.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20beta">Link to this property</a>

<details>

<summary>

class\_: Optional\[Literal\["free", "premium", "blocked", 2 more]]

Specify which account types can create policies for this category. <code>blocked</code> Blocks unconditionally for all accounts. <code>removalPending</code> Allows removal from policies but disables addition. <code>noBlock</code> Prevents blocking.

</summary>

One of the following:

"free"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20class%20%3E%20(member)%200">Link to this property</a>

"premium"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20class%20%3E%20(member)%201">Link to this property</a>

"blocked"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20class%20%3E%20(member)%202">Link to this property</a>

"removalPending"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20class%20%3E%20(member)%203">Link to this property</a>

"noBlock"

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20class%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20class">Link to this property</a>

description: Optional\[str]

Provide a short summary of domains in the category.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Specify the category name.

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)%20%3E%20(property)%20subcategories">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.categories%20%3E%20(model)%20category%20%3E%20(schema)>)

#### GatewayApp Types

##### [List application and application type mappings](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/app_types/methods/list)

zero\_trust.gateway.app\_types.list(AppTypeListParams\*\*kwargs) -> SyncSinglePage\[[AppType](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/app\_types

##### ModelsExpand Collapse

<details>

<summary>

<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)">AppType</a>

</summary>

One of the following:

<details>

<summary>

class ZeroTrustGatewayApplication: …

</summary>

id: Optional\[int]

Identify this application. Only one application per ID.

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

application\_type\_id: Optional\[int]

Identify the type of this application. Multiple applications can share the same type. Refers to the <code>id</code> of a returned application type.

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20application_type_id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

name: Optional\[str]

Specify the name of the application or application type.

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class ZeroTrustGatewayApplicationType: …

</summary>

id: Optional\[int]

Identify the type of this application. Multiple applications can share the same type. Refers to the <code>id</code> of a returned application type.

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Provide a short summary of applications with this type.

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Specify the name of the application or application type.

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.app_types%20%3E%20(model)%20app_type%20%3E%20(schema)>)

#### GatewayConfigurations

##### [Get Zero Trust account configuration](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/configurations/methods/get)

zero\_trust.gateway.configurations.get(ConfigurationGetParams\*\*kwargs) -> [ConfigurationGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/configuration

##### [Update Zero Trust account configuration](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/configurations/methods/update)

zero\_trust.gateway.configurations.update(ConfigurationUpdateParams\*\*kwargs) -> [ConfigurationUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/configuration

##### [Patch Zero Trust account configuration](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/configurations/methods/edit)

zero\_trust.gateway.configurations.edit(ConfigurationEditParams\*\*kwargs) -> [ConfigurationEditResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/gateway/configuration

##### ModelsExpand Collapse

<details>

<summary>

class ActivityLogSettings: …

Specify activity log settings.

</summary>

enabled: Optional\[bool]

Specify whether to log activity.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20activity_log_settings%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20activity_log_settings%20%3E%20(schema)>)

<details>

<summary>

class AntiVirusSettings: …

Specify anti-virus settings.

</summary>

enabled\_download\_phase: Optional\[bool]

Specify whether to enable anti-virus scanning on downloads.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20anti_virus_settings%20%3E%20(schema)%20%3E%20(property)%20enabled_download_phase">Link to this property</a>

enabled\_upload\_phase: Optional\[bool]

Specify whether to enable anti-virus scanning on uploads.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20anti_virus_settings%20%3E%20(schema)%20%3E%20(property)%20enabled_upload_phase">Link to this property</a>

fail\_closed: Optional\[bool]

Specify whether to block requests for unscannable files.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20anti_virus_settings%20%3E%20(schema)%20%3E%20(property)%20fail_closed">Link to this property</a>

notification\_settings: Optional\[NotificationSettings]

Configure the message the user’s device shows during an antivirus scan.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20anti_virus_settings%20%3E%20(schema)%20%3E%20(property)%20notification_settings">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20anti_virus_settings%20%3E%20(schema)>)

<details>

<summary>

class BlockPageSettings: …

Specify block page layout settings.

</summary>

background\_color: Optional\[str]

Specify the block page background color in <code>#rrggbb</code> format when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20background_color">Link to this property</a>

enabled: Optional\[bool]

Specify whether to enable the custom block page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

footer\_text: Optional\[str]

Specify the block page footer text when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20footer_text">Link to this property</a>

header\_text: Optional\[str]

Specify the block page header text when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20header_text">Link to this property</a>

include\_context: Optional\[bool]

Specify whether to append context to target\_uri as query parameters. This applies only when the mode is redirect\_uri.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20include_context">Link to this property</a>

logo\_path: Optional\[str]

Specify the full URL to the logo file when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20logo_path">Link to this property</a>

mailto\_address: Optional\[str]

Specify the admin email for users to contact when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20mailto_address">Link to this property</a>

mailto\_subject: Optional\[str]

Specify the subject line for emails created from the block page when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20mailto_subject">Link to this property</a>

<details>

<summary>

mode: Optional\[Literal\["", "customized\_block\_page", "redirect\_uri"]]

Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI.

</summary>

One of the following:

""

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

"customized\_block\_page"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

"redirect\_uri"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20mode">Link to this property</a>

name: Optional\[str]

Specify the block page title when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

read\_only: Optional\[bool]

Indicate that this setting was shared via the Orgs API and read only for the current account.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

source\_account: Optional\[str]

Indicate the account tag of the account that shared this setting.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20source_account">Link to this property</a>

suppress\_footer: Optional\[bool]

Specify whether to suppress detailed information at the bottom of the block page when the mode is customized\_block\_page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20suppress_footer">Link to this property</a>

target\_uri: Optional\[str]

Specify the URI to redirect users to when the mode is redirect\_uri.

formaturi

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20target_uri">Link to this property</a>

version: Optional\[int]

Indicate the version number of the setting.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20block_page_settings%20%3E%20(schema)>)

<details>

<summary>

class BodyScanningSettings: …

Specify the DLP inspection mode.

</summary>

<details>

<summary>

inspection\_mode: Optional\[Literal\["deep", "shallow"]]

Specify the inspection mode as either <code>deep</code> or <code>shallow</code>.

</summary>

One of the following:

"deep"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20body_scanning_settings%20%3E%20(schema)%20%3E%20(property)%20inspection_mode%20%3E%20(member)%200">Link to this property</a>

"shallow"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20body_scanning_settings%20%3E%20(schema)%20%3E%20(property)%20inspection_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20body_scanning_settings%20%3E%20(schema)%20%3E%20(property)%20inspection_mode">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20body_scanning_settings%20%3E%20(schema)>)

<details>

<summary>

class BrowserIsolationSettings: …

Specify Clientless Browser Isolation settings.

</summary>

non\_identity\_enabled: Optional\[bool]

Specify whether to enable non-identity onramp support for Browser Isolation.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20browser_isolation_settings%20%3E%20(schema)%20%3E%20(property)%20non_identity_enabled">Link to this property</a>

url\_browser\_isolation\_enabled: Optional\[bool]

Specify whether to enable Clientless Browser Isolation.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20browser_isolation_settings%20%3E%20(schema)%20%3E%20(property)%20url_browser_isolation_enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20browser_isolation_settings%20%3E%20(schema)>)

<details>

<summary>

class CustomCertificateSettings: …

Specify custom certificate settings for BYO-PKI. This field is deprecated; use <code>certificate</code> instead.

</summary>

enabled: Optional\[bool]

Specify whether to enable a custom certificate authority for signing Gateway traffic.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20custom_certificate_settings%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

id: Optional\[str]

Specify the UUID of the certificate (ID from MTLS certificate store).

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20custom_certificate_settings%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

binding\_status: Optional\[str]

Indicate the internal certificate status.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20custom_certificate_settings%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20custom_certificate_settings%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20custom_certificate_settings%20%3E%20(schema)>)

<details>

<summary>

class ExtendedEmailMatching: …

Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses <code>.</code> or <code>+</code> modifiers.

