---
title: List Access identity providers
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Zero Trust](https://developers.cloudflare.com/api/python/resources/zero_trust)

[Identity Providers](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/identity_providers)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List Access identity providers

zero\_trust.identity\_providers.list(IdentityProviderListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[IdentityProviderListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)>)]

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers

Lists all configured identity providers.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Access: Organizations, Identity Providers, and Groups Write``Access: Organizations, Identity Providers, and Groups Read`

##### ParametersExpand Collapse

account\_id: Optional\[str]

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

zone\_id: Optional\[str]

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone_id%20%3E%20(schema)>)

page: Optional\[int]

Page number of results.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page%20%3E%20(schema)>)

per\_page: Optional\[int]

Number of results per page.

maximum1000

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page%20%3E%20(schema)>)

scim\_enabled: Optional\[str]

Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20scim_enabled%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

<a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)">IdentityProviderListResponse</a>

</summary>

One of the following:

<details>

<summary>

class AzureAD: …

</summary>

<details>

<summary>

config: Config

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

conditional\_access\_enabled: Optional\[bool]

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20conditional_access_enabled">Link to this property</a>

directory\_id: Optional\[str]

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20directory_id">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

prompt: Optional\[Literal\["login", "select\_account", "none"]]

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

</summary>

One of the following:

"login"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

"select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

"none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

support\_groups: Optional\[bool]

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config%20%3E%20(property)%20support_groups">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[SAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[SAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20azure_ad%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class AccessCentrify: …

</summary>

<details>

<summary>

config: AccessCentrifyConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

centrify\_account: Optional\[str]

Your centrify account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20centrify_account">Link to this property</a>

centrify\_app\_id: Optional\[str]

Your centrify app id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20centrify_app_id">Link to this property</a>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessCentrifySAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessCentrifySAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

class AccessFacebook: …

</summary>

<details>

<summary>

config: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessFacebookSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessFacebookSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

class AccessGitHub: …

</summary>

<details>

<summary>

config: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessGitHubSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessGitHubSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

class AccessGoogle: …

</summary>

<details>

<summary>

config: AccessGoogleConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessGoogleSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessGoogleSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

class AccessGoogleApps: …

</summary>

<details>

<summary>

config: AccessGoogleAppsConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

apps\_domain: Optional\[str]

Your companies TLD

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20apps_domain">Link to this property</a>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

<details>

<summary>

prompt: Optional\[Literal\["none", "consent", "select\_account"]]

Configures the prompt behavior for Google authentication.

</summary>

One of the following:

"none"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%200">Link to this property</a>

"consent"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%201">Link to this property</a>

"select\_account"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20prompt">Link to this property</a>

use\_login\_hint: Optional\[bool]

Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config%20%3E%20(property)%20use_login_hint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessGoogleAppsSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessGoogleAppsSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

class AccessLinkedin: …

</summary>

<details>

<summary>

config: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessLinkedinSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessLinkedinSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

class AccessOIDC: …

</summary>

<details>

<summary>

config: AccessOIDCConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

auth\_url: Optional\[str]

The authorization\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20auth_url">Link to this property</a>

certs\_url: Optional\[str]

The jwks\_uri endpoint of your IdP to allow the IdP keys to sign the tokens

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20certs_url">Link to this property</a>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

pkce\_enabled: Optional\[bool]

Enable Proof Key for Code Exchange (PKCE)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20pkce_enabled">Link to this property</a>

scopes: Optional\[List\[str]]

OAuth scopes

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20scopes">Link to this property</a>

token\_url: Optional\[str]

The token\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config%20%3E%20(property)%20token_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessOIDCSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessOIDCSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

<details>

<summary>

class AccessOkta: …

</summary>

<details>

<summary>

config: AccessOktaConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

authorization\_server\_id: Optional\[str]

Your okta authorization server id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20authorization_server_id">Link to this property</a>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

okta\_account: Optional\[str]

Your okta account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config%20%3E%20(property)%20okta_account">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessOktaSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessOktaSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%208">Link to this property</a>

<details>

<summary>

class AccessOnelogin: …

</summary>

<details>

<summary>

config: AccessOneloginConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

onelogin\_account: Optional\[str]

Your OneLogin account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config%20%3E%20(property)%20onelogin_account">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessOneloginSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessOneloginSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%209">Link to this property</a>

