---
title: Access
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/typescript)

[Zero Trust](https://developers.cloudflare.com/api/typescript/resources/zero_trust)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Access

#### AccessAI Controls

#### AccessAI ControlsMcp

#### AccessAI ControlsMcpPortals

##### [List MCP Portals](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/list)

client.zeroTrust.access.aiControls.mcp.portals.list(PortalListParams {account\_id, page, per\_page, search } params, RequestOptionsoptions?): V4PagePaginationArray< [PortalListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)>) {id, hostname, name, 9 more } >

GET/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Create a new MCP Portal](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/create)

client.zeroTrust.access.aiControls.mcp.portals.create(PortalCreateParams {account\_id, id, hostname, 6 more } params, RequestOptionsoptions?): [PortalCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)>) {id, hostname, name, 9 more }

POST/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Read details of an MCP Portal](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/read)

client.zeroTrust.access.aiControls.mcp.portals.read(stringid, PortalReadParams {account\_id } params, RequestOptionsoptions?): [PortalReadResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)>) {id, hostname, name, 9 more }

GET/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Update an MCP Portal](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/update)

client.zeroTrust.access.aiControls.mcp.portals.update(stringid, PortalUpdateParams {account\_id, allow\_code\_mode, code\_mode, 5 more } params, RequestOptionsoptions?): [PortalUpdateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)>) {id, hostname, name, 9 more }

PUT/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Delete an MCP Portal](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/delete)

client.zeroTrust.access.aiControls.mcp.portals.delete(stringid, PortalDeleteParams {account\_id } params, RequestOptionsoptions?): [PortalDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)>) {id, hostname, name, 8 more }

DELETE/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### ModelsExpand Collapse

<details>

<summary>

PortalListResponse {id, hostname, name, 9 more }

</summary>

id: string

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: string

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: Array&lt;Server&gt;

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled?: boolean

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode?: boolean

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode?: "off"| "opt\_in"| "default\_on"| "enforced"

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_list_response%20%3E%20(schema)>)

<details>

<summary>

PortalCreateResponse {id, hostname, name, 9 more }

</summary>

id: string

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: string

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: Array&lt;Server&gt;

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled?: boolean

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode?: boolean

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode?: "off"| "opt\_in"| "default\_on"| "enforced"

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_create_response%20%3E%20(schema)>)

<details>

<summary>

PortalReadResponse {id, hostname, name, 9 more }

</summary>

id: string

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: string

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: Array&lt;Server&gt;

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled?: boolean

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode?: boolean

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode?: "off"| "opt\_in"| "default\_on"| "enforced"

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_read_response%20%3E%20(schema)>)

<details>

<summary>

PortalUpdateResponse {id, hostname, name, 9 more }

</summary>

id: string

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: string

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

servers: Array&lt;Server&gt;

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20prompts">Link to this property</a>

server\_id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20server_id">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20created_by">Link to this property</a>

default\_disabled?: boolean

Hide this server’s tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated\_tools or updated\_prompts.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20default_disabled">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20modified_by">Link to this property</a>

on\_behalf?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20on_behalf">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

</summary>

name: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

enabled?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

portal\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_alias">Link to this property</a>

portal\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20portal_description">Link to this property</a>

server\_alias?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_alias">Link to this property</a>

server\_description?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20server_description">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers%20%3E%20(items)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20servers">Link to this property</a>

Deprecatedallow\_code\_mode?: boolean

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode?: "off"| "opt\_in"| "default\_on"| "enforced"

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_update_response%20%3E%20(schema)>)

<details>

<summary>

PortalDeleteResponse {id, hostname, name, 8 more }

</summary>

id: string

Unique identifier for the MCP portal.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

hostname: string

Hostname where the MCP portal is available.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP portal.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

Deprecatedallow\_code\_mode?: boolean

Deprecated: use <code>code_mode</code> for new integrations. <code>true</code> maps to any non-off Code Mode policy; <code>false</code> maps to <code>code_mode: off</code>. If both fields are sent, they must be consistent or the request returns a 400.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20allow_code_mode">Link to this property</a>

<details>

<summary>

code\_mode?: "off"| "opt\_in"| "default\_on"| "enforced"

Code Mode policy for this portal. <code>off</code>: Code Mode is unavailable; query parameters are ignored. <code>opt_in</code>: Code Mode is off by default; clients turn it on with <code>?codemode=search_and_execute</code>. <code>default_on</code>: Code Mode is on by default; clients can opt out with <code>?codemode=off</code>. <code>enforced</code>: Code Mode is always on; query parameters are ignored. Defaults to <code>opt_in</code> when omitted on create. If both <code>code_mode</code> and <code>allow_code_mode</code> are sent, they must be consistent or the request returns a 400.

