---
title: Zero Trust
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Zero Trust

#### Zero TrustDevicesDEX Tests

#### resource cloudflare\_zero\_trust\_dex\_test

##### required Expand Collapse

account\_id: String

Unique identifier linked to an account.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

enabled: Bool

Determines whether or not the test is active.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

interval: String

How often the test will run.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20interval>)

name: String

The name of the DEX test. Must be unique.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

<details>

<summary>

data: Attributes

The configuration object which contains the details for the WARP client to conduct the test.

</summary>

host: String

The desired endpoint to test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20data%20%3E%20(attribute)%20host">Link to this property</a>

kind: String

The type of test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20data%20%3E%20(attribute)%20kind">Link to this property</a>

method?: String

The HTTP request method type.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20data%20%3E%20(attribute)%20method">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20data>)

##### optional Expand Collapse

description?: String

Additional details about the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

<details>

<summary>

target\_policies?: List\[Attributes]

DEX rules targeted by this test

</summary>

id: String

The id of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20id">Link to this property</a>

default: Bool

Whether the DEX rule is the account default.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20default">Link to this property</a>

name: String

The name of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_policies>)

##### computed Expand Collapse

id: String

The unique identifier for the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

test\_id: String

The unique identifier for the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20test_id>)

created: Time

Date the test was created, in RFC 3339 format.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created>)

targeted: Bool

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20targeted>)

updated: Time

Date the test was last updated, in RFC 3339 format.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated>)

### cloudflare\_zero\_trust\_dex\_test

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_dex_test" "example_zero_trust_dex_test" {
  account_id = "01a7362d577a6c3019a474fd6f485823"
  data = {
    host = "https://dash.cloudflare.com"
    kind = "http"
    method = "GET"
  }
  enabled = true
  interval = "30m"
  name = "HTTP dash health check"
  description = "Checks the dash endpoint every 30 minutes"
  target_policies = [{
    id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
    default = true
    name = "name"
  }]
}
```

#### data cloudflare\_zero\_trust\_dex\_test

##### required Expand Collapse

account\_id: String

Unique identifier linked to an account.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

dex\_test\_id?: String

The unique identifier for the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dex_test_id>)

<details>

<summary>

filter?: Attributes

</summary>

kind?: String

Filter by test type.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20kind">Link to this property</a>

test\_name?: String

Filter by test name.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20test_name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

The unique identifier for the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created: Time

Date the test was created, in RFC 3339 format.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created>)

description: String

Additional details about the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

enabled: Bool

Determines whether or not the test is active.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

interval: String

How often the test will run.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20interval>)

name: String

The name of the DEX test. Must be unique.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

targeted: Bool

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20targeted>)

test\_id: String

The unique identifier for the test.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20test_id>)

updated: Time

Date the test was last updated, in RFC 3339 format.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated>)

<details>

<summary>

data: Attributes

The configuration object which contains the details for the WARP client to conduct the test.

</summary>

host: String

The desired endpoint to test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20data%20%3E%20(attribute)%20host">Link to this property</a>

kind: String

The type of test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20data%20%3E%20(attribute)%20kind">Link to this property</a>

method: String

The HTTP request method type.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20data%20%3E%20(attribute)%20method">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20data>)

<details>

<summary>

target\_policies: List\[Attributes]

DEX rules targeted by this test

</summary>

id: String

The id of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20id">Link to this property</a>

default: Bool

Whether the DEX rule is the account default.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20default">Link to this property</a>

name: String

The name of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_policies>)

### cloudflare\_zero\_trust\_dex\_test

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_dex_test" "example_zero_trust_dex_test" {
  account_id = "01a7362d577a6c3019a474fd6f485823"
  dex_test_id = "372e67954025e0ba6aaa6d586b9e0b59"
}
```

#### data cloudflare\_zero\_trust\_dex\_tests

##### required Expand Collapse

account\_id: String

Unique identifier linked to an account.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

kind?: String

Filter by test type.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20kind>)

test\_name?: String

Filter by test name.

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20test_name>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The unique identifier for the test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

data: Attributes

The configuration object which contains the details for the WARP client to conduct the test.

</summary>

host: String

The desired endpoint to test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20data%20%3E%20(attribute)%20host">Link to this property</a>

kind: String

The type of test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20data%20%3E%20(attribute)%20kind">Link to this property</a>

method: String

The HTTP request method type.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20data%20%3E%20(attribute)%20method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20data">Link to this property</a>

enabled: Bool

Determines whether or not the test is active.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20enabled">Link to this property</a>

interval: String

How often the test will run.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20interval">Link to this property</a>

name: String

The name of the DEX test. Must be unique.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

created: Time

Date the test was created, in RFC 3339 format.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created">Link to this property</a>

description: String

Additional details about the test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

<details>

<summary>

target\_policies: List\[Attributes]

DEX rules targeted by this test

</summary>

id: String

The id of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20id">Link to this property</a>

default: Bool

Whether the DEX rule is the account default.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20default">Link to this property</a>

name: String

The name of the DEX rule.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_policies%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_policies">Link to this property</a>

targeted: Bool

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20targeted">Link to this property</a>

test\_id: String

The unique identifier for the test.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20test_id">Link to this property</a>

updated: Time

Date the test was last updated, in RFC 3339 format.

<a href="#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.dex_tests%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_dex\_tests

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_dex_tests" "example_zero_trust_dex_tests" {
  account_id = "01a7362d577a6c3019a474fd6f485823"
  kind = "http"
  test_name = "testName"
}
```

#### Zero TrustDevicesIP Profiles

#### resource cloudflare\_zero\_trust\_device\_ip\_profile

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

match: String

The wirefilter expression to match registrations. Available values: “identity.name”, “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.saml\_attributes”.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20match>)

name: String

A user-friendly name for the Device IP profile.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

precedence: Int64

The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20precedence>)

subnet\_id: String

The ID of the Subnet.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20subnet_id>)

##### optional Expand Collapse

description?: String

An optional description of the Device IP profile.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

enabled?: Bool

Whether the Device IP profile will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

##### computed Expand Collapse

id: String

The ID of the Device IP profile.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_at: String

The RFC3339Nano timestamp when the Device IP profile was created.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

updated\_at: String

The RFC3339Nano timestamp when the Device IP profile was last updated.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_device\_ip\_profile

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_ip_profile" "example_zero_trust_device_ip_profile" {
  account_id = "account_id"
  match = "identity.email == \"test@cloudflare.com\""
  name = "IPv4 Cloudflare Source IPs"
  precedence = 100
  subnet_id = "b70ff985-a4ef-4643-bbbc-4a0ed4fc8415"
  description = "example comment"
  enabled = true
}
```

#### data cloudflare\_zero\_trust\_device\_ip\_profile

##### required Expand Collapse

profile\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20profile_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_at: String

The RFC3339Nano timestamp when the Device IP profile was created.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

description: String

An optional description of the Device IP profile.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

enabled: Bool

Whether the Device IP profile is enabled.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

match: String

The wirefilter expression to match registrations. Available values: “identity.name”, “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.saml\_attributes”.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20match>)

name: String

A user-friendly name for the Device IP profile.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

precedence: Int64

The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20precedence>)

subnet\_id: String

The ID of the Subnet.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20subnet_id>)

updated\_at: String

The RFC3339Nano timestamp when the Device IP profile was last updated.

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_device\_ip\_profile

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_ip_profile" "example_zero_trust_device_ip_profile" {
  account_id = "account_id"
  profile_id = "profile_id"
}
```

#### data cloudflare\_zero\_trust\_device\_ip\_profiles

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The ID of the Device IP profile.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

created\_at: String

The RFC3339Nano timestamp when the Device IP profile was created.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

description: String

An optional description of the Device IP profile.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

enabled: Bool

Whether the Device IP profile is enabled.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20enabled">Link to this property</a>

match: String

The wirefilter expression to match registrations. Available values: “identity.name”, “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.saml\_attributes”.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20match">Link to this property</a>

name: String

A user-friendly name for the Device IP profile.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

precedence: Int64

The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20precedence">Link to this property</a>

subnet\_id: String

The ID of the Subnet.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20subnet_id">Link to this property</a>

updated\_at: String

The RFC3339Nano timestamp when the Device IP profile was last updated.

<a href="#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.ip_profiles%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_device\_ip\_profiles

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_ip_profiles" "example_zero_trust_device_ip_profiles" {
  account_id = "account_id"
}
```

#### Zero TrustDevicesDeployment Groups

#### resource cloudflare\_zero\_trust\_device\_deployment\_groups

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

name: String

A user-friendly name for the deployment group.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

<details>

<summary>

version\_config: List\[Attributes]

Contains at least one version configuration.

</summary>

target\_environment: String

The target environment for the client version (e.g., windows, macos).

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20version_config%20%3E%20(attribute)%20target_environment">Link to this property</a>

version: String

The specific client version to deploy.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20version_config%20%3E%20(attribute)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20version_config>)

##### optional Expand Collapse

policy\_ids?: List\[String]

Contains an optional list of policy IDs assigned to a group.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policy_ids>)

##### computed Expand Collapse

id: String

The ID of the deployment group.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_at: String

The RFC3339Nano timestamp when the deployment group was created.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

updated\_at: String

The RFC3339Nano timestamp when the deployment group was last updated.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_device\_deployment\_groups

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_deployment_groups" "example_zero_trust_device_deployment_groups" {
  account_id = "account_id"
  name = "Engineering Ring 0"
  version_config = [{
    target_environment = "windows"
    version = "2026.6.234.0"
  }]
  policy_ids = ["string"]
}
```

#### data cloudflare\_zero\_trust\_device\_deployment\_groups

##### required Expand Collapse

group\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20group_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_at: String

The RFC3339Nano timestamp when the deployment group was created.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

name: String

A user-friendly name for the deployment group.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

updated\_at: String

The RFC3339Nano timestamp when the deployment group was last updated.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

policy\_ids: List\[String]

Contains a list of policy IDs assigned to this deployment group.

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policy_ids>)

<details>

<summary>

version\_config: List\[Attributes]

Contains version configurations for different target environments.

</summary>

target\_environment: String

The target environment for the client version (e.g., windows, macos).

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20version_config%20%3E%20(attribute)%20target_environment">Link to this property</a>

version: String

The specific client version to deploy.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20version_config%20%3E%20(attribute)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20version_config>)

### cloudflare\_zero\_trust\_device\_deployment\_groups

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_deployment_groups" "example_zero_trust_device_deployment_groups" {
  account_id = "account_id"
  group_id = "group_id"
}
```

#### data cloudflare\_zero\_trust\_device\_deployment\_groups\_list

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The ID of the deployment group.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

created\_at: String

The RFC3339Nano timestamp when the deployment group was created.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

name: String

A user-friendly name for the deployment group.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

updated\_at: String

The RFC3339Nano timestamp when the deployment group was last updated.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

<details>

<summary>

version\_config: List\[Attributes]

Contains version configurations for different target environments.

</summary>

target\_environment: String

The target environment for the client version (e.g., windows, macos).

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20version_config%20%3E%20(attribute)%20target_environment">Link to this property</a>

version: String

The specific client version to deploy.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20version_config%20%3E%20(attribute)%20version">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20version_config">Link to this property</a>

policy\_ids: List\[String]

Contains a list of policy IDs assigned to this deployment group.

<a href="#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policy_ids">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.deployment_groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_device\_deployment\_groups\_list

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_deployment_groups_list" "example_zero_trust_device_deployment_groups_list" {
  account_id = "account_id"
}
```

#### Zero TrustDevicesNetworks

#### resource cloudflare\_zero\_trust\_device\_managed\_networks

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

name: String

The name of the device managed network. This name must be unique.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

type: String

The type of device managed network.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

<details>

<summary>

config: Attributes

The configuration object containing information for the WARP client to detect the managed network.

</summary>

tls\_sockaddr: String

A network address of the form “host:port” that the WARP client will use to detect the presence of a TLS host.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20tls_sockaddr">Link to this property</a>

sha256?: String

The SHA-256 hash of the TLS certificate presented by the host found at tls\_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sha256">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config>)

##### computed Expand Collapse

id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

network\_id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20network_id>)

### cloudflare\_zero\_trust\_device\_managed\_networks

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_managed_networks" "example_zero_trust_device_managed_networks" {
  account_id = "699d98642c564d2e855e9661899b7252"
  config = {
    tls_sockaddr = "foo.bar:1234"
    sha256 = "b5bb9d8014a0f9b1d61e21e796d78dccdf1352f23cd32812f4850b878ae4944c"
  }
  name = "managed-network-1"
  type = "tls"
}
```

#### data cloudflare\_zero\_trust\_device\_managed\_networks

##### required Expand Collapse

network\_id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20network_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

name: String

The name of the device managed network. This name must be unique.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

type: String

The type of device managed network.

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20type>)

<details>

<summary>

config: Attributes

The configuration object containing information for the WARP client to detect the managed network.

</summary>

tls\_sockaddr: String

A network address of the form “host:port” that the WARP client will use to detect the presence of a TLS host.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20tls_sockaddr">Link to this property</a>

sha256: String

The SHA-256 hash of the TLS certificate presented by the host found at tls\_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sha256">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config>)

### cloudflare\_zero\_trust\_device\_managed\_networks

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_managed_networks" "example_zero_trust_device_managed_networks" {
  account_id = "699d98642c564d2e855e9661899b7252"
  network_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
}
```

#### data cloudflare\_zero\_trust\_device\_managed\_networks\_list

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

API UUID.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

config: Attributes

The configuration object containing information for the WARP client to detect the managed network.

</summary>

tls\_sockaddr: String

A network address of the form “host:port” that the WARP client will use to detect the presence of a TLS host.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20tls_sockaddr">Link to this property</a>

sha256: String

The SHA-256 hash of the TLS certificate presented by the host found at tls\_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sha256">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config">Link to this property</a>

name: String

The name of the device managed network. This name must be unique.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

network\_id: String

API UUID.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20network_id">Link to this property</a>

type: String

The type of device managed network.

<a href="#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.networks%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_device\_managed\_networks\_list

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_managed_networks_list" "example_zero_trust_device_managed_networks_list" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesPoliciesDefault

#### resource cloudflare\_zero\_trust\_device\_default\_profile

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

lan\_allow\_minutes?: Float64

The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20lan_allow_minutes>)

lan\_allow\_subnet\_size?: Float64

The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20lan_allow_subnet_size>)

<details>

<summary>

virtual\_networks?: Attributes

Virtual network access settings for the device.

</summary>

allowed: List\[String]

List of virtual network IDs the device is allowed to access. When virtual\_networks is set, at least one entry is required.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20allowed">Link to this property</a>

default: String

The default virtual network ID. Must be included in the <code>allowed</code> list.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20default">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20virtual_networks>)

allow\_mode\_switch?: Bool

Whether to allow the user to switch WARP between modes.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allow_mode_switch>)

allow\_updates?: Bool

Whether to receive update notifications when a new version of the client is available.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allow_updates>)

allowed\_to\_leave?: Bool

Whether to allow devices to leave the organization.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allowed_to_leave>)

auto\_connect?: Float64

The amount of time in seconds to reconnect after having been disabled.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auto_connect>)

captive\_portal?: Float64

Turn on the captive portal after the specified amount of time.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20captive_portal>)

disable\_auto\_fallback?: Bool

If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20disable_auto_fallback>)

exclude\_office\_ips?: Bool

Whether to add Microsoft IPs to Split Tunnel exclusions.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude_office_ips>)

register\_interface\_ip\_with\_dns?: Bool

Determines if the operating system will register WARP’s local interface IP with your on-premises DNS server.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20register_interface_ip_with_dns>)

sccm\_vpn\_boundary\_support?: Bool

Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20sccm_vpn_boundary_support>)

support\_url?: String

The URL to launch when the Send Feedback button is clicked.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20support_url>)

switch\_locked?: Bool

Whether to allow the user to turn off the WARP switch and disconnect the client.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20switch_locked>)

tunnel\_protocol?: String

Determines which tunnel protocol to use.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20tunnel_protocol>)

uninstall\_protection?: Bool

Determines whether uninstalling the WARP client requires an override code. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20uninstall_protection>)

<details>

<summary>

dns\_search\_suffixes?: List\[Attributes]

List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.

</summary>

suffix: String

The DNS search suffix to append when resolving short hostnames.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20suffix">Link to this property</a>

description?: String

A description of the DNS search suffix.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20description">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_search_suffixes>)

<details>

<summary>

exclude?: List\[Attributes]

List of routes excluded in the WARP client’s tunnel. Both ‘exclude’ and ‘include’ cannot be set in the same request.

</summary>

address?: String

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20address">Link to this property</a>

description?: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20description">Link to this property</a>

host?: String

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

global\_acceleration?: Attributes

Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See <a href="https://developers.cloudflare.com/china-network/concepts/global-acceleration/">https://developers.cloudflare.com/china-network/concepts/global-acceleration/</a>.

</summary>

api\_endpoints: List\[String]

IP:port entries for the API endpoints.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20api_endpoints">Link to this property</a>

enabled: Bool

Global acceleration settings are used only when “enabled”.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20enabled">Link to this property</a>

masque\_endpoints: List\[String]

IP:port entries for the MASQUE tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20masque_endpoints">Link to this property</a>

wireguard\_endpoints: List\[String]

IP:port entries for the WireGuard tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20wireguard_endpoints">Link to this property</a>

autoswitch?: Bool

Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20autoswitch">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration>)

<details>

<summary>

include?: List\[Attributes]

List of routes included in the WARP client’s tunnel. Both ‘exclude’ and ‘include’ cannot be set in the same request.

</summary>

address?: String

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20address">Link to this property</a>

description?: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20description">Link to this property</a>

host?: String

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include>)

<details>

<summary>

service\_mode\_v2?: Attributes

</summary>

mode?: String

The mode to run the WARP client under.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20mode">Link to this property</a>

port?: Float64

The port number when used with proxy mode.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20port">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_mode_v2>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

default: Bool

Whether the policy will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20default>)

enabled: Bool

Whether the policy will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

gateway\_unique\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20gateway_unique_id>)

policy\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policy_id>)

profile\_type: String

The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20profile_type>)

<details>

<summary>

fallback\_domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains>)

### cloudflare\_zero\_trust\_device\_default\_profile

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_default_profile" "example_zero_trust_device_default_profile" {
  account_id = "699d98642c564d2e855e9661899b7252"
  allow_mode_switch = true
  allow_updates = true
  allowed_to_leave = true
  auto_connect = 0
  captive_portal = 180
  disable_auto_fallback = true
  dns_search_suffixes = [{
    suffix = "internal.corp"
    description = "Example internal domains"
  }]
  exclude = [{
    address = "192.0.2.0/24"
    description = "Exclude testing domains from the tunnel"
  }]
  exclude_office_ips = true
  global_acceleration = {
    api_endpoints = ["198.51.100.1:443"]
    enabled = true
    masque_endpoints = ["198.51.100.1:443"]
    wireguard_endpoints = ["198.51.100.1:2408"]
    autoswitch = true
  }
  include = [{
    address = "192.0.2.0/24"
    description = "Include testing domains in the tunnel"
  }]
  lan_allow_minutes = 30
  lan_allow_subnet_size = 24
  register_interface_ip_with_dns = true
  sccm_vpn_boundary_support = false
  service_mode_v2 = {
    mode = "proxy"
    port = 3000
  }
  support_url = "https://1.1.1.1/help"
  switch_locked = true
  tunnel_protocol = "wireguard"
  uninstall_protection = false
  virtual_networks = {
    allowed = ["f174e90a-fafe-4643-bbbc-4a0ed4fc8415"]
    default = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  }
}
```

#### data cloudflare\_zero\_trust\_device\_default\_profile

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

allow\_mode\_switch: Bool

Whether to allow the user to switch WARP between modes.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allow_mode_switch>)

allow\_updates: Bool

Whether to receive update notifications when a new version of the client is available.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allow_updates>)

allowed\_to\_leave: Bool

Whether to allow devices to leave the organization.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allowed_to_leave>)

auto\_connect: Float64

The amount of time in seconds to reconnect after having been disabled.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auto_connect>)

captive\_portal: Float64

Turn on the captive portal after the specified amount of time.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20captive_portal>)

default: Bool

Whether the policy will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20default>)

disable\_auto\_fallback: Bool

If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20disable_auto_fallback>)

enabled: Bool

Whether the policy will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

exclude\_office\_ips: Bool

Whether to add Microsoft IPs to Split Tunnel exclusions.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude_office_ips>)

gateway\_unique\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20gateway_unique_id>)

policy\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policy_id>)

profile\_type: String

The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20profile_type>)

register\_interface\_ip\_with\_dns: Bool

Determines if the operating system will register WARP’s local interface IP with your on-premises DNS server.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20register_interface_ip_with_dns>)

sccm\_vpn\_boundary\_support: Bool

Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20sccm_vpn_boundary_support>)

support\_url: String

The URL to launch when the Send Feedback button is clicked.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20support_url>)

switch\_locked: Bool

Whether to allow the user to turn off the WARP switch and disconnect the client.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20switch_locked>)

tunnel\_protocol: String

Determines which tunnel protocol to use.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20tunnel_protocol>)

uninstall\_protection: Bool

Determines whether uninstalling the WARP client requires an override code. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20uninstall_protection>)

<details>

<summary>

dns\_search\_suffixes: List\[Attributes]

List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.