<details>

<summary>

class AccessPingone: …

</summary>

<details>

<summary>

config: AccessPingoneConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims: Optional\[List\[str]]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20claims">Link to this property</a>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20client_secret">Link to this property</a>

email\_claim\_name: Optional\[str]

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20email_claim_name">Link to this property</a>

ping\_env\_id: Optional\[str]

Your PingOne environment identifier

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config%20%3E%20(property)%20ping_env_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessPingoneSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessPingoneSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2010">Link to this property</a>

<details>

<summary>

class AccessSAML: …

</summary>

<details>

<summary>

config: AccessSAMLConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

attributes: Optional\[List\[str]]

A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20attributes">Link to this property</a>

email\_attribute\_name: Optional\[str]

The attribute name for email in the SAML response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20email_attribute_name">Link to this property</a>

enable\_encryption: Optional\[bool]

Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set.

To enable encryption:

1. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>
2. Set this field to <code>true</code> and include <code>saml_certificate_set_id</code> in the PUT request
3. Configure the public certificate in your external Identity Provider

Note: Requires <code>saml_certificate_set_id</code> to be set when <code>true</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20enable_encryption">Link to this property</a>

force\_authn: Optional\[bool]

Asks the IdP to reauthenticate the user for each SAML authentication request.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20force_authn">Link to this property</a>

<details>

<summary>

header\_attributes: Optional\[List\[AccessSAMLConfigHeaderAttribute]]

Add a list of attribute names that will be returned in the response header from the Access callback.

</summary>

attribute\_name: Optional\[str]

attribute name from the IDP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes%20%3E%20(items)%20%3E%20(property)%20attribute_name">Link to this property</a>

header\_name: Optional\[str]

header that will be added on the request to the origin

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes%20%3E%20(items)%20%3E%20(property)%20header_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20header_attributes">Link to this property</a>

idp\_public\_certs: Optional\[List\[str]]

X509 certificate to verify the signature in the SAML authentication response

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20idp_public_certs">Link to this property</a>

issuer\_url: Optional\[str]

IdP Entity ID or Issuer URL

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20issuer_url">Link to this property</a>

max\_sso\_url\_length: Optional\[int]

The maximum URL length the IdP accepts for the SSO redirect URL. When the constructed SSO URL would exceed this length, the RelayState is stored server-side and a short nonce is passed to the IdP instead. Set this if your IdP enforces a URL length limit.

maximum100000

minimum512

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20max_sso_url_length">Link to this property</a>

sign\_request: Optional\[bool]

Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20sign_request">Link to this property</a>

sso\_target\_url: Optional\[str]

URL to send the SAML authentication requests to

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config%20%3E%20(property)%20sso_target_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessSAMLSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessSAMLSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2011">Link to this property</a>

<details>

<summary>

class AccessYandex: …

</summary>

<details>

<summary>

config: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)">GenericOAuthConfig</a>

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

client\_id: Optional\[str]

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: Optional\[str]

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20generic_oauth_config%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessYandexSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessYandexSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2012">Link to this property</a>

<details>

<summary>

class AccessOnetimepin: …

</summary>

<details>

<summary>

config: AccessOnetimepinConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

redirect\_url: Optional\[str]

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessOnetimepinSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessOnetimepinSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2013">Link to this property</a>

<details>

<summary>

class AccessCloudflare: …

</summary>

<details>

<summary>

config: AccessCloudflareConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

redirect\_url: Optional\[str]

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

restrict\_to\_account\_members: Optional\[bool]

When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config%20%3E%20(property)%20restrict_to_account_members">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessCloudflareSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessCloudflareSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2014">Link to this property</a>

<details>

<summary>

class AccessPasskeys: …

</summary>

<details>

<summary>

config: AccessPasskeysConfig

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

login\_page\_auto\_prompt: Optional\[bool]

When enabled, the Access login page automatically prompts the user to authenticate with a passkey.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config%20%3E%20(property)%20login_page_auto_prompt">Link to this property</a>

redirect\_url: Optional\[str]

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config%20%3E%20(property)%20redirect_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20config">Link to this property</a>

name: str

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

type: <a href="https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)">IdentityProviderType</a>

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

One of the following:

"onetimepin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"azureAD"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saml"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"centrify"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"facebook"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"github"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"google-apps"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"google"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"linkedin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"okta"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"onelogin"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"pingone"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"yandex"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"cloudflare"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

"passkeys"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_type%20%3E%20(schema)%20%3E%20(member)%2015">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20type">Link to this property</a>

id: Optional\[str]