</summary>

One of the following:

"off"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%200">Link to this property</a>

"opt\_in"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%201">Link to this property</a>

"default\_on"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%202">Link to this property</a>

"enforced"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20code_mode">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string

Optional description of the MCP portal.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound MCP traffic through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.portals%20%3E%20(model)%20portal_delete_response%20%3E%20(schema)>)

#### AccessAI ControlsMcpServers

##### [List MCP Servers](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/list)

client.zeroTrust.access.aiControls.mcp.servers.list(ServerListParams {account\_id, page, per\_page, search } params, RequestOptionsoptions?): V4PagePaginationArray< [ServerListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)>) {id, auth\_type, hostname, 19 more } >

GET/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Create a new MCP Server](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/create)

client.zeroTrust.access.aiControls.mcp.servers.create(ServerCreateParams {account\_id, id, auth\_type, 9 more } params, RequestOptionsoptions?): [ServerCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)>) {id, auth\_type, hostname, 19 more }

POST/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Read the details of an MCP Server](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/read)

client.zeroTrust.access.aiControls.mcp.servers.read(stringid, ServerReadParams {account\_id } params, RequestOptionsoptions?): [ServerReadResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)>) {id, auth\_type, hostname, 19 more }

GET/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Update an MCP Server](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/update)

client.zeroTrust.access.aiControls.mcp.servers.update(stringid, ServerUpdateParams {account\_id, auth\_credentials, client\_secret, 6 more } params, RequestOptionsoptions?): [ServerUpdateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)>) {id, auth\_type, hostname, 19 more }

PUT/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Delete an MCP Server](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/delete)

client.zeroTrust.access.aiControls.mcp.servers.delete(stringid, ServerDeleteParams {account\_id } params, RequestOptionsoptions?): [ServerDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)>) {id, auth\_type, hostname, 19 more }

DELETE/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Sync MCP Server Capabilities](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/sync)

client.zeroTrust.access.aiControls.mcp.servers.sync(stringid, ServerSyncParams {account\_id } params, RequestOptionsoptions?): [ServerSyncResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)>) {error, error\_details, status }

POST/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}/sync

##### ModelsExpand Collapse

<details>

<summary>

ServerListResponse {id, auth\_type, hostname, 19 more }

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

Server-wide prompt capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

Server-wide tool capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_list_response%20%3E%20(schema)>)

<details>

<summary>

ServerCreateResponse {id, auth\_type, hostname, 19 more }

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

Server-wide prompt capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

Server-wide tool capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_create_response%20%3E%20(schema)>)

<details>

<summary>

ServerReadResponse {id, auth\_type, hostname, 19 more }

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

Server-wide prompt capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

Server-wide tool capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_read_response%20%3E%20(schema)>)

<details>

<summary>

ServerUpdateResponse {id, auth\_type, hostname, 19 more }

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

Server-wide prompt capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

Server-wide tool capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_update_response%20%3E%20(schema)>)

<details>

<summary>

ServerDeleteResponse {id, auth\_type, hostname, 19 more }

</summary>

id: string

Unique identifier for the MCP server.

maxLength32

minLength1

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

auth\_type: "oauth"| "bearer"| "unauthenticated"

Authentication method used to connect to the upstream MCP server.

</summary>

One of the following:

"oauth"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"bearer"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

"unauthenticated"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

hostname: string

URL of the upstream MCP endpoint.

formaturi

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

name: string

Display name for the MCP server.

maxLength350

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

prompts: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20prompts">Link to this property</a>

tools: Array&lt;Record&lt;string, unknown&gt;&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20tools">Link to this property</a>

<details>

<summary>

auth\_config\_summary?: AuthConfigSummary {auth\_mode, client\_secret\_version, config, 2 more }

Safe subset of auth\_credentials surfaced to the dashboard. Includes auth\_mode (dcr|manual), has\_client\_secret, client\_secret\_version, and the OAuth endpoints + client\_id for manual servers. Never includes the secret value.

</summary>

<details>

<summary>

auth\_mode?: "dcr"| "manual"

</summary>

One of the following:

"dcr"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%200">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20auth_mode">Link to this property</a>

client\_secret\_version?: number

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20client_secret_version">Link to this property</a>

<details>

<summary>

config?: Config {authorization\_endpoint, issuer, resource, 2 more }

</summary>

authorization\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20authorization_endpoint">Link to this property</a>

issuer?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20issuer">Link to this property</a>

resource?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20resource">Link to this property</a>

revocation\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20revocation_endpoint">Link to this property</a>

token\_endpoint?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config%20%3E%20(property)%20token_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20config">Link to this property</a>

has\_client\_secret?: boolean

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20has_client_secret">Link to this property</a>

<details>

<summary>

registration\_info?: RegistrationInfo {client\_id, redirect\_uris, scope, token\_endpoint\_auth\_method }

</summary>

client\_id?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20client_id">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20redirect_uris">Link to this property</a>

scope?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20scope">Link to this property</a>

token\_endpoint\_auth\_method?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info%20%3E%20(property)%20token_endpoint_auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary%20%3E%20(property)%20registration_info">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20auth_config_summary">Link to this property</a>

<details>

<summary>

authentication\_status?: "not\_required"| "required"| "connected"| 2 more

Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.

