---
title: Organizations
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Zero Trust](https://developers.cloudflare.com/api/python/resources/zero_trust)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Organizations

##### [Get your Zero Trust organization](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/organizations/methods/list)

zero\_trust.organizations.list(OrganizationListParams\*\*kwargs) -> [OrganizationListResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)>)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Create your Zero Trust organization](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/organizations/methods/create)

zero\_trust.organizations.create(OrganizationCreateParams\*\*kwargs) -> [Organization](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Update your Zero Trust organization](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/organizations/methods/update)

zero\_trust.organizations.update(OrganizationUpdateParams\*\*kwargs) -> [Organization](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Revoke all Access tokens for a user](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/organizations/methods/revoke_users)

zero\_trust.organizations.revoke\_users(OrganizationRevokeUsersParams\*\*kwargs) -> [OrganizationRevokeUsersResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_revoke_users_response%20%3E%20(schema)>)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations/revoke\_user

##### ModelsExpand Collapse

<details>

<summary>

class LoginDesign: …

</summary>

background\_color: Optional\[str]

The background color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20background_color">Link to this property</a>

footer\_text: Optional\[str]

The text at the bottom of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20footer_text">Link to this property</a>

header\_text: Optional\[str]

The text at the top of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20header_text">Link to this property</a>

logo\_path: Optional\[str]

The URL of the logo on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20logo_path">Link to this property</a>

text\_color: Optional\[str]

The text color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)%20%3E%20(property)%20text_color">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20login_design%20%3E%20(schema)>)

<details>

<summary>

class Organization: …

</summary>

allow\_authenticate\_via\_warp: Optional\[bool]

When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20allow_authenticate_via_warp">Link to this property</a>

auth\_domain: Optional\[str]

The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format <code>adjective-noun-hex4</code> (e.g. <code>frosty-moon-7a3b.cloudflareaccess.com</code>).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20auth_domain">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

<details>

<summary>

custom\_pages: Optional\[CustomPages]

</summary>

forbidden: Optional\[str]

The uid of the custom page to use when a user is denied access after failing a non-identity rule.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20forbidden">Link to this property</a>

identity\_denied: Optional\[str]

The uid of the custom page to use when a user is denied access.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20identity_denied">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20custom_pages">Link to this property</a>

deny\_unmatched\_requests: Optional\[bool]

Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the <code>deny_unmatched_requests_exempted_zone_names</code> array.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests">Link to this property</a>

deny\_unmatched\_requests\_exempted\_zone\_names: Optional\[List\[str]]

Contains zone names to exempt from the <code>deny_unmatched_requests</code> feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests_exempted_zone_names">Link to this property</a>

is\_ui\_read\_only: Optional\[bool]

Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20is_ui_read_only">Link to this property</a>

login\_design: Optional\[LoginDesign]

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20login_design">Link to this property</a>

<details>

<summary>

mfa\_config: Optional\[MfaConfig]

Configures multi-factor authentication (MFA) settings for an organization.

</summary>

<details>

<summary>

allowed\_authenticators: Optional\[List\[Literal\["totp", "biometrics", "security\_key", 2 more]]]

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"piv\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"ssh\_fido2\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

amr\_matching\_session\_duration: Optional\[str]

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20amr_matching_session_duration">Link to this property</a>

required\_aaguids: Optional\[str]

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

formatuuid

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20required_aaguids">Link to this property</a>

session\_duration: Optional\[str]

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

<details>

<summary>

mfa\_piv\_key\_requirements: Optional\[MfaPivKeyRequirements]

Configures PIV key requirements for MFA using hardware security keys.

</summary>

<details>

<summary>

pin\_policy: Optional\[Literal\["never", "once", "always"]]

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

</summary>

One of the following:

"never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%200">Link to this property</a>

"once"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%201">Link to this property</a>

"always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy">Link to this property</a>

require\_fips\_device: Optional\[bool]

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20require_fips_device">Link to this property</a>

<details>

<summary>

ssh\_key\_size: Optional\[List\[Literal\[256, 384, 521, 3 more]]]

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

</summary>

One of the following:

256

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

384

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

521

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

2048

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

3072

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

4096

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size">Link to this property</a>

<details>

<summary>

ssh\_key\_type: Optional\[List\[Literal\["ecdsa", "ed25519", "rsa"]]]

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

</summary>

One of the following:

"ecdsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"ed25519"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"rsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type">Link to this property</a>

<details>

<summary>

touch\_policy: Optional\[Literal\["never", "always", "cached"]]

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

</summary>

One of the following:

"never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%200">Link to this property</a>

"always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%201">Link to this property</a>

"cached"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements">Link to this property</a>

mfa\_required\_for\_all\_apps: Optional\[bool]

Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20mfa_required_for_all_apps">Link to this property</a>

name: Optional\[str]

The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

service\_token\_inactivity: Optional\[ServiceTokenInactivity]

Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

<details>

<summary>

action: Literal\["disable", "delete"]

The action applied to an inactive service token.