</summary>

suffix: String

The DNS search suffix to append when resolving short hostnames.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the DNS search suffix.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20description">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_search_suffixes>)

<details>

<summary>

exclude: List\[Attributes]

List of routes excluded in the WARP client’s tunnel.

</summary>

address: String

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20address">Link to this property</a>

description: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20description">Link to this property</a>

host: String

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

fallback\_domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains>)

<details>

<summary>

global\_acceleration: Attributes

Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See <a href="https://developers.cloudflare.com/china-network/concepts/global-acceleration/">https://developers.cloudflare.com/china-network/concepts/global-acceleration/</a>.

</summary>

api\_endpoints: List\[String]

IP:port entries for the API endpoints.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20api_endpoints">Link to this property</a>

enabled: Bool

Global acceleration settings are used only when “enabled”.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20enabled">Link to this property</a>

masque\_endpoints: List\[String]

IP:port entries for the MASQUE tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20masque_endpoints">Link to this property</a>

wireguard\_endpoints: List\[String]

IP:port entries for the WireGuard tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20wireguard_endpoints">Link to this property</a>

autoswitch: Bool

Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20autoswitch">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration>)

<details>

<summary>

include: List\[Attributes]

List of routes included in the WARP client’s tunnel.

</summary>

address: String

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20address">Link to this property</a>

description: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20description">Link to this property</a>

host: String

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include>)

<details>

<summary>

service\_mode\_v2: Attributes

</summary>

mode: String

The mode to run the WARP client under.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20mode">Link to this property</a>

port: Float64

The port number when used with proxy mode.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20port">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_mode_v2>)

<details>

<summary>

virtual\_networks: Attributes

Virtual network access settings for the device.

</summary>

allowed: List\[String]

List of virtual network IDs the device is allowed to access. When virtual\_networks is set, at least one entry is required.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20allowed">Link to this property</a>

default: String

The default virtual network ID. Must be included in the <code>allowed</code> list.

<a href="#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20default">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20virtual_networks>)

### cloudflare\_zero\_trust\_device\_default\_profile

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_default_profile" "example_zero_trust_device_default_profile" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesPoliciesDefaultFallback Domains

#### resource cloudflare\_zero\_trust\_device\_default\_profile\_local\_domain\_fallback

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

<details>

<summary>

domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description?: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server?: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

### cloudflare\_zero\_trust\_device\_default\_profile\_local\_domain\_fallback

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_default_profile_local_domain_fallback" "example_zero_trust_device_default_profile_local_domain_fallback" {
  account_id = "699d98642c564d2e855e9661899b7252"
  domains = [{
    suffix = "example.com"
    description = "Domain bypass for local development"
    dns_server = ["1.1.1.1"]
  }]
}
```

#### data cloudflare\_zero\_trust\_device\_default\_profile\_local\_domain\_fallback

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

description: String

A description of the fallback domain, displayed in the client UI.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

suffix: String

The domain suffix to match when resolving locally.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20suffix>)

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_server>)

### cloudflare\_zero\_trust\_device\_default\_profile\_local\_domain\_fallback

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_default_profile_local_domain_fallback" "example_zero_trust_device_default_profile_local_domain_fallback" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesPoliciesDefaultCertificates

#### resource cloudflare\_zero\_trust\_device\_default\_profile\_certificates

##### required Expand Collapse

zone\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

enabled: Bool

The current status of the device policy certificate provisioning feature for WARP clients.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

### cloudflare\_zero\_trust\_device\_default\_profile\_certificates

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_default_profile_certificates" "example_zero_trust_device_default_profile_certificates" {
  zone_id = "699d98642c564d2e855e9661899b7252"
  enabled = true
}
```

#### data cloudflare\_zero\_trust\_device\_default\_profile\_certificates

##### required Expand Collapse

zone\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

enabled: Bool

The current status of the device policy certificate provisioning feature for WARP clients.

[Link to this property](<#(resource)%20zero_trust.devices.policies.default.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

### cloudflare\_zero\_trust\_device\_default\_profile\_certificates

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_default_profile_certificates" "example_zero_trust_device_default_profile_certificates" {
  zone_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesPoliciesCustom

#### resource cloudflare\_zero\_trust\_device\_custom\_profile

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

name: String

The name of the device settings profile.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

##### optional Expand Collapse

profile\_type?: String

The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20profile_type>)

lan\_allow\_minutes?: Float64

The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20lan_allow_minutes>)

lan\_allow\_subnet\_size?: Float64

The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20lan_allow_subnet_size>)

match?: String

The wirefilter expression to match devices. Available values: “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.service\_token\_uuid”, “identity.saml\_attributes”, “network”, “os.name”, “os.version”.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20match>)

precedence?: Float64

The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20precedence>)

<details>

<summary>

browser\_extension\_config?: Attributes

Browser extension proxy settings. Required when profile\_type is browser\_extension and invalid for WARP profiles.

</summary>

proxy\_control: String

Whether the user may disable the browser extension proxy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20browser_extension_config%20%3E%20(attribute)%20proxy_control">Link to this property</a>

proxy\_enabled: Bool

Whether the browser extension proxy is active.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20browser_extension_config%20%3E%20(attribute)%20proxy_enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20browser_extension_config>)

<details>

<summary>

virtual\_networks?: Attributes

Virtual network access settings for the device.

</summary>

allowed: List\[String]

List of virtual network IDs the device is allowed to access. When virtual\_networks is set, at least one entry is required.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20allowed">Link to this property</a>

default: String

The default virtual network ID. Must be included in the <code>allowed</code> list.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20default">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20virtual_networks>)

allow\_mode\_switch?: Bool

Whether to allow the user to switch WARP between modes.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allow_mode_switch>)

allow\_updates?: Bool

Whether to receive update notifications when a new version of the client is available.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allow_updates>)

allowed\_to\_leave?: Bool

Whether to allow devices to leave the organization.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allowed_to_leave>)

auto\_connect?: Float64

The amount of time in seconds to reconnect after having been disabled.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auto_connect>)

captive\_portal?: Float64

Turn on the captive portal after the specified amount of time.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20captive_portal>)

default?: Bool

Whether the policy is the account default. WARP group profiles cannot set this field.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20default>)

description?: String

A description of the policy.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

disable\_auto\_fallback?: Bool

If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20disable_auto_fallback>)

enabled?: Bool

Whether the policy will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

exclude\_office\_ips?: Bool

Whether to add Microsoft IPs to Split Tunnel exclusions.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude_office_ips>)

register\_interface\_ip\_with\_dns?: Bool

Determines if the operating system will register WARP’s local interface IP with your on-premises DNS server.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20register_interface_ip_with_dns>)

sccm\_vpn\_boundary\_support?: Bool

Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20sccm_vpn_boundary_support>)

support\_url?: String

The URL to launch when the Send Feedback button is clicked.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20support_url>)

switch\_locked?: Bool

Whether to allow the user to turn off the WARP switch and disconnect the client.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20switch_locked>)

tunnel\_protocol?: String

Determines which tunnel protocol to use.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20tunnel_protocol>)

uninstall\_protection?: Bool

Determines whether uninstalling the WARP client requires an override code. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20uninstall_protection>)

<details>

<summary>

dns\_search\_suffixes?: List\[Attributes]

List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.

</summary>

suffix: String

The DNS search suffix to append when resolving short hostnames.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20suffix">Link to this property</a>

description?: String

A description of the DNS search suffix.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20description">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_search_suffixes>)

<details>

<summary>

exclude?: List\[Attributes]

List of routes excluded in the WARP client’s tunnel. Both ‘exclude’ and ‘include’ cannot be set in the same request.

</summary>

address?: String

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20address">Link to this property</a>

description?: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20description">Link to this property</a>

host?: String

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

global\_acceleration?: Attributes

Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See <a href="https://developers.cloudflare.com/china-network/concepts/global-acceleration/">https://developers.cloudflare.com/china-network/concepts/global-acceleration/</a>.

</summary>

api\_endpoints: List\[String]

IP:port entries for the API endpoints.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20api_endpoints">Link to this property</a>

enabled: Bool

Global acceleration settings are used only when “enabled”.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20enabled">Link to this property</a>

masque\_endpoints: List\[String]

IP:port entries for the MASQUE tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20masque_endpoints">Link to this property</a>

wireguard\_endpoints: List\[String]

IP:port entries for the WireGuard tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20wireguard_endpoints">Link to this property</a>

autoswitch?: Bool

Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20autoswitch">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20global_acceleration>)

<details>

<summary>

include?: List\[Attributes]

List of routes included in the WARP client’s tunnel. Both ‘exclude’ and ‘include’ cannot be set in the same request.

</summary>

address?: String

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20address">Link to this property</a>

description?: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20description">Link to this property</a>

host?: String

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include>)

<details>

<summary>

service\_mode\_v2?: Attributes

</summary>

mode?: String

The mode to run the WARP client under.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20mode">Link to this property</a>

port?: Float64

The port number when used with proxy mode.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20port">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_mode_v2>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

policy\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policy_id>)

gateway\_unique\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20gateway_unique_id>)

<details>

<summary>

fallback\_domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fallback_domains>)

<details>

<summary>

Deprecatedtarget\_tests: List\[Attributes]

</summary>

id: String

The id of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_tests%20%3E%20(attribute)%20id">Link to this property</a>

name: String

The name of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_tests%20%3E%20(attribute)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20target_tests>)

### cloudflare\_zero\_trust\_device\_custom\_profile

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_custom_profile" "example_zero_trust_device_custom_profile" {
  account_id = "699d98642c564d2e855e9661899b7252"
  name = "Allow Developers"
  allow_mode_switch = true
  allow_updates = true
  allowed_to_leave = true
  auto_connect = 0
  browser_extension_config = {
    proxy_control = "unlocked"
    proxy_enabled = true
  }
  captive_portal = 180
  default = false
  description = "Policy for test teams."
  disable_auto_fallback = true
  dns_search_suffixes = [{
    suffix = "internal.corp"
    description = "Example internal domains"
  }]
  enabled = true
  exclude = [{
    address = "192.0.2.0/24"
    description = "Exclude testing domains from the tunnel"
  }]
  exclude_office_ips = true
  global_acceleration = {
    api_endpoints = ["198.51.100.1:443"]
    enabled = true
    masque_endpoints = ["198.51.100.1:443"]
    wireguard_endpoints = ["198.51.100.1:2408"]
    autoswitch = true
  }
  include = [{
    address = "192.0.2.0/24"
    description = "Include testing domains in the tunnel"
  }]
  lan_allow_minutes = 30
  lan_allow_subnet_size = 24
  match = "identity.email == \"test@cloudflare.com\""
  precedence = 100
  profile_type = "warp"
  register_interface_ip_with_dns = true
  sccm_vpn_boundary_support = false
  service_mode_v2 = {
    mode = "proxy"
    port = 3000
  }
  support_url = "https://1.1.1.1/help"
  switch_locked = true
  tunnel_protocol = "wireguard"
  uninstall_protection = false
  virtual_networks = {
    allowed = ["f174e90a-fafe-4643-bbbc-4a0ed4fc8415"]
    default = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  }
}
```

#### data cloudflare\_zero\_trust\_device\_custom\_profile

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

policy\_id?: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policy_id>)

<details>

<summary>

filter?: Attributes

</summary>

profile\_type?: String

Filter profiles by client type. When omitted, only WARP profiles are returned.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20profile_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

allow\_mode\_switch: Bool

Whether to allow the user to switch WARP between modes.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allow_mode_switch>)

allow\_updates: Bool

Whether to receive update notifications when a new version of the client is available.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allow_updates>)

allowed\_to\_leave: Bool

Whether to allow devices to leave the organization.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allowed_to_leave>)

auto\_connect: Float64

The amount of time in seconds to reconnect after having been disabled.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auto_connect>)

captive\_portal: Float64

Turn on the captive portal after the specified amount of time.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20captive_portal>)

default: Bool

Whether the policy is the account default. WARP group profiles cannot set this field.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20default>)

description: String

A description of the policy.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

disable\_auto\_fallback: Bool

If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20disable_auto_fallback>)

enabled: Bool

Whether the policy will be applied to matching devices.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

exclude\_office\_ips: Bool

Whether to add Microsoft IPs to Split Tunnel exclusions.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude_office_ips>)

gateway\_unique\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20gateway_unique_id>)

lan\_allow\_minutes: Float64

The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20lan_allow_minutes>)

lan\_allow\_subnet\_size: Float64

The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20lan_allow_subnet_size>)

match: String

The wirefilter expression to match devices. Available values: “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.service\_token\_uuid”, “identity.saml\_attributes”, “network”, “os.name”, “os.version”.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20match>)

name: String

The name of the device settings profile.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

precedence: Float64

The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20precedence>)

profile\_type: String

The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20profile_type>)

register\_interface\_ip\_with\_dns: Bool

Determines if the operating system will register WARP’s local interface IP with your on-premises DNS server.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20register_interface_ip_with_dns>)

sccm\_vpn\_boundary\_support: Bool

Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20sccm_vpn_boundary_support>)

support\_url: String

The URL to launch when the Send Feedback button is clicked.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20support_url>)

switch\_locked: Bool

Whether to allow the user to turn off the WARP switch and disconnect the client.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20switch_locked>)

tunnel\_protocol: String

Determines which tunnel protocol to use.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20tunnel_protocol>)

uninstall\_protection: Bool

Determines whether uninstalling the WARP client requires an override code. (Windows only).

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20uninstall_protection>)

<details>

<summary>

browser\_extension\_config: Attributes

Browser extension proxy settings. Required when profile\_type is browser\_extension and invalid for WARP profiles.

</summary>

proxy\_control: String

Whether the user may disable the browser extension proxy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20browser_extension_config%20%3E%20(attribute)%20proxy_control">Link to this property</a>

proxy\_enabled: Bool

Whether the browser extension proxy is active.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20browser_extension_config%20%3E%20(attribute)%20proxy_enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20browser_extension_config>)

<details>

<summary>

dns\_search\_suffixes: List\[Attributes]

List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.

</summary>

suffix: String

The DNS search suffix to append when resolving short hostnames.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the DNS search suffix.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20description">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_search_suffixes>)

<details>

<summary>

exclude: List\[Attributes]

List of routes excluded in the WARP client’s tunnel.

</summary>

address: String

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20address">Link to this property</a>

description: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20description">Link to this property</a>

host: String

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

fallback\_domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fallback_domains>)

<details>

<summary>

global\_acceleration: Attributes

Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See <a href="https://developers.cloudflare.com/china-network/concepts/global-acceleration/">https://developers.cloudflare.com/china-network/concepts/global-acceleration/</a>.

</summary>

api\_endpoints: List\[String]

IP:port entries for the API endpoints.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20api_endpoints">Link to this property</a>

enabled: Bool

Global acceleration settings are used only when “enabled”.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20enabled">Link to this property</a>

masque\_endpoints: List\[String]

IP:port entries for the MASQUE tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20masque_endpoints">Link to this property</a>

wireguard\_endpoints: List\[String]

IP:port entries for the WireGuard tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20wireguard_endpoints">Link to this property</a>

autoswitch: Bool

Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20autoswitch">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20global_acceleration>)

<details>

<summary>

include: List\[Attributes]

List of routes included in the WARP client’s tunnel.

</summary>

address: String

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20address">Link to this property</a>

description: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20description">Link to this property</a>

host: String

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20host">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include>)

<details>

<summary>

service\_mode\_v2: Attributes

</summary>

mode: String

The mode to run the WARP client under.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20mode">Link to this property</a>

port: Float64

The port number when used with proxy mode.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20port">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_mode_v2>)

<details>

<summary>

Deprecatedtarget\_tests: List\[Attributes]

</summary>

id: String

The id of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_tests%20%3E%20(attribute)%20id">Link to this property</a>

name: String

The name of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_tests%20%3E%20(attribute)%20name">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_tests>)

<details>

<summary>

virtual\_networks: Attributes

Virtual network access settings for the device.

</summary>

allowed: List\[String]

List of virtual network IDs the device is allowed to access. When virtual\_networks is set, at least one entry is required.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20allowed">Link to this property</a>

default: String

The default virtual network ID. Must be included in the <code>allowed</code> list.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20default">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20virtual_networks>)

### cloudflare\_zero\_trust\_device\_custom\_profile

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_custom_profile" "example_zero_trust_device_custom_profile" {
  account_id = "699d98642c564d2e855e9661899b7252"
  policy_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
}
```

#### data cloudflare\_zero\_trust\_device\_custom\_profiles

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

profile\_type?: String

Filter profiles by client type. When omitted, only WARP profiles are returned.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20profile_type>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

allow\_mode\_switch: Bool

Whether to allow the user to switch WARP between modes.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20allow_mode_switch">Link to this property</a>

allow\_updates: Bool

Whether to receive update notifications when a new version of the client is available.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20allow_updates">Link to this property</a>

allowed\_to\_leave: Bool

Whether to allow devices to leave the organization.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20allowed_to_leave">Link to this property</a>

auto\_connect: Float64

The amount of time in seconds to reconnect after having been disabled.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auto_connect">Link to this property</a>

<details>

<summary>

browser\_extension\_config: Attributes

Browser extension proxy settings. Required when profile\_type is browser\_extension and invalid for WARP profiles.