</summary>

One of the following:

"not\_required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%200">Link to this property</a>

"required"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%201">Link to this property</a>

"connected"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%202">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%203">Link to this property</a>

"manual"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20authentication_status">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

created\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_by">Link to this property</a>

description?: string| null

Optional description of the MCP server.

maxLength512

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

is\_shared\_oauth\_callback\_enabled?: boolean

When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect\_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20is_shared_oauth_callback_enabled">Link to this property</a>

last\_successful\_sync?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20last_successful_sync">Link to this property</a>

last\_synced?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20last_synced">Link to this property</a>

modified\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

modified\_by?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20modified_by">Link to this property</a>

secure\_web\_gateway?: boolean

Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20secure_web_gateway">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

Current sync state of the server

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

updated\_prompts?: Array&lt;UpdatedPrompt&gt;

Server-wide prompt capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_prompts">Link to this property</a>

<details>

<summary>

updated\_tools?: Array&lt;UpdatedTool&gt;

Server-wide tool capability overrides.

</summary>

name: string

Name of the tool or prompt capability to override.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

alias?: string

Custom name exposed for the capability.

maxLength40

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20alias">Link to this property</a>

description?: string

Custom description exposed for the capability.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

enabled?: boolean

Whether the capability is available through the MCP server.

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_tools">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_delete_response%20%3E%20(schema)>)

<details>

<summary>

ServerSyncResponse {error, error\_details, status }

</summary>

error?: string

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error">Link to this property</a>

<details>

<summary>

error\_details?: ErrorDetails {cause, is\_upstream, mcp\_code, 2 more }

</summary>

cause?: string

Underlying error message

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20cause">Link to this property</a>

is\_upstream?: boolean

True = MCP server returned an error. False = couldn’t reach the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20is_upstream">Link to this property</a>

mcp\_code?: number

MCP protocol error code

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20mcp_code">Link to this property</a>

retryable?: boolean

Whether the error is transient and worth retrying

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20retryable">Link to this property</a>

status\_code?: number

HTTP status code from the server

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details%20%3E%20(property)%20status_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20error_details">Link to this property</a>

<details>

<summary>

status?: "waiting"| "ready"| "stale"| "error"

</summary>

One of the following:

"waiting"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"ready"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"stale"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"error"

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.ai_controls.mcp.servers%20%3E%20(model)%20server_sync_response%20%3E%20(schema)>)

#### AccessGateway CA

##### [List SSH Certificate Authorities (CA)](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/list)

client.zeroTrust.access.gatewayCA.list(GatewayCAListParams {account\_id } params, RequestOptionsoptions?): SinglePage< [GatewayCAListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)>) {id, public\_key } >

GET/accounts/{account\_id}/access/gateway\_ca

##### [Add a new SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/create)

client.zeroTrust.access.gatewayCA.create(GatewayCACreateParams {account\_id } params, RequestOptionsoptions?): [GatewayCACreateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)>) {id, public\_key }

POST/accounts/{account\_id}/access/gateway\_ca

##### [Delete an SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/delete)

client.zeroTrust.access.gatewayCA.delete(stringcertificateID, GatewayCADeleteParams {account\_id } params, RequestOptionsoptions?): [GatewayCADeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/access/gateway\_ca/{certificate\_id}

##### ModelsExpand Collapse

<details>

<summary>

GatewayCAListResponse {id, public\_key }

</summary>

id?: string

The key ID of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

public\_key?: string

The public key of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_list_response%20%3E%20(schema)>)

<details>

<summary>

GatewayCACreateResponse {id, public\_key }

</summary>

id?: string

The key ID of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

public\_key?: string

The public key of this certificate.

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_create_response%20%3E%20(schema)>)

<details>

<summary>

GatewayCADeleteResponse {id }

</summary>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.gateway_ca%20%3E%20(model)%20gateway_ca_delete_response%20%3E%20(schema)>)

#### AccessIdP Federation Grants

##### [List IdP federation grants](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/list)

client.zeroTrust.access.IdPFederationGrants.list(IdPFederationGrantListParams {account\_id } params, RequestOptionsoptions?): [IdPFederationGrantListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_list_response%20%3E%20(schema)>) {id, idp\_id }

GET/accounts/{account\_id}/access/idp\_federation\_grants

##### [Create an IdP federation grant](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/create)

client.zeroTrust.access.IdPFederationGrants.create(IdPFederationGrantCreateParams {account\_id, idp\_id } params, RequestOptionsoptions?): [IdPFederationGrant](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>) {id, idp\_id }

POST/accounts/{account\_id}/access/idp\_federation\_grants

##### [Get an IdP federation grant](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/get)

client.zeroTrust.access.IdPFederationGrants.get(stringgrantID, IdPFederationGrantGetParams {account\_id } params, RequestOptionsoptions?): [IdPFederationGrant](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>) {id, idp\_id }

GET/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### [Delete an IdP federation grant](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/delete)

client.zeroTrust.access.IdPFederationGrants.delete(stringgrantID, IdPFederationGrantDeleteParams {account\_id } params, RequestOptionsoptions?): [IdPFederationGrantDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_delete_response%20%3E%20(schema)>) {id }

DELETE/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### ModelsExpand Collapse

<details>

<summary>

IdPFederationGrant {id, idp\_id }

</summary>

id: string

UID of the IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

idp\_id: string

UID of the identity provider being federated.

