Skip to content
Start here

Tokens

List Tokens
client.user.tokens.list(TokenListParams { direction, include_expired, page, per_page } query?, RequestOptionsoptions?): V4PagePaginationArray<Token { id, condition, creator_email_at_creation, 10 more } >
GET/user/tokens
Token Details
client.user.tokens.get(stringtokenID, RequestOptionsoptions?): Token { id, condition, creator_email_at_creation, 10 more }
GET/user/tokens/{token_id}
Create Token
client.user.tokens.create(TokenCreateParams { name, policies, condition, 2 more } body, RequestOptionsoptions?): TokenCreateResponse { id, condition, creator_email_at_creation, 11 more }
POST/user/tokens
Update Token
client.user.tokens.update(stringtokenID, TokenUpdateParams { name, policies, condition, 3 more } body, RequestOptionsoptions?): Token { id, condition, creator_email_at_creation, 10 more }
PUT/user/tokens/{token_id}
Delete Token
client.user.tokens.delete(stringtokenID, RequestOptionsoptions?): TokenDeleteResponse { id } | null
DELETE/user/tokens/{token_id}
Verify Token
client.user.tokens.verify(RequestOptionsoptions?): TokenVerifyResponse { id, status, expires_on, not_before }
GET/user/tokens/verify
ModelsExpand Collapse
TokenCreateResponse { id, condition, creator_email_at_creation, 11 more }
id?: string

Token identifier tag.

maxLength32
condition?: Condition { request_ip }
request_ip?: RequestIP { in, not_in }

Client IP restrictions.

List of IPv4/IPv6 CIDR addresses.

not_in?: Array<TokenConditionCIDRList>

List of IPv4/IPv6 CIDR addresses.

creator_email_at_creation?: string

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

maxLength90
expires_on?: string

The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time
issued_on?: string

The time on which the token was created.

formatdate-time
last_used_on?: string

Last time the token was used.

formatdate-time
modified_on?: string

Last time the token was modified.

formatdate-time
name?: string

Token name.

maxLength120
not_before?: string

The time before which the token MUST NOT be accepted for processing.

formatdate-time
policies?: Array<TokenPolicy { id, effect, permission_groups, resources } >

List of access policies assigned to the token.

id: string

Policy identifier.

effect: "allow" | "deny"

Allow or deny operations against the resources.

One of the following:
"allow"
"deny"
permission_groups: Array<PermissionGroup>

A set of permission groups that are specified to the policy.

id: string

Identifier of the permission group.

meta?: Meta { category, deprecated, description, 5 more }

Attributes associated to the permission group.

category?: string

A category used to group permission groups.

deprecated?: string

Indicates whether the permission group is deprecated.

description?: string

Additional information about the permission group.

editable?: string

Indicates whether the permission group can be edited.

eol_at?: string

The planned end-of-life date and time, when provided.

formatdate-time
label?: string

A label identifying the permission group.

scopes?: string

The scope associated with the permission group.

visibility?: string

Indicates the permission group’s availability or visibility.

name?: string

Name of the permission group.

resources: Record<string, string> | Record<string, Record<string, string>>

A list of resource names that the policy applies to.

One of the following:
Record<string, string>
Record<string, Record<string, string>>
provisioner_id?: string | null

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when provisioner_type is present and null when the identifier is unavailable.

provisioner_type?: string

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

status?: "active" | "disabled" | "expired"

Status of the token.

One of the following:
"active"
"disabled"
"expired"
value?: TokenValue

The token value.

maxLength80
minLength40
TokenDeleteResponse { id }
id: string

Identifier

maxLength32
minLength32
TokenVerifyResponse { id, status, expires_on, not_before }
id: string

Token identifier tag.

maxLength32
status: "active" | "disabled" | "expired"

Status of the token.

One of the following:
"active"
"disabled"
"expired"
expires_on?: string

The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time
not_before?: string

The time before which the token MUST NOT be accepted for processing.

formatdate-time

TokensPermission Groups

List Token Permission Groups
client.user.tokens.permissionGroups.list(PermissionGroupListParams { name, scope } query?, RequestOptionsoptions?): SinglePage<PermissionGroupListResponse { id, category, is_selectable, 2 more } >
GET/user/tokens/permission_groups
ModelsExpand Collapse
PermissionGroupListResponse { id, category, is_selectable, 2 more }
id?: string

Public ID.

category?: "developer_platform" | "ai_and_machine_learning" | "dns_and_zones" | 10 more

Product category that this permission group belongs to.

One of the following:
"developer_platform"
"ai_and_machine_learning"
"dns_and_zones"
"app_security"
"rules_and_configuration"
"cloudflare_one_and_zero_trust"
"analytics_and_logs"
"network_services"
"media"
"email_and_messaging"
"cache_and_performance"
"account_and_billing"
"other"
is_selectable?: boolean

Whether the caller can select this permission group when creating a token.

name?: string

Permission Group Name

scopes?: Array<"com.cloudflare.api.account" | "com.cloudflare.api.account.zone" | "com.cloudflare.api.user" | "com.cloudflare.edge.r2.bucket">

Resources to which the Permission Group is scoped

One of the following:
"com.cloudflare.api.account"
"com.cloudflare.api.account.zone"
"com.cloudflare.api.user"
"com.cloudflare.edge.r2.bucket"

TokensValue

Roll Token
client.user.tokens.value.update(stringtokenID, RequestOptionsoptions?): TokenValue
PUT/user/tokens/{token_id}/value