</summary>

proxy\_control: String

Whether the user may disable the browser extension proxy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20browser_extension_config%20%3E%20(attribute)%20proxy_control">Link to this property</a>

proxy\_enabled: Bool

Whether the browser extension proxy is active.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20browser_extension_config%20%3E%20(attribute)%20proxy_enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20browser_extension_config">Link to this property</a>

captive\_portal: Float64

Turn on the captive portal after the specified amount of time.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20captive_portal">Link to this property</a>

default: Bool

Whether the policy is the account default. WARP group profiles cannot set this field.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20default">Link to this property</a>

description: String

A description of the policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

disable\_auto\_fallback: Bool

If the <code>dns_server</code> field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to <code>true</code>.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20disable_auto_fallback">Link to this property</a>

<details>

<summary>

dns\_search\_suffixes: List\[Attributes]

List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.

</summary>

suffix: String

The DNS search suffix to append when resolving short hostnames.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the DNS search suffix.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dns_search_suffixes%20%3E%20(attribute)%20description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dns_search_suffixes">Link to this property</a>

enabled: Bool

Whether the policy will be applied to matching devices.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20enabled">Link to this property</a>

<details>

<summary>

exclude: List\[Attributes]

List of routes excluded in the WARP client’s tunnel.

</summary>

address: String

The address in CIDR format to exclude from the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20address">Link to this property</a>

description: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20description">Link to this property</a>

host: String

The domain name to exclude from the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20host">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude">Link to this property</a>

exclude\_office\_ips: Bool

Whether to add Microsoft IPs to Split Tunnel exclusions.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude_office_ips">Link to this property</a>

<details>

<summary>

fallback\_domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20fallback_domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20fallback_domains">Link to this property</a>

gateway\_unique\_id: String

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20gateway_unique_id">Link to this property</a>

<details>

<summary>

global\_acceleration: Attributes

Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See <a href="https://developers.cloudflare.com/china-network/concepts/global-acceleration/">https://developers.cloudflare.com/china-network/concepts/global-acceleration/</a>.

</summary>

api\_endpoints: List\[String]

IP:port entries for the API endpoints.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20api_endpoints">Link to this property</a>

enabled: Bool

Global acceleration settings are used only when “enabled”.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20enabled">Link to this property</a>

masque\_endpoints: List\[String]

IP:port entries for the MASQUE tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20masque_endpoints">Link to this property</a>

wireguard\_endpoints: List\[String]

IP:port entries for the WireGuard tunnel endpoints. Either wireguard\_endpoints or masque\_endpoints must be provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20wireguard_endpoints">Link to this property</a>

autoswitch: Bool

Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20global_acceleration%20%3E%20(attribute)%20autoswitch">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20global_acceleration">Link to this property</a>

<details>

<summary>

include: List\[Attributes]

List of routes included in the WARP client’s tunnel.

</summary>

address: String

The address in CIDR format to include in the tunnel. If <code>address</code> is present, <code>host</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20address">Link to this property</a>

description: String

A description of the Split Tunnel item, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20description">Link to this property</a>

host: String

The domain name to include in the tunnel. If <code>host</code> is present, <code>address</code> must not be present.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20host">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include">Link to this property</a>

lan\_allow\_minutes: Float64

The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20lan_allow_minutes">Link to this property</a>

lan\_allow\_subnet\_size: Float64

The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20lan_allow_subnet_size">Link to this property</a>

match: String

The wirefilter expression to match devices. Available values: “identity.email”, “identity.groups.id”, “identity.groups.name”, “identity.groups.email”, “identity.service\_token\_uuid”, “identity.saml\_attributes”, “network”, “os.name”, “os.version”.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20match">Link to this property</a>

name: String

The name of the device settings profile.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

policy\_id: String

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policy_id">Link to this property</a>

precedence: Float64

The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20precedence">Link to this property</a>

profile\_type: String

The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20profile_type">Link to this property</a>

register\_interface\_ip\_with\_dns: Bool

Determines if the operating system will register WARP’s local interface IP with your on-premises DNS server.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20register_interface_ip_with_dns">Link to this property</a>

sccm\_vpn\_boundary\_support: Bool

Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only).

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20sccm_vpn_boundary_support">Link to this property</a>

<details>

<summary>

service\_mode\_v2: Attributes

</summary>

mode: String

The mode to run the WARP client under.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20mode">Link to this property</a>

port: Float64

The port number when used with proxy mode.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20service_mode_v2%20%3E%20(attribute)%20port">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20service_mode_v2">Link to this property</a>

support\_url: String

The URL to launch when the Send Feedback button is clicked.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20support_url">Link to this property</a>

switch\_locked: Bool

Whether to allow the user to turn off the WARP switch and disconnect the client.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20switch_locked">Link to this property</a>

<details>

<summary>

Deprecatedtarget\_tests: List\[Attributes]

</summary>

id: String

The id of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_tests%20%3E%20(attribute)%20id">Link to this property</a>

name: String

The name of the DEX test targeting this policy.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_tests%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20target_tests">Link to this property</a>

tunnel\_protocol: String

Determines which tunnel protocol to use.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20tunnel_protocol">Link to this property</a>

uninstall\_protection: Bool

Determines whether uninstalling the WARP client requires an override code. (Windows only).

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20uninstall_protection">Link to this property</a>

<details>

<summary>

virtual\_networks: Attributes

Virtual network access settings for the device.

</summary>

allowed: List\[String]

List of virtual network IDs the device is allowed to access. When virtual\_networks is set, at least one entry is required.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20allowed">Link to this property</a>

default: String

The default virtual network ID. Must be included in the <code>allowed</code> list.

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20virtual_networks%20%3E%20(attribute)%20default">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20virtual_networks">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_device\_custom\_profiles

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_custom_profiles" "example_zero_trust_device_custom_profiles" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesPoliciesCustomFallback Domains

#### resource cloudflare\_zero\_trust\_device\_custom\_profile\_local\_domain\_fallback

##### required Expand Collapse

policy\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policy_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

<details>

<summary>

domains: List\[Attributes]

</summary>

suffix: String

The domain suffix to match when resolving locally.

<a href="#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains%20%3E%20(attribute)%20suffix">Link to this property</a>

description?: String

A description of the fallback domain, displayed in the client UI.

<a href="#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains%20%3E%20(attribute)%20description">Link to this property</a>

dns\_server?: List\[String]

A list of IP addresses to handle domain resolution.

<a href="#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains%20%3E%20(attribute)%20dns_server">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20domains>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

### cloudflare\_zero\_trust\_device\_custom\_profile\_local\_domain\_fallback

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_custom_profile_local_domain_fallback" "example_zero_trust_device_custom_profile_local_domain_fallback" {
  account_id = "699d98642c564d2e855e9661899b7252"
  policy_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  domains = [{
    suffix = "example.com"
    description = "Domain bypass for local development"
    dns_server = ["1.1.1.1"]
  }]
}
```

#### data cloudflare\_zero\_trust\_device\_custom\_profile\_local\_domain\_fallback

##### required Expand Collapse

policy\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policy_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

description: String

A description of the fallback domain, displayed in the client UI.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

suffix: String

The domain suffix to match when resolving locally.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20suffix>)

dns\_server: List\[String]

A list of IP addresses to handle domain resolution.

[Link to this property](<#(resource)%20zero_trust.devices.policies.custom.fallback_domains%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_server>)

### cloudflare\_zero\_trust\_device\_custom\_profile\_local\_domain\_fallback

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_custom_profile_local_domain_fallback" "example_zero_trust_device_custom_profile_local_domain_fallback" {
  account_id = "699d98642c564d2e855e9661899b7252"
  policy_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
}
```

#### Zero TrustDevicesPosture

#### resource cloudflare\_zero\_trust\_device\_posture\_rule

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

name: String

The name of the device posture rule.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

type: String

The type of device posture rule.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

##### optional Expand Collapse

description?: String

The description of the device posture rule.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

expiration?: String

Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expiration>)

schedule?: String

Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20schedule>)

<details>

<summary>

input?: Attributes

The value to be checked against.

</summary>

operating\_system?: String

Operating system.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operating_system">Link to this property</a>

path?: String

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20path">Link to this property</a>

exists?: Bool

Whether or not file exists.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20exists">Link to this property</a>

sha256?: String

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20sha256">Link to this property</a>

thumbprint?: String

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20thumbprint">Link to this property</a>

id?: String

List ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20id">Link to this property</a>

domain?: String

Domain.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20domain">Link to this property</a>

operator?: String

Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operator">Link to this property</a>

version?: String

Version of OS.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20version">Link to this property</a>

os\_distro\_name?: String

Operating System Distribution Name (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_distro_name">Link to this property</a>

os\_distro\_revision?: String

Version of OS Distribution (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_distro_revision">Link to this property</a>

os\_version\_extra?: String

Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_version_extra">Link to this property</a>

enabled?: Bool

Enabled.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20enabled">Link to this property</a>

check\_disks?: List\[String]

List of volume names to be checked for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20check_disks">Link to this property</a>

require\_all?: Bool

Whether to check all disks for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20require_all">Link to this property</a>

certificate\_id?: String

UUID of Cloudflare managed certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20certificate_id">Link to this property</a>

cn?: String

Common Name that is protected by the certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20cn">Link to this property</a>

check\_private\_key?: Bool

Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20check_private_key">Link to this property</a>

extended\_key\_usage?: List\[String]

List of values indicating purposes for which the certificate public key can be used.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20extended_key_usage">Link to this property</a>

<details>

<summary>

locations?: Attributes

</summary>

paths?: List\[String]

List of paths to check for client certificate on linux.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations%20%3E%20(attribute)%20paths">Link to this property</a>

trust\_stores?: List\[String]

List of trust stores to check for client certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations%20%3E%20(attribute)%20trust_stores">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations">Link to this property</a>

subject\_alternative\_names?: List\[String]

List of certificate Subject Alternative Names.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20subject_alternative_names">Link to this property</a>

update\_window\_days?: Float64

Number of days that the antivirus should be updated within.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20update_window_days">Link to this property</a>

compliance\_status?: String

Compliance Status.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20compliance_status">Link to this property</a>

connection\_id?: String

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20connection_id">Link to this property</a>

last\_seen?: String

For more details on last seen, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20last_seen">Link to this property</a>

os?: String

Os Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os">Link to this property</a>

overall?: String

Overall.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20overall">Link to this property</a>

sensor\_config?: String

SensorConfig.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20sensor_config">Link to this property</a>

state?: String

For more details on state, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20state">Link to this property</a>

version\_operator?: String

Version Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20version_operator">Link to this property</a>

auth\_state?: List\[String]

The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20auth_state">Link to this property</a>

count\_operator?: String

Count Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20count_operator">Link to this property</a>

issue\_count?: String

The Number of Issues.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20issue_count">Link to this property</a>

eid\_last\_seen?: String

For more details on eid last seen, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20eid_last_seen">Link to this property</a>

risk\_level?: String

For more details on risk level, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20risk_level">Link to this property</a>

score\_operator?: String

Score Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20score_operator">Link to this property</a>

total\_score?: Float64

For more details on total score, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20total_score">Link to this property</a>

active\_threats?: Float64

The Number of active threats.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20active_threats">Link to this property</a>

infected?: Bool

Whether device is infected.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20infected">Link to this property</a>

is\_active?: Bool

Whether device is active.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20is_active">Link to this property</a>

network\_status?: String

Network status of device.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20network_status">Link to this property</a>

operational\_state?: String

Agent operational state.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operational_state">Link to this property</a>

score?: Float64

A value between 0-100 assigned to devices set by the 3rd party posture provider.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20score">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20input>)

<details>

<summary>

match?: List\[Attributes]

The conditions that the client must match to run the rule.

</summary>

platform?: String

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20match%20%3E%20(attribute)%20platform">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20match>)

##### computed Expand Collapse

id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

enabled: Bool

Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue\_count input, and true otherwise.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

### cloudflare\_zero\_trust\_device\_posture\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_posture_rule" "example_zero_trust_device_posture_rule" {
  account_id = "699d98642c564d2e855e9661899b7252"
  name = "Admin Serial Numbers"
  type = "file"
  description = "The rule for admin serial numbers"
  expiration = "1h"
  input = {
    operating_system = "linux"
    path = "/bin/cat"
    exists = true
    sha256 = "https://api.us-2.crowdstrike.com"
    thumbprint = "0aabab210bdb998e9cf45da2c9ce352977ab531c681b74cf1e487be1bbe9fe6e"
  }
  match = [{
    platform = "windows"
  }]
  schedule = "1h"
}
```

#### data cloudflare\_zero\_trust\_device\_posture\_rule

##### required Expand Collapse

rule\_id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20rule_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

description: String

The description of the device posture rule.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

enabled: Bool

Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue\_count input, and true otherwise.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

expiration: String

Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expiration>)

name: String

The name of the device posture rule.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

schedule: String

Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20schedule>)

type: String

The type of device posture rule.

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20type>)

<details>

<summary>

input: Attributes

The value to be checked against.

</summary>

operating\_system: String

Operating system.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operating_system">Link to this property</a>

path: String

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20path">Link to this property</a>

exists: Bool

Whether or not file exists.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20exists">Link to this property</a>

sha256: String

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20sha256">Link to this property</a>

thumbprint: String

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20thumbprint">Link to this property</a>

id: String

List ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20id">Link to this property</a>

domain: String

Domain.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20domain">Link to this property</a>

operator: String

Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operator">Link to this property</a>

version: String

Version of OS.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20version">Link to this property</a>

os\_distro\_name: String

Operating System Distribution Name (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_distro_name">Link to this property</a>

os\_distro\_revision: String

Version of OS Distribution (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_distro_revision">Link to this property</a>

os\_version\_extra: String

Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_version_extra">Link to this property</a>

enabled: Bool

Enabled.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20enabled">Link to this property</a>

check\_disks: List\[String]

List of volume names to be checked for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20check_disks">Link to this property</a>

require\_all: Bool

Whether to check all disks for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20require_all">Link to this property</a>

certificate\_id: String

UUID of Cloudflare managed certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20certificate_id">Link to this property</a>

cn: String

Common Name that is protected by the certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20cn">Link to this property</a>

check\_private\_key: Bool

Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20check_private_key">Link to this property</a>

extended\_key\_usage: List\[String]

List of values indicating purposes for which the certificate public key can be used.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20extended_key_usage">Link to this property</a>

<details>

<summary>

locations: Attributes

</summary>

paths: List\[String]

List of paths to check for client certificate on linux.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations%20%3E%20(attribute)%20paths">Link to this property</a>

trust\_stores: List\[String]

List of trust stores to check for client certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations%20%3E%20(attribute)%20trust_stores">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations">Link to this property</a>

subject\_alternative\_names: List\[String]

List of certificate Subject Alternative Names.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20subject_alternative_names">Link to this property</a>

update\_window\_days: Float64

Number of days that the antivirus should be updated within.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20update_window_days">Link to this property</a>

compliance\_status: String

Compliance Status.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20compliance_status">Link to this property</a>

connection\_id: String

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20connection_id">Link to this property</a>

last\_seen: String

For more details on last seen, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20last_seen">Link to this property</a>

os: String

Os Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os">Link to this property</a>

overall: String

Overall.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20overall">Link to this property</a>

sensor\_config: String

SensorConfig.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20sensor_config">Link to this property</a>

state: String

For more details on state, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20state">Link to this property</a>

version\_operator: String

Version Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20version_operator">Link to this property</a>

auth\_state: List\[String]

The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20auth_state">Link to this property</a>

count\_operator: String

Count Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20count_operator">Link to this property</a>

issue\_count: String

The Number of Issues.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20issue_count">Link to this property</a>

eid\_last\_seen: String

For more details on eid last seen, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20eid_last_seen">Link to this property</a>

risk\_level: String

For more details on risk level, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20risk_level">Link to this property</a>

score\_operator: String

Score Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20score_operator">Link to this property</a>

total\_score: Float64

For more details on total score, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20total_score">Link to this property</a>

active\_threats: Float64

The Number of active threats.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20active_threats">Link to this property</a>

infected: Bool

Whether device is infected.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20infected">Link to this property</a>

is\_active: Bool

Whether device is active.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20is_active">Link to this property</a>

network\_status: String

Network status of device.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20network_status">Link to this property</a>

operational\_state: String

Agent operational state.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operational_state">Link to this property</a>

score: Float64

A value between 0-100 assigned to devices set by the 3rd party posture provider.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input%20%3E%20(attribute)%20score">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20input>)

<details>

<summary>

match: List\[Attributes]

The conditions that the client must match to run the rule.

</summary>

platform: String

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20match%20%3E%20(attribute)%20platform">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20match>)

### cloudflare\_zero\_trust\_device\_posture\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_posture_rule" "example_zero_trust_device_posture_rule" {
  account_id = "699d98642c564d2e855e9661899b7252"
  rule_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
}
```

#### data cloudflare\_zero\_trust\_device\_posture\_rules

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

API UUID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

description: String

The description of the device posture rule.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

enabled: Bool

Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue\_count input, and true otherwise.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20enabled">Link to this property</a>

expiration: String

Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expiration">Link to this property</a>

<details>

<summary>

input: Attributes

The value to be checked against.

</summary>

operating\_system: String

Operating system.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operating_system">Link to this property</a>

path: String

File path.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20path">Link to this property</a>

exists: Bool

Whether or not file exists.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20exists">Link to this property</a>

sha256: String

SHA-256.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20sha256">Link to this property</a>

thumbprint: String

Signing certificate thumbprint.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20thumbprint">Link to this property</a>

id: String

List ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20id">Link to this property</a>

domain: String

Domain.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20domain">Link to this property</a>

operator: String

Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operator">Link to this property</a>

version: String

Version of OS.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20version">Link to this property</a>

os\_distro\_name: String

Operating System Distribution Name (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_distro_name">Link to this property</a>

os\_distro\_revision: String

Version of OS Distribution (linux only).