formatuuid

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20idp_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)>)

<details>

<summary>

IdPFederationGrantListResponse = Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)">IdPFederationGrant</a> {id, idp\_id } &gt;

</summary>

id: string

UID of the IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

idp\_id: string

UID of the identity provider being federated.

formatuuid

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant%20%3E%20(schema)%20%3E%20(property)%20idp_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_list_response%20%3E%20(schema)>)

<details>

<summary>

IdPFederationGrantDeleteResponse {id }

</summary>

id?: string

UID of the deleted IdP federation grant.

maxLength32

<a href="#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.idp_federation_grants%20%3E%20(model)%20idp_federation_grant_delete_response%20%3E%20(schema)>)

#### AccessSAML Certificates

##### [List SAML certificate sets](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/list)

client.zeroTrust.access.samlCertificates.list(SAMLCertificateListParams {account\_id, id, page, per\_page } params, RequestOptionsoptions?): V4PagePaginationArray< [SAMLCertificateListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)>) {created\_at, uid, updated\_at, 2 more } >

GET/accounts/{account\_id}/access/saml\_certificates

##### [Get SAML certificate set](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get)

client.zeroTrust.access.samlCertificates.get(stringsamlCERTSetID, SAMLCertificateGetParams {account\_id } params, RequestOptionsoptions?): [SAMLCertificateGetResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)>) {created\_at, uid, updated\_at, 2 more }

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}

##### [Rotate SAML certificate](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/rotate)

client.zeroTrust.access.samlCertificates.rotate(stringsamlCERTSetID, SAMLCertificateRotateParams {account\_id } params, RequestOptionsoptions?): [SAMLCertificateRotateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)>) {created\_at, uid, updated\_at, 2 more }

POST/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/rotate

##### [Download current certificate in PEM format](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get_pem)

client.zeroTrust.access.samlCertificates.getPem(stringsamlCERTSetID, SAMLCertificateGetPemParams {account\_id } params, RequestOptionsoptions?): Response

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/pem

##### ModelsExpand Collapse

<details>

<summary>

SAMLCertificateListResponse {created\_at, uid, updated\_at, 2 more }

</summary>

created\_at: string

When the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

uid: string

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: string

When the certificate set was last updated

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate?: CurrentCertificate {is\_current, not\_after, public\_certificate, uid }

The current active certificate

</summary>

is\_current: boolean

Indicates whether the certificate can be used for IdP configuration.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: string

Certificate expiration date

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: string

The public certificate in PEM format

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: string

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate?: unknown

The previous certificate (maintained during rotation period). May be null when no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_list_response%20%3E%20(schema)>)

<details>

<summary>

SAMLCertificateGetResponse {created\_at, uid, updated\_at, 2 more }

</summary>

created\_at: string

When the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

uid: string

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: string

When the certificate set was last updated

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate?: CurrentCertificate {is\_current, not\_after, public\_certificate, uid }

The current active certificate

</summary>

is\_current: boolean

Indicates whether the certificate can be used for IdP configuration.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: string

Certificate expiration date

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: string

The public certificate in PEM format

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: string

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate?: unknown

The previous certificate (maintained during rotation period). May be null when no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_get_response%20%3E%20(schema)>)

<details>

<summary>

SAMLCertificateRotateResponse {created\_at, uid, updated\_at, 2 more }

</summary>

created\_at: string

When the certificate set was created

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

uid: string

Unique identifier for the certificate set

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20uid">Link to this property</a>

updated\_at: string

When the certificate set was last updated

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

<details>

<summary>

current\_certificate?: CurrentCertificate {is\_current, not\_after, public\_certificate, uid }

The current active certificate

</summary>

is\_current: boolean

Indicates whether the certificate can be used for IdP configuration.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20is_current">Link to this property</a>

not\_after: string

Certificate expiration date

formatdate-time

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20not_after">Link to this property</a>

public\_certificate: string

The public certificate in PEM format

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20public_certificate">Link to this property</a>

uid: string

Unique identifier for the certificate

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate%20%3E%20(property)%20uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20current_certificate">Link to this property</a>

previous\_certificate?: unknown

The previous certificate (maintained during rotation period). May be null when no rotation has occurred. Mirrors the structure of <code>saml_certificate</code>.

<a href="#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)%20%3E%20(property)%20previous_certificate">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.saml_certificates%20%3E%20(model)%20saml_certificate_rotate_response%20%3E%20(schema)>)

#### AccessInfrastructure

#### AccessInfrastructureTargets

##### [List all targets](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/list)

client.zeroTrust.access.infrastructure.targets.list(TargetListParams {account\_id, created\_after, created\_before, 19 more } params, RequestOptionsoptions?): V4PagePaginationArray< [TargetListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)>) {id, created\_at, hostname, 3 more } >

GET/accounts/{account\_id}/infrastructure/targets

##### [Get target](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/get)

client.zeroTrust.access.infrastructure.targets.get(stringtargetID, TargetGetParams {account\_id } params, RequestOptionsoptions?): [TargetGetResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)>) {id, created\_at, hostname, 3 more }