</summary>

enabled: Optional\[bool]

Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20extended_email_matching%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

read\_only: Optional\[bool]

Indicate that this setting was shared via the Orgs API and read only for the current account.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20extended_email_matching%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

source\_account: Optional\[str]

Indicate the account tag of the account that shared this setting.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20extended_email_matching%20%3E%20(schema)%20%3E%20(property)%20source_account">Link to this property</a>

version: Optional\[int]

Indicate the version number of the setting.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20extended_email_matching%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20extended_email_matching%20%3E%20(schema)>)

<details>

<summary>

class FipsSettings: …

Specify FIPS settings.

</summary>

tls: Optional\[bool]

Enforce cipher suites and TLS versions compliant with FIPS 140-2.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20fips_settings%20%3E%20(schema)%20%3E%20(property)%20tls">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20fips_settings%20%3E%20(schema)>)

<details>

<summary>

class GatewayConfigurationSettings: …

Specify account settings.

</summary>

activity\_log: Optional\[ActivityLogSettings]

Specify activity log settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20activity_log">Link to this property</a>

antivirus: Optional\[AntiVirusSettings]

Specify anti-virus settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20antivirus">Link to this property</a>

block\_page: Optional\[BlockPageSettings]

Specify block page layout settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20block_page">Link to this property</a>

body\_scanning: Optional\[BodyScanningSettings]

Specify the DLP inspection mode.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20body_scanning">Link to this property</a>

browser\_isolation: Optional\[BrowserIsolationSettings]

Specify Clientless Browser Isolation settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20browser_isolation">Link to this property</a>

<details>

<summary>

certificate: Optional\[Certificate]

Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.

</summary>

id: str

Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called ‘active’). A nil UUID directs Cloudflare to use the Root CA.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20certificate%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

Deprecatedcustom\_certificate: Optional\[CustomCertificateSettings]

Specify custom certificate settings for BYO-PKI. This field is deprecated; use <code>certificate</code> instead.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20custom_certificate">Link to this property</a>

extended\_email\_matching: Optional\[ExtendedEmailMatching]

Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses <code>.</code> or <code>+</code> modifiers.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20extended_email_matching">Link to this property</a>

fips: Optional\[FipsSettings]

Specify FIPS settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20fips">Link to this property</a>

<details>

<summary>

host\_selector: Optional\[HostSelector]

Enable host selection in egress policies.

</summary>

enabled: Optional\[bool]

Specify whether to enable filtering via hosts for egress policies.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20host_selector%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20host_selector">Link to this property</a>

<details>

<summary>

inspection: Optional\[Inspection]

Define the proxy inspection mode.

</summary>

<details>

<summary>

mode: Optional\[Literal\["static", "dynamic"]]

Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic.

</summary>

One of the following:

"static"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20inspection%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

"dynamic"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20inspection%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20inspection%20%3E%20(property)%20mode">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20inspection">Link to this property</a>

max\_ttl\_secs: Optional\[int]

Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location <code>max_ttl</code> setting.

maximum36000

minimum60

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20max_ttl_secs">Link to this property</a>

protocol\_detection: Optional\[ProtocolDetection]

Specify whether to detect protocols from the initial bytes of client traffic.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20protocol_detection">Link to this property</a>

<details>

<summary>

sandbox: Optional\[Sandbox]

Specify whether to enable the sandbox.

</summary>

enabled: Optional\[bool]

Specify whether to enable the sandbox.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20sandbox%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

fallback\_action: Optional\[Literal\["allow", "block"]]

Specify the action to take when the system cannot scan the file.

</summary>

One of the following:

"allow"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20sandbox%20%3E%20(property)%20fallback_action%20%3E%20(member)%200">Link to this property</a>

"block"

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20sandbox%20%3E%20(property)%20fallback_action%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20sandbox%20%3E%20(property)%20fallback_action">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20sandbox">Link to this property</a>

tls\_decrypt: Optional\[TLSSettings]

Specify whether to inspect encrypted HTTP traffic.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)%20%3E%20(property)%20tls_decrypt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20gateway_configuration_settings%20%3E%20(schema)>)

<details>

<summary>

class NotificationSettings: …

Configure the message the user’s device shows during an antivirus scan.

</summary>

enabled: Optional\[bool]

Specify whether to enable notifications.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20notification_settings%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

include\_context: Optional\[bool]

Specify whether to include context information as query parameters.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20notification_settings%20%3E%20(schema)%20%3E%20(property)%20include_context">Link to this property</a>

msg: Optional\[str]

Specify the message to show in the notification.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20notification_settings%20%3E%20(schema)%20%3E%20(property)%20msg">Link to this property</a>

support\_url: Optional\[str]

Specify a URL that directs users to more information. If unset, the notification opens a block page.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20notification_settings%20%3E%20(schema)%20%3E%20(property)%20support_url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20notification_settings%20%3E%20(schema)>)

<details>

<summary>

class ProtocolDetection: …

Specify whether to detect protocols from the initial bytes of client traffic.

</summary>

enabled: Optional\[bool]

Specify whether to detect protocols from the initial bytes of client traffic.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20protocol_detection%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20protocol_detection%20%3E%20(schema)>)

<details>

<summary>

class TLSSettings: …

Specify whether to inspect encrypted HTTP traffic.

</summary>

enabled: Optional\[bool]

Specify whether to inspect encrypted HTTP traffic.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20tls_settings%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20tls_settings%20%3E%20(schema)>)

<details>

<summary>

class ConfigurationGetResponse: …

Specify account settings.

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

settings: Optional\[GatewayConfigurationSettings]

Specify account settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_get_response%20%3E%20(schema)%20%3E%20(property)%20settings">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_get_response%20%3E%20(schema)>)

<details>

<summary>

class ConfigurationUpdateResponse: …

Specify account settings.

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

settings: Optional\[GatewayConfigurationSettings]

Specify account settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_update_response%20%3E%20(schema)%20%3E%20(property)%20settings">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_update_response%20%3E%20(schema)>)

<details>

<summary>

class ConfigurationEditResponse: …

Specify account settings.

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

settings: Optional\[GatewayConfigurationSettings]

Specify account settings.

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_edit_response%20%3E%20(schema)%20%3E%20(property)%20settings">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_edit_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20configuration_edit_response%20%3E%20(schema)>)

#### GatewayConfigurationsCustom Certificate

##### [Get Zero Trust certificate configuration](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/configurations/subresources/custom_certificate/methods/get)

Deprecated

zero\_trust.gateway.configurations.custom\_certificate.get(CustomCertificateGetParams\*\*kwargs) -> [CustomCertificateSettings](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.configurations%20%3E%20(model)%20custom_certificate_settings%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/configuration/custom\_certificate

#### GatewayLists

##### [List Zero Trust lists](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/methods/list)

zero\_trust.gateway.lists.list(ListListParams\*\*kwargs) -> SyncSinglePage\[[GatewayList](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/lists

##### [Get Zero Trust list details](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/methods/get)

zero\_trust.gateway.lists.get(strlist\_id, ListGetParams\*\*kwargs) -> [GatewayList](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/lists/{list\_id}

##### [Create Zero Trust list](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/methods/create)

zero\_trust.gateway.lists.create(ListCreateParams\*\*kwargs) -> [ListCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/lists

##### [Update Zero Trust list](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/methods/update)

zero\_trust.gateway.lists.update(strlist\_id, ListUpdateParams\*\*kwargs) -> [GatewayList](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/lists/{list\_id}

##### [Patch Zero Trust list.](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/methods/edit)

zero\_trust.gateway.lists.edit(strlist\_id, ListEditParams\*\*kwargs) -> [GatewayList](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/gateway/lists/{list\_id}

##### [Delete Zero Trust list](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/methods/delete)

zero\_trust.gateway.lists.delete(strlist\_id, ListDeleteParams\*\*kwargs) -> object

DELETE/accounts/{account\_id}/gateway/lists/{list\_id}

##### ModelsExpand Collapse

<details>

<summary>

class GatewayItem: …

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Provide the list item description (optional).

minimum0

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

value: Optional\[str]

Specify the item value.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)>)

<details>

<summary>

class GatewayList: …

</summary>

id: Optional\[str]

Identify the API resource with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

count: Optional\[float]

Indicate the number of items in the list.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20count">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Provide the list description.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

items: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)">GatewayItem</a>]]

Provide the list items.