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_distro_revision">Link to this property</a>

os\_version\_extra: String

Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os_version_extra">Link to this property</a>

enabled: Bool

Enabled.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20enabled">Link to this property</a>

check\_disks: List\[String]

List of volume names to be checked for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20check_disks">Link to this property</a>

require\_all: Bool

Whether to check all disks for encryption.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20require_all">Link to this property</a>

certificate\_id: String

UUID of Cloudflare managed certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20certificate_id">Link to this property</a>

cn: String

Common Name that is protected by the certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20cn">Link to this property</a>

check\_private\_key: Bool

Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20check_private_key">Link to this property</a>

extended\_key\_usage: List\[String]

List of values indicating purposes for which the certificate public key can be used.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20extended_key_usage">Link to this property</a>

<details>

<summary>

locations: Attributes

</summary>

paths: List\[String]

List of paths to check for client certificate on linux.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations%20%3E%20(attribute)%20paths">Link to this property</a>

trust\_stores: List\[String]

List of trust stores to check for client certificate.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations%20%3E%20(attribute)%20trust_stores">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20locations">Link to this property</a>

subject\_alternative\_names: List\[String]

List of certificate Subject Alternative Names.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20subject_alternative_names">Link to this property</a>

update\_window\_days: Float64

Number of days that the antivirus should be updated within.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20update_window_days">Link to this property</a>

compliance\_status: String

Compliance Status.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20compliance_status">Link to this property</a>

connection\_id: String

Posture Integration ID.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20connection_id">Link to this property</a>

last\_seen: String

For more details on last seen, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20last_seen">Link to this property</a>

os: String

Os Version.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20os">Link to this property</a>

overall: String

Overall.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20overall">Link to this property</a>

sensor\_config: String

SensorConfig.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20sensor_config">Link to this property</a>

state: String

For more details on state, please refer to the Crowdstrike documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20state">Link to this property</a>

version\_operator: String

Version Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20version_operator">Link to this property</a>

auth\_state: List\[String]

The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20auth_state">Link to this property</a>

count\_operator: String

Count Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20count_operator">Link to this property</a>

issue\_count: String

The Number of Issues.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20issue_count">Link to this property</a>

eid\_last\_seen: String

For more details on eid last seen, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20eid_last_seen">Link to this property</a>

risk\_level: String

For more details on risk level, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20risk_level">Link to this property</a>

score\_operator: String

Score Operator.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20score_operator">Link to this property</a>

total\_score: Float64

For more details on total score, refer to the Tanium documentation.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20total_score">Link to this property</a>

active\_threats: Float64

The Number of active threats.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20active_threats">Link to this property</a>

infected: Bool

Whether device is infected.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20infected">Link to this property</a>

is\_active: Bool

Whether device is active.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20is_active">Link to this property</a>

network\_status: String

Network status of device.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20network_status">Link to this property</a>

operational\_state: String

Agent operational state.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20operational_state">Link to this property</a>

score: Float64

A value between 0-100 assigned to devices set by the 3rd party posture provider.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input%20%3E%20(attribute)%20score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20input">Link to this property</a>

<details>

<summary>

match: List\[Attributes]

The conditions that the client must match to run the rule.

</summary>

platform: String

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20match%20%3E%20(attribute)%20platform">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20match">Link to this property</a>

name: String

The name of the device posture rule.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

schedule: String

Polling frequency for the WARP client posture check. Default: <code>5m</code> (poll every five minutes). Minimum: <code>1m</code>.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20schedule">Link to this property</a>

type: String

The type of device posture rule.

<a href="#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_device\_posture\_rules

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_posture_rules" "example_zero_trust_device_posture_rules" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesPostureIntegrations

#### resource cloudflare\_zero\_trust\_device\_posture\_integration

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

interval: String

The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`).

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20interval>)

name: String

The name of the device posture integration.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

type: String

The type of device posture integration.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

<details>

<summary>

config: Attributes

The configuration object containing third-party integration information.

</summary>

api\_url?: String

The Workspace One API URL provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20api_url">Link to this property</a>

auth\_url?: String

The Workspace One Authorization URL depending on your region.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20auth_url">Link to this property</a>

client\_id?: String

The Workspace One client ID provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_id">Link to this property</a>

client\_secret?: String

The Workspace One client secret provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_secret">Link to this property</a>

customer\_id?: String

The Crowdstrike customer ID.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20customer_id">Link to this property</a>

client\_key?: String

The Uptycs client secret.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_key">Link to this property</a>

access\_client\_id?: String

If present, this id will be passed in the <code>CF-Access-Client-ID</code> header when hitting the <code>api_url</code>.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20access_client_id">Link to this property</a>

access\_client\_secret?: String

If present, this secret will be passed in the <code>CF-Access-Client-Secret</code> header when hitting the <code>api_url</code>.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20access_client_secret">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config>)

##### computed Expand Collapse

id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

### cloudflare\_zero\_trust\_device\_posture\_integration

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_posture_integration" "example_zero_trust_device_posture_integration" {
  account_id = "699d98642c564d2e855e9661899b7252"
  config = {
    api_url = "https://as123.awmdm.com/API"
    auth_url = "https://na.uemauth.workspaceone.com/connect/token"
    client_id = "example client id"
    client_secret = "example client secret"
  }
  interval = "10m"
  name = "My Workspace One Integration"
  type = "workspace_one"
}
```

#### data cloudflare\_zero\_trust\_device\_posture\_integration

##### required Expand Collapse

integration\_id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20integration_id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

API UUID.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

interval: String

The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`).

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20interval>)

name: String

The name of the device posture integration.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

type: String

The type of device posture integration.

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20type>)

<details>

<summary>

config: Attributes

The configuration object containing third-party integration information.

</summary>

api\_url: String

The Workspace One API URL provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20api_url">Link to this property</a>

auth\_url: String

The Workspace One Authorization URL depending on your region.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20auth_url">Link to this property</a>

client\_id: String

The Workspace One client ID provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config>)

### cloudflare\_zero\_trust\_device\_posture\_integration

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_posture_integration" "example_zero_trust_device_posture_integration" {
  account_id = "699d98642c564d2e855e9661899b7252"
  integration_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
}
```

#### data cloudflare\_zero\_trust\_device\_posture\_integrations

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

API UUID.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

config: Attributes

The configuration object containing third-party integration information.

</summary>

api\_url: String

The Workspace One API URL provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20api_url">Link to this property</a>

auth\_url: String

The Workspace One Authorization URL depending on your region.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20auth_url">Link to this property</a>

client\_id: String

The Workspace One client ID provided in the Workspace One Admin Dashboard.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config">Link to this property</a>

interval: String

The interval between each posture check with the third-party API. Use <code>m</code> for minutes (e.g. <code>5m</code>) and <code>h</code> for hours (e.g. <code>12h</code>).

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20interval">Link to this property</a>

name: String

The name of the device posture integration.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

type: String

The type of device posture integration.

<a href="#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.devices.posture.integrations%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_device\_posture\_integrations

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_posture_integrations" "example_zero_trust_device_posture_integrations" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustDevicesSettings

#### resource cloudflare\_zero\_trust\_device\_settings

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

disable\_for\_time?: Float64

Sets the time limit, in seconds, that a user can use an override code to bypass WARP.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20disable_for_time>)

external\_emergency\_signal\_enabled?: Bool

Controls whether the external emergency disconnect feature is enabled.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20external_emergency_signal_enabled>)

external\_emergency\_signal\_fingerprint?: String

The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external\_emergency\_signal\_url. If provided, the WARP client will use this value to verify the server’s identity. The device will ignore any response if the server’s certificate fingerprint does not exactly match this value.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20external_emergency_signal_fingerprint>)

external\_emergency\_signal\_interval?: String

The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., “5m”, “2m30s”, “1h”). Minimum 30 seconds.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20external_emergency_signal_interval>)

external\_emergency\_signal\_url?: String

The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20external_emergency_signal_url>)

gateway\_proxy\_enabled?: Bool

Enable gateway proxy filtering on TCP.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20gateway_proxy_enabled>)

gateway\_udp\_proxy\_enabled?: Bool

Enable gateway proxy filtering on UDP.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20gateway_udp_proxy_enabled>)

root\_certificate\_installation\_enabled?: Bool

Enable installation of cloudflare managed root certificate.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20root_certificate_installation_enabled>)

use\_zt\_virtual\_ip?: Bool

Enable using CGNAT virtual IPv4.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20use_zt_virtual_ip>)

### cloudflare\_zero\_trust\_device\_settings

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_device_settings" "example_zero_trust_device_settings" {
  account_id = "699d98642c564d2e855e9661899b7252"
  disable_for_time = 0
  external_emergency_signal_enabled = true
  external_emergency_signal_fingerprint = "abcd1234567890abcd1234567890abcd1234567890abcd1234567890abcd1234"
  external_emergency_signal_interval = "5m"
  external_emergency_signal_url = "https://192.0.2.1/signal"
  gateway_proxy_enabled = true
  gateway_udp_proxy_enabled = true
  root_certificate_installation_enabled = true
  use_zt_virtual_ip = true
}
```

#### data cloudflare\_zero\_trust\_device\_settings

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

disable\_for\_time: Float64

Sets the time limit, in seconds, that a user can use an override code to bypass WARP.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20disable_for_time>)

external\_emergency\_signal\_enabled: Bool

Controls whether the external emergency disconnect feature is enabled.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20external_emergency_signal_enabled>)

external\_emergency\_signal\_fingerprint: String

The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external\_emergency\_signal\_url. If provided, the WARP client will use this value to verify the server’s identity. The device will ignore any response if the server’s certificate fingerprint does not exactly match this value.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20external_emergency_signal_fingerprint>)

external\_emergency\_signal\_interval: String

The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., “5m”, “2m30s”, “1h”). Minimum 30 seconds.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20external_emergency_signal_interval>)

external\_emergency\_signal\_url: String

The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20external_emergency_signal_url>)

gateway\_proxy\_enabled: Bool

Enable gateway proxy filtering on TCP.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20gateway_proxy_enabled>)

gateway\_udp\_proxy\_enabled: Bool

Enable gateway proxy filtering on UDP.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20gateway_udp_proxy_enabled>)

root\_certificate\_installation\_enabled: Bool

Enable installation of cloudflare managed root certificate.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20root_certificate_installation_enabled>)

use\_zt\_virtual\_ip: Bool

Enable using CGNAT virtual IPv4.

[Link to this property](<#(resource)%20zero_trust.devices.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20use_zt_virtual_ip>)

### cloudflare\_zero\_trust\_device\_settings

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_device_settings" "example_zero_trust_device_settings" {
  account_id = "699d98642c564d2e855e9661899b7252"
}
```

#### Zero TrustIdentity Providers

#### resource cloudflare\_zero\_trust\_access\_identity\_provider

##### required Expand Collapse

name: String

The name of the identity provider, shown to users on the login page.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

type: String

The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

<details>

<summary>

config: Attributes

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims?: List\[String]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20claims">Link to this property</a>

client\_id?: String

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_id">Link to this property</a>

client\_secret?: String

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_secret">Link to this property</a>

conditional\_access\_enabled?: Bool

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20conditional_access_enabled">Link to this property</a>

directory\_id?: String

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20directory_id">Link to this property</a>

email\_claim\_name?: String

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20email_claim_name">Link to this property</a>

prompt?: String

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20prompt">Link to this property</a>

support\_groups?: Bool

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20support_groups">Link to this property</a>

centrify\_account?: String

Your centrify account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20centrify_account">Link to this property</a>

centrify\_app\_id?: String

Your centrify app id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20centrify_app_id">Link to this property</a>

apps\_domain?: String

Your companies TLD

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20apps_domain">Link to this property</a>

use\_login\_hint?: Bool

Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20use_login_hint">Link to this property</a>

auth\_url?: String

The authorization\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20auth_url">Link to this property</a>

certs\_url?: String

The jwks\_uri endpoint of your IdP to allow the IdP keys to sign the tokens

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20certs_url">Link to this property</a>

pkce\_enabled?: Bool

Enable Proof Key for Code Exchange (PKCE)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20pkce_enabled">Link to this property</a>

scopes?: List\[String]

OAuth scopes

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20scopes">Link to this property</a>

token\_url?: String

The token\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_url">Link to this property</a>

authorization\_server\_id?: String

Your okta authorization server id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_server_id">Link to this property</a>

okta\_account?: String

Your okta account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20okta_account">Link to this property</a>

onelogin\_account?: String

Your OneLogin account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20onelogin_account">Link to this property</a>

ping\_env\_id?: String

Your PingOne environment identifier

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20ping_env_id">Link to this property</a>

attributes?: List\[String]

A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20attributes">Link to this property</a>

email\_attribute\_name?: String

The attribute name for email in the SAML response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20email_attribute_name">Link to this property</a>

enable\_encryption?: Bool

Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set.

To enable encryption:

1. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>
2. Set this field to <code>true</code> and include <code>saml_certificate_set_id</code> in the PUT request
3. Configure the public certificate in your external Identity Provider

Note: Requires <code>saml_certificate_set_id</code> to be set when <code>true</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20enable_encryption">Link to this property</a>

force\_authn?: Bool

Asks the IdP to reauthenticate the user for each SAML authentication request.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20force_authn">Link to this property</a>

<details>

<summary>

header\_attributes?: List\[Attributes]

Add a list of attribute names that will be returned in the response header from the Access callback.

</summary>

attribute\_name?: String

attribute name from the IDP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes%20%3E%20(attribute)%20attribute_name">Link to this property</a>

header\_name?: String

header that will be added on the request to the origin

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes%20%3E%20(attribute)%20header_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes">Link to this property</a>

idp\_public\_certs?: List\[String]

X509 certificate to verify the signature in the SAML authentication response

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20idp_public_certs">Link to this property</a>

issuer\_url?: String

IdP Entity ID or Issuer URL

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer_url">Link to this property</a>

max\_sso\_url\_length?: Int64

The maximum URL length the IdP accepts for the SSO redirect URL. When the constructed SSO URL would exceed this length, the RelayState is stored server-side and a short nonce is passed to the IdP instead. Set this if your IdP enforces a URL length limit.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20max_sso_url_length">Link to this property</a>

sign\_request?: Bool

Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sign_request">Link to this property</a>

sso\_target\_url?: String

URL to send the SAML authentication requests to

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sso_target_url">Link to this property</a>

redirect\_url: String

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20redirect_url">Link to this property</a>

restrict\_to\_account\_members?: Bool

When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20restrict_to_account_members">Link to this property</a>

login\_page\_auto\_prompt?: Bool

When enabled, the Access login page automatically prompts the user to authenticate with a passkey.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20login_page_auto_prompt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20config>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

saml\_certificate\_set\_id?: String

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set_id>)

<details>

<summary>

scim\_config?: Attributes

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled?: Bool

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20enabled">Link to this property</a>

identity\_update\_behavior?: String

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: String

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20scim_base_url">Link to this property</a>

seat\_deprovision?: Bool

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20seat_deprovision">Link to this property</a>

secret: String

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20secret">Link to this property</a>

user\_deprovision?: Bool

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20user_deprovision">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scim_config>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

read\_only: Bool

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20read_only>)

<details>

<summary>

saml\_certificate\_set: Attributes

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: Time

Timestamp when the certificate set was created

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20created_at">Link to this property</a>

uid: String

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20uid">Link to this property</a>

updated\_at: Time

Timestamp when the certificate set was last updated (e.g., during rotation)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Attributes

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: Bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20is_current">Link to this property</a>

not\_after: Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20not_after">Link to this property</a>

public\_certificate: String

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20public_certificate">Link to this property</a>

uid: String

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate">Link to this property</a>

previous\_certificate: JSON

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20saml_certificate_set>)