GET/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new target](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/create)

client.zeroTrust.access.infrastructure.targets.create(TargetCreateParams {account\_id, hostname, ip, tags } params, RequestOptionsoptions?): [TargetCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)>) {id, created\_at, hostname, 3 more }

POST/accounts/{account\_id}/infrastructure/targets

##### [Update target](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/update)

client.zeroTrust.access.infrastructure.targets.update(stringtargetID, TargetUpdateParams {account\_id, hostname, ip, tags } params, RequestOptionsoptions?): [TargetUpdateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)>) {id, created\_at, hostname, 3 more }

PUT/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Delete target](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/delete)

client.zeroTrust.access.infrastructure.targets.delete(stringtargetID, TargetDeleteParams {account\_id } params, RequestOptionsoptions?): void

DELETE/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new targets](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_update)

client.zeroTrust.access.infrastructure.targets.bulkUpdate(TargetBulkUpdateParams {account\_id, body } params, RequestOptionsoptions?): SinglePage< [TargetBulkUpdateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)>) {id, created\_at, hostname, 3 more } >

PUT/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets (Deprecated)](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete)

Deprecated

client.zeroTrust.access.infrastructure.targets.bulkDelete(TargetBulkDeleteParams {account\_id } params, RequestOptionsoptions?): void

DELETE/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete_v2)

client.zeroTrust.access.infrastructure.targets.bulkDeleteV2(TargetBulkDeleteV2Params {account\_id, target\_ids } params, RequestOptionsoptions?): void

POST/accounts/{account\_id}/infrastructure/targets/batch\_delete

##### ModelsExpand Collapse

<details>

<summary>

TargetListResponse {id, created\_at, hostname, 3 more }

</summary>

id: string

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: string

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP {ipv4, ipv6 }

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4?: IPV4 {ip\_addr, virtual\_network\_id }

The target’s IPv4 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6?: IPV6 {ip\_addr, virtual\_network\_id }

The target’s IPv6 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: string

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags?: Record&lt;string, string&gt;| null

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_list_response%20%3E%20(schema)>)

<details>

<summary>

TargetGetResponse {id, created\_at, hostname, 3 more }

</summary>

id: string

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: string

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP {ipv4, ipv6 }

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4?: IPV4 {ip\_addr, virtual\_network\_id }

The target’s IPv4 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6?: IPV6 {ip\_addr, virtual\_network\_id }

The target’s IPv6 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: string

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags?: Record&lt;string, string&gt;| null

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_get_response%20%3E%20(schema)>)

<details>

<summary>

TargetCreateResponse {id, created\_at, hostname, 3 more }

</summary>

id: string

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: string

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP {ipv4, ipv6 }

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4?: IPV4 {ip\_addr, virtual\_network\_id }

The target’s IPv4 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6?: IPV6 {ip\_addr, virtual\_network\_id }

The target’s IPv6 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: string

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags?: Record&lt;string, string&gt;| null

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_create_response%20%3E%20(schema)>)

<details>

<summary>

TargetUpdateResponse {id, created\_at, hostname, 3 more }

</summary>

id: string

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: string

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP {ipv4, ipv6 }

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4?: IPV4 {ip\_addr, virtual\_network\_id }

The target’s IPv4 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6?: IPV6 {ip\_addr, virtual\_network\_id }

The target’s IPv6 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: string

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags?: Record&lt;string, string&gt;| null

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_update_response%20%3E%20(schema)>)

<details>

<summary>

TargetBulkUpdateResponse {id, created\_at, hostname, 3 more }

</summary>

id: string

Target identifier

formatuuid

maxLength36

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created\_at: string

Date and time at which the target was created

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

hostname: string

A non-unique field that refers to a target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

ip: IP {ipv4, ipv6 }

The IPv4/IPv6 address that identifies where to reach a target

</summary>

<details>

<summary>

ipv4?: IPV4 {ip\_addr, virtual\_network\_id }

The target’s IPv4 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv4">Link to this property</a>

<details>

<summary>

ipv6?: IPV6 {ip\_addr, virtual\_network\_id }

The target’s IPv6 address

</summary>

ip\_addr?: string

IP address of the target

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20ip_addr">Link to this property</a>

virtual\_network\_id?: string

(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used.

formatuuid

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6%20%3E%20(property)%20virtual_network_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ipv6">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

modified\_at: string

Date and time at which the target was modified

formatdate-time

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20modified_at">Link to this property</a>

tags?: Record&lt;string, string&gt;| null

Tags assigned to the target. Empty when no tags are assigned.

