Skip to content
Start here

Get a policy configuration by ID

GET/accounts/{account_id}/data-security/posture/policies/{policy_id}

Retrieves the details of a specific policy configuration, including its associated remediation and webhook actions.

Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
Accepted Permissions (at least one required)
Zero Trust ReadZero Trust Write
Path ParametersExpand Collapse
account_id: string
policy_id: string
formatuuid
ReturnsExpand Collapse
errors: array of object { code, message, documentation_url, source }
code: number

Error or message code.

minimum1000
message: string

Human-readable message.

documentation_url: optional string

Link to relevant documentation.

formaturi
source: optional object { pointer }
pointer: optional string

JSON pointer to the source of the error.

messages: array of object { code, message, documentation_url, source }
code: number

Error or message code.

minimum1000
message: string

Human-readable message.

documentation_url: optional string

Link to relevant documentation.

formaturi
source: optional object { pointer }
pointer: optional string

JSON pointer to the source of the error.

success: boolean

Whether the API call was successful.

result: optional object { id, actions, applies_to_all_integrations, 9 more }

Response body for a policy configuration.

id: string

Unique identifier for the policy configuration.

formatuuid
actions: object { remediation_types, webhook_configs }

The actions configured for this policy.

remediation_types: array of object { display_name, remediation_type, remediation_type_id }

List of remediation types that will be executed.

display_name: string

Display name/label of the remediation type.

remediation_type: string

The system name of the remediation type.

remediation_type_id: string

Unique identifier for the remediation type.

formatuuid
webhook_configs: array of object { display_name, webhook_config_id }

List of webhook configurations that will be triggered.

display_name: string

Display name/label of the webhook configuration.

webhook_config_id: string

Unique identifier for the webhook configuration.

formatuuid
applies_to_all_integrations: boolean

When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids.

created_at: string

Timestamp when the policy was created.

formatdate-time
description: string

User-set description of what this policy does. Limited to 1000 characters.

display_name: string

Display name for the policy configuration. Limited to 255 characters.

enabled: boolean

Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset).

finding_type_id: string

The finding type this policy is associated with. Immutable after creation; changing it replaces the policy.

formatuuid
integration_ids: array of string

The integrations this policy applies to.

updated_at: string

Timestamp when the policy was last updated.

formatdate-time
disabled_at: optional string

Timestamp when the policy was disabled. Omitted from the response when the policy is enabled.

formatdate-time
last_triggered_at: optional string

Timestamp of the most recent successful policy invocation. Omitted from the response when the policy has never been successfully triggered. Only populated on GET responses; absent on responses from create/update endpoints.

formatdate-time

Get a policy configuration by ID

curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/data-security/posture/policies/$POLICY_ID \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
{
  "errors": [
    {
      "code": 1000,
      "message": "Request processed successfully",
      "documentation_url": "https://api-docs.dnstools.im/api/operations/list-findings",
      "source": {
        "pointer": "/data/attributes/name"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "Request processed successfully",
      "documentation_url": "https://api-docs.dnstools.im/api/operations/list-findings",
      "source": {
        "pointer": "/data/attributes/name"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "actions": {
      "remediation_types": [
        {
          "display_name": "Remove Public Access",
          "remediation_type": "remove_public_access",
          "remediation_type_id": "5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a"
        }
      ],
      "webhook_configs": [
        {
          "display_name": "Send to Slack",
          "webhook_config_id": "3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e"
        }
      ]
    },
    "applies_to_all_integrations": false,
    "created_at": "2025-03-18T17:25:38.700541Z",
    "description": "Automatically remove public access from files when detected",
    "display_name": "Auto-remediate public files",
    "enabled": true,
    "finding_type_id": "5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a",
    "integration_ids": [
      "497f6eca-6276-4993-bfeb-53cbbbba6f08"
    ],
    "updated_at": "2025-03-18T17:25:38.700541Z",
    "disabled_at": "2025-03-18T17:25:38.700541Z",
    "last_triggered_at": "2025-03-18T17:25:38.700541Z"
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "Request processed successfully",
      "documentation_url": "https://api-docs.dnstools.im/api/operations/list-findings",
      "source": {
        "pointer": "/data/attributes/name"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "Request processed successfully",
      "documentation_url": "https://api-docs.dnstools.im/api/operations/list-findings",
      "source": {
        "pointer": "/data/attributes/name"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "actions": {
      "remediation_types": [
        {
          "display_name": "Remove Public Access",
          "remediation_type": "remove_public_access",
          "remediation_type_id": "5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a"
        }
      ],
      "webhook_configs": [
        {
          "display_name": "Send to Slack",
          "webhook_config_id": "3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e"
        }
      ]
    },
    "applies_to_all_integrations": false,
    "created_at": "2025-03-18T17:25:38.700541Z",
    "description": "Automatically remove public access from files when detected",
    "display_name": "Auto-remediate public files",
    "enabled": true,
    "finding_type_id": "5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a",
    "integration_ids": [
      "497f6eca-6276-4993-bfeb-53cbbbba6f08"
    ],
    "updated_at": "2025-03-18T17:25:38.700541Z",
    "disabled_at": "2025-03-18T17:25:38.700541Z",
    "last_triggered_at": "2025-03-18T17:25:38.700541Z"
  }
}