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Provide the list item description (optional).

minimum0

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

value: Optional\[str]

Specify the item value.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

name: Optional\[str]

Specify the list name.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["SERIAL", "URL", "DOMAIN", 6 more]]

Specify the list type.

</summary>

One of the following:

"SERIAL"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"URL"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"EMAIL"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"IP"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"CATEGORY"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"LOCATION"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"DEVICE"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"AAGUID"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_list%20%3E%20(schema)>)

<details>

<summary>

class ListCreateResponse: …

</summary>

id: Optional\[str]

Identify the API resource with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Provide the list description.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

items: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)">GatewayItem</a>]]

Provide the list items.

</summary>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Provide the list item description (optional).

minimum0

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

value: Optional\[str]

Specify the item value.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

name: Optional\[str]

Specify the list name.

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["SERIAL", "URL", "DOMAIN", 6 more]]

Specify the list type.

</summary>

One of the following:

"SERIAL"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"URL"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"DOMAIN"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"EMAIL"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"IP"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"CATEGORY"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"LOCATION"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"DEVICE"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"AAGUID"

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20list_create_response%20%3E%20(schema)>)

#### GatewayListsItems

##### [Get Zero Trust list items](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/lists/subresources/items/methods/list)

zero\_trust.gateway.lists.items.list(strlist\_id, ItemListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[GatewayItem](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.lists%20%3E%20(model)%20gateway_item%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/lists/{list\_id}/items

#### GatewayLocations

##### [List Zero Trust Gateway locations](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/locations/methods/list)

zero\_trust.gateway.locations.list(LocationListParams\*\*kwargs) -> SyncSinglePage\[[Location](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/locations

##### [Get Zero Trust Gateway location details](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/locations/methods/get)

zero\_trust.gateway.locations.get(strlocation\_id, LocationGetParams\*\*kwargs) -> [Location](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/locations/{location\_id}

##### [Create a Zero Trust Gateway location](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/locations/methods/create)

zero\_trust.gateway.locations.create(LocationCreateParams\*\*kwargs) -> [Location](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/locations

##### [Update a Zero Trust Gateway location](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/locations/methods/update)

zero\_trust.gateway.locations.update(strlocation\_id, LocationUpdateParams\*\*kwargs) -> [Location](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/locations/{location\_id}

##### [Delete a Zero Trust Gateway location](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/locations/methods/delete)

zero\_trust.gateway.locations.delete(strlocation\_id, LocationDeleteParams\*\*kwargs) -> object

DELETE/accounts/{account\_id}/gateway/locations/{location\_id}

##### ModelsExpand Collapse

<details>

<summary>

class DOHEndpoint: …

</summary>

enabled: Optional\[bool]

Indicate whether the DOH endpoint is enabled for this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20doh_endpoint%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

networks: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ip_network%20%3E%20(schema)">IPNetwork</a>]]

Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.

</summary>

network: str

Specify the IP address or IP CIDR.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ip_network%20%3E%20(schema)%20%3E%20(property)%20network">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20doh_endpoint%20%3E%20(schema)%20%3E%20(property)%20networks">Link to this property</a>

require\_token: Optional\[bool]

Specify whether the DOH endpoint requires user identity authentication.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20doh_endpoint%20%3E%20(schema)%20%3E%20(property)%20require_token">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20doh_endpoint%20%3E%20(schema)>)

<details>

<summary>

class DOTEndpoint: …

</summary>

enabled: Optional\[bool]

Indicate whether the DOT endpoint is enabled for this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20dot_endpoint%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

networks: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ip_network%20%3E%20(schema)">IPNetwork</a>]]

Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.

</summary>

network: str

Specify the IP address or IP CIDR.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ip_network%20%3E%20(schema)%20%3E%20(property)%20network">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20dot_endpoint%20%3E%20(schema)%20%3E%20(property)%20networks">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20dot_endpoint%20%3E%20(schema)>)

<details>

<summary>

class Endpoint: …

Configure the destination endpoints for this location.

</summary>

doh: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20doh_endpoint%20%3E%20(schema)">DOHEndpoint</a>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20endpoint%20%3E%20(schema)%20%3E%20(property)%20doh">Link to this property</a>

dot: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20dot_endpoint%20%3E%20(schema)">DOTEndpoint</a>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20endpoint%20%3E%20(schema)%20%3E%20(property)%20dot">Link to this property</a>

ipv4: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv4_endpoint%20%3E%20(schema)">IPV4Endpoint</a>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20endpoint%20%3E%20(schema)%20%3E%20(property)%20ipv4">Link to this property</a>

ipv6: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_endpoint%20%3E%20(schema)">IPV6Endpoint</a>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20endpoint%20%3E%20(schema)%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20endpoint%20%3E%20(schema)>)

<details>

<summary>

class IPNetwork: …

</summary>

network: str

Specify the IP address or IP CIDR.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ip_network%20%3E%20(schema)%20%3E%20(property)%20network">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ip_network%20%3E%20(schema)>)

<details>

<summary>

class IPV4Endpoint: …

</summary>

enabled: Optional\[bool]

Indicate whether the IPv4 endpoint is enabled for this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv4_endpoint%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv4_endpoint%20%3E%20(schema)>)

<details>

<summary>

class IPV6Endpoint: …

</summary>

enabled: Optional\[bool]

Indicate whether the IPV6 endpoint is enabled for this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_endpoint%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

networks: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_network%20%3E%20(schema)">IPV6Network</a>]]

Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.

</summary>

network: str

Specify the IPv6 address or IPv6 CIDR.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_network%20%3E%20(schema)%20%3E%20(property)%20network">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_endpoint%20%3E%20(schema)%20%3E%20(property)%20networks">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_endpoint%20%3E%20(schema)>)

<details>

<summary>

class IPV6Network: …

</summary>

network: str

Specify the IPv6 address or IPv6 CIDR.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_network%20%3E%20(schema)%20%3E%20(property)%20network">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20ipv6_network%20%3E%20(schema)>)

<details>

<summary>

class Location: …

</summary>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

client\_default: Optional\[bool]

Indicate whether this location is the default location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20client_default">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

dns\_destination\_ips\_id: Optional\[str]

Indicate the identifier of the pair of IPv4 addresses assigned to this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20dns_destination_ips_id">Link to this property</a>

dns\_destination\_ipv6\_block\_id: Optional\[str]

Specify the UUID of the IPv6 block brought to the gateway so that this location’s IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20dns_destination_ipv6_block_id">Link to this property</a>

doh\_subdomain: Optional\[str]

Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20doh_subdomain">Link to this property</a>

ecs\_support: Optional\[bool]

Indicate whether the location must resolve EDNS queries.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20ecs_support">Link to this property</a>

endpoints: Optional\[Endpoint]

Configure the destination endpoints for this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20endpoints">Link to this property</a>

ip: Optional\[str]

Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

ipv4\_destination: Optional\[str]

Show the primary destination IPv4 address from the pair identified dns\_destination\_ips\_id. This field read-only.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20ipv4_destination">Link to this property</a>

ipv4\_destination\_backup: Optional\[str]

Show the backup destination IPv4 address from the pair identified dns\_destination\_ips\_id. This field read-only.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20ipv4_destination_backup">Link to this property</a>

<details>

<summary>

max\_ttl: Optional\[MaxTTL]

Controls how DNS response TTLs are capped for this location relative to the account <code>max_ttl_secs</code> setting. Omitting <code>max_ttl</code> on update resets it to <code>inherit</code>.

</summary>

<details>

<summary>

mode: Literal\["inherit", "override", "disabled"]

<code>inherit</code> uses the account <code>max_ttl_secs</code>. <code>override</code> uses this location’s <code>ttl_secs</code>. <code>disabled</code> leaves returned TTLs unchanged.