<a href="#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.infrastructure.targets%20%3E%20(model)%20target_bulk_update_response%20%3E%20(schema)>)

#### AccessApplications

##### [List Access applications](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/applications/methods/list)

client.zeroTrust.access.applications.list(ApplicationListParams {account\_id, zone\_id, aud, 7 more } params?, RequestOptionsoptions?): V4PagePaginationArray< [ApplicationListResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)>)>

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Get an Access application](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/applications/methods/get)

client.zeroTrust.access.applications.get([AppID](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)appID, ApplicationGetParams {account\_id, zone\_id } params?, RequestOptionsoptions?): [ApplicationGetResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_get_response%20%3E%20(schema)>)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Add an Access application](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/applications/methods/create)

client.zeroTrust.access.applications.create(ApplicationCreateParamsparams, RequestOptionsoptions?): [ApplicationCreateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_create_response%20%3E%20(schema)>)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Update an Access application](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/applications/methods/update)

client.zeroTrust.access.applications.update([AppID](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)appID, ApplicationUpdateParamsparams, RequestOptionsoptions?): [ApplicationUpdateResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_update_response%20%3E%20(schema)>)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Delete an Access application](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/applications/methods/delete)

client.zeroTrust.access.applications.delete([AppID](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)appID, ApplicationDeleteParams {account\_id, zone\_id } params?, RequestOptionsoptions?): [ApplicationDeleteResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_delete_response%20%3E%20(schema)>) {id }

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Revoke application tokens](https://developers.cloudflare.com/api/typescript/resources/zero_trust/subresources/access/subresources/applications/methods/revoke_tokens)

client.zeroTrust.access.applications.revokeTokens([AppID](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)appID, ApplicationRevokeTokensParams {account\_id, zone\_id } params?, RequestOptionsoptions?): [ApplicationRevokeTokensResponse](<https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_revoke_tokens_response%20%3E%20(schema)>)| null

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/revoke\_tokens

##### ModelsExpand Collapse

AllowedHeaders = string

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)>)

AllowedIdPs = string

The identity providers selected for application.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)>)

<details>

<summary>

AllowedMethods = "GET"| "POST"| "HEAD"| 6 more

</summary>

One of the following:

"GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)>)

AllowedOrigins = string

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)>)

AppID = string

Identifier.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20app_id%20%3E%20(schema)>)

<details>

<summary>

Application = SelfHostedApplication {domain, type, id, 22 more } | SaaSApplication {id, allowed\_idps, app\_launcher\_visible, 9 more } | BrowserSSHApplication {domain, type, id, 22 more } | 5 more

</summary>

One of the following:

<details>

<summary>

SelfHostedApplication {domain, type, id, 22 more }

</summary>

domain: string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20domain">Link to this property</a>

type: string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

allow\_iframe?: boolean

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible?: boolean

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a> {allow\_all\_headers, allow\_all\_methods, allow\_all\_origins, 5 more }

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20cors_headers">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

custom\_deny\_message?: string

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url?: string

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20custom_deny_url">Link to this property</a>

eager\_redirect\_cookie\_setting?: boolean

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie?: boolean

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute?: boolean

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url?: string

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20logo_url">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

options\_preflight\_bypass?: boolean

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

same\_site\_cookie\_attribute?: string

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20scim_config">Link to this property</a>

service\_auth\_401\_redirect?: boolean

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

session\_duration?: string

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20session_duration">Link to this property</a>

skip\_interstitial?: boolean

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20skip_interstitial">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

use\_clientless\_isolation\_app\_launcher\_url?: boolean

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

SaaSApplication {id, allowed\_idps, app\_launcher\_visible, 9 more }

</summary>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible?: boolean

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

logo\_url?: string

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20logo_url">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

saas\_app?: AccessSAMLSaaSApp2 {auth\_type, consumer\_service\_url, created\_at, 8 more } | AccessOIDCSaaSApp2 {access\_token\_lifetime, allow\_pkce\_without\_client\_secret, app\_launcher\_url, 13 more }

</summary>

One of the following:

<details>

<summary>

AccessSAMLSaaSApp2 {auth\_type, consumer\_service\_url, created\_at, 8 more }

</summary>

<details>

<summary>

auth\_type?: "saml"| "oidc"

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20auth_type">Link to this property</a>

consumer\_service\_url?: string

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20consumer_service_url">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

custom\_attributes?: Array&lt;CustomAttribute&gt;

</summary>

friendly\_name?: string

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

name?: string

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_format?: "urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"| "urn:oasis:names:tc:SAML:2.0:attrname-format:basic"| "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

A globally unique name for an identity or service provider.

</summary>

One of the following:

"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

required?: boolean

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

source?: Source {name, name\_by\_idp }

</summary>

name?: string

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

name\_by\_idp?: Record&lt;string, string&gt;

A mapping from IdP ID to attribute name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20custom_attributes">Link to this property</a>

idp\_entity\_id?: string

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20idp_entity_id">Link to this property</a>

name\_id\_format?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a>

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_format">Link to this property</a>

name\_id\_transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

public\_key?: string

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20public_key">Link to this property</a>

sp\_entity\_id?: string

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sp_entity_id">Link to this property</a>

sso\_endpoint?: string

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20sso_endpoint">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

AccessOIDCSaaSApp2 {access\_token\_lifetime, allow\_pkce\_without\_client\_secret, app\_launcher\_url, 13 more }

</summary>

access\_token\_lifetime?: string

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

allow\_pkce\_without\_client\_secret?: boolean

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

app\_launcher\_url?: string

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

auth\_type?: "saml"| "oidc"

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20auth_type">Link to this property</a>

client\_id?: string

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret?: string

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20client_secret">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20created_at">Link to this property</a>

<details>

<summary>

custom\_claims?: Array&lt;CustomClaim&gt;

</summary>

name?: string

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

required?: boolean

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

scope?: "groups"| "profile"| "email"| "openid"

The scope of the claim.

