Skip to content
Start here

Create Token

client.user.tokens.create(TokenCreateParams { name, policies, condition, 2 more } body, RequestOptionsoptions?): TokenCreateResponse { id, condition, creator_email_at_creation, 11 more }
POST/user/tokens

Create a new access token.

Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
Accepted Permissions (at least one required)
API Tokens Write
ParametersExpand Collapse
body: TokenCreateParams { name, policies, condition, 2 more }
name: string

Token name.

maxLength120
policies: Array<TokenPolicy { id, effect, permission_groups, resources } >

List of access policies assigned to the token.

id: string

Policy identifier.

effect: "allow" | "deny"

Allow or deny operations against the resources.

One of the following:
"allow"
"deny"
permission_groups: Array<PermissionGroup>

A set of permission groups that are specified to the policy.

id: string

Identifier of the permission group.

meta?: Meta { category, deprecated, description, 5 more }

Attributes associated to the permission group.

category?: string

A category used to group permission groups.

deprecated?: string

Indicates whether the permission group is deprecated.

description?: string

Additional information about the permission group.

editable?: string

Indicates whether the permission group can be edited.

eol_at?: string

The planned end-of-life date and time, when provided.

formatdate-time
label?: string

A label identifying the permission group.

scopes?: string

The scope associated with the permission group.

visibility?: string

Indicates the permission group’s availability or visibility.

name?: string

Name of the permission group.

resources: Record<string, string> | Record<string, Record<string, string>>

A list of resource names that the policy applies to.

One of the following:
Record<string, string>
Record<string, Record<string, string>>
condition?: Condition
request_ip?: RequestIP { in, not_in }

Client IP restrictions.

List of IPv4/IPv6 CIDR addresses.

not_in?: Array<TokenConditionCIDRList>

List of IPv4/IPv6 CIDR addresses.

expires_on?: string

The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time
not_before?: string

The time before which the token MUST NOT be accepted for processing.

formatdate-time
ReturnsExpand Collapse
TokenCreateResponse { id, condition, creator_email_at_creation, 11 more }
id?: string

Token identifier tag.

maxLength32
condition?: Condition { request_ip }
request_ip?: RequestIP { in, not_in }

Client IP restrictions.

List of IPv4/IPv6 CIDR addresses.

not_in?: Array<TokenConditionCIDRList>

List of IPv4/IPv6 CIDR addresses.

creator_email_at_creation?: string

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

maxLength90
expires_on?: string

The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time
issued_on?: string

The time on which the token was created.

formatdate-time
last_used_on?: string

Last time the token was used.

formatdate-time
modified_on?: string

Last time the token was modified.

formatdate-time
name?: string

Token name.

maxLength120
not_before?: string

The time before which the token MUST NOT be accepted for processing.

formatdate-time
policies?: Array<TokenPolicy { id, effect, permission_groups, resources } >

List of access policies assigned to the token.

id: string

Policy identifier.

effect: "allow" | "deny"

Allow or deny operations against the resources.

One of the following:
"allow"
"deny"
permission_groups: Array<PermissionGroup>

A set of permission groups that are specified to the policy.

id: string

Identifier of the permission group.

meta?: Meta { category, deprecated, description, 5 more }

Attributes associated to the permission group.

category?: string

A category used to group permission groups.

deprecated?: string

Indicates whether the permission group is deprecated.

description?: string

Additional information about the permission group.

editable?: string

Indicates whether the permission group can be edited.

eol_at?: string

The planned end-of-life date and time, when provided.

formatdate-time
label?: string

A label identifying the permission group.

scopes?: string

The scope associated with the permission group.

visibility?: string

Indicates the permission group’s availability or visibility.

name?: string

Name of the permission group.

resources: Record<string, string> | Record<string, Record<string, string>>

A list of resource names that the policy applies to.

One of the following:
Record<string, string>
Record<string, Record<string, string>>
provisioner_id?: string | null

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when provisioner_type is present and null when the identifier is unavailable.

provisioner_type?: string

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

status?: "active" | "disabled" | "expired"

Status of the token.