</summary>

One of the following:

"inherit"

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20max_ttl%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

"override"

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20max_ttl%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20max_ttl%20%3E%20(property)%20mode%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20max_ttl%20%3E%20(property)%20mode">Link to this property</a>

ttl\_secs: Optional\[int]

Location-specific cap on DNS response TTLs, in seconds. Required when <code>mode</code> is <code>override</code>. Must be omitted when <code>mode</code> is <code>inherit</code> or <code>disabled</code>.

maximum36000

minimum60

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20max_ttl%20%3E%20(property)%20ttl_secs">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20max_ttl">Link to this property</a>

name: Optional\[str]

Specify the location name.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

networks: Optional\[List\[Network]]

Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.

</summary>

network: str

Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24.

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20networks%20%3E%20(items)%20%3E%20(property)%20network">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20networks">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.locations%20%3E%20(model)%20location%20%3E%20(schema)>)

#### GatewayLogging

##### [Get logging settings for the Zero Trust account](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/logging/methods/get)

zero\_trust.gateway.logging.get(LoggingGetParams\*\*kwargs) -> [LoggingSetting](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/logging

##### [Update Zero Trust account logging settings](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/logging/methods/update)

zero\_trust.gateway.logging.update(LoggingUpdateParams\*\*kwargs) -> [LoggingSetting](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/logging

##### ModelsExpand Collapse

<details>

<summary>

class LoggingSetting: …

</summary>

redact\_pii: Optional\[bool]

Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent).

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20redact_pii">Link to this property</a>

<details>

<summary>

settings\_by\_rule\_type: Optional\[SettingsByRuleType]

Configure logging settings for each rule type.

</summary>

<details>

<summary>

dns: Optional\[SettingsByRuleTypeDNS]

Configure logging settings for DNS firewall.

</summary>

log\_all: Optional\[bool]

Specify whether to log all requests to this service.

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20dns%20%3E%20(property)%20log_all">Link to this property</a>

log\_blocks: Optional\[bool]

Specify whether to log only blocking requests to this service.

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20dns%20%3E%20(property)%20log_blocks">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20dns">Link to this property</a>

<details>

<summary>

http: Optional\[SettingsByRuleTypeHTTP]

Configure logging settings for HTTP/HTTPS firewall.

</summary>

log\_all: Optional\[bool]

Specify whether to log all requests to this service.

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20http%20%3E%20(property)%20log_all">Link to this property</a>

log\_blocks: Optional\[bool]

Specify whether to log only blocking requests to this service.

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20http%20%3E%20(property)%20log_blocks">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20http">Link to this property</a>

<details>

<summary>

l4: Optional\[SettingsByRuleTypeL4]

Configure logging settings for Network firewall.

</summary>

log\_all: Optional\[bool]

Specify whether to log all requests to this service.

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20l4%20%3E%20(property)%20log_all">Link to this property</a>

log\_blocks: Optional\[bool]

Specify whether to log only blocking requests to this service.

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20l4%20%3E%20(property)%20log_blocks">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type%20%3E%20(property)%20l4">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)%20%3E%20(property)%20settings_by_rule_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.logging%20%3E%20(model)%20logging_setting%20%3E%20(schema)>)

#### GatewayProxy Endpoints

##### [List proxy endpoints](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/list)

zero\_trust.gateway.proxy\_endpoints.list(ProxyEndpointListParams\*\*kwargs) -> SyncSinglePage\[[ProxyEndpoint](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/proxy\_endpoints

##### [Get a proxy endpoint](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/get)

zero\_trust.gateway.proxy\_endpoints.get(strproxy\_endpoint\_id, ProxyEndpointGetParams\*\*kwargs) -> [ProxyEndpoint](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/proxy\_endpoints/{proxy\_endpoint\_id}

##### [Create a proxy endpoint](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/create)

zero\_trust.gateway.proxy\_endpoints.create(ProxyEndpointCreateParams\*\*kwargs) -> [ProxyEndpoint](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/proxy\_endpoints

##### [Update a proxy endpoint](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/edit)

zero\_trust.gateway.proxy\_endpoints.edit(strproxy\_endpoint\_id, ProxyEndpointEditParams\*\*kwargs) -> [ProxyEndpoint](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/gateway/proxy\_endpoints/{proxy\_endpoint\_id}

##### [Delete a proxy endpoint](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/delete)

zero\_trust.gateway.proxy\_endpoints.delete(strproxy\_endpoint\_id, ProxyEndpointDeleteParams\*\*kwargs) -> object

DELETE/accounts/{account\_id}/gateway/proxy\_endpoints/{proxy\_endpoint\_id}

##### ModelsExpand Collapse

str

Specify an IPv4 or IPv6 CIDR. Limit IPv6 to a maximum of /109 and IPv4 to a maximum of /25.

[Link to this property](<#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20gateway_ips%20%3E%20(schema)>)

<details>

<summary>

<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)">ProxyEndpoint</a>

</summary>

One of the following:

<details>

<summary>

class ZeroTrustGatewayProxyEndpointIP: …

</summary>

ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20gateway_ips%20%3E%20(schema)">GatewayIPs</a>]

Specify the list of CIDRs to restrict ingress connections.

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20ips">Link to this property</a>

name: str

Specify the name of the proxy endpoint.

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

kind: Optional\[Literal\["ip"]]

The proxy endpoint kind

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20kind">Link to this property</a>

subdomain: Optional\[str]

Specify the subdomain to use as the destination in the proxy client.

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20subdomain">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

class ZeroTrustGatewayProxyEndpointIdentity: …

</summary>

kind: Literal\["identity"]

The proxy endpoint kind

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20kind">Link to this property</a>

name: str

Specify the name of the proxy endpoint.

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

subdomain: Optional\[str]

Specify the subdomain to use as the destination in the proxy client.

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20subdomain">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.proxy_endpoints%20%3E%20(model)%20proxy_endpoint%20%3E%20(schema)>)

#### GatewayRules

##### [List Zero Trust Gateway rules](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/list)

zero\_trust.gateway.rules.list(RuleListParams\*\*kwargs) -> SyncSinglePage\[[GatewayRule](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/rules

##### [Get Zero Trust Gateway rule details.](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/get)

zero\_trust.gateway.rules.get(strrule\_id, RuleGetParams\*\*kwargs) -> [GatewayRule](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/rules/{rule\_id}

##### [Create a Zero Trust Gateway rule](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/create)

zero\_trust.gateway.rules.create(RuleCreateParams\*\*kwargs) -> [GatewayRule](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/rules

##### [Update a Zero Trust Gateway rule](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/update)

zero\_trust.gateway.rules.update(strrule\_id, RuleUpdateParams\*\*kwargs) -> [GatewayRule](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/rules/{rule\_id}

##### [Delete a Zero Trust Gateway rule](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/delete)

zero\_trust.gateway.rules.delete(strrule\_id, RuleDeleteParams\*\*kwargs) -> object

DELETE/accounts/{account\_id}/gateway/rules/{rule\_id}

##### [List Zero Trust Gateway rules inherited from the parent account](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/list_tenant)

zero\_trust.gateway.rules.list\_tenant(RuleListTenantParams\*\*kwargs) -> SyncSinglePage\[[GatewayRule](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/rules/tenant

##### [Reset the expiration of a Zero Trust Gateway Rule](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/rules/methods/reset_expiration)

zero\_trust.gateway.rules.reset\_expiration(strrule\_id, RuleResetExpirationParams\*\*kwargs) -> [GatewayRule](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/rules/{rule\_id}/reset\_expiration

##### ModelsExpand Collapse

<details>

<summary>

class DNSResolverSettingsV4: …

</summary>

ip: str

Specify the IPv4 address of the upstream resolver.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

port: Optional\[int]

Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20port">Link to this property</a>

route\_through\_private\_network: Optional\[bool]

Indicate whether to connect to this resolver over a private network. Must set when vnet\_id set.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20route_through_private_network">Link to this property</a>

vnet\_id: Optional\[str]

Specify an optional virtual network for this resolver. Uses default virtual network id if omitted.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)>)

<details>

<summary>

class DNSResolverSettingsV6: …

</summary>

ip: str

Specify the IPv6 address of the upstream resolver.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

port: Optional\[int]

Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20port">Link to this property</a>

route\_through\_private\_network: Optional\[bool]

Indicate whether to connect to this resolver over a private network. Must set when vnet\_id set.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20route_through_private_network">Link to this property</a>

vnet\_id: Optional\[str]

Specify an optional virtual network for this resolver. Uses default virtual network id if omitted.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)>)

<details>

<summary>

Literal\["http", "dns", "l4", 2 more]

Specify the protocol or layer to use.