</summary>

One of the following:

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

source?: Source {name, name\_by\_idp }

</summary>

name?: string

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_by\_idp?: Array&lt;NameByIdP&gt;

A mapping from IdP ID to attribute name.

</summary>

idp\_id?: string

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

source\_name?: string

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

grant\_types?: Array&lt;"authorization\_code"| "authorization\_code\_with\_pkce"| "refresh\_tokens"| 2 more&gt;

The OIDC flows supported by this application

</summary>

One of the following:

"authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20grant_types">Link to this property</a>

group\_filter\_regex?: string

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

hybrid\_and\_implicit\_options?: HybridAndImplicitOptions {return\_access\_token\_from\_authorization\_endpoint, return\_id\_token\_from\_authorization\_endpoint }

</summary>

return\_access\_token\_from\_authorization\_endpoint?: boolean

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

return\_id\_token\_from\_authorization\_endpoint?: boolean

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

public\_key?: string

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20public_key">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

refresh\_token\_options?: RefreshTokenOptions {lifetime }

</summary>

lifetime?: string

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

scopes?: Array&lt;"openid"| "groups"| "email"| "profile"&gt;

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20scopes">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20saas_app">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20scim_config">Link to this property</a>

type?: string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

BrowserSSHApplication {domain, type, id, 22 more }

</summary>

domain: string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20domain">Link to this property</a>

type: string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20id">Link to this property</a>

allow\_iframe?: boolean

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible?: boolean

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a> {allow\_all\_headers, allow\_all\_methods, allow\_all\_origins, 5 more }

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20cors_headers">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20created_at">Link to this property</a>

custom\_deny\_message?: string

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url?: string

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20custom_deny_url">Link to this property</a>

eager\_redirect\_cookie\_setting?: boolean

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie?: boolean

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute?: boolean

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url?: string

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20logo_url">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20name">Link to this property</a>

options\_preflight\_bypass?: boolean

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

same\_site\_cookie\_attribute?: string

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20scim_config">Link to this property</a>

service\_auth\_401\_redirect?: boolean

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

session\_duration?: string

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20session_duration">Link to this property</a>

skip\_interstitial?: boolean

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20skip_interstitial">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20updated_at">Link to this property</a>

use\_clientless\_isolation\_app\_launcher\_url?: boolean

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

BrowserVNCApplication {domain, type, id, 22 more }

</summary>

domain: string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20domain">Link to this property</a>

type: string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20id">Link to this property</a>

allow\_iframe?: boolean

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible?: boolean

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a> {allow\_all\_headers, allow\_all\_methods, allow\_all\_origins, 5 more }

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20cors_headers">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20created_at">Link to this property</a>

custom\_deny\_message?: string

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url?: string

The custom URL a user is redirected to when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20custom_deny_url">Link to this property</a>

eager\_redirect\_cookie\_setting?: boolean

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie?: boolean

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute?: boolean

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url?: string

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20logo_url">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20name">Link to this property</a>

options\_preflight\_bypass?: boolean

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

same\_site\_cookie\_attribute?: string

Sets the SameSite cookie setting, which provides increased security against CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20same_site_cookie_attribute">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20scim_config">Link to this property</a>

service\_auth\_401\_redirect?: boolean

Returns a 401 status code when the request is blocked by a Service Auth policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20service_auth_401_redirect">Link to this property</a>

session\_duration?: string

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20session_duration">Link to this property</a>

skip\_interstitial?: boolean

Enables automatic authentication through cloudflared.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20skip_interstitial">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20updated_at">Link to this property</a>

use\_clientless\_isolation\_app\_launcher\_url?: boolean

Determines if users can access this application via a clientless browser isolation URL. This allows users to access private domains without connecting to Gateway. The option requires Clientless Browser Isolation to be set up with policies that allow users of this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203%20%3E%20(property)%20use_clientless_isolation_app_launcher_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

AppLauncherApplication {type, id, allowed\_idps, 8 more }

</summary>

<details>

<summary>

type: "self\_hosted"| "saas"| "ssh"| 6 more

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20domain">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20scim_config">Link to this property</a>

session\_duration?: string

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

DeviceEnrollmentPermissionsApplication {type, id, allowed\_idps, 8 more }

</summary>

<details>

<summary>

type: "self\_hosted"| "saas"| "ssh"| 6 more

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20domain">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20scim_config">Link to this property</a>

session\_duration?: string

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

BrowserIsolationPermissionsApplication {type, id, allowed\_idps, 8 more }

</summary>

<details>

<summary>

type: "self\_hosted"| "saas"| "ssh"| 6 more

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20created_at">Link to this property</a>

domain?: string

The domain and path that Access will secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20domain">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20scim_config">Link to this property</a>

session\_duration?: string

The amount of time that tokens issued for this application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

BookmarkApplication {domain, type, id, 7 more }

</summary>

domain: string

The URL or domain of the bookmark.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20domain">Link to this property</a>

type: string

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20id">Link to this property</a>

app\_launcher\_visible?: boolean

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20aud">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20created_at">Link to this property</a>

logo\_url?: string

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20logo_url">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

scim\_config?: SCIMConfig {idp\_uid, remote\_uri, authentication, 3 more }

Configuration for provisioning to this application via SCIM. This is currently in closed beta.

