---
title: User
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# User

#### resource cloudflare\_user

##### optional Expand Collapse

country?: String

The country in which the user lives.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20country>)

first\_name?: String

User’s first name

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20first_name>)

last\_name?: String

User’s last name

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20last_name>)

telephone?: String

User’s telephone number

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20telephone>)

zipcode?: String

The zipcode or postal code where the user lives.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zipcode>)

##### computed Expand Collapse

id: String

Identifier of the user.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

email: String

Current email address of the user.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20email>)

has\_business\_zones: Bool

Indicates whether user has any business zones

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20has_business_zones>)

has\_enterprise\_zones: Bool

Indicates whether user has any enterprise zones

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20has_enterprise_zones>)

has\_pro\_zones: Bool

Indicates whether user has any pro zones

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20has_pro_zones>)

suspended: Bool

Indicates whether user has been suspended

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20suspended>)

two\_factor\_authentication\_enabled: Bool

Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20two_factor_authentication_enabled>)

two\_factor\_authentication\_locked: Bool

Indicates whether two-factor authentication is required by one of the accounts that the user is a member of.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20two_factor_authentication_locked>)

betas: List\[String]

Lists the betas that the user is participating in.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20betas>)

<details>

<summary>

organizations: List\[Attributes]

</summary>

id: String

Identifier

<a href="#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20id">Link to this property</a>

name: String

Organization name.

<a href="#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20name">Link to this property</a>

permissions: List\[String]

Access permissions for this User.

<a href="#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20permissions">Link to this property</a>

roles: List\[String]

List of roles that a user has within an organization.

<a href="#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20roles">Link to this property</a>

status: String

Whether the user is a member of the organization or has an invitation pending.

<a href="#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20organizations>)

### cloudflare\_user

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_user" "example_user" {
  country = "US"
  first_name = "John"
  last_name = "Appleseed"
  telephone = "+1 123-123-1234"
  zipcode = "12345"
}
```

#### data cloudflare\_user

##### computed Expand Collapse

country: String

The country in which the user lives.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20country>)

email: String

Current email address of the user.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20email>)

first\_name: String

User’s first name

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20first_name>)

has\_business\_zones: Bool

Indicates whether user has any business zones

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20has_business_zones>)

has\_enterprise\_zones: Bool

Indicates whether user has any enterprise zones

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20has_enterprise_zones>)

has\_pro\_zones: Bool

Indicates whether user has any pro zones

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20has_pro_zones>)

id: String

Identifier of the user.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

last\_name: String

User’s last name

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20last_name>)

suspended: Bool

Indicates whether user has been suspended

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20suspended>)

telephone: String

User’s telephone number

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20telephone>)

two\_factor\_authentication\_enabled: Bool

Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20two_factor_authentication_enabled>)

two\_factor\_authentication\_locked: Bool

Indicates whether two-factor authentication is required by one of the accounts that the user is a member of.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20two_factor_authentication_locked>)

zipcode: String

The zipcode or postal code where the user lives.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zipcode>)

betas: List\[String]

Lists the betas that the user is participating in.

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20betas>)

<details>

<summary>

organizations: List\[Attributes]

</summary>

id: String

Identifier

<a href="#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20id">Link to this property</a>

name: String

Organization name.

<a href="#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20name">Link to this property</a>

permissions: List\[String]

Access permissions for this User.

<a href="#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20permissions">Link to this property</a>

roles: List\[String]

List of roles that a user has within an organization.

<a href="#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20roles">Link to this property</a>

status: String

Whether the user is a member of the organization or has an invitation pending.

<a href="#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizations%20%3E%20(attribute)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20organizations>)

### cloudflare\_user

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_user" "example_user" {

}
```

#### UserTokens

#### resource cloudflare\_api\_token

##### required Expand Collapse

name: String

Token name.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

<details>

<summary>

policies: List\[Attributes]

List of access policies assigned to the token.

</summary>

id: String

Policy identifier.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20id">Link to this property</a>

effect: String

Allow or deny operations against the resources.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20effect">Link to this property</a>

<details>

<summary>

permission\_groups: List\[Attributes]

A set of permission groups that are specified to the policy.

</summary>

id: String

Identifier of the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

meta?: Attributes

Attributes associated to the permission group.