One of the following:
"active"
"disabled"
"expired"
value?: TokenValue

The token value.

maxLength80
minLength40

Create Token

import Cloudflare from 'cloudflare';

const client = new Cloudflare({
  apiToken: process.env['CLOUDFLARE_API_TOKEN'], // This is the default and can be omitted
});

const token = await client.user.tokens.create({
  name: 'readonly token',
  policies: [
    {
      effect: 'allow',
      permission_groups: [
        { id: 'c8fed203ed3043cba015a93ad1616f1f' },
        { id: '82e64a83756745bbbb1c9c2701bf816b' },
      ],
      resources: { 'com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43': '*' },
    },
  ],
});

console.log(token.id);
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "ed17574386854bf78a67040be0a770b0",
    "condition": {
      "request_ip": {
        "in": [
          "123.123.123.0/24",
          "2606:4700::/32"
        ],
        "not_in": [
          "123.123.123.100/24",
          "2606:4700:4700::/48"
        ]
      }
    },
    "creator_email_at_creation": "user@example.com",
    "expires_on": "2020-01-01T00:00:00Z",
    "issued_on": "2018-07-01T05:20:00Z",
    "last_used_on": "2020-01-02T12:34:00Z",
    "modified_on": "2018-07-02T05:20:00Z",
    "name": "readonly token",
    "not_before": "2018-07-01T05:20:00Z",
    "policies": [
      {
        "id": "f267e341f3dd4697bd3b9f71dd96247f",
        "effect": "allow",
        "permission_groups": [
          {
            "id": "c8fed203ed3043cba015a93ad1616f1f",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "load_balancer_admin",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Zone Read"
          },
          {
            "id": "82e64a83756745bbbb1c9c2701bf816b",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "fbm_user",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Magic Network Monitoring"
          }
        ],
        "resources": {
          "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
        }
      }
    ],
    "provisioner_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
    "provisioner_type": "com.cloudflare.api.oauthtoken",
    "status": "active",
    "value": "8M7wS6hCpXVc-DoRnPPY_UCWPgy8aea4Wy6kCe5T"
  }
}
Returns Examples
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "ed17574386854bf78a67040be0a770b0",
    "condition": {
      "request_ip": {
        "in": [
          "123.123.123.0/24",
          "2606:4700::/32"
        ],
        "not_in": [
          "123.123.123.100/24",
          "2606:4700:4700::/48"
        ]
      }
    },
    "creator_email_at_creation": "user@example.com",
    "expires_on": "2020-01-01T00:00:00Z",
    "issued_on": "2018-07-01T05:20:00Z",
    "last_used_on": "2020-01-02T12:34:00Z",
    "modified_on": "2018-07-02T05:20:00Z",
    "name": "readonly token",
    "not_before": "2018-07-01T05:20:00Z",
    "policies": [
      {
        "id": "f267e341f3dd4697bd3b9f71dd96247f",
        "effect": "allow",
        "permission_groups": [
          {
            "id": "c8fed203ed3043cba015a93ad1616f1f",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "load_balancer_admin",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Zone Read"
          },
          {
            "id": "82e64a83756745bbbb1c9c2701bf816b",
            "meta": {
              "category": "category",
              "deprecated": "deprecated",
              "description": "description",
              "editable": "editable",
              "eol_at": "2019-12-27T18:11:19.117Z",
              "label": "fbm_user",
              "scopes": "com.cloudflare.api.account",
              "visibility": "visibility"
            },
            "name": "Magic Network Monitoring"
          }
        ],
        "resources": {
          "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
        }
      }
    ],
    "provisioner_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
    "provisioner_type": "com.cloudflare.api.oauthtoken",
    "status": "active",
    "value": "8M7wS6hCpXVc-DoRnPPY_UCWPgy8aea4Wy6kCe5T"
  }
}