</summary>

One of the following:

"disable"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

"delete"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action">Link to this property</a>

enabled: bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20enabled">Link to this property</a>

inactivity\_threshold\_days: int

The number of days a service token must be inactive before the configured action is applied.

maximum365

minimum30

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20inactivity_threshold_days">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for applications will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

strict\_service\_token\_auth: Optional\[bool]

Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20strict_service_token_auth">Link to this property</a>

ui\_read\_only\_toggle\_reason: Optional\[str]

A description of the reason why the UI read only field is being toggled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20ui_read_only_toggle_reason">Link to this property</a>

user\_seat\_expiration\_inactive\_time: Optional\[str]

The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: <code>ns</code>, <code>us</code> (or <code>µs</code>), <code>ms</code>, <code>s</code>, <code>m</code>, <code>h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20user_seat_expiration_inactive_time">Link to this property</a>

warp\_auth\_non\_browser\_401: Optional\[bool]

When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20warp_auth_non_browser_401">Link to this property</a>

warp\_auth\_session\_duration: Optional\[str]

The amount of time that tokens issued for applications will be valid. Must be in the format <code>30m</code> or <code>2h45m</code>. Valid time units are: m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)%20%3E%20(property)%20warp_auth_session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization%20%3E%20(schema)>)

<details>

<summary>

class OrganizationListResponse: …

</summary>

allow\_authenticate\_via\_warp: Optional\[bool]

When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20allow_authenticate_via_warp">Link to this property</a>

auth\_domain: Optional\[str]

The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format <code>adjective-noun-hex4</code> (e.g. <code>frosty-moon-7a3b.cloudflareaccess.com</code>).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_domain">Link to this property</a>

auto\_redirect\_to\_identity: Optional\[bool]

When set to <code>true</code>, users skip the identity provider selection step during login.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

<details>

<summary>

custom\_pages: Optional\[CustomPages]

</summary>

forbidden: Optional\[str]

The uid of the custom page to use when a user is denied access after failing a non-identity rule.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20forbidden">Link to this property</a>

identity\_denied: Optional\[str]

The uid of the custom page to use when a user is denied access.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20custom_pages%20%3E%20(property)%20identity_denied">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20custom_pages">Link to this property</a>

deny\_unmatched\_requests: Optional\[bool]

Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the <code>deny_unmatched_requests_exempted_zone_names</code> array.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests">Link to this property</a>

deny\_unmatched\_requests\_exempted\_zone\_names: Optional\[List\[str]]

Contains zone names to exempt from the <code>deny_unmatched_requests</code> feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20deny_unmatched_requests_exempted_zone_names">Link to this property</a>

is\_ui\_read\_only: Optional\[bool]

Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20is_ui_read_only">Link to this property</a>

login\_design: Optional\[LoginDesign]

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20login_design">Link to this property</a>

<details>

<summary>

mfa\_config: Optional\[MfaConfig]

Configures multi-factor authentication (MFA) settings for an organization.

</summary>

<details>

<summary>

allowed\_authenticators: Optional\[List\[Literal\["totp", "biometrics", "security\_key", 2 more]]]

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"piv\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"ssh\_fido2\_key"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

amr\_matching\_session\_duration: Optional\[str]

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20amr_matching_session_duration">Link to this property</a>

required\_aaguids: Optional\[str]

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

formatuuid

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20required_aaguids">Link to this property</a>

session\_duration: Optional\[str]

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

<details>

<summary>

mfa\_piv\_key\_requirements: Optional\[MfaPivKeyRequirements]

Configures PIV key requirements for MFA using hardware security keys.

</summary>

<details>

<summary>

pin\_policy: Optional\[Literal\["never", "once", "always"]]

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

</summary>

One of the following:

"never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%200">Link to this property</a>

"once"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%201">Link to this property</a>

"always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20pin_policy">Link to this property</a>

require\_fips\_device: Optional\[bool]

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20require_fips_device">Link to this property</a>

<details>

<summary>

ssh\_key\_size: Optional\[List\[Literal\[256, 384, 521, 3 more]]]

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

</summary>

One of the following:

256

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

384

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

521

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

2048

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

3072

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

4096

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_size">Link to this property</a>

<details>

<summary>

ssh\_key\_type: Optional\[List\[Literal\["ecdsa", "ed25519", "rsa"]]]

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

</summary>

One of the following:

"ecdsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"ed25519"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"rsa"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20ssh_key_type">Link to this property</a>

<details>

<summary>

touch\_policy: Optional\[Literal\["never", "always", "cached"]]

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

</summary>

One of the following:

"never"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%200">Link to this property</a>

"always"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%201">Link to this property</a>

"cached"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements%20%3E%20(property)%20touch_policy">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_piv_key_requirements">Link to this property</a>

mfa\_required\_for\_all\_apps: Optional\[bool]

Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20mfa_required_for_all_apps">Link to this property</a>

name: Optional\[str]

The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

service\_token\_inactivity: Optional\[ServiceTokenInactivity]

Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

<details>

<summary>

action: Literal\["disable", "delete"]

The action applied to an inactive service token.