</summary>

category?: String

A category used to group permission groups.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20category">Link to this property</a>

deprecated?: String

Indicates whether the permission group is deprecated.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20deprecated">Link to this property</a>

description?: String

Additional information about the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20description">Link to this property</a>

editable?: String

Indicates whether the permission group can be edited.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20editable">Link to this property</a>

eol\_at?: Time

The planned end-of-life date and time, when provided.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20eol_at">Link to this property</a>

label?: String

A label identifying the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20label">Link to this property</a>

scopes?: String

The scope associated with the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20scopes">Link to this property</a>

visibility?: String

Indicates the permission group’s availability or visibility.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20visibility">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta">Link to this property</a>

name: String

Name of the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups">Link to this property</a>

resources: Map\[String]

A list of resource names that the policy applies to.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20resources">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policies>)

##### optional Expand Collapse

expires\_on?: Time

The expiration time on or after which the JWT MUST NOT be accepted for processing.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expires_on>)

not\_before?: Time

The time before which the token MUST NOT be accepted for processing.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20not_before>)

<details>

<summary>

condition?: Attributes

</summary>

<details>

<summary>

request\_ip?: Attributes

Client IP restrictions.

</summary>

in?: List\[String]

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip%20%3E%20(attribute)%20in">Link to this property</a>

not\_in?: List\[String]

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip%20%3E%20(attribute)%20not_in">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20condition>)

status?: String

Status of the token.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20status>)

##### computed Expand Collapse

id: String

Token identifier tag.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

creator\_email\_at\_creation: String

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20creator_email_at_creation>)

issued\_on: Time

The time on which the token was created.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20issued_on>)

last\_used\_on: Time

Last time the token was used.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20last_used_on>)

modified\_on: Time

Last time the token was modified.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

provisioner\_id: String

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when `provisioner_type` is present and null when the identifier is unavailable.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20provisioner_id>)

provisioner\_type: String

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20provisioner_type>)

value: String

The token value.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20value>)

### cloudflare\_api\_token

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_api_token" "example_api_token" {
  name = "readonly token"
  policies = [{
    effect = "allow"
    permission_groups = [{
      id = "c8fed203ed3043cba015a93ad1616f1f"
      meta = {
        category = "category"
        deprecated = "deprecated"
        description = "description"
        editable = "editable"
        eol_at = "2019-12-27T18:11:19.117Z"
        label = "load_balancer_admin"
        scopes = "com.cloudflare.api.account"
        visibility = "visibility"
      }
    }, {
      id = "82e64a83756745bbbb1c9c2701bf816b"
      meta = {
        category = "category"
        deprecated = "deprecated"
        description = "description"
        editable = "editable"
        eol_at = "2019-12-27T18:11:19.117Z"
        label = "fbm_user"
        scopes = "com.cloudflare.api.account"
        visibility = "visibility"
      }
    }]
    resources = {
      "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43" = "*"
    }
  }]
  condition = {
    request_ip = {
      in = ["123.123.123.0/24", "2606:4700::/32"]
      not_in = ["123.123.123.100/24", "2606:4700:4700::/48"]
    }
  }
  expires_on = "2020-01-01T00:00:00Z"
  not_before = "2018-07-01T05:20:00Z"
}
```

#### data cloudflare\_api\_token

##### optional Expand Collapse

token\_id?: String

Token identifier tag.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20token_id>)

<details>

<summary>

filter?: Attributes

</summary>

direction?: String

Direction to order results.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20direction">Link to this property</a>

include\_expired?: Bool

When true, includes recently-expired tokens in the response.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20include_expired">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

Token identifier tag.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

creator\_email\_at\_creation: String

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20creator_email_at_creation>)

expires\_on: Time

The expiration time on or after which the JWT MUST NOT be accepted for processing.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expires_on>)

issued\_on: Time

The time on which the token was created.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20issued_on>)

last\_used\_on: Time

Last time the token was used.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20last_used_on>)

modified\_on: Time

Last time the token was modified.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

name: String

Token name.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

not\_before: Time

The time before which the token MUST NOT be accepted for processing.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20not_before>)

provisioner\_id: String

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when `provisioner_type` is present and null when the identifier is unavailable.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20provisioner_id>)

provisioner\_type: String

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20provisioner_type>)

status: String

Status of the token.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20status>)

<details>

<summary>

condition: Attributes

</summary>

<details>

<summary>

request\_ip: Attributes

Client IP restrictions.

</summary>

in: List\[String]

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip%20%3E%20(attribute)%20in">Link to this property</a>

not\_in: List\[String]

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip%20%3E%20(attribute)%20not_in">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20condition>)

<details>

<summary>

policies: List\[Attributes]

List of access policies assigned to the token.

</summary>

id: String

Policy identifier.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20id">Link to this property</a>

effect: String

Allow or deny operations against the resources.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20effect">Link to this property</a>

<details>

<summary>

permission\_groups: List\[Attributes]

A set of permission groups that are specified to the policy.

</summary>

id: String

Identifier of the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

meta: Attributes

Attributes associated to the permission group.

</summary>

category: String

A category used to group permission groups.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20category">Link to this property</a>

deprecated: String

Indicates whether the permission group is deprecated.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20deprecated">Link to this property</a>

description: String

Additional information about the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20description">Link to this property</a>

editable: String

Indicates whether the permission group can be edited.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20editable">Link to this property</a>

eol\_at: Time

The planned end-of-life date and time, when provided.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20eol_at">Link to this property</a>

label: String

A label identifying the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20label">Link to this property</a>

scopes: String

The scope associated with the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20scopes">Link to this property</a>

visibility: String

Indicates the permission group’s availability or visibility.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20visibility">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta">Link to this property</a>

name: String

Name of the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups">Link to this property</a>

resources: Map\[String]

A list of resource names that the policy applies to.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20resources">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policies>)

### cloudflare\_api\_token

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_api_token" "example_api_token" {
  token_id = "ed17574386854bf78a67040be0a770b0"
}
```