### cloudflare\_zero\_trust\_access\_identity\_provider

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_identity_provider" "example_zero_trust_access_identity_provider" {
  config = {
    claims = ["email_verified", "preferred_username", "custom_claim_name"]
    client_id = "<your client id>"
    client_secret = "<your client secret>"
    conditional_access_enabled = true
    directory_id = "<your azure directory uuid>"
    email_claim_name = "custom_claim_name"
    prompt = "login"
    support_groups = true
  }
  name = "Widget Corps IDP"
  type = "onetimepin"
  zone_id = "zone_id"
  saml_certificate_set_id = "c409ef44-e72c-41c8-8c0b-278c8a6f4fd8"
  scim_config = {
    enabled = true
    identity_update_behavior = "automatic"
    seat_deprovision = true
    user_deprovision = true
  }
}
```

#### data cloudflare\_zero\_trust\_access\_identity\_provider

##### optional Expand Collapse

identity\_provider\_id?: String

UUID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20identity_provider_id>)

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

<details>

<summary>

filter?: Attributes

</summary>

scim\_enabled?: String

Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20scim_enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

name: String

The name of the identity provider, shown to users on the login page.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

read\_only: Bool

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20read_only>)

saml\_certificate\_set\_id: String

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set_id>)

type: String

The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20type>)

<details>

<summary>

config: Attributes

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims: List\[String]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20claims">Link to this property</a>

client\_id: String

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_id">Link to this property</a>

client\_secret: String

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_secret">Link to this property</a>

conditional\_access\_enabled: Bool

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20conditional_access_enabled">Link to this property</a>

directory\_id: String

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20directory_id">Link to this property</a>

email\_claim\_name: String

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20email_claim_name">Link to this property</a>

prompt: String

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20prompt">Link to this property</a>

support\_groups: Bool

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20support_groups">Link to this property</a>

centrify\_account: String

Your centrify account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20centrify_account">Link to this property</a>

centrify\_app\_id: String

Your centrify app id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20centrify_app_id">Link to this property</a>

apps\_domain: String

Your companies TLD

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20apps_domain">Link to this property</a>

use\_login\_hint: Bool

Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20use_login_hint">Link to this property</a>

auth\_url: String

The authorization\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20auth_url">Link to this property</a>

certs\_url: String

The jwks\_uri endpoint of your IdP to allow the IdP keys to sign the tokens

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20certs_url">Link to this property</a>

pkce\_enabled: Bool

Enable Proof Key for Code Exchange (PKCE)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20pkce_enabled">Link to this property</a>

scopes: List\[String]

OAuth scopes

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20scopes">Link to this property</a>

token\_url: String

The token\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_url">Link to this property</a>

authorization\_server\_id: String

Your okta authorization server id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_server_id">Link to this property</a>

okta\_account: String

Your okta account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20okta_account">Link to this property</a>

onelogin\_account: String

Your OneLogin account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20onelogin_account">Link to this property</a>

ping\_env\_id: String

Your PingOne environment identifier

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20ping_env_id">Link to this property</a>

attributes: List\[String]

A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20attributes">Link to this property</a>

email\_attribute\_name: String

The attribute name for email in the SAML response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20email_attribute_name">Link to this property</a>

enable\_encryption: Bool

Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set.

To enable encryption:

1. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>
2. Set this field to <code>true</code> and include <code>saml_certificate_set_id</code> in the PUT request
3. Configure the public certificate in your external Identity Provider

Note: Requires <code>saml_certificate_set_id</code> to be set when <code>true</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20enable_encryption">Link to this property</a>

force\_authn: Bool

Asks the IdP to reauthenticate the user for each SAML authentication request.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20force_authn">Link to this property</a>

<details>

<summary>

header\_attributes: List\[Attributes]

Add a list of attribute names that will be returned in the response header from the Access callback.

</summary>

attribute\_name: String

attribute name from the IDP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes%20%3E%20(attribute)%20attribute_name">Link to this property</a>

header\_name: String

header that will be added on the request to the origin

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes%20%3E%20(attribute)%20header_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes">Link to this property</a>

idp\_public\_certs: List\[String]

X509 certificate to verify the signature in the SAML authentication response

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20idp_public_certs">Link to this property</a>

issuer\_url: String

IdP Entity ID or Issuer URL

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer_url">Link to this property</a>

max\_sso\_url\_length: Int64

The maximum URL length the IdP accepts for the SSO redirect URL. When the constructed SSO URL would exceed this length, the RelayState is stored server-side and a short nonce is passed to the IdP instead. Set this if your IdP enforces a URL length limit.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20max_sso_url_length">Link to this property</a>

sign\_request: Bool

Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sign_request">Link to this property</a>

sso\_target\_url: String

URL to send the SAML authentication requests to

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sso_target_url">Link to this property</a>

redirect\_url: String

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20redirect_url">Link to this property</a>

restrict\_to\_account\_members: Bool

When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20restrict_to_account_members">Link to this property</a>

login\_page\_auto\_prompt: Bool

When enabled, the Access login page automatically prompts the user to authenticate with a passkey.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config%20%3E%20(attribute)%20login_page_auto_prompt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20config>)

<details>

<summary>

saml\_certificate\_set: Attributes

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: Time

Timestamp when the certificate set was created

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20created_at">Link to this property</a>

uid: String

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20uid">Link to this property</a>

updated\_at: Time

Timestamp when the certificate set was last updated (e.g., during rotation)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Attributes

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: Bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20is_current">Link to this property</a>

not\_after: Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20not_after">Link to this property</a>

public\_certificate: String

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20public_certificate">Link to this property</a>

uid: String

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate">Link to this property</a>

previous\_certificate: JSON

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20saml_certificate_set>)

<details>

<summary>

scim\_config: Attributes

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Bool

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20enabled">Link to this property</a>

identity\_update\_behavior: String

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: String

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20scim_base_url">Link to this property</a>

seat\_deprovision: Bool

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20seat_deprovision">Link to this property</a>

secret: String

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20secret">Link to this property</a>

user\_deprovision: Bool

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20user_deprovision">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scim_config>)

### cloudflare\_zero\_trust\_access\_identity\_provider

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_identity_provider" "example_zero_trust_access_identity_provider" {
  identity_provider_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_identity\_providers

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

scim\_enabled?: String

Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled.

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20scim_enabled>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

<details>

<summary>

config: Attributes

The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

</summary>

claims: List\[String]

Custom claims

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20claims">Link to this property</a>

client\_id: String

Your OAuth Client ID

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_id">Link to this property</a>

client\_secret: String

Your OAuth Client Secret

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20client_secret">Link to this property</a>

conditional\_access\_enabled: Bool

Should Cloudflare try to load authentication contexts from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20conditional_access_enabled">Link to this property</a>

directory\_id: String

Your Azure directory uuid

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20directory_id">Link to this property</a>

email\_claim\_name: String

The claim name for email in the id\_token response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20email_claim_name">Link to this property</a>

prompt: String

Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn’t presented with any interactive prompt. If the request can’t be completed silently by using single-sign on, the Microsoft identity platform returns an interaction\_required error. prompt=select\_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20prompt">Link to this property</a>

support\_groups: Bool

Should Cloudflare try to load groups from your account

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20support_groups">Link to this property</a>

centrify\_account: String

Your centrify account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20centrify_account">Link to this property</a>

centrify\_app\_id: String

Your centrify app id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20centrify_app_id">Link to this property</a>

apps\_domain: String

Your companies TLD

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20apps_domain">Link to this property</a>

use\_login\_hint: Bool

Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20use_login_hint">Link to this property</a>

auth\_url: String

The authorization\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20auth_url">Link to this property</a>

certs\_url: String

The jwks\_uri endpoint of your IdP to allow the IdP keys to sign the tokens

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20certs_url">Link to this property</a>

pkce\_enabled: Bool

Enable Proof Key for Code Exchange (PKCE)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20pkce_enabled">Link to this property</a>

scopes: List\[String]

OAuth scopes

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20scopes">Link to this property</a>

token\_url: String

The token\_endpoint URL of your IdP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_url">Link to this property</a>

authorization\_server\_id: String

Your okta authorization server id

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_server_id">Link to this property</a>

okta\_account: String

Your okta account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20okta_account">Link to this property</a>

onelogin\_account: String

Your OneLogin account url

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20onelogin_account">Link to this property</a>

ping\_env\_id: String

Your PingOne environment identifier

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20ping_env_id">Link to this property</a>

attributes: List\[String]

A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20attributes">Link to this property</a>

email\_attribute\_name: String

The attribute name for email in the SAML response.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20email_attribute_name">Link to this property</a>

enable\_encryption: Bool

Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt SAML assertions using the certificate from the assigned certificate set.

To enable encryption:

1. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>
2. Set this field to <code>true</code> and include <code>saml_certificate_set_id</code> in the PUT request
3. Configure the public certificate in your external Identity Provider

Note: Requires <code>saml_certificate_set_id</code> to be set when <code>true</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20enable_encryption">Link to this property</a>

force\_authn: Bool

Asks the IdP to reauthenticate the user for each SAML authentication request.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20force_authn">Link to this property</a>

<details>

<summary>

header\_attributes: List\[Attributes]

Add a list of attribute names that will be returned in the response header from the Access callback.

</summary>

attribute\_name: String

attribute name from the IDP

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes%20%3E%20(attribute)%20attribute_name">Link to this property</a>

header\_name: String

header that will be added on the request to the origin

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes%20%3E%20(attribute)%20header_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20header_attributes">Link to this property</a>

idp\_public\_certs: List\[String]

X509 certificate to verify the signature in the SAML authentication response

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20idp_public_certs">Link to this property</a>

issuer\_url: String

IdP Entity ID or Issuer URL

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer_url">Link to this property</a>

max\_sso\_url\_length: Int64

The maximum URL length the IdP accepts for the SSO redirect URL. When the constructed SSO URL would exceed this length, the RelayState is stored server-side and a short nonce is passed to the IdP instead. Set this if your IdP enforces a URL length limit.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20max_sso_url_length">Link to this property</a>

sign\_request: Bool

Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sign_request">Link to this property</a>

sso\_target\_url: String

URL to send the SAML authentication requests to

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20sso_target_url">Link to this property</a>

redirect\_url: String

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20redirect_url">Link to this property</a>

restrict\_to\_account\_members: Bool

When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20restrict_to_account_members">Link to this property</a>

login\_page\_auto\_prompt: Bool

When enabled, the Access login page automatically prompts the user to authenticate with a passkey.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config%20%3E%20(attribute)%20login_page_auto_prompt">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20config">Link to this property</a>

name: String

The name of the identity provider, shown to users on the login page.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

type: String

The type of identity provider. To determine the value for a specific provider, refer to our <a href="https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/">developer documentation</a>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20type">Link to this property</a>

id: String

UUID.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

read\_only: Bool

Indicates that the identity provider is immutable and cannot be updated or deleted via the API.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20read_only">Link to this property</a>

<details>

<summary>

saml\_certificate\_set: Attributes

The SAML encryption certificate set details, including current and previous certificates. Only present for SAML identity providers with a certificate set assigned.

</summary>

created\_at: Time

Timestamp when the certificate set was created

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20created_at">Link to this property</a>

uid: String

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20uid">Link to this property</a>

updated\_at: Time

Timestamp when the certificate set was last updated (e.g., during rotation)

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate: Attributes

The currently active certificate used for encrypting SAML assertions

</summary>

is\_current: Bool

Indicates whether this is the currently active certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20is_current">Link to this property</a>

not\_after: Time

Certificate expiration date. Certificates are automatically rotated 30 days before expiration.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20not_after">Link to this property</a>

public\_certificate: String

PEM-encoded X.509 certificate containing the public key. Configure this certificate in your external SAML Identity Provider to enable encryption.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20public_certificate">Link to this property</a>

uid: String

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate%20%3E%20(attribute)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20current_certificate">Link to this property</a>

previous\_certificate: JSON

The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set%20%3E%20(attribute)%20previous_certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set">Link to this property</a>

saml\_certificate\_set\_id: String

The UID of the SAML encryption certificate set assigned to this Identity Provider. Only present for SAML identity providers with encryption configured. Create a certificate set via POST to <code>/identity_providers/{id}/saml_certificate</code>.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20saml_certificate_set_id">Link to this property</a>

<details>

<summary>

scim\_config: Attributes

The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.

</summary>

enabled: Bool

A flag to enable or disable SCIM for the identity provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20enabled">Link to this property</a>

identity\_update\_behavior: String

Indicates how a SCIM event updates a user identity used for policy evaluation. Use “automatic” to automatically update a user’s identity and augment it with fields from the SCIM user resource. Use “reauth” to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With “reauth” identities will not contain fields from the SCIM user resource. With “no\_action” identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20identity_update_behavior">Link to this property</a>

scim\_base\_url: String

The base URL of Cloudflare’s SCIM V2.0 API endpoint.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20scim_base_url">Link to this property</a>

seat\_deprovision: Bool

A flag to remove a user’s seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user\_deprovision is also enabled.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20seat_deprovision">Link to this property</a>

secret: String

A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity\_providers/:idpID/refresh\_scim\_secret.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20secret">Link to this property</a>

user\_deprovision: Bool

A flag to enable revoking a user’s session in Access and Gateway when they have been deprovisioned in the Identity Provider.

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config%20%3E%20(attribute)%20user_deprovision">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scim_config">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.identity_providers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_identity\_providers

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_identity_providers" "example_zero_trust_access_identity_providers" {
  account_id = "account_id"
  zone_id = "zone_id"
  scim_enabled = "scim_enabled"
}
```

#### Zero TrustOrganizations

#### resource cloudflare\_zero\_trust\_organization

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

auth\_domain?: String

The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format `adjective-noun-hex4` (e.g. `frosty-moon-7a3b.cloudflareaccess.com`).

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_domain>)

deny\_unmatched\_requests?: Bool

Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the `deny_unmatched_requests_exempted_zone_names` array.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20deny_unmatched_requests>)

name?: String

The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

session\_duration?: String

The amount of time that tokens issued for applications will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20session_duration>)

strict\_service\_token\_auth?: Bool

Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20strict_service_token_auth>)

user\_seat\_expiration\_inactive\_time?: String

The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format `300ms` or `2h45m`. Valid time units are: `ns`, `us` (or `µs`), `ms`, `s`, `m`, `h`.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20user_seat_expiration_inactive_time>)

warp\_auth\_session\_duration?: String

The amount of time that tokens issued for applications will be valid. Must be in the format `30m` or `2h45m`. Valid time units are: m, h.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20warp_auth_session_duration>)

deny\_unmatched\_requests\_exempted\_zone\_names?: List\[String]

Contains zone names to exempt from the `deny_unmatched_requests` feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20deny_unmatched_requests_exempted_zone_names>)

<details>

<summary>

custom\_pages?: Attributes

</summary>

forbidden?: String

The uid of the custom page to use when a user is denied access after failing a non-identity rule.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20custom_pages%20%3E%20(attribute)%20forbidden">Link to this property</a>

identity\_denied?: String

The uid of the custom page to use when a user is denied access.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20custom_pages%20%3E%20(attribute)%20identity_denied">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20custom_pages>)

<details>

<summary>

login\_design?: Attributes

</summary>

background\_color?: String

The background color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20background_color">Link to this property</a>

footer\_text?: String

The text at the bottom of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20footer_text">Link to this property</a>

header\_text?: String

The text at the top of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20header_text">Link to this property</a>

logo\_path?: String

The URL of the logo on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20logo_path">Link to this property</a>

text\_color?: String

The text color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20text_color">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20login_design>)

<details>

<summary>

mfa\_config?: Attributes

Configures multi-factor authentication (MFA) settings for an organization.

</summary>

allowed\_authenticators?: List\[String]

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20allowed_authenticators">Link to this property</a>

amr\_matching\_session\_duration?: String

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20amr_matching_session_duration">Link to this property</a>

required\_aaguids?: String

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20required_aaguids">Link to this property</a>

session\_duration?: String

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config>)

<details>

<summary>

mfa\_piv\_key\_requirements?: Attributes

Configures PIV key requirements for MFA using hardware security keys.

</summary>

pin\_policy?: String

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20pin_policy">Link to this property</a>

require\_fips\_device?: Bool

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20require_fips_device">Link to this property</a>

ssh\_key\_size?: List\[Int64]

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20ssh_key_size">Link to this property</a>

ssh\_key\_type?: List\[String]

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20ssh_key_type">Link to this property</a>

touch\_policy?: String

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20touch_policy">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_piv_key_requirements>)

<details>

<summary>

service\_token\_inactivity?: Attributes

Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

action: String

The action applied to an inactive service token.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_token_inactivity%20%3E%20(attribute)%20action">Link to this property</a>

enabled: Bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_token_inactivity%20%3E%20(attribute)%20enabled">Link to this property</a>

inactivity\_threshold\_days: Int64

The number of days a service token must be inactive before the configured action is applied.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_token_inactivity%20%3E%20(attribute)%20inactivity_threshold_days">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20service_token_inactivity>)

allow\_authenticate\_via\_warp?: Bool

When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allow_authenticate_via_warp>)

auto\_redirect\_to\_identity?: Bool

When set to `true`, users skip the identity provider selection step during login.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auto_redirect_to_identity>)

is\_ui\_read\_only?: Bool

Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20is_ui_read_only>)

mfa\_required\_for\_all\_apps?: Bool

Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_required_for_all_apps>)

ui\_read\_only\_toggle\_reason?: String

A description of the reason why the UI read only field is being toggled.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ui_read_only_toggle_reason>)

warp\_auth\_non\_browser\_401?: Bool

When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20warp_auth_non_browser_401>)

##### computed Expand Collapse

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

trusted\_accounts: List\[String]

The account tags of organizations trusted by this organization for policy and device posture sharing.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20trusted_accounts>)