</summary>

One of the following:

"http"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"dns"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"l4"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"egress"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"dns\_resolver"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)>)

<details>

<summary>

class GatewayRule: …

</summary>

<details>

<summary>

action: Literal\["on", "off", "allow", 13 more]

Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to <code>true</code>.

</summary>

One of the following:

"on"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

"off"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

"allow"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%202">Link to this property</a>

"block"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%203">Link to this property</a>

"scan"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%204">Link to this property</a>

"noscan"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%205">Link to this property</a>

"safesearch"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%206">Link to this property</a>

"ytrestricted"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%207">Link to this property</a>

"isolate"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%208">Link to this property</a>

"noisolate"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%209">Link to this property</a>

"override"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%2010">Link to this property</a>

"l4\_override"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%2011">Link to this property</a>

"egress"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%2012">Link to this property</a>

"resolve"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%2013">Link to this property</a>

"quarantine"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%2014">Link to this property</a>

"redirect"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

enabled: bool

Specify whether the rule is enabled.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

filters: List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)">GatewayFilter</a>]

Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value.

</summary>

One of the following:

"http"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"dns"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"l4"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"egress"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"dns\_resolver"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_filter%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20filters">Link to this property</a>

name: str

Specify the rule name.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

precedence: int

Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to <a href="http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform">Order of enforcement</a> to manage precedence via Terraform.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20precedence">Link to this property</a>

traffic: str

Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20traffic">Link to this property</a>

id: Optional\[str]

Identify the API resource with a UUID.

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

deleted\_at: Optional\[datetime]

Indicate the date of deletion, if any.

formatdate-time

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20deleted_at">Link to this property</a>

description: Optional\[str]

Specify the rule description.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

device\_posture: Optional\[str]

Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

<details>

<summary>

expiration: Optional\[Expiration]

Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy’s <code>schedule</code> configuration, if any. This does not apply to HTTP or network policies. Settable only for <code>dns</code> rules.

</summary>

expires\_at: datetime

Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires\_at time.

formatdate-time

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20expiration%20%3E%20(property)%20expires_at">Link to this property</a>

duration: Optional\[int]

Defines the default duration a policy active in minutes. Must set in order to use the <code>reset_expiration</code> endpoint on this rule.

minimum5

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20expiration%20%3E%20(property)%20duration">Link to this property</a>

expired: Optional\[bool]

Indicates whether the policy is expired.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20expiration%20%3E%20(property)%20expired">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20expiration">Link to this property</a>

identity: Optional\[str]

Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20identity">Link to this property</a>

read\_only: Optional\[bool]

Indicate that this rule is shared via the Orgs API and read only.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

rule\_settings: Optional\[RuleSetting]

Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20rule_settings">Link to this property</a>

schedule: Optional\[Schedule]

Defines the schedule for activating DNS policies. Settable only for <code>dns</code> and <code>dns_resolver</code> rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20schedule">Link to this property</a>

sharable: Optional\[bool]

Indicate that this rule is sharable via the Orgs API.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20sharable">Link to this property</a>

source\_account: Optional\[str]

Provide the account tag of the account that created the rule.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20source_account">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

version: Optional\[int]

Indicate the version number of the rule(read-only).

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

warning\_status: Optional\[str]

Indicate a warning for a misconfigured rule, if any.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)%20%3E%20(property)%20warning_status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20gateway_rule%20%3E%20(schema)>)

<details>

<summary>

class RuleSetting: …

Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.

</summary>

add\_headers: Optional\[Dict\[str, List\[str]]]

Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain <code>@{selector.name}</code> variable references that are interpolated at the edge. Use <code>@@{</code> to escape a literal <code>@{</code>. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for <code>http</code> rules with the action set to <code>allow</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20add_headers">Link to this property</a>

allow\_child\_bypass: Optional\[bool]

Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20allow_child_bypass">Link to this property</a>

<details>

<summary>

audit\_ssh: Optional\[AuditSSH]

Define the settings for the Audit SSH action. Settable only for <code>l4</code> rules with <code>audit_ssh</code> action.

</summary>

command\_logging: Optional\[bool]

Enable SSH command logging.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20audit_ssh%20%3E%20(property)%20command_logging">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20audit_ssh">Link to this property</a>

<details>

<summary>

biso\_admin\_controls: Optional\[BISOAdminControls]

Configure browser isolation behavior. Settable only for <code>http</code> rules with the action set to <code>isolate</code>.

</summary>

<details>

<summary>

copy: Optional\[Literal\["enabled", "disabled", "remote\_only"]]

Configure copy behavior. If set to remote\_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == “v2”.

</summary>

One of the following:

"enabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20copy%20%3E%20(member)%200">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20copy%20%3E%20(member)%201">Link to this property</a>

"remote\_only"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20copy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20copy">Link to this property</a>

dcp: Optional\[bool]

Set to false to enable copy-pasting. Only applies when <code>version == "v1"</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20dcp">Link to this property</a>

dd: Optional\[bool]

Set to false to enable downloading. Only applies when <code>version == "v1"</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20dd">Link to this property</a>

dk: Optional\[bool]

Set to false to enable keyboard usage. Only applies when <code>version == "v1"</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20dk">Link to this property</a>

<details>

<summary>

download: Optional\[Literal\["enabled", "disabled", "remote\_only"]]

Configure download behavior. When set to remote\_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == “v2”.

</summary>

One of the following:

"enabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20download%20%3E%20(member)%200">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20download%20%3E%20(member)%201">Link to this property</a>

"remote\_only"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20download%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20download">Link to this property</a>

dp: Optional\[bool]

Set to false to enable printing. Only applies when <code>version == "v1"</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20dp">Link to this property</a>

du: Optional\[bool]

Set to false to enable uploading. Only applies when <code>version == "v1"</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20du">Link to this property</a>

<details>

<summary>

keyboard: Optional\[Literal\["enabled", "disabled"]]

Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == “v2”.

</summary>

One of the following:

"enabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20keyboard%20%3E%20(member)%200">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20keyboard%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20keyboard">Link to this property</a>

<details>

<summary>

paste: Optional\[Literal\["enabled", "disabled", "remote\_only"]]

Configure paste behavior. If set to remote\_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == “v2”.

</summary>

One of the following:

"enabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20paste%20%3E%20(member)%200">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20paste%20%3E%20(member)%201">Link to this property</a>

"remote\_only"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20paste%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20paste">Link to this property</a>

<details>

<summary>

printing: Optional\[Literal\["enabled", "disabled"]]

Configure print behavior. Default, Printing is enabled. Applies only when version == “v2”.

</summary>

One of the following:

"enabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20printing%20%3E%20(member)%200">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20printing%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20printing">Link to this property</a>

<details>

<summary>

upload: Optional\[Literal\["enabled", "disabled"]]

Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == “v2”.

</summary>

One of the following:

"enabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20upload%20%3E%20(member)%200">Link to this property</a>

"disabled"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20upload%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20upload">Link to this property</a>

<details>

<summary>

version: Optional\[Literal\["v1", "v2"]]

Indicate which version of the browser isolation controls should apply.

</summary>

One of the following:

"v1"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20version%20%3E%20(member)%200">Link to this property</a>

"v2"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20version%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20version">Link to this property</a>

wm\_id: Optional\[str]

Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser.

formatuuid

maxLength36

minLength1

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls%20%3E%20(property)%20wm_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20biso_admin_controls">Link to this property</a>

<details>

<summary>

block\_page: Optional\[BlockPage]

Configure custom block page settings. If missing or null, use the account settings. Settable only for <code>http</code> rules with the action set to <code>block</code>.