#### data cloudflare\_api\_tokens

##### optional Expand Collapse

direction?: String

Direction to order results.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20direction>)

include\_expired?: Bool

When true, includes recently-expired tokens in the response.

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20include_expired>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Token identifier tag.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

condition: Attributes

</summary>

<details>

<summary>

request\_ip: Attributes

Client IP restrictions.

</summary>

in: List\[String]

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip%20%3E%20(attribute)%20in">Link to this property</a>

not\_in: List\[String]

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip%20%3E%20(attribute)%20not_in">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20condition%20%3E%20(attribute)%20request_ip">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20condition">Link to this property</a>

creator\_email\_at\_creation: String

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20creator_email_at_creation">Link to this property</a>

expires\_on: Time

The expiration time on or after which the JWT MUST NOT be accepted for processing.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expires_on">Link to this property</a>

issued\_on: Time

The time on which the token was created.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20issued_on">Link to this property</a>

last\_used\_on: Time

Last time the token was used.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20last_used_on">Link to this property</a>

modified\_on: Time

Last time the token was modified.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_on">Link to this property</a>

name: String

Token name.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

not\_before: Time

The time before which the token MUST NOT be accepted for processing.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20not_before">Link to this property</a>

<details>

<summary>

policies: List\[Attributes]

List of access policies assigned to the token.

</summary>

id: String

Policy identifier.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20id">Link to this property</a>

effect: String

Allow or deny operations against the resources.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20effect">Link to this property</a>

<details>

<summary>

permission\_groups: List\[Attributes]

A set of permission groups that are specified to the policy.

</summary>

id: String

Identifier of the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

meta: Attributes

Attributes associated to the permission group.

</summary>

category: String

A category used to group permission groups.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20category">Link to this property</a>

deprecated: String

Indicates whether the permission group is deprecated.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20deprecated">Link to this property</a>

description: String

Additional information about the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20description">Link to this property</a>

editable: String

Indicates whether the permission group can be edited.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20editable">Link to this property</a>

eol\_at: Time

The planned end-of-life date and time, when provided.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20eol_at">Link to this property</a>

label: String

A label identifying the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20label">Link to this property</a>

scopes: String

The scope associated with the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20scopes">Link to this property</a>

visibility: String

Indicates the permission group’s availability or visibility.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta%20%3E%20(attribute)%20visibility">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20meta">Link to this property</a>

name: String

Name of the permission group.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20permission_groups">Link to this property</a>

resources: Map\[String]

A list of resource names that the policy applies to.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies%20%3E%20(attribute)%20resources">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policies">Link to this property</a>

provisioner\_id: String

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when <code>provisioner_type</code> is present and null when the identifier is unavailable.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20provisioner_id">Link to this property</a>

provisioner\_type: String

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20provisioner_type">Link to this property</a>

status: String

Status of the token.

<a href="#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_api\_tokens

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_api_tokens" "example_api_tokens" {
  direction = "desc"
}
```

#### UserTokensPermission Groups

#### data cloudflare\_api\_token\_permission\_groups\_list

##### optional Expand Collapse

name?: String

Filter by the name of the permission group. The value must be URL-encoded.

[Link to this property](<#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20name>)

scope?: String

Filter by the scope of the permission group. The value must be URL-encoded.

[Link to this property](<#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20scope>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Public ID.

<a href="#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

category: String

Product category that this permission group belongs to.

<a href="#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20category">Link to this property</a>

is\_selectable: Bool

Whether the caller can select this permission group when creating a token.

<a href="#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_selectable">Link to this property</a>

name: String

Permission Group Name

<a href="#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

scopes: List\[String]

Resources to which the Permission Group is scoped

<a href="#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens.permission_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_api\_token\_permission\_groups\_list

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_api_token_permission_groups_list" "example_api_token_permission_groups_list" {
  name = "Account%20Settings%20Write"
  scope = "com.cloudflare.api.account.zone"
}
```