### cloudflare\_zero\_trust\_organization

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_organization" "example_zero_trust_organization" {
  zone_id = "zone_id"
  allow_authenticate_via_warp = true
  auth_domain = "test.cloudflareaccess.com"
  auto_redirect_to_identity = true
  custom_pages = {
    forbidden = "699d98642c564d2e855e9661899b7252"
    identity_denied = "699d98642c564d2e855e9661899b7252"
  }
  deny_unmatched_requests = true
  deny_unmatched_requests_exempted_zone_names = ["example.com"]
  is_ui_read_only = true
  login_design = {
    background_color = "#c5ed1b"
    footer_text = "This is an example description."
    header_text = "This is an example description."
    logo_path = "https://example.com/logo.png"
    text_color = "#c5ed1b"
  }
  mfa_config = {
    allowed_authenticators = ["totp", "biometrics", "security_key"]
    amr_matching_session_duration = "12h"
    required_aaguids = "2fc0579f-8113-47ea-b116-bb5a8db9202a"
    session_duration = "24h"
  }
  mfa_piv_key_requirements = {
    pin_policy = "always"
    require_fips_device = true
    ssh_key_size = [256, 2048]
    ssh_key_type = ["ecdsa", "rsa"]
    touch_policy = "always"
  }
  mfa_required_for_all_apps = false
  name = "Widget Corps Internal Applications"
  service_token_inactivity = {
    action = "disable"
    enabled = true
    inactivity_threshold_days = 30
  }
  session_duration = "24h"
  strict_service_token_auth = true
  ui_read_only_toggle_reason = "Temporarily turn off the UI read only lock to make a change via the UI"
  user_seat_expiration_inactive_time = "730h"
  warp_auth_non_browser_401 = false
  warp_auth_session_duration = "24h"
}
```

#### data cloudflare\_zero\_trust\_organization

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

allow\_authenticate\_via\_warp: Bool

When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allow_authenticate_via_warp>)

auth\_domain: String

The unique subdomain assigned to your Zero Trust organization. If omitted on creation, a unique subdomain is auto-generated in the format `adjective-noun-hex4` (e.g. `frosty-moon-7a3b.cloudflareaccess.com`).

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_domain>)

auto\_redirect\_to\_identity: Bool

When set to `true`, users skip the identity provider selection step during login.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auto_redirect_to_identity>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

deny\_unmatched\_requests: Bool

Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the `deny_unmatched_requests_exempted_zone_names` array.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20deny_unmatched_requests>)

is\_ui\_read\_only: Bool

Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_ui_read_only>)

mfa\_required\_for\_all\_apps: Bool

Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: ‘allowed\_authenticators’ cannot contain only the infrastructure SSH authenticators (‘piv\_key’ and ‘ssh\_fido2\_key’) if the organization has any non-infrastructure applications.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_required_for_all_apps>)

name: String

The name of your Zero Trust organization. When omitted on creation, defaults to the provided auth\_domain; when both are omitted, defaults to the auto-generated subdomain slug (e.g. frosty-moon-7a3b).

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

session\_duration: String

The amount of time that tokens issued for applications will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20session_duration>)

strict\_service\_token\_auth: Bool

Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF\_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20strict_service_token_auth>)

ui\_read\_only\_toggle\_reason: String

A description of the reason why the UI read only field is being toggled.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ui_read_only_toggle_reason>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

user\_seat\_expiration\_inactive\_time: String

The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format `300ms` or `2h45m`. Valid time units are: `ns`, `us` (or `µs`), `ms`, `s`, `m`, `h`.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20user_seat_expiration_inactive_time>)

warp\_auth\_non\_browser\_401: Bool

When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20warp_auth_non_browser_401>)

warp\_auth\_session\_duration: String

The amount of time that tokens issued for applications will be valid. Must be in the format `30m` or `2h45m`. Valid time units are: m, h.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20warp_auth_session_duration>)

deny\_unmatched\_requests\_exempted\_zone\_names: List\[String]

Contains zone names to exempt from the `deny_unmatched_requests` feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20deny_unmatched_requests_exempted_zone_names>)

trusted\_accounts: List\[String]

The account tags of organizations trusted by this organization for policy and device posture sharing.

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20trusted_accounts>)

<details>

<summary>

custom\_pages: Attributes

</summary>

forbidden: String

The uid of the custom page to use when a user is denied access after failing a non-identity rule.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_pages%20%3E%20(attribute)%20forbidden">Link to this property</a>

identity\_denied: String

The uid of the custom page to use when a user is denied access.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_pages%20%3E%20(attribute)%20identity_denied">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_pages>)

<details>

<summary>

login\_design: Attributes

</summary>

background\_color: String

The background color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20background_color">Link to this property</a>

footer\_text: String

The text at the bottom of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20footer_text">Link to this property</a>

header\_text: String

The text at the top of your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20header_text">Link to this property</a>

logo\_path: String

The URL of the logo on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20logo_path">Link to this property</a>

text\_color: String

The text color on your login page.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20login_design%20%3E%20(attribute)%20text_color">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20login_design>)

<details>

<summary>

mfa\_config: Attributes

Configures multi-factor authentication (MFA) settings for an organization.

</summary>

allowed\_authenticators: List\[String]

Lists the MFA methods that users can authenticate with. The <code>piv_key</code> and <code>ssh_fido2_key</code> values are supported only for infrastructure applications.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20allowed_authenticators">Link to this property</a>

amr\_matching\_session\_duration: String

Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains “mfa”. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20amr_matching_session_duration">Link to this property</a>

required\_aaguids: String

Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20required_aaguids">Link to this property</a>

session\_duration: String

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_config>)

<details>

<summary>

mfa\_piv\_key\_requirements: Attributes

Configures PIV key requirements for MFA using hardware security keys.

</summary>

pin\_policy: String

Defines when a PIN is required to use the SSH key. Valid values: <code>never</code> (no PIN required), <code>once</code> (PIN required once per session), <code>always</code> (PIN required for each use).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20pin_policy">Link to this property</a>

require\_fips\_device: Bool

Requires the PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20require_fips_device">Link to this property</a>

ssh\_key\_size: List\[Int64]

Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20ssh_key_size">Link to this property</a>

ssh\_key\_type: List\[String]

Specifies the allowed SSH key types. Valid values are <code>ecdsa</code>, <code>ed25519</code>, and <code>rsa</code>.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20ssh_key_type">Link to this property</a>

touch\_policy: String

Defines when physical touch is required to use the SSH key. Valid values: <code>never</code> (no touch required), <code>always</code> (touch required for each use), <code>cached</code> (touch cached for 15 seconds).

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_piv_key_requirements%20%3E%20(attribute)%20touch_policy">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mfa_piv_key_requirements>)

<details>

<summary>

service\_token\_inactivity: Attributes

Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.

</summary>

action: String

The action applied to an inactive service token.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_token_inactivity%20%3E%20(attribute)%20action">Link to this property</a>

enabled: Bool

Whether automatic enforcement for inactive service tokens is enabled.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_token_inactivity%20%3E%20(attribute)%20enabled">Link to this property</a>

inactivity\_threshold\_days: Int64

The number of days a service token must be inactive before the configured action is applied.

<a href="#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_token_inactivity%20%3E%20(attribute)%20inactivity_threshold_days">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.organizations%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_token_inactivity>)

### cloudflare\_zero\_trust\_organization

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_organization" "example_zero_trust_organization" {
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### Zero TrustAccessAI ControlsMcpPortals

#### resource cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_portal

##### required Expand Collapse

id: String

Unique identifier for the MCP portal.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

hostname: String

Hostname where the MCP portal is available.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hostname>)

name: String

Display name for the MCP portal.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

##### optional Expand Collapse

Deprecatedallow\_code\_mode?: Bool

Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allow_code_mode>)

code\_mode?: String

Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20code_mode>)

description?: String

Optional description of the MCP portal.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

<details>

<summary>

servers?: Set\[Attributes]

MCP servers attached to the portal and their portal-specific settings.

</summary>

server\_id: String

Unique identifier for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20server_id">Link to this property</a>

default\_disabled?: Bool

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in this server entry’s updated\_tools or updated\_prompts fields when creating or updating the portal.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20default_disabled">Link to this property</a>

on\_behalf?: Bool

Use end-user OAuth credentials when connecting this server to the portal.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20on_behalf">Link to this property</a>

<details>

<summary>

updated\_prompts?: List\[Attributes]

Portal-specific prompt overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20name">Link to this property</a>

alias?: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20alias">Link to this property</a>

description?: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20description">Link to this property</a>

enabled?: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: List\[Attributes]

Portal-specific tool overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20name">Link to this property</a>

alias?: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20alias">Link to this property</a>

description?: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20description">Link to this property</a>

enabled?: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20servers>)

secure\_web\_gateway?: Bool

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20secure_web_gateway>)

##### computed Expand Collapse

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

created\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_by>)

modified\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_at>)

modified\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_by>)

### cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_portal

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_ai_controls_mcp_portal" "example_zero_trust_access_ai_controls_mcp_portal" {
  account_id = "a86a8f5c339544d7bdc89926de14fb8c"
  id = "my-mcp-portal"
  hostname = "example.com"
  name = "My MCP Portal"
  allow_code_mode = true
  code_mode = "opt_in"
  description = "This is my custom MCP Portal"
  secure_web_gateway = false
  servers = [{
    server_id = "my-mcp-server"
    default_disabled = true
    on_behalf = true
    updated_prompts = [{
      name = "name"
      alias = "my-custom-alias"
      description = "description"
      enabled = true
    }]
    updated_tools = [{
      name = "name"
      alias = "my-custom-alias"
      description = "description"
      enabled = true
    }]
  }]
}
```

#### data cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_portal

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

id?: String

Unique identifier for the MCP portal.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

<details>

<summary>

filter?: Attributes

</summary>

search?: String

Search by id, name, hostname

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20search">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

Deprecatedallow\_code\_mode: Bool

Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allow_code_mode>)

code\_mode: String

Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20code_mode>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

created\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_by>)

description: String

Optional description of the MCP portal.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

hostname: String

Hostname where the MCP portal is available.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hostname>)

modified\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_at>)

modified\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_by>)

name: String

Display name for the MCP portal.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

secure\_web\_gateway: Bool

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20secure_web_gateway>)

<details>

<summary>

servers: Set\[Attributes]

</summary>

id: String

Unique identifier for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20id">Link to this property</a>

auth\_type: String

Authentication method used to connect to the upstream MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_type">Link to this property</a>

hostname: String

URL of the upstream MCP endpoint.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20hostname">Link to this property</a>

name: String

Display name for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20name">Link to this property</a>

prompts: List\[Map\[JSON]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20prompts">Link to this property</a>

server\_id: String

Unique identifier for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20server_id">Link to this property</a>

tools: List\[Map\[JSON]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Attributes

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

auth\_mode: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20auth_mode">Link to this property</a>

client\_secret\_version: Float64

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Attributes

</summary>

authorization\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_endpoint">Link to this property</a>

issuer: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer">Link to this property</a>

resource: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20resource">Link to this property</a>

revocation\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20revocation_endpoint">Link to this property</a>

token\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config">Link to this property</a>

has\_client\_secret: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Attributes

</summary>

client\_id: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20client_id">Link to this property</a>

redirect\_uris: List\[String]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20redirect_uris">Link to this property</a>

scope: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary">Link to this property</a>

authentication\_status: String

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20authentication_status">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20created_at">Link to this property</a>

created\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20created_by">Link to this property</a>

default\_disabled: Bool

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20default_disabled">Link to this property</a>

description: String

Optional description of the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20description">Link to this property</a>

error: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error">Link to this property</a>

<details>

<summary>

error\_details: Attributes

</summary>

cause: String

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20cause">Link to this property</a>

is\_upstream: Bool

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20is_upstream">Link to this property</a>

mcp\_code: Float64

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20mcp_code">Link to this property</a>

retryable: Bool

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20retryable">Link to this property</a>

status\_code: Float64

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Bool

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20last_successful_sync">Link to this property</a>

last\_synced: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20last_synced">Link to this property</a>

modified\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20modified_at">Link to this property</a>

modified\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20modified_by">Link to this property</a>

on\_behalf: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20on_behalf">Link to this property</a>

secure\_web\_gateway: Bool

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20secure_web_gateway">Link to this property</a>

status: String

Current sync state of the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: List\[Attributes]

</summary>

name: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20name">Link to this property</a>

enabled: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20enabled">Link to this property</a>

portal\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20portal_alias">Link to this property</a>

portal\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20portal_description">Link to this property</a>

server\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20server_alias">Link to this property</a>

server\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: List\[Attributes]

</summary>

name: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20name">Link to this property</a>

enabled: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20enabled">Link to this property</a>

portal\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20portal_alias">Link to this property</a>

portal\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20portal_description">Link to this property</a>

server\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20server_alias">Link to this property</a>

server\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20servers>)

### cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_portal

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_ai_controls_mcp_portal" "example_zero_trust_access_ai_controls_mcp_portal" {
  account_id = "a86a8f5c339544d7bdc89926de14fb8c"
  id = "my-mcp-portal"
}
```

#### data cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_portals

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

search?: String

Search by id, name, hostname

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20search>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Unique identifier for the MCP portal.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

hostname: String

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20hostname">Link to this property</a>

name: String

Display name for the MCP portal.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

<details>

<summary>

servers: Set\[Attributes]

</summary>

id: String

Unique identifier for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20id">Link to this property</a>

auth\_type: String

Authentication method used to connect to the upstream MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_type">Link to this property</a>

hostname: String

URL of the upstream MCP endpoint.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20hostname">Link to this property</a>

name: String

Display name for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20name">Link to this property</a>

prompts: List\[Map\[JSON]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20prompts">Link to this property</a>

server\_id: String

Unique identifier for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20server_id">Link to this property</a>

tools: List\[Map\[JSON]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Attributes

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

auth\_mode: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20auth_mode">Link to this property</a>

client\_secret\_version: Float64

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Attributes

</summary>

authorization\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_endpoint">Link to this property</a>

issuer: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer">Link to this property</a>

resource: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20resource">Link to this property</a>

revocation\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20revocation_endpoint">Link to this property</a>

token\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config">Link to this property</a>

has\_client\_secret: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Attributes

</summary>

client\_id: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20client_id">Link to this property</a>

redirect\_uris: List\[String]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20redirect_uris">Link to this property</a>

scope: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20auth_config_summary">Link to this property</a>

authentication\_status: String

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20authentication_status">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20created_at">Link to this property</a>

created\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20created_by">Link to this property</a>

default\_disabled: Bool

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20default_disabled">Link to this property</a>

description: String

Optional description of the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20description">Link to this property</a>

error: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error">Link to this property</a>

<details>

<summary>

error\_details: Attributes

</summary>

cause: String

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20cause">Link to this property</a>

is\_upstream: Bool

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20is_upstream">Link to this property</a>

mcp\_code: Float64

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20mcp_code">Link to this property</a>

retryable: Bool

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20retryable">Link to this property</a>

status\_code: Float64

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Bool

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20last_successful_sync">Link to this property</a>

last\_synced: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20last_synced">Link to this property</a>

modified\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20modified_at">Link to this property</a>

modified\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20modified_by">Link to this property</a>

on\_behalf: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20on_behalf">Link to this property</a>

secure\_web\_gateway: Bool

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20secure_web_gateway">Link to this property</a>

status: String

Current sync state of the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: List\[Attributes]

</summary>

name: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20name">Link to this property</a>

enabled: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20enabled">Link to this property</a>

portal\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20portal_alias">Link to this property</a>

portal\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20portal_description">Link to this property</a>

server\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20server_alias">Link to this property</a>

server\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: List\[Attributes]

</summary>

name: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20name">Link to this property</a>

enabled: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20enabled">Link to this property</a>

portal\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20portal_alias">Link to this property</a>

portal\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20portal_description">Link to this property</a>

server\_alias: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20server_alias">Link to this property</a>

server\_description: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers%20%3E%20(attribute)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode: Bool

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20allow_code_mode">Link to this property</a>

code\_mode: String

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20code_mode">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

created\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_by">Link to this property</a>

description: String

Optional description of the MCP portal.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

modified\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_at">Link to this property</a>

modified\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_by">Link to this property</a>

secure\_web\_gateway: Bool

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_portals

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_ai_controls_mcp_portals" "example_zero_trust_access_ai_controls_mcp_portals" {
  account_id = "a86a8f5c339544d7bdc89926de14fb8c"
  search = "search"
}
```

#### Zero TrustAccessAI ControlsMcpServers

#### resource cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_server

##### required Expand Collapse

id: String

Unique identifier for the MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

account\_id: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

auth\_type: String

Authentication method used to connect to the upstream MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_type>)

hostname: String

URL of the upstream MCP endpoint.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hostname>)

name: String

Display name for the MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

##### optional Expand Collapse

auth\_credentials?: String

Credential configuration for the upstream MCP server. For auth\_type “bearer”, either a raw token string (e.g. “sk-abc123”), which is wrapped server-side as `Authorization: Bearer <token>`, or a JSON-encoded object of the form `{"headers":{"Header-Name":"value",...}}` for custom or multiple static headers (e.g. Cloudflare Access service tokens: `{"headers":{"cf-access-client-id":"...","cf-access-client-secret":"..."}}`). For auth\_type “oauth” with a pre-registered client, send a JSON-encoded object containing `auth_mode:"manual"`, `config.authorization_endpoint`, `config.token_endpoint`, and `registration_info.client_id`. Also provide `registration_info.redirect_uris` unless `is_shared_oauth_callback_enabled` is true. Optional fields include `config.issuer`, `config.revocation_endpoint`, `registration_info.scope`, and `registration_info.token_endpoint_auth_method`. Send the client secret in the separate `client_secret` field. Omit `auth_credentials` on update to preserve the existing configuration.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_credentials>)

client\_secret?: String

Pre-registered OAuth client\_secret. Write-only - accepted on create/update when auth\_credentials.auth\_mode is ‘manual’. Required when creating a manual OAuth server or converting an existing server to manual mode. Omit it on update to preserve the existing secret; provide it to rotate the secret. Stored AES-GCM-encrypted in server\_oauth\_secrets; never returned by read endpoints.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20client_secret>)

description?: String

Optional description of the MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

<details>

<summary>

updated\_prompts?: List\[Attributes]

Server-wide prompt capability overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20name">Link to this property</a>

alias?: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20alias">Link to this property</a>

description?: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20description">Link to this property</a>

enabled?: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_prompts>)

<details>

<summary>

updated\_tools?: List\[Attributes]

Server-wide tool capability overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20name">Link to this property</a>

alias?: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20alias">Link to this property</a>

description?: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20description">Link to this property</a>

enabled?: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_tools>)

is\_shared\_oauth\_callback\_enabled?: Bool

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20is_shared_oauth_callback_enabled>)

secure\_web\_gateway?: Bool

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20secure_web_gateway>)

##### computed Expand Collapse

authentication\_status: String

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20authentication_status>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

created\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_by>)

error: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error>)

last\_successful\_sync: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20last_successful_sync>)

last\_synced: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20last_synced>)

modified\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_at>)

modified\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_by>)

status: String

Current sync state of the server

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20status>)

prompts: List\[Map\[JSON]]

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20prompts>)

tools: List\[Map\[JSON]]

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20tools>)

<details>

<summary>

auth\_config\_summary: Attributes

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

auth\_mode: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20auth_mode">Link to this property</a>

client\_secret\_version: Float64

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Attributes

</summary>

authorization\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_endpoint">Link to this property</a>

issuer: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer">Link to this property</a>

resource: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20resource">Link to this property</a>

revocation\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20revocation_endpoint">Link to this property</a>

token\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config">Link to this property</a>

has\_client\_secret: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Attributes

</summary>

client\_id: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20client_id">Link to this property</a>

redirect\_uris: List\[String]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20redirect_uris">Link to this property</a>

scope: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20auth_config_summary>)

<details>

<summary>

error\_details: Attributes

</summary>

cause: String

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20cause">Link to this property</a>

is\_upstream: Bool

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20is_upstream">Link to this property</a>

mcp\_code: Float64

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20mcp_code">Link to this property</a>

retryable: Bool

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20retryable">Link to this property</a>

status\_code: Float64

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20status_code">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20error_details>)

### cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_server

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_ai_controls_mcp_server" "example_zero_trust_access_ai_controls_mcp_server" {
  account_id = "a86a8f5c339544d7bdc89926de14fb8c"
  id = "my-mcp-server"
  auth_type = "unauthenticated"
  hostname = "https://example.com/mcp"
  name = "My MCP Server"
  auth_credentials = "sk-my-bearer-token"
  client_secret = "client_secret"
  description = "This is one remote MCP server"
  is_shared_oauth_callback_enabled = true
  secure_web_gateway = false
  updated_prompts = [{
    name = "name"
    alias = "my-custom-alias"
    description = "description"
    enabled = true
  }]
  updated_tools = [{
    name = "name"
    alias = "my-custom-alias"
    description = "description"
    enabled = true
  }]
}
```

#### data cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_server

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

id?: String

Unique identifier for the MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

<details>

<summary>

filter?: Attributes

</summary>

search?: String

Search by id, name

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20search">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

auth\_type: String

Authentication method used to connect to the upstream MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_type>)

authentication\_status: String

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20authentication_status>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

created\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_by>)

description: String

Optional description of the MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

error: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error>)

hostname: String

URL of the upstream MCP endpoint.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hostname>)

is\_shared\_oauth\_callback\_enabled: Bool

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_shared_oauth_callback_enabled>)

last\_successful\_sync: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20last_successful_sync>)

last\_synced: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20last_synced>)

modified\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_at>)

modified\_by: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_by>)

name: String

Display name for the MCP server.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

secure\_web\_gateway: Bool

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20secure_web_gateway>)

status: String

Current sync state of the server

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20status>)

prompts: List\[Map\[JSON]]

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20prompts>)

tools: List\[Map\[JSON]]

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20tools>)

<details>

<summary>

auth\_config\_summary: Attributes

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

auth\_mode: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20auth_mode">Link to this property</a>

client\_secret\_version: Float64

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Attributes

</summary>

authorization\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_endpoint">Link to this property</a>

issuer: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer">Link to this property</a>

resource: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20resource">Link to this property</a>

revocation\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20revocation_endpoint">Link to this property</a>

token\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config">Link to this property</a>

has\_client\_secret: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Attributes

</summary>

client\_id: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20client_id">Link to this property</a>

redirect\_uris: List\[String]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20redirect_uris">Link to this property</a>

scope: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20auth_config_summary>)

<details>

<summary>

error\_details: Attributes

</summary>

cause: String

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20cause">Link to this property</a>

is\_upstream: Bool

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20is_upstream">Link to this property</a>

mcp\_code: Float64

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20mcp_code">Link to this property</a>

retryable: Bool

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20retryable">Link to this property</a>

status\_code: Float64

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20status_code">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20error_details>)

<details>

<summary>

updated\_prompts: List\[Attributes]

Server-wide prompt capability overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20name">Link to this property</a>

alias: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20alias">Link to this property</a>

description: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20description">Link to this property</a>

enabled: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_prompts>)

<details>

<summary>

updated\_tools: List\[Attributes]

Server-wide tool capability overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20name">Link to this property</a>

alias: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20alias">Link to this property</a>

description: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20description">Link to this property</a>

enabled: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_tools>)

### cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_server

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_ai_controls_mcp_server" "example_zero_trust_access_ai_controls_mcp_server" {
  account_id = "a86a8f5c339544d7bdc89926de14fb8c"
  id = "my-mcp-server"
}
```