UUID.

maxLength36

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20id">Link to this property</a>

read\_only: Optional\[bool]

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Optional\[AccessPasskeysSAMLCertificateSet]

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: datetime

Timestamp when the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20created_at">Link to this property</a>

uid: str

Unique identifier for the certificate set

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: datetime

Timestamp when the certificate set was last updated (e.g., during rotation)

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Optional\[AccessPasskeysSAMLCertificateSetCurrentCertificate]

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: datetime

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

formatdate-time

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: str

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: str

Unique identifier for the certificate

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate: Optional\[object]

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: Optional\[str]

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

formatuuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Optional\[IdentityProviderSCIMConfig]

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Optional\[bool]

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

identity\_update\_behavior: Optional\[Literal\["automatic", "reauth", "no\_action"]]

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

</summary>

One of the following:

"automatic"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%200">Link to this property</a>

"reauth"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%201">Link to this property</a>

"no\_action"

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: Optional\[str]

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20scim_base_url">Link to this property</a>

seat\_deprovision: Optional\[bool]

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20seat_deprovision">Link to this property</a>

secret: Optional\[str]

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20secret">Link to this property</a>

user\_deprovision: Optional\[bool]

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config%20%2B%20(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_scim_config%20%3E%20(schema)%20%3E%20(property)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015%20%3E%20(property)%20scim_config">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)%20%3E%20(variant)%2015">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(model)%20identity_provider_list_response%20%3E%20(schema)>)

### List Access identity providers

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
page = client.zero_trust.identity_providers.list(
    account_id="account_id",
)
page = page.result[0]
print(page)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "config": {
        "claims": [
          "email_verified",
          "preferred_username",
          "custom_claim_name"
        ],
        "client_id": "<your client id>",
        "client_secret": "<your client secret>",
        "conditional_access_enabled": true,
        "directory_id": "<your azure directory uuid>",
        "email_claim_name": "custom_claim_name",
        "prompt": "login",
        "support_groups": true
      },
      "name": "Widget Corps IDP",
      "type": "onetimepin",
      "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
      "read_only": true,
      "saml_certificate_set": {
        "created_at": "2026-05-07T19:16:19.821162Z",
        "uid": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
        "updated_at": "2026-05-07T19:16:19.821162Z",
        "current_certificate": {
          "is_current": true,
          "not_after": "2027-05-07T19:11:00Z",
          "public_certificate": "-----BEGIN CERTIFICATE-----\nMIIEpzCCA4+gAwIBAgIUTh2VSDDJ0oB/gabio6j1L9QwWoUwDQYJKoZIhvcNAQEL\n...\n-----END CERTIFICATE-----\n",
          "uid": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
        },
        "previous_certificate": {}
      },
      "saml_certificate_set_id": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
      "scim_config": {
        "enabled": true,
        "identity_update_behavior": "automatic",
        "scim_base_url": "scim_base_url",
        "seat_deprovision": true,
        "secret": "secret",
        "user_deprovision": true
      }
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "config": {
        "claims": [
          "email_verified",
          "preferred_username",
          "custom_claim_name"
        ],
        "client_id": "<your client id>",
        "client_secret": "<your client secret>",
        "conditional_access_enabled": true,
        "directory_id": "<your azure directory uuid>",
        "email_claim_name": "custom_claim_name",
        "prompt": "login",
        "support_groups": true
      },
      "name": "Widget Corps IDP",
      "type": "onetimepin",
      "id": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415",
      "read_only": true,
      "saml_certificate_set": {
        "created_at": "2026-05-07T19:16:19.821162Z",
        "uid": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
        "updated_at": "2026-05-07T19:16:19.821162Z",
        "current_certificate": {
          "is_current": true,
          "not_after": "2027-05-07T19:11:00Z",
          "public_certificate": "-----BEGIN CERTIFICATE-----\nMIIEpzCCA4+gAwIBAgIUTh2VSDDJ0oB/gabio6j1L9QwWoUwDQYJKoZIhvcNAQEL\n...\n-----END CERTIFICATE-----\n",
          "uid": "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
        },
        "previous_certificate": {}
      },
      "saml_certificate_set_id": "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8",
      "scim_config": {
        "enabled": true,
        "identity_update_behavior": "automatic",
        "scim_base_url": "scim_base_url",
        "seat_deprovision": true,
        "secret": "secret",
        "user_deprovision": true
      }
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```