---
title: Get risk event/score information for a specific user
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api)

[Zero Trust](https://developers.cloudflare.com/api/resources/zero_trust)

[Risk Scoring](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Get risk event/score information for a specific user

GET/accounts/{account\_id}/zt\_risk\_scoring/{user\_id}

Retrieves the detailed risk score breakdown for a specific user, including contributing factors.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Zero Trust: PII Read`

##### P ath ParametersExpand Collapse

account\_id: string

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

user\_id: string

formatuuid

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(params)%20default%20%3E%20(param)%20user_id%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

errors: array of object {code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20errors>)

<details>

<summary>

messages: array of object {code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20messages>)

success: true

Whether the API call was successful.

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20success>)

<details>

<summary>

result: optional object {email, events, name, 2 more }

</summary>

email: string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

<details>

<summary>

events: array of object {id, name, risk\_level, 2 more }

</summary>

id: string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

name: string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

risk\_level: "low"or "medium"or "high"

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20risk_level%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20risk_level%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20risk_level%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20risk_level">Link to this property</a>

timestamp: string

formatdate-time

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20timestamp">Link to this property</a>

event\_details: optional unknown

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events%20%3E%20(items)%20%3E%20(property)%20event_details">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20events">Link to this property</a>

name: string

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

last\_reset\_time: optional string

formatdate-time

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20last_reset_time">Link to this property</a>

<details>

<summary>

risk\_level: optional "low"or "medium"or "high"

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20risk_level%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result%20%2B%20(resource)%20zero_trust.risk_scoring%20%3E%20(model)%20risk_scoring_get_response%20%3E%20(schema)%20%3E%20(property)%20risk_level">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result>)

<details>

<summary>

result\_info: optional object {count, page, per\_page, 2 more }

</summary>

count: optional number

Total number of results for the requested service.

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20count">Link to this property</a>

page: optional number

Current page within paginated list of results.

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20page">Link to this property</a>

per\_page: optional number

Number of results per page of results.

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20per_page">Link to this property</a>

total\_count: optional number

Total results available without any search parameters.

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20total_count">Link to this property</a>

total\_pages: optional number

The number of total pages in the entire result set.

<a href="#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20total_pages">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.risk_scoring%20%3E%20(method)%20get%20%3E%20(network%20schema)%20%3E%20(property)%20result_info>)

### Get risk event/score information for a specific user

HTTP

HTTPTypeScriptPythonGoTerraform

```
curl https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/zt_risk_scoring/$USER_ID \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "email": "email",
    "events": [
      {
        "id": "id",
        "name": "name",
        "risk_level": "low",
        "timestamp": "2019-12-27T18:11:19.117Z",
        "event_details": {}
      }
    ],
    "name": "name",
    "last_reset_time": "2019-12-27T18:11:19.117Z",
    "risk_level": "low"
  },
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "email": "email",
    "events": [
      {
        "id": "id",
        "name": "name",
        "risk_level": "low",
        "timestamp": "2019-12-27T18:11:19.117Z",
        "event_details": {}
      }
    ],
    "name": "name",
    "last_reset_time": "2019-12-27T18:11:19.117Z",
    "risk_level": "low"
  },
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  }
}
```