#### data cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_servers

##### required Expand Collapse

account\_id: String

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

search?: String

Search by id, name

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20search>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Unique identifier for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

auth\_type: String

Authentication method used to connect to the upstream MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_type">Link to this property</a>

hostname: String

URL of the upstream MCP endpoint.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20hostname">Link to this property</a>

name: String

Display name for the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

prompts: List\[Map\[JSON]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20prompts">Link to this property</a>

tools: List\[Map\[JSON]]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary: Attributes

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

auth\_mode: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20auth_mode">Link to this property</a>

client\_secret\_version: Float64

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20client_secret_version">Link to this property</a>

<details>

<summary>

config: Attributes

</summary>

authorization\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20authorization_endpoint">Link to this property</a>

issuer: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20issuer">Link to this property</a>

resource: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20resource">Link to this property</a>

revocation\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20revocation_endpoint">Link to this property</a>

token\_endpoint: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config%20%3E%20(attribute)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20config">Link to this property</a>

has\_client\_secret: Bool

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info: Attributes

</summary>

client\_id: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20client_id">Link to this property</a>

redirect\_uris: List\[String]

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20redirect_uris">Link to this property</a>

scope: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20scope">Link to this property</a>

token\_endpoint\_auth\_method: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info%20%3E%20(attribute)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary%20%3E%20(attribute)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20auth_config_summary">Link to this property</a>

authentication\_status: String

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20authentication_status">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

created\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_by">Link to this property</a>

description: String

Optional description of the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

error: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error">Link to this property</a>

<details>

<summary>

error\_details: Attributes

</summary>

cause: String

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20cause">Link to this property</a>

is\_upstream: Bool

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20is_upstream">Link to this property</a>

mcp\_code: Float64

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20mcp_code">Link to this property</a>

retryable: Bool

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20retryable">Link to this property</a>

status\_code: Float64

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error_details%20%3E%20(attribute)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled: Bool

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20last_successful_sync">Link to this property</a>

last\_synced: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20last_synced">Link to this property</a>

modified\_at: Time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_at">Link to this property</a>

modified\_by: String

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_by">Link to this property</a>

secure\_web\_gateway: Bool

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20secure_web_gateway">Link to this property</a>

status: String

Current sync state of the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts: List\[Attributes]

Server-wide prompt capability overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20name">Link to this property</a>

alias: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20alias">Link to this property</a>

description: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20description">Link to this property</a>

enabled: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_prompts%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools: List\[Attributes]

Server-wide tool capability overrides.

</summary>

name: String

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20name">Link to this property</a>

alias: String

Custom name exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20alias">Link to this property</a>

description: String

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20description">Link to this property</a>

enabled: Bool

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_tools%20%3E%20(attribute)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_ai\_controls\_mcp\_servers

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_ai_controls_mcp_servers" "example_zero_trust_access_ai_controls_mcp_servers" {
  account_id = "a86a8f5c339544d7bdc89926de14fb8c"
  search = "search"
}
```

#### Zero TrustAccessInfrastructureTargets

#### resource cloudflare\_zero\_trust\_access\_infrastructure\_target

##### required Expand Collapse

account\_id: String

Account identifier

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

hostname: String

A non-unique field that refers to a target. Case insensitive, maximum length of 255 characters, supports the use of special characters dash and period, does not support spaces, and must start and end with an alphanumeric character.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hostname>)

<details>

<summary>

ip: Attributes

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4?: Attributes

The target’s IPv4 address

</summary>

ip\_addr?: String

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4%20%3E%20(attribute)%20ip_addr">Link to this property</a>

virtual\_network\_id?: String

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6?: Attributes

The target’s IPv6 address

</summary>

ip\_addr?: String

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6%20%3E%20(attribute)%20ip_addr">Link to this property</a>

virtual\_network\_id?: String

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ip>)

##### optional Expand Collapse

tags?: Map\[String]

Optional tags to associate with the target. Keys and values are user-defined strings.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20tags>)

##### computed Expand Collapse

id: String

Target identifier

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_at: Time

Date and time at which the target was created

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

modified\_at: Time

Date and time at which the target was modified

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_at>)

### cloudflare\_zero\_trust\_access\_infrastructure\_target

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_infrastructure_target" "example_zero_trust_access_infrastructure_target" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  hostname = "infra-access-target"
  ip = {
    ipv4 = {
      ip_addr = "187.26.29.249"
      virtual_network_id = "c77b744e-acc8-428f-9257-6878c046ed55"
    }
    ipv6 = {
      ip_addr = "64c0:64e8:f0b4:8dbf:7104:72b0:ec8f:f5e0"
      virtual_network_id = "c77b744e-acc8-428f-9257-6878c046ed55"
    }
  }
  tags = {
    foo = "string"
  }
}
```

#### data cloudflare\_zero\_trust\_access\_infrastructure\_target

##### required Expand Collapse

account\_id: String

Account identifier

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

target\_id?: String

Target identifier

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20target_id>)

<details>

<summary>

filter?: Attributes

</summary>

created\_after?: Time

Date and time at which the target was created after (inclusive)

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20created_after">Link to this property</a>

created\_before?: Time

Date and time at which the target was created before (inclusive)

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20created_before">Link to this property</a>

direction?: String

The sorting direction.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20direction">Link to this property</a>

hostname?: String

Hostname of a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20hostname">Link to this property</a>

hostname\_contains?: String

Partial match to the hostname of a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20hostname_contains">Link to this property</a>

ip\_like?: String

Filters for targets whose IP addresses look like the specified string. Supports <code>*</code> as a wildcard character

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ip_like">Link to this property</a>

ip\_v4?: String

IPv4 address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ip_v4">Link to this property</a>

ip\_v6?: String

IPv6 address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ip_v6">Link to this property</a>

ips?: List\[String]

Filters for targets that have any of the following IP addresses. Specify <code>ips</code> multiple times in query parameter to build list of candidates.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ips">Link to this property</a>

ipv4\_end?: String

Defines an IPv4 filter range’s ending value (inclusive). Requires <code>ipv4_start</code> to be specified as well.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ipv4_end">Link to this property</a>

ipv4\_start?: String

Defines an IPv4 filter range’s starting value (inclusive). Requires <code>ipv4_end</code> to be specified as well.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ipv4_start">Link to this property</a>

ipv6\_end?: String

Defines an IPv6 filter range’s ending value (inclusive). Requires <code>ipv6_start</code> to be specified as well.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ipv6_end">Link to this property</a>

ipv6\_start?: String

Defines an IPv6 filter range’s starting value (inclusive). Requires <code>ipv6_end</code> to be specified as well.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ipv6_start">Link to this property</a>

modified\_after?: Time

Date and time at which the target was modified after (inclusive)

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20modified_after">Link to this property</a>

modified\_before?: Time

Date and time at which the target was modified before (inclusive)

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20modified_before">Link to this property</a>

order?: String

The field to sort by.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20order">Link to this property</a>

tag?: List\[String]

Filter by tag key:value pairs. Multiple <code>tag</code> params are AND’d. Format: <code>tag=key:value</code> (e.g., <code>tag=environment:production</code>). Key and value must both be non-empty; <code>tag=:value</code> and <code>tag=key:</code> return 400.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20tag">Link to this property</a>

target\_ids?: List\[String]

Filters for targets that have any of the following UUIDs. Specify <code>target_ids</code> multiple times in query parameter to build list of candidates.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20target_ids">Link to this property</a>

virtual\_network\_id?: String

Private virtual network identifier of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

Target identifier

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_at: Time

Date and time at which the target was created

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

hostname: String

A non-unique field that refers to a target

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hostname>)

modified\_at: Time

Date and time at which the target was modified

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_at>)

tags: Map\[String]

Tags assigned to the target. Empty when no tags are assigned.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20tags>)

<details>

<summary>

ip: Attributes

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Attributes

The target’s IPv4 address

</summary>

ip\_addr: String

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4%20%3E%20(attribute)%20ip_addr">Link to this property</a>

virtual\_network\_id: String

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Attributes

The target’s IPv6 address

</summary>

ip\_addr: String

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6%20%3E%20(attribute)%20ip_addr">Link to this property</a>

virtual\_network\_id: String

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ip>)

### cloudflare\_zero\_trust\_access\_infrastructure\_target

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_infrastructure_target" "example_zero_trust_access_infrastructure_target" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  target_id = "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"
}
```

#### data cloudflare\_zero\_trust\_access\_infrastructure\_targets

##### required Expand Collapse

account\_id: String

Account identifier

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

created\_after?: Time

Date and time at which the target was created after (inclusive)

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20created_after>)

created\_before?: Time

Date and time at which the target was created before (inclusive)

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20created_before>)

direction?: String

The sorting direction.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20direction>)

hostname?: String

Hostname of a target

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20hostname>)

hostname\_contains?: String

Partial match to the hostname of a target

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20hostname_contains>)

ip\_like?: String

Filters for targets whose IP addresses look like the specified string. Supports `*` as a wildcard character

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ip_like>)

ip\_v4?: String

IPv4 address of the target

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ip_v4>)

ip\_v6?: String

IPv6 address of the target

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ip_v6>)

ipv4\_end?: String

Defines an IPv4 filter range’s ending value (inclusive). Requires `ipv4_start` to be specified as well.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ipv4_end>)

ipv4\_start?: String

Defines an IPv4 filter range’s starting value (inclusive). Requires `ipv4_end` to be specified as well.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ipv4_start>)

ipv6\_end?: String

Defines an IPv6 filter range’s ending value (inclusive). Requires `ipv6_start` to be specified as well.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ipv6_end>)

ipv6\_start?: String

Defines an IPv6 filter range’s starting value (inclusive). Requires `ipv6_end` to be specified as well.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ipv6_start>)

modified\_after?: Time

Date and time at which the target was modified after (inclusive)

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20modified_after>)

modified\_before?: Time

Date and time at which the target was modified before (inclusive)

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20modified_before>)

order?: String

The field to sort by.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20order>)

virtual\_network\_id?: String

Private virtual network identifier of the target

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20virtual_network_id>)

ips?: List\[String]

Filters for targets that have any of the following IP addresses. Specify `ips` multiple times in query parameter to build list of candidates.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ips>)

tag?: List\[String]

Filter by tag key:value pairs. Multiple `tag` params are AND’d. Format: `tag=key:value` (e.g., `tag=environment:production`). Key and value must both be non-empty; `tag=:value` and `tag=key:` return 400.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20tag>)

target\_ids?: List\[String]

Filters for targets that have any of the following UUIDs. Specify `target_ids` multiple times in query parameter to build list of candidates.

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20target_ids>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Target identifier

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

created\_at: Time

Date and time at which the target was created

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

hostname: String

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20hostname">Link to this property</a>

<details>

<summary>

ip: Attributes

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4: Attributes

The target’s IPv4 address

</summary>

ip\_addr: String

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4%20%3E%20(attribute)%20ip_addr">Link to this property</a>

virtual\_network\_id: String

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6: Attributes

The target’s IPv6 address

</summary>

ip\_addr: String

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6%20%3E%20(attribute)%20ip_addr">Link to this property</a>

virtual\_network\_id: String

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6%20%3E%20(attribute)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ip">Link to this property</a>

modified\_at: Time

Date and time at which the target was modified

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_at">Link to this property</a>

tags: Map\[String]

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_infrastructure\_targets

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_infrastructure_targets" "example_zero_trust_access_infrastructure_targets" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  created_after = "2019-12-27T18:11:19.117Z"
  created_before = "2019-12-27T18:11:19.117Z"
  direction = "asc"
  hostname = "hostname"
  hostname_contains = "hostname_contains"
  ip_like = "ip_like"
  ip_v4 = "ip_v4"
  ip_v6 = "ip_v6"
  ips = ["string"]
  ipv4_end = "ipv4_end"
  ipv4_start = "ipv4_start"
  ipv6_end = "ipv6_end"
  ipv6_start = "ipv6_start"
  modified_after = "2019-12-27T18:11:19.117Z"
  modified_before = "2019-12-27T18:11:19.117Z"
  order = "hostname"
  tag = ["string"]
  target_ids = ["182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"]
  virtual_network_id = "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"
}
```

#### Zero TrustAccessApplicationsCAs

#### resource cloudflare\_zero\_trust\_access\_short\_lived\_certificate

##### required Expand Collapse

app\_id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20app_id>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

aud: String

The Application Audience (AUD) tag. Identifies the application associated with the CA.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20aud>)

public\_key: String

The public key to add to your SSH server configuration.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20public_key>)

### cloudflare\_zero\_trust\_access\_short\_lived\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_short_lived_certificate" "example_zero_trust_access_short_lived_certificate" {
  app_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_short\_lived\_certificate

##### required Expand Collapse

app\_id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20app_id>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

aud: String

The Application Audience (AUD) tag. Identifies the application associated with the CA.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20aud>)

public\_key: String

The public key to add to your SSH server configuration.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20public_key>)

### cloudflare\_zero\_trust\_access\_short\_lived\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_short_lived_certificate" "example_zero_trust_access_short_lived_certificate" {
  app_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_short\_lived\_certificates

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The ID of the CA.

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

aud: String

The Application Audience (AUD) tag. Identifies the application associated with the CA.

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20aud">Link to this property</a>

public\_key: String

The public key to add to your SSH server configuration.

<a href="#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications.cas%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_short\_lived\_certificates

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_short_lived_certificates" "example_zero_trust_access_short_lived_certificates" {
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### Zero TrustAccessCertificates

#### resource cloudflare\_zero\_trust\_access\_mtls\_certificate

##### required Expand Collapse

certificate: String

The certificate content.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate>)

name: String

The name of the certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

associated\_hostnames?: List\[String]

The hostnames of the applications that will use this certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20associated_hostnames>)

##### computed Expand Collapse

id: String

The ID of the application that will use this certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

expires\_on: Time

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expires_on>)

fingerprint: String

The MD5 fingerprint of the certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20fingerprint>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_mtls\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_mtls_certificate" "example_zero_trust_access_mtls_certificate" {
  certificate = <<EOT
  -----BEGIN CERTIFICATE-----
  MIIGAjCCA+qgAwIBAgIJAI7kymlF7CWT...N4RI7KKB7nikiuUf8vhULKy5IX10
  DrUtmu/B
  -----END CERTIFICATE-----
  EOT
  name = "Allow devs"
  zone_id = "zone_id"
  associated_hostnames = ["admin.example.com"]
}
```

#### data cloudflare\_zero\_trust\_access\_mtls\_certificate

##### required Expand Collapse

certificate\_id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_id>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

expires\_on: Time

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expires_on>)

fingerprint: String

The MD5 fingerprint of the certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20fingerprint>)

name: String

The name of the certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

associated\_hostnames: List\[String]

The hostnames of the applications that will use this certificate.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20associated_hostnames>)

### cloudflare\_zero\_trust\_access\_mtls\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_mtls_certificate" "example_zero_trust_access_mtls_certificate" {
  certificate_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_mtls\_certificates

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The ID of the application that will use this certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

associated\_hostnames: List\[String]

The hostnames of the applications that will use this certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20associated_hostnames">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

expires\_on: Time

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expires_on">Link to this property</a>

fingerprint: String

The MD5 fingerprint of the certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20fingerprint">Link to this property</a>

name: String

The name of the certificate.

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

updated\_at: Time

<a href="#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_mtls\_certificates

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_mtls_certificates" "example_zero_trust_access_mtls_certificates" {
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### Zero TrustAccessCertificatesSettings

#### resource cloudflare\_zero\_trust\_access\_mtls\_hostname\_settings

##### required Expand Collapse

<details>

<summary>

settings: List\[Attributes]

</summary>

china\_network: Bool

Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled.

<a href="#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20settings%20%3E%20(attribute)%20china_network">Link to this property</a>

client\_certificate\_forwarding: Bool

Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin.

<a href="#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20settings%20%3E%20(attribute)%20client_certificate_forwarding">Link to this property</a>

hostname: String

The hostname that these settings apply to.

<a href="#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20settings%20%3E%20(attribute)%20hostname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20settings>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

china\_network: Bool

Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20china_network>)

client\_certificate\_forwarding: Bool

Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20client_certificate_forwarding>)

hostname: String

The hostname that these settings apply to.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hostname>)

### cloudflare\_zero\_trust\_access\_mtls\_hostname\_settings

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_mtls_hostname_settings" "example_zero_trust_access_mtls_hostname_settings" {
  settings = [{
    china_network = false
    client_certificate_forwarding = true
    hostname = "admin.example.com"
  }]
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_mtls\_hostname\_settings

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

china\_network: Bool

Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20china_network>)

client\_certificate\_forwarding: Bool

Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20client_certificate_forwarding>)

hostname: String

The hostname that these settings apply to.

[Link to this property](<#(resource)%20zero_trust.access.certificates.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hostname>)

### cloudflare\_zero\_trust\_access\_mtls\_hostname\_settings

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_mtls_hostname_settings" "example_zero_trust_access_mtls_hostname_settings" {
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### Zero TrustAccessGroups

#### resource cloudflare\_zero\_trust\_access\_group

##### required Expand Collapse

name: String

The name of the Access group.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

<details>

<summary>

include: List\[Attributes]

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

<details>

<summary>

group?: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token?: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context?: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method?: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad?: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate?: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name?: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo?: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture?: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id?: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain?: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list?: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email?: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email">Link to this property</a>

everyone?: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation?: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team?: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite?: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method?: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list?: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip?: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml?: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc?: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token?: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token?: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score?: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member?: Attributes

</summary>

account\_id?: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

is\_default?: Bool

Whether this is the default group

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20is_default>)

<details>

<summary>

exclude?: List\[Attributes]

Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.

</summary>

<details>

<summary>

group?: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token?: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context?: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method?: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad?: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate?: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name?: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo?: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture?: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id?: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain?: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list?: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email?: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email">Link to this property</a>

everyone?: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation?: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team?: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite?: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method?: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list?: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip?: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml?: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc?: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token?: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token?: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score?: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member?: Attributes

</summary>

account\_id?: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

require?: List\[Attributes]

Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.

</summary>

<details>

<summary>

group?: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token?: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context?: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method?: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad?: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate?: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name?: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo?: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture?: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id?: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain?: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list?: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email?: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email">Link to this property</a>

everyone?: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation?: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team?: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite?: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method?: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list?: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip?: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml?: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc?: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token?: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token?: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score?: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member?: Attributes

</summary>

account\_id?: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_group

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_group" "example_zero_trust_access_group" {
  include = [{
    certificate = {

    }
  }]
  name = "Allow devs"
  zone_id = "zone_id"
  exclude = [{
    certificate = {

    }
  }]
  is_default = true
  require = [{
    certificate = {

    }
  }]
}
```

#### data cloudflare\_zero\_trust\_access\_group

##### optional Expand Collapse

group\_id?: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20group_id>)

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

<details>

<summary>

filter?: Attributes

</summary>

name?: String

The name of the group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20name">Link to this property</a>

search?: String

Search for groups by other listed query parameters.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20search">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

name: String

The name of the Access group.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

<details>

<summary>

exclude: List\[Attributes]

Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

include: List\[Attributes]

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20include>)

<details>

<summary>

is\_default: List\[Attributes]

Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20is_default>)

<details>

<summary>

require: List\[Attributes]

Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20require>)

### cloudflare\_zero\_trust\_access\_group

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_group" "example_zero_trust_access_group" {
  group_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_groups

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

name?: String

The name of the group.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20name>)

search?: String

Search for groups by other listed query parameters.

