Accounts
List Accounts
Account Details
Create an Account
Update Account
Delete a specific account
AccountsAccount Organizations
Move account to organization
AccountsAccount Profile
Get account profile
Update account profile
AccountsMembers
List Members
Member Details
Add Member
Update Member
Remove Member
AccountsRoles
AccountsSubscriptions
List Subscriptions
Get Subscription
Create Subscription
Update Subscription
Delete Subscription
Cancel Delayed Downgrade
AccountsSubscriptionsCancel Reason
Create Cancel Reason
Get Cancel Reason
AccountsSubscriptionsActions
Append Subscription Action
AccountsSubscriptionsBulk
Create Subscriptions
AccountsTokens
List Tokens
Token Details
Create Token
Update Token
Delete Token
Verify Token
ModelsExpand Collapse
TokenCreateResponse object { id, condition, creator_email_at_creation, 11 more }
condition: optional object { request_ip }
The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.
The expiration time on or after which the JWT MUST NOT be accepted for processing.
The time before which the token MUST NOT be accepted for processing.
List of access policies assigned to the token.
List of access policies assigned to the token.
The identifier of the service that provisioned the token. For an
OAuth-provisioned token, this is the OAuth client identifier. Present
when provisioner_type is present and null when the identifier is
unavailable.
The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.
AccountsTokensPermission Groups
List Permission Groups
List Permission Groups
ModelsExpand Collapse
PermissionGroupListResponse object { id, category, is_selectable, 2 more }
category: optional "developer_platform" or "ai_and_machine_learning" or "dns_and_zones" or 10 moreProduct category that this permission group belongs to.
Product category that this permission group belongs to.
Whether the caller can select this permission group when creating a token.
PermissionGroupGetResponse = array of object { id, category, is_selectable, 2 more }
category: optional "developer_platform" or "ai_and_machine_learning" or "dns_and_zones" or 10 moreProduct category that this permission group belongs to.
Product category that this permission group belongs to.
Whether the caller can select this permission group when creating a token.
AccountsTokensValue
Roll Token
AccountsLogs
AccountsLogsAudit
Get account audit logs (Version 2)
Get resource change history from an account audit log entry (Version 2)
List account audit log product categories (Version 2)
ModelsExpand Collapse
AuditListResponse object { id, account, action, 4 more }
action: optional object { description, result, time, type } Provides information about the action performed.
Provides information about the action performed.
actor: optional object { id, context, email, 4 more } Provides details about the actor who performed the action.
Provides details about the actor who performed the action.
The ID of the actor who performed the action. If a user performed the action, this will be their User ID.
context: optional "api" or "api_key" or "api_token" or 3 moreThe context in which the action was initiated.
api: The action was performed through the API. The specific credential type was not recorded.
api_key: The action was authenticated with a Cloudflare Global API Key.
api_token: The action was authenticated with an API token.
dash: The action was performed through the Cloudflare dashboard.
oauth: The action was authenticated with an OAuth token.
origin_ca_key: The action was authenticated with an Origin CA key.
The context in which the action was initiated.
api: The action was performed through the API. The specific credential type was not recorded.api_key: The action was authenticated with a Cloudflare Global API Key.api_token: The action was authenticated with an API token.dash: The action was performed through the Cloudflare dashboard.oauth: The action was authenticated with an OAuth token.origin_ca_key: The action was authenticated with an Origin CA key.
raw: optional object { cf_ray_id, method, status_code, 2 more } Provides raw information about the request and response.
Provides raw information about the request and response.
AuditHistoryResponse = array of object { id, account, action, 4 more }
action: optional object { description, result, time, type } Provides information about the action performed.
Provides information about the action performed.
actor: optional object { id, context, email, 4 more } Provides details about the actor who performed the action.
Provides details about the actor who performed the action.
The ID of the actor who performed the action. If a user performed the action, this will be their User ID.
context: optional "api" or "api_key" or "api_token" or 3 moreThe context in which the action was initiated.
api: The action was performed through the API. The specific credential type was not recorded.
api_key: The action was authenticated with a Cloudflare Global API Key.
api_token: The action was authenticated with an API token.
dash: The action was performed through the Cloudflare dashboard.
oauth: The action was authenticated with an OAuth token.
origin_ca_key: The action was authenticated with an Origin CA key.
The context in which the action was initiated.
api: The action was performed through the API. The specific credential type was not recorded.api_key: The action was authenticated with a Cloudflare Global API Key.api_token: The action was authenticated with an API token.dash: The action was performed through the Cloudflare dashboard.oauth: The action was authenticated with an OAuth token.origin_ca_key: The action was authenticated with an Origin CA key.
raw: optional object { cf_ray_id, method, status_code, 2 more } Provides raw information about the request and response.
Provides raw information about the request and response.
AccountsEntitlements
Get Account Entitlements
ModelsExpand Collapse
EntitlementListResponse object { id, allocation, created_date, 3 more } A single entitlement record for a zone or account.
A single entitlement record for a zone or account.
allocation: object { type, value } Represents the allocation value for an entitlement. The shape of value depends on type: bool uses a boolean, max_count uses an integer, enum_number uses an array of numbers, range uses an object with min and max integer fields, and string uses a string.
Represents the allocation value for an entitlement. The shape of value depends on type: bool uses a boolean, max_count uses an integer, enum_number uses an array of numbers, range uses an object with min and max integer fields, and string uses a string.
ISO 8601 timestamp (microsecond precision, no timezone offset) when the entitlement was created. Format: YYYY-MM-DDTHH:MM:SS.ffffff.
ISO 8601 timestamp when the entitlement was deleted, or empty string if not deleted.
ISO 8601 timestamp (microsecond precision, no timezone offset) when the entitlement was last edited.