</summary>

target\_uri: str

Specify the URI to which the user is redirected.

formaturi

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20block_page%20%3E%20(property)%20target_uri">Link to this property</a>

include\_context: Optional\[bool]

Specify whether to pass the context information as query parameters.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20block_page%20%3E%20(property)%20include_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20block_page">Link to this property</a>

block\_page\_enabled: Optional\[bool]

Enable the custom block page. Settable only for <code>dns</code> rules with action <code>block</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20block_page_enabled">Link to this property</a>

block\_reason: Optional\[str]

Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for <code>dns</code>, <code>l4</code>, and <code>http</code> rules when the action set to <code>block</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20block_reason">Link to this property</a>

bypass\_parent\_rule: Optional\[bool]

Set to enable MSP accounts to bypass their parent’s rules. Only MSP child accounts can set this. Settable for all types of rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20bypass_parent_rule">Link to this property</a>

<details>

<summary>

check\_session: Optional\[CheckSession]

Configure session check behavior. Settable only for <code>l4</code> and <code>http</code> rules with the action set to <code>allow</code>.

</summary>

duration: Optional\[str]

Sets the required session freshness threshold. The API returns a normalized version of this value.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20check_session%20%3E%20(property)%20duration">Link to this property</a>

enforce: Optional\[bool]

Enable session enforcement.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20check_session%20%3E%20(property)%20enforce">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20check_session">Link to this property</a>

delete\_headers: Optional\[List\[str]]

Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for <code>http</code> rules with the action set to <code>allow</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20delete_headers">Link to this property</a>

<details>

<summary>

dns\_resolvers: Optional\[DNSResolvers]

Configure custom resolvers to route queries that match the resolver policy. Unused with ‘resolve\_dns\_through\_cloudflare’ or ‘resolve\_dns\_internally’ settings. DNS queries get routed to the address closest to their origin. Only valid when a rule’s action set to ‘resolve’. Settable only for <code>dns_resolver</code> rules.

</summary>

<details>

<summary>

ipv4: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)">DNSResolverSettingsV4</a>]]

</summary>

ip: str

Specify the IPv4 address of the upstream resolver.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

port: Optional\[int]

Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20port">Link to this property</a>

route\_through\_private\_network: Optional\[bool]

Indicate whether to connect to this resolver over a private network. Must set when vnet\_id set.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20route_through_private_network">Link to this property</a>

vnet\_id: Optional\[str]

Specify an optional virtual network for this resolver. Uses default virtual network id if omitted.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v4%20%3E%20(schema)%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20dns_resolvers%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)">DNSResolverSettingsV6</a>]]

</summary>

ip: str

Specify the IPv6 address of the upstream resolver.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

port: Optional\[int]

Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20port">Link to this property</a>

route\_through\_private\_network: Optional\[bool]

Indicate whether to connect to this resolver over a private network. Must set when vnet\_id set.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20route_through_private_network">Link to this property</a>

vnet\_id: Optional\[str]

Specify an optional virtual network for this resolver. Uses default virtual network id if omitted.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20dns_resolver_settings_v6%20%3E%20(schema)%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20dns_resolvers%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20dns_resolvers">Link to this property</a>

<details>

<summary>

egress: Optional\[Egress]

Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for <code>egress</code> rules.

</summary>

ipv4: Optional\[str]

Specify the IPv4 address to use for egress.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20egress%20%3E%20(property)%20ipv4">Link to this property</a>

ipv4\_fallback: Optional\[str]

Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set ‘0.0.0.0’ to indicate local egress via WARP IPs.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20egress%20%3E%20(property)%20ipv4_fallback">Link to this property</a>

ipv6: Optional\[str]

Specify the IPv6 range to use for egress.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20egress%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20egress">Link to this property</a>

<details>

<summary>

forensic\_copy: Optional\[ForensicCopy]

Configure whether a copy of the HTTP request will be sent to storage when the rule matches.

</summary>

enabled: Optional\[bool]

Enable sending the copy to storage.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20forensic_copy%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20forensic_copy">Link to this property</a>

ignore\_cname\_category\_matches: Optional\[bool]

Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for <code>dns</code> and <code>dns_resolver</code> rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20ignore_cname_category_matches">Link to this property</a>

insecure\_disable\_dnssec\_validation: Optional\[bool]

Specify whether to disable DNSSEC validation (for Allow actions) \[INSECURE]. Settable only for <code>dns</code> rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20insecure_disable_dnssec_validation">Link to this property</a>

ip\_categories: Optional\[bool]

Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for <code>dns</code> and <code>dns_resolver</code> rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20ip_categories">Link to this property</a>

ip\_indicator\_feeds: Optional\[bool]

Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for <code>dns</code> and <code>dns_resolver</code> rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20ip_indicator_feeds">Link to this property</a>

<details>

<summary>

l4override: Optional\[L4override]

Send matching traffic to the supplied destination IP address and port. Settable only for <code>l4</code> rules with the action set to <code>l4_override</code>.

</summary>

ip: Optional\[str]

Defines the IPv4 or IPv6 address.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20l4override%20%3E%20(property)%20ip">Link to this property</a>

port: Optional\[int]

Defines a port number to use for TCP/UDP overrides.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20l4override%20%3E%20(property)%20port">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20l4override">Link to this property</a>

<details>

<summary>

notification\_settings: Optional\[NotificationSettings]

Configure a notification to display on the user’s device when this rule matched. Settable for all types of rules with the action set to <code>block</code>.

</summary>

enabled: Optional\[bool]

Enable notification.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20notification_settings%20%3E%20(property)%20enabled">Link to this property</a>

include\_context: Optional\[bool]

Indicates whether to pass the context information as query parameters.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20notification_settings%20%3E%20(property)%20include_context">Link to this property</a>

msg: Optional\[str]

Customize the message shown in the notification.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20notification_settings%20%3E%20(property)%20msg">Link to this property</a>

support\_url: Optional\[str]

Defines an optional URL to direct users to additional information. If unset, the notification opens a block page.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20notification_settings%20%3E%20(property)%20support_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20notification_settings">Link to this property</a>

override\_host: Optional\[str]

Defines a hostname for override, for the matching DNS queries. Settable only for <code>dns</code> rules with the action set to <code>override</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20override_host">Link to this property</a>

override\_ips: Optional\[List\[str]]

Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for <code>dns</code> rules with the action set to <code>override</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20override_ips">Link to this property</a>

<details>

<summary>

payload\_log: Optional\[PayloadLog]

Configure DLP payload logging. Settable only for <code>http</code> rules.

</summary>

enabled: Optional\[bool]

Enable DLP payload logging for this rule.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20payload_log%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20payload_log">Link to this property</a>

<details>

<summary>

quarantine: Optional\[Quarantine]

Configure settings that apply to quarantine rules. Settable only for <code>http</code> rules.

</summary>

<details>

<summary>

file\_types: Optional\[List\[Literal\["exe", "pdf", "doc", 10 more]]]

Specify the types of files to sandbox.

</summary>

One of the following:

"exe"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"pdf"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"doc"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"docm"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"docx"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"rtf"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

"ppt"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%206">Link to this property</a>

"pptx"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%207">Link to this property</a>

"xls"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%208">Link to this property</a>

"xlsm"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%209">Link to this property</a>

"xlsx"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%2010">Link to this property</a>

"zip"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%2011">Link to this property</a>

"rar"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types%20%3E%20(items)%20%3E%20(member)%2012">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine%20%3E%20(property)%20file_types">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20quarantine">Link to this property</a>

<details>

<summary>

redirect: Optional\[Redirect]

Apply settings to redirect rules. Settable only for <code>http</code> rules with the action set to <code>redirect</code>.