</summary>

idp\_uid: string

The UID of the IdP to use as the source for SCIM resources to provision to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20idp_uid">Link to this property</a>

remote\_uri: string

The base URI for the application’s SCIM-compatible API.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20remote_uri">Link to this property</a>

<details>

<summary>

authentication?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | 2 more

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

One of the following:

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">SCIMConfigAuthenticationHTTPBasic</a> {password, scheme, user } | AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme } | <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">SCIMConfigAuthenticationOauth2</a> {authorization\_url, client\_id, client\_secret, 3 more } | AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme } &gt;

</summary>

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationOAuthBearerToken2 {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessSCIMConfigAuthenticationAccessServiceToken {client\_id, client\_secret, scheme }

Attributes for configuring Access Service Token authentication scheme for SCIM provisioning to an application.

</summary>

client\_id: string

Client ID of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Client secret of the Access service token used to authenticate with the remote service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "access\_service\_token"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20scheme">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20authentication">Link to this property</a>

deactivate\_on\_delete?: boolean

If false, we propagate DELETE requests to the target application for SCIM resources. If true, we only set <code>active</code> to false on the SCIM resource. This is useful because some targets do not support DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20deactivate_on_delete">Link to this property</a>

enabled?: boolean

Whether SCIM provisioning is turned on for this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

mappings?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)">SCIMConfigMapping</a> {schema, enabled, filter, 3 more } &gt;

A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config%20%3E%20(property)%20mappings">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20scim_config">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)%20%3E%20(variant)%207">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application%20%3E%20(schema)>)

<details>

<summary>

ApplicationPolicy {id, approval\_groups, approval\_required, 13 more }

</summary>

id?: string

The UUID of the policy

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

approval\_groups?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a> {approvals\_needed, email\_addresses, email\_list\_uuid } &gt;

Administrators who can approve a temporary authentication request.

</summary>

approvals\_needed: number

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

email\_addresses?: Array&lt;string&gt;

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

email\_list\_uuid?: string

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_groups">Link to this property</a>

approval\_required?: boolean

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20approval_required">Link to this property</a>

<details>

<summary>

connection\_rules?: ConnectionRules {rdp }

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

rdp?: RDP {allowed\_clipboard\_local\_to\_remote\_formats, allowed\_clipboard\_remote\_to\_local\_formats }

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

<details>

<summary>

allowed\_clipboard\_local\_to\_remote\_formats?: Array&lt;"text"| "file"&gt;

Clipboard formats allowed when copying from local machine to remote RDP session.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

<details>

<summary>

allowed\_clipboard\_remote\_to\_local\_formats?: Array&lt;"text"| "file"&gt;

Clipboard formats allowed when copying from remote RDP session to local machine.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20connection_rules">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

decision?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a>

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

exclude?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>&gt;

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

GroupRule {group }

Matches an Access group.

</summary>

<details>

<summary>

group: Group {id }

</summary>

id: string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AnyValidServiceTokenRule {any\_valid\_service\_token }

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessAuthContextRule {auth\_context }

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AuthContext {id, ac\_id, identity\_provider\_id }

</summary>

id: string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

AuthenticationMethodRule {auth\_method }

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod {auth\_method }

</summary>

auth\_method: string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AzureGroupRule {azureAD }

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azureAD: AzureAD {id, identity\_provider\_id }

</summary>

id: string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

CertificateRule {certificate }

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessCommonNameRule {common\_name }

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: CommonName {common\_name }

</summary>

common\_name: string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

CountryRule {geo }

Matches a specific country

</summary>

<details>

<summary>

geo: Geo {country\_code }

</summary>

country\_code: string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessDevicePostureRule {device\_posture }

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture {integration\_uid, account\_id }

</summary>

integration\_uid: string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id?: string

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

DomainRule {email\_domain }

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain {domain }

</summary>

domain: string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailListRule {email\_list }

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList {id }

</summary>

id: string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailRule {email }

Matches a specific email.

</summary>

<details>

<summary>

email: Email {email }

</summary>

email: string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EveryoneRule {everyone }

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ExternalEvaluationRule {external\_evaluation }

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation {evaluate\_url, keys\_url }

</summary>

evaluate\_url: string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GitHubOrganizationRule {github-organization }

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

"github-organization": GitHubOrganization {identity\_provider\_id, name, team }

</summary>

identity\_provider\_id: string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team?: string

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GSuiteGroupRule {gsuite }

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite {email, identity\_provider\_id }

</summary>

email: string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLoginMethodRule {login\_method }

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: LoginMethod {id }

</summary>

id: string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

IPListRule {ip\_list }

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList {id }

</summary>

id: string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

IPRule {ip }

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP {ip }

</summary>

ip: string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

OktaGroupRule {okta }

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta {identity\_provider\_id, name }

</summary>