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20search>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

UUID.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

<details>

<summary>

exclude: List\[Attributes]

Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20exclude">Link to this property</a>

<details>

<summary>

include: List\[Attributes]

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20include">Link to this property</a>

<details>

<summary>

is\_default: List\[Attributes]

Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20is_default">Link to this property</a>

name: String

The name of the Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

<details>

<summary>

require: List\[Attributes]

Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.

</summary>

<details>

<summary>

group: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate: Attributes

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20email">Link to this property</a>

everyone: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team: String

The name of the team

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member: Attributes

</summary>

account\_id: String

Identifier.

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20require">Link to this property</a>

updated\_at: Time

<a href="#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.groups%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_groups

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_groups" "example_zero_trust_access_groups" {
  account_id = "account_id"
  zone_id = "zone_id"
  name = "name"
  search = "search"
}
```

#### Zero TrustAccessService Tokens

#### resource cloudflare\_zero\_trust\_access\_service\_token

##### required Expand Collapse

name: String

The name of the service token.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

enabled?: Bool

Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous `client_secret` stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

previous\_client\_secret\_expires\_at?: Time

The expiration of the previous `client_secret`. This can be modified at any point after a rotation. For example, you may extend it further into the future if you need more time to update services with the new secret; or move it into the past to immediately invalidate the previous token in case of compromise.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20previous_client_secret_expires_at>)

client\_secret\_version?: Float64

A version number identifying the current `client_secret` associated with the service token. Incrementing it triggers a rotation; the previous secret will still be accepted until the time indicated by `previous_client_secret_expires_at`.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20client_secret_version>)

duration?: String

The duration for how long the service token will be valid. Must be in the format `300ms` or `2h45m`, or the special value `forever` for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h).

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20duration>)

##### computed Expand Collapse

id: String

The ID of the service token.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

client\_id: String

The Client ID for the service token. Access will check for this value in the `CF-Access-Client-ID` request header.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20client_id>)

client\_secret: String

The Client Secret for the service token. Access will check for this value in the `CF-Access-Client-Secret` request header.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20client_secret>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

expires\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expires_at>)

last\_seen\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20last_seen_at>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_service\_token

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_service_token" "example_zero_trust_access_service_token" {
  name = "CI/CD token"
  zone_id = "zone_id"
  client_secret_version = 0
  duration = "60m"
  enabled = true
  previous_client_secret_expires_at = "2014-01-01T05:20:00.12345Z"
}
```

#### data cloudflare\_zero\_trust\_access\_service\_token

##### optional Expand Collapse

service\_token\_id?: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20service_token_id>)

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

<details>

<summary>

filter?: Attributes

</summary>

name?: String

The name of the service token.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20name">Link to this property</a>

search?: String

Search for service tokens by other listed query parameters.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20search">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

client\_id: String

The Client ID for the service token. Access will check for this value in the `CF-Access-Client-ID` request header.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20client_id>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

duration: String

The duration for how long the service token will be valid. Must be in the format `300ms` or `2h45m`, or the special value `forever` for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h).

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20duration>)

enabled: Bool

Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous `client_secret` stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

expires\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expires_at>)

last\_seen\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20last_seen_at>)

name: String

The name of the service token.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_service\_token

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_service_token" "example_zero_trust_access_service_token" {
  service_token_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### data cloudflare\_zero\_trust\_access\_service\_tokens

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

name?: String

The name of the service token.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20name>)

search?: String

Search for service tokens by other listed query parameters.

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20search>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The ID of the service token.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

client\_id: String

The Client ID for the service token. Access will check for this value in the <code>CF-Access-Client-ID</code> request header.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20client_id">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

duration: String

The duration for how long the service token will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>, or the special value <code>forever</code> for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h).

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20duration">Link to this property</a>

enabled: Bool

Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous <code>client_secret</code> stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20enabled">Link to this property</a>

expires\_at: Time

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expires_at">Link to this property</a>

last\_seen\_at: Time

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20last_seen_at">Link to this property</a>

name: String

The name of the service token.

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

updated\_at: Time

<a href="#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.service_tokens%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_service\_tokens

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_service_tokens" "example_zero_trust_access_service_tokens" {
  account_id = "account_id"
  zone_id = "zone_id"
  name = "name"
  search = "search"
}
```

#### Zero TrustAccessKeys

#### resource cloudflare\_zero\_trust\_access\_key\_configuration

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

key\_rotation\_interval\_days: Float64

The number of days between key rotations.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20key_rotation_interval_days>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

days\_until\_next\_rotation: Float64

The number of days until the next key rotation.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20days_until_next_rotation>)

last\_key\_rotation\_at: Time

The timestamp of the previous key rotation.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20last_key_rotation_at>)

### cloudflare\_zero\_trust\_access\_key\_configuration

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_key_configuration" "example_zero_trust_access_key_configuration" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  key_rotation_interval_days = 30
}
```

#### data cloudflare\_zero\_trust\_access\_key\_configuration

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

days\_until\_next\_rotation: Float64

The number of days until the next key rotation.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20days_until_next_rotation>)

key\_rotation\_interval\_days: Float64

The number of days between key rotations.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20key_rotation_interval_days>)

last\_key\_rotation\_at: Time

The timestamp of the previous key rotation.

[Link to this property](<#(resource)%20zero_trust.access.keys%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20last_key_rotation_at>)

### cloudflare\_zero\_trust\_access\_key\_configuration

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_key_configuration" "example_zero_trust_access_key_configuration" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```

#### Zero TrustAccessCustom Pages

#### resource cloudflare\_zero\_trust\_access\_custom\_page

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

custom\_html: String

Custom page HTML.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20custom_html>)

name: String

Custom page name.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

type: String

Custom page type.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

##### optional Expand Collapse

app\_count?: Int64

Number of apps the custom page is assigned to.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20app_count>)

contract\_version?: Int64

Contract version of the page’s Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20contract_version>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

uid: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20uid>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

<details>

<summary>

warnings: List\[Attributes]

Advisory validation findings returned when creating or updating a template. Omitted when empty.

</summary>

message: String

Human-readable description of the finding.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20warnings%20%3E%20(attribute)%20message">Link to this property</a>

tier: String

The validation tier that produced the finding (e.g. html, liquid).

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20warnings%20%3E%20(attribute)%20tier">Link to this property</a>

ref: String

Optional pointer to the part of the template the finding refers to.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20warnings%20%3E%20(attribute)%20ref">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20warnings>)

### cloudflare\_zero\_trust\_access\_custom\_page

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_custom_page" "example_zero_trust_access_custom_page" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  custom_html = "<html><body><h1>Access Denied</h1></body></html>"
  name = "name"
  type = "identity_denied"
  contract_version = 0
}
```

#### data cloudflare\_zero\_trust\_access\_custom\_page

##### required Expand Collapse

custom\_page\_id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_page_id>)

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

app\_count: Int64

Number of apps the custom page is assigned to.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20app_count>)

contract\_version: Int64

Contract version of the page’s Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20contract_version>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

custom\_html: String

Custom page HTML.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_html>)

name: String

Custom page name.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

type: String

Custom page type.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20type>)

uid: String

UUID.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20uid>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_custom\_page

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_custom_page" "example_zero_trust_access_custom_page" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  custom_page_id = "f174e90a-fafe-4643-bbbc-4a0ed4fc8415"
}
```

#### data cloudflare\_zero\_trust\_access\_custom\_pages

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

UUID.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

name: String

Custom page name.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

type: String

Custom page type.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20type">Link to this property</a>

app\_count: Int64

Number of apps the custom page is assigned to.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20app_count">Link to this property</a>

contract\_version: Int64

Contract version of the page’s Liquid template. Present (&gt;= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20contract_version">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

uid: String

UUID.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20uid">Link to this property</a>

updated\_at: Time

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

<details>

<summary>

warnings: List\[Attributes]

Advisory validation findings returned when creating or updating a template. Omitted when empty.

</summary>

message: String

Human-readable description of the finding.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20warnings%20%3E%20(attribute)%20message">Link to this property</a>

tier: String

The validation tier that produced the finding (e.g. html, liquid).

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20warnings%20%3E%20(attribute)%20tier">Link to this property</a>

ref: String

Optional pointer to the part of the template the finding refers to.

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20warnings%20%3E%20(attribute)%20ref">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20warnings">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.custom_pages%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_custom\_pages

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_custom_pages" "example_zero_trust_access_custom_pages" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```

#### Zero TrustAccessTags

#### resource cloudflare\_zero\_trust\_access\_tag

##### required Expand Collapse

name: String

The name of the tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

The name of the tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

app\_count: Int64

The number of applications that have this tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20app_count>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_at>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_tag

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zero_trust_access_tag" "example_zero_trust_access_tag" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  name = "engineers"
}
```

#### data cloudflare\_zero\_trust\_access\_tag

##### required Expand Collapse

tag\_name: String

The name of the tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20tag_name>)

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

The name of the tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

app\_count: Int64

The number of applications that have this tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20app_count>)

created\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_at>)

name: String

The name of the tag

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

updated\_at: Time

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20updated_at>)

### cloudflare\_zero\_trust\_access\_tag

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_tag" "example_zero_trust_access_tag" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  tag_name = "engineers"
}
```

#### data cloudflare\_zero\_trust\_access\_tags

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The name of the tag

<a href="#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

name: String

The name of the tag

<a href="#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

app\_count: Int64

The number of applications that have this tag

<a href="#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20app_count">Link to this property</a>

created\_at: Time

<a href="#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_at">Link to this property</a>

updated\_at: Time

<a href="#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.tags%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zero\_trust\_access\_tags

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zero_trust_access_tags" "example_zero_trust_access_tags" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```

#### Zero TrustAccessPolicies

#### resource cloudflare\_zero\_trust\_access\_policy

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

decision: String

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20decision>)

name: String

The name of the Access policy.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

##### optional Expand Collapse

approval\_required?: Bool

Requires the user to request access from an administrator at the start of each session.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20approval_required>)

isolation\_required?: Bool

Require this application to be served in an isolated browser for users matching this policy. ‘Client Web Isolation’ must be on for the account in order to use this feature.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20isolation_required>)

purpose\_justification\_prompt?: String

A custom message that will appear on the purpose justification screen.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20purpose_justification_prompt>)

purpose\_justification\_required?: Bool

Require users to enter a justification when they log in to the application.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20purpose_justification_required>)

session\_duration?: String

The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20session_duration>)

<details>

<summary>

approval\_groups?: Set\[Attributes]

Administrators who can approve a temporary authentication request.

</summary>

approvals\_needed: Float64

The number of approvals needed to obtain access.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20approval_groups%20%3E%20(attribute)%20approvals_needed">Link to this property</a>

email\_addresses?: List\[String]

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20approval_groups%20%3E%20(attribute)%20email_addresses">Link to this property</a>

email\_list\_uuid?: String

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20approval_groups%20%3E%20(attribute)%20email_list_uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20approval_groups>)

<details>

<summary>

connection\_rules?: Attributes

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

rdp?: Attributes

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

allowed\_clipboard\_local\_to\_remote\_formats?: List\[String]

Clipboard formats allowed when copying from local machine to remote RDP session.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20connection_rules%20%3E%20(attribute)%20rdp%20%3E%20(attribute)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

allowed\_clipboard\_remote\_to\_local\_formats?: List\[String]

Clipboard formats allowed when copying from remote RDP session to local machine.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20connection_rules%20%3E%20(attribute)%20rdp%20%3E%20(attribute)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20connection_rules%20%3E%20(attribute)%20rdp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20connection_rules>)

<details>

<summary>

mfa\_config?: Attributes

Configures multi-factor authentication (MFA) settings.

</summary>

allowed\_authenticators?: List\[String]

Lists the MFA methods that users can authenticate with.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20allowed_authenticators">Link to this property</a>

mfa\_disabled?: Bool

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20mfa_disabled">Link to this property</a>

session\_duration?: String

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config%20%3E%20(attribute)%20session_duration">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mfa_config>)

<details>

<summary>

exclude?: Set\[Attributes]

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

<details>

<summary>

group?: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token?: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context?: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method?: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad?: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate?: Attributes

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name?: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo?: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture?: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id?: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain?: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list?: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email?: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20email">Link to this property</a>

everyone?: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation?: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team?: String

The name of the team

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite?: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method?: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list?: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip?: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml?: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc?: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token?: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token?: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score?: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member?: Attributes

</summary>

account\_id?: String

Identifier.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20exclude>)

<details>

<summary>

include?: Set\[Attributes]

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

<details>

<summary>

group?: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token?: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context?: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method?: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad?: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate?: Attributes

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name?: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo?: Attributes

</summary>

country\_code: String

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo%20%3E%20(attribute)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20geo">Link to this property</a>

<details>

<summary>

device\_posture?: Attributes

</summary>

integration\_uid: String

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20integration_uid">Link to this property</a>

account\_id?: String

The ID of the account that owns the device posture integration.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20device_posture">Link to this property</a>

<details>

<summary>

email\_domain?: Attributes

</summary>

domain: String

The email domain to match.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain%20%3E%20(attribute)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_domain">Link to this property</a>

<details>

<summary>

email\_list?: Attributes

</summary>

id: String

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email_list">Link to this property</a>

<details>

<summary>

email?: Attributes

</summary>

email: String

The email of the user.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email%20%3E%20(attribute)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20email">Link to this property</a>

everyone?: Attributes

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20everyone">Link to this property</a>

<details>

<summary>

external\_evaluation?: Attributes

</summary>

evaluate\_url: String

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20evaluate_url">Link to this property</a>

keys\_url: String

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation%20%3E%20(attribute)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20external_evaluation">Link to this property</a>

<details>

<summary>

github\_organization?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the organization.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20name">Link to this property</a>

team?: String

The name of the team

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization%20%3E%20(attribute)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20github_organization">Link to this property</a>

<details>

<summary>

gsuite?: Attributes

</summary>

email: String

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20email">Link to this property</a>

identity\_provider\_id: String

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20gsuite">Link to this property</a>

<details>

<summary>

login\_method?: Attributes

</summary>

id: String

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20login_method">Link to this property</a>

<details>

<summary>

ip\_list?: Attributes

</summary>

id: String

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip_list">Link to this property</a>

<details>

<summary>

ip?: Attributes

</summary>

ip: String

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip%20%3E%20(attribute)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20ip">Link to this property</a>

<details>

<summary>

okta?: Attributes

</summary>

identity\_provider\_id: String

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

name: String

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta%20%3E%20(attribute)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20okta">Link to this property</a>

<details>

<summary>

saml?: Attributes

</summary>

attribute\_name: String

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_name">Link to this property</a>

attribute\_value: String

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20attribute_value">Link to this property</a>

identity\_provider\_id: String

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20saml">Link to this property</a>

<details>

<summary>

oidc?: Attributes

</summary>

claim\_name: String

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_name">Link to this property</a>

claim\_value: String

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20claim_value">Link to this property</a>

identity\_provider\_id: String

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20oidc">Link to this property</a>

<details>

<summary>

service\_token?: Attributes

</summary>

token\_id: String

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token%20%3E%20(attribute)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20service_token">Link to this property</a>

<details>

<summary>

linked\_app\_token?: Attributes

</summary>

app\_uid: String

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token%20%3E%20(attribute)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20linked_app_token">Link to this property</a>

<details>

<summary>

user\_risk\_score?: Attributes

</summary>

user\_risk\_score: List\[String]

A list of risk score levels to match. Values can be low, medium, high, or unscored.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20user_risk_score">Link to this property</a>

<details>

<summary>

cloudflare\_account\_member?: Attributes

</summary>

account\_id?: String

Identifier.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member%20%3E%20(attribute)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include%20%3E%20(attribute)%20cloudflare_account_member">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20include>)

<details>

<summary>

require?: Set\[Attributes]

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

<details>

<summary>

group?: Attributes

</summary>

id: String

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group%20%3E%20(attribute)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20group">Link to this property</a>

any\_valid\_service\_token?: Attributes

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20any_valid_service_token">Link to this property</a>

<details>

<summary>

auth\_context?: Attributes

</summary>

id: String

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20id">Link to this property</a>

ac\_id: String

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20ac_id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_context">Link to this property</a>

<details>

<summary>

auth\_method?: Attributes

</summary>

auth\_method: String

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method%20%3E%20(attribute)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20auth_method">Link to this property</a>

<details>

<summary>

azure\_ad?: Attributes

</summary>

id: String

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20id">Link to this property</a>

identity\_provider\_id: String

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad%20%3E%20(attribute)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20azure_ad">Link to this property</a>

certificate?: Attributes

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20certificate">Link to this property</a>

<details>

<summary>

common\_name?: Attributes

</summary>

common\_name: String

The common name to match.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name%20%3E%20(attribute)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20require%20%3E%20(attribute)%20common_name">Link to this property</a>

<details>

<summary>

geo?: Attributes

</summary>

</details>

</details>

<!-- Cloudflare Markdown for Agents: incomplete conversion; source HTML truncated at the conversion size limit -->