</summary>

target\_uri: str

Specify the URI to which the user is redirected.

formaturi

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20redirect%20%3E%20(property)%20target_uri">Link to this property</a>

include\_context: Optional\[bool]

Specify whether to pass the context information as query parameters.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20redirect%20%3E%20(property)%20include_context">Link to this property</a>

preserve\_path\_and\_query: Optional\[bool]

Specify whether to append the path and query parameters from the original request to target\_uri.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20redirect%20%3E%20(property)%20preserve_path_and_query">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20redirect">Link to this property</a>

<details>

<summary>

resolve\_dns\_internally: Optional\[ResolveDNSInternally]

Configure to forward the query to the internal DNS service, passing the specified ‘view\_id’ as input. Not used when ‘dns\_resolvers’ is specified or ‘resolve\_dns\_through\_cloudflare’ is set. Only valid when a rule’s action set to ‘resolve’. Settable only for <code>dns_resolver</code> rules.

</summary>

<details>

<summary>

fallback: Optional\[Literal\["none", "public\_dns"]]

Specify the fallback behavior to apply when the internal DNS response code differs from ‘NOERROR’ or when the response data contains only CNAME records for ‘A’ or ‘AAAA’ queries.

</summary>

One of the following:

"none"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20resolve_dns_internally%20%3E%20(property)%20fallback%20%3E%20(member)%200">Link to this property</a>

"public\_dns"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20resolve_dns_internally%20%3E%20(property)%20fallback%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20resolve_dns_internally%20%3E%20(property)%20fallback">Link to this property</a>

view\_id: Optional\[str]

Specify the internal DNS view identifier to pass to the internal DNS service.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20resolve_dns_internally%20%3E%20(property)%20view_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20resolve_dns_internally">Link to this property</a>

resolve\_dns\_through\_cloudflare: Optional\[bool]

Enable to send queries that match the policy to Cloudflare’s default 1.1.1.1 DNS resolver. Cannot set when ‘dns\_resolvers’ specified or ‘resolve\_dns\_internally’ is set. Only valid when a rule’s action set to ‘resolve’. Settable only for <code>dns_resolver</code> rules.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20resolve_dns_through_cloudflare">Link to this property</a>

set\_headers: Optional\[Dict\[str, List\[str]]]

Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain <code>@{selector.name}</code> variable references that are interpolated at the edge. Use <code>@@{</code> to escape a literal <code>@{</code>. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for <code>http</code> rules with the action set to <code>allow</code>.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20set_headers">Link to this property</a>

<details>

<summary>

untrusted\_cert: Optional\[UntrustedCERT]

Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for <code>http</code> rules with the action set to <code>allow</code>.

</summary>

<details>

<summary>

action: Optional\[Literal\["pass\_through", "block", "error"]]

Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526.

</summary>

One of the following:

"pass\_through"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20untrusted_cert%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

"block"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20untrusted_cert%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20untrusted_cert%20%3E%20(property)%20action%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20untrusted_cert%20%3E%20(property)%20action">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)%20%3E%20(property)%20untrusted_cert">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20rule_setting%20%3E%20(schema)>)

<details>

<summary>

class Schedule: …

Defines the schedule for activating DNS policies. Settable only for <code>dns</code> and <code>dns_resolver</code> rules.

</summary>

fri: Optional\[str]

Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20fri">Link to this property</a>

mon: Optional\[str]

Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20mon">Link to this property</a>

sat: Optional\[str]

Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20sat">Link to this property</a>

sun: Optional\[str]

Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20sun">Link to this property</a>

thu: Optional\[str]

Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20thu">Link to this property</a>

time\_zone: Optional\[str]

Specify the time zone for rule evaluation. When a <a href="https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List">valid time zone city name</a> is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user’s IP address. Colo time zone is used when the user’s IP address does not resolve to a location.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20time_zone">Link to this property</a>

tue: Optional\[str]

Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20tue">Link to this property</a>

wed: Optional\[str]

Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used.

<a href="#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)%20%3E%20(property)%20wed">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.rules%20%3E%20(model)%20schedule%20%3E%20(schema)>)

#### GatewayCertificates

##### [List Zero Trust certificates](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/certificates/methods/list)

zero\_trust.gateway.certificates.list(CertificateListParams\*\*kwargs) -> SyncSinglePage\[[CertificateListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/certificates

##### [Get Zero Trust certificate details](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/certificates/methods/get)

zero\_trust.gateway.certificates.get(strcertificate\_id, CertificateGetParams\*\*kwargs) -> [CertificateGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/certificates/{certificate\_id}

##### [Create Zero Trust certificate](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/certificates/methods/create)

zero\_trust.gateway.certificates.create(CertificateCreateParams\*\*kwargs) -> [CertificateCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/certificates

##### [Delete Zero Trust certificate](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/certificates/methods/delete)

zero\_trust.gateway.certificates.delete(strcertificate\_id, CertificateDeleteParams\*\*kwargs) -> [CertificateDeleteResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/gateway/certificates/{certificate\_id}

##### [Activate a Zero Trust certificate](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/certificates/methods/activate)

zero\_trust.gateway.certificates.activate(strcertificate\_id, CertificateActivateParams\*\*kwargs) -> [CertificateActivateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/certificates/{certificate\_id}/activate

##### [Deactivate a Zero Trust certificate](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/certificates/methods/deactivate)

zero\_trust.gateway.certificates.deactivate(strcertificate\_id, CertificateDeactivateParams\*\*kwargs) -> [CertificateDeactivateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/certificates/{certificate\_id}/deactivate

##### ModelsExpand Collapse

<details>

<summary>

class CertificateListResponse: …

</summary>

id: Optional\[str]

Identify the certificate with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

binding\_status: Optional\[Literal\["pending\_deployment", "available", "pending\_deletion", "inactive"]]

Indicate the read-only deployment status of the certificate on Cloudflare’s edge. Gateway TLS interception can use certificates in the ‘available’ (previously called ‘active’) state.

</summary>

One of the following:

"pending\_deployment"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%200">Link to this property</a>

"available"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%201">Link to this property</a>

"pending\_deletion"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%202">Link to this property</a>

"inactive"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

certificate: Optional\[str]

Provide the CA certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

expires\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

fingerprint: Optional\[str]

Provide the SHA256 fingerprint of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

in\_use: Optional\[bool]

Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named <code>certificate</code> (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20in_use">Link to this property</a>

issuer\_org: Optional\[str]

Indicate the organization that issued the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20issuer_org">Link to this property</a>

issuer\_raw: Optional\[str]

Provide the entire issuer field of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20issuer_raw">Link to this property</a>

region: Optional\[str]

Indicate the read-only region the certificate authority’s key material is pinned to. Omitted for certificates that were created without a region.

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20region">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed"]]

Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.

</summary>

One of the following:

"custom"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_list_response%20%3E%20(schema)>)

<details>

<summary>

class CertificateGetResponse: …

</summary>

id: Optional\[str]

Identify the certificate with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

binding\_status: Optional\[Literal\["pending\_deployment", "available", "pending\_deletion", "inactive"]]

Indicate the read-only deployment status of the certificate on Cloudflare’s edge. Gateway TLS interception can use certificates in the ‘available’ (previously called ‘active’) state.

</summary>

One of the following:

"pending\_deployment"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%200">Link to this property</a>

"available"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%201">Link to this property</a>

"pending\_deletion"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%202">Link to this property</a>

"inactive"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

certificate: Optional\[str]

Provide the CA certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

expires\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

fingerprint: Optional\[str]

Provide the SHA256 fingerprint of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

in\_use: Optional\[bool]

Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named <code>certificate</code> (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20in_use">Link to this property</a>

issuer\_org: Optional\[str]

Indicate the organization that issued the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20issuer_org">Link to this property</a>

issuer\_raw: Optional\[str]

Provide the entire issuer field of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20issuer_raw">Link to this property</a>

region: Optional\[str]

Indicate the read-only region the certificate authority’s key material is pinned to. Omitted for certificates that were created without a region.

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20region">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed"]]

Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.

</summary>

One of the following:

"custom"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_get_response%20%3E%20(schema)>)

<details>

<summary>

class CertificateCreateResponse: …

</summary>

id: Optional\[str]

Identify the certificate with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

binding\_status: Optional\[Literal\["pending\_deployment", "available", "pending\_deletion", "inactive"]]

Indicate the read-only deployment status of the certificate on Cloudflare’s edge. Gateway TLS interception can use certificates in the ‘available’ (previously called ‘active’) state.