</summary>

One of the following:

"disable"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%200">Link to this property</a>

"delete"

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20action">Link to this property</a>

enabled: bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20enabled">Link to this property</a>

inactivity\_threshold\_days: int

The number of days a service token must be inactive before the configured action is applied.

maximum365

minimum30

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity%20%3E%20(property)%20inactivity_threshold_days">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20service_token_inactivity">Link to this property</a>

session\_duration: Optional\[str]

The amount of time that tokens issued for applications will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

strict\_service\_token\_auth: Optional\[bool]

Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20strict_service_token_auth">Link to this property</a>

trusted\_accounts: Optional\[List\[str]]

The account tags of organizations trusted by this organization for policy and device posture sharing.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20trusted_accounts">Link to this property</a>

ui\_read\_only\_toggle\_reason: Optional\[str]

A description of the reason why the UI read only field is being toggled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20ui_read_only_toggle_reason">Link to this property</a>

user\_seat\_expiration\_inactive\_time: Optional\[str]

The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: <code>ns</code>, <code>us</code> (or <code>µs</code>), <code>ms</code>, <code>s</code>, <code>m</code>, <code>h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20user_seat_expiration_inactive_time">Link to this property</a>

warp\_auth\_non\_browser\_401: Optional\[bool]

When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20warp_auth_non_browser_401">Link to this property</a>

warp\_auth\_session\_duration: Optional\[str]

The amount of time that tokens issued for applications will be valid. Must be in the format <code>30m</code> or <code>2h45m</code>. Valid time units are: m, h.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)%20%3E%20(property)%20warp_auth_session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_list_response%20%3E%20(schema)>)

<details>

<summary>

Literal\[true, false]

</summary>

One of the following:

true

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_revoke_users_response%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

false

<a href="#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_revoke_users_response%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(model)%20organization_revoke_users_response%20%3E%20(schema)>)

#### OrganizationsDOH

##### [Get your Zero Trust organization DoH settings](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/organizations/subresources/doh/methods/get)

zero\_trust.organizations.doh.get(DOHGetParams\*\*kwargs) -> [DOHGetResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/access/organizations/doh

##### [Update your Zero Trust organization DoH settings](https://developers.cloudflare.com/api/python/resources/zero_trust/subresources/organizations/subresources/doh/methods/update)

zero\_trust.organizations.doh.update(DOHUpdateParams\*\*kwargs) -> [DOHUpdateResponse](<https://developers.cloudflare.com/api/python/resources/zero_trust#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/access/organizations/doh

##### ModelsExpand Collapse

<details>

<summary>

class DOHGetResponse: …

</summary>

id: Optional\[str]

The ID of the service token.

maxLength36

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

client\_id: Optional\[str]

The Client ID for the service token. Access will check for this value in the <code>CF-Access-Client-ID</code> request header.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

doh\_jwt\_duration: Optional\[str]

The duration the DoH JWT is valid for. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h. Note that the maximum duration for this setting is the same as the key rotation period on the account.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20doh_jwt_duration">Link to this property</a>

duration: Optional\[str]

The duration for how long the service token will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>, or the special value <code>forever</code> for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h).

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20duration">Link to this property</a>

enabled: Optional\[bool]

Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous <code>client_secret</code> stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

expires\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20expires_at">Link to this property</a>

name: Optional\[str]

The name of the service token.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_get_response%20%3E%20(schema)>)

<details>

<summary>

class DOHUpdateResponse: …

</summary>

id: Optional\[str]

The ID of the service token.

maxLength36

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

client\_id: Optional\[str]

The Client ID for the service token. Access will check for this value in the <code>CF-Access-Client-ID</code> request header.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

doh\_jwt\_duration: Optional\[str]

The duration the DoH JWT is valid for. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h. Note that the maximum duration for this setting is the same as the key rotation period on the account. Default expiration is 24h

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20doh_jwt_duration">Link to this property</a>

duration: Optional\[str]

The duration for how long the service token will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>, or the special value <code>forever</code> for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h).

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20duration">Link to this property</a>

enabled: Optional\[bool]

Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous <code>client_secret</code> stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

expires\_at: Optional\[datetime]

formatdate-time

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20expires_at">Link to this property</a>

name: Optional\[str]

The name of the service token.

<a href="#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations.doh%20%3E%20(model)%20doh_update_response%20%3E%20(schema)>)