</summary>

One of the following:

"pending\_deployment"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%200">Link to this property</a>

"available"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%201">Link to this property</a>

"pending\_deletion"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%202">Link to this property</a>

"inactive"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

certificate: Optional\[str]

Provide the CA certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

expires\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

fingerprint: Optional\[str]

Provide the SHA256 fingerprint of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

in\_use: Optional\[bool]

Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named <code>certificate</code> (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20in_use">Link to this property</a>

issuer\_org: Optional\[str]

Indicate the organization that issued the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20issuer_org">Link to this property</a>

issuer\_raw: Optional\[str]

Provide the entire issuer field of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20issuer_raw">Link to this property</a>

region: Optional\[str]

Indicate the read-only region the certificate authority’s key material is pinned to. Omitted for certificates that were created without a region.

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20region">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed"]]

Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.

</summary>

One of the following:

"custom"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_create_response%20%3E%20(schema)>)

<details>

<summary>

class CertificateDeleteResponse: …

</summary>

id: Optional\[str]

Identify the certificate with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

binding\_status: Optional\[Literal\["pending\_deployment", "available", "pending\_deletion", "inactive"]]

Indicate the read-only deployment status of the certificate on Cloudflare’s edge. Gateway TLS interception can use certificates in the ‘available’ (previously called ‘active’) state.

</summary>

One of the following:

"pending\_deployment"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%200">Link to this property</a>

"available"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%201">Link to this property</a>

"pending\_deletion"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%202">Link to this property</a>

"inactive"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

certificate: Optional\[str]

Provide the CA certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

expires\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

fingerprint: Optional\[str]

Provide the SHA256 fingerprint of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

in\_use: Optional\[bool]

Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named <code>certificate</code> (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20in_use">Link to this property</a>

issuer\_org: Optional\[str]

Indicate the organization that issued the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20issuer_org">Link to this property</a>

issuer\_raw: Optional\[str]

Provide the entire issuer field of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20issuer_raw">Link to this property</a>

region: Optional\[str]

Indicate the read-only region the certificate authority’s key material is pinned to. Omitted for certificates that were created without a region.

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20region">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed"]]

Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.

</summary>

One of the following:

"custom"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_delete_response%20%3E%20(schema)>)

<details>

<summary>

class CertificateActivateResponse: …

</summary>

id: Optional\[str]

Identify the certificate with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

binding\_status: Optional\[Literal\["pending\_deployment", "available", "pending\_deletion", "inactive"]]

Indicate the read-only deployment status of the certificate on Cloudflare’s edge. Gateway TLS interception can use certificates in the ‘available’ (previously called ‘active’) state.

</summary>

One of the following:

"pending\_deployment"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%200">Link to this property</a>

"available"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%201">Link to this property</a>

"pending\_deletion"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%202">Link to this property</a>

"inactive"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

certificate: Optional\[str]

Provide the CA certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

expires\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

fingerprint: Optional\[str]

Provide the SHA256 fingerprint of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

in\_use: Optional\[bool]

Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named <code>certificate</code> (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20in_use">Link to this property</a>

issuer\_org: Optional\[str]

Indicate the organization that issued the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20issuer_org">Link to this property</a>

issuer\_raw: Optional\[str]

Provide the entire issuer field of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20issuer_raw">Link to this property</a>

region: Optional\[str]

Indicate the read-only region the certificate authority’s key material is pinned to. Omitted for certificates that were created without a region.

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20region">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed"]]

Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.

</summary>

One of the following:

"custom"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_activate_response%20%3E%20(schema)>)

<details>

<summary>

class CertificateDeactivateResponse: …

</summary>

id: Optional\[str]

Identify the certificate with a UUID.

maxLength36

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

binding\_status: Optional\[Literal\["pending\_deployment", "available", "pending\_deletion", "inactive"]]

Indicate the read-only deployment status of the certificate on Cloudflare’s edge. Gateway TLS interception can use certificates in the ‘available’ (previously called ‘active’) state.

</summary>

One of the following:

"pending\_deployment"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%200">Link to this property</a>

"available"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%201">Link to this property</a>

"pending\_deletion"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%202">Link to this property</a>

"inactive"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20binding_status">Link to this property</a>

certificate: Optional\[str]

Provide the CA certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

expires\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

fingerprint: Optional\[str]

Provide the SHA256 fingerprint of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20fingerprint">Link to this property</a>

in\_use: Optional\[bool]

Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named <code>certificate</code> (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20in_use">Link to this property</a>

issuer\_org: Optional\[str]

Indicate the organization that issued the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20issuer_org">Link to this property</a>

issuer\_raw: Optional\[str]

Provide the entire issuer field of the certificate (read-only).

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20issuer_raw">Link to this property</a>

region: Optional\[str]

Indicate the read-only region the certificate authority’s key material is pinned to. Omitted for certificates that were created without a region.

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20region">Link to this property</a>

<details>

<summary>

type: Optional\[Literal\["custom", "gateway\_managed"]]

Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.

</summary>

One of the following:

"custom"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"gateway\_managed"

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

uploaded\_on: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)%20%3E%20(property)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.certificates%20%3E%20(model)%20certificate_deactivate_response%20%3E%20(schema)>)

#### GatewayPacfiles

##### [List PAC files](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/list)

zero\_trust.gateway.pacfiles.list(PacfileListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[PacfileListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/gateway/pacfiles

##### [Get a PAC file](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/get)

zero\_trust.gateway.pacfiles.get(strpacfile\_id, PacfileGetParams\*\*kwargs) -> [PacfileGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/gateway/pacfiles/{pacfile\_id}

##### [Create a PAC file](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/create)

zero\_trust.gateway.pacfiles.create(PacfileCreateParams\*\*kwargs) -> [PacfileCreateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/gateway/pacfiles

##### [Update a Zero Trust Gateway PAC file](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/update)

zero\_trust.gateway.pacfiles.update(strpacfile\_id, PacfileUpdateParams\*\*kwargs) -> [PacfileUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/gateway/pacfiles/{pacfile\_id}

##### [Delete a PAC file](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/delete)

zero\_trust.gateway.pacfiles.delete(strpacfile\_id, PacfileDeleteParams\*\*kwargs) -> object

DELETE/accounts/{account\_id}/gateway/pacfiles/{pacfile\_id}

##### ModelsExpand Collapse

<details>

<summary>

class PacfileListResponse: …

</summary>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Detailed description of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Name of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

slug: Optional\[str]

URL-friendly version of the PAC file name.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20slug">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: Optional\[str]

Unique URL to download the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_list_response%20%3E%20(schema)>)

<details>

<summary>

class PacfileGetResponse: …

</summary>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

contents: Optional\[str]

Actual contents of the PAC file

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20contents">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Detailed description of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Name of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

slug: Optional\[str]

URL-friendly version of the PAC file name.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20slug">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: Optional\[str]

Unique URL to download the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_get_response%20%3E%20(schema)>)

<details>

<summary>

class PacfileCreateResponse: …

</summary>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

contents: Optional\[str]

Actual contents of the PAC file

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20contents">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Detailed description of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Name of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

slug: Optional\[str]

URL-friendly version of the PAC file name.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20slug">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: Optional\[str]

Unique URL to download the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_create_response%20%3E%20(schema)>)

<details>

<summary>

class PacfileUpdateResponse: …

</summary>

id: Optional\[str]

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

contents: Optional\[str]

Actual contents of the PAC file

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20contents">Link to this property</a>

created\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

description: Optional\[str]

Detailed description of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

name: Optional\[str]

Name of the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

slug: Optional\[str]

URL-friendly version of the PAC file name.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20slug">Link to this property</a>

updated\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: Optional\[str]

Unique URL to download the PAC file.

<a href="#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.gateway.pacfiles%20%3E%20(model)%20pacfile_update_response%20%3E%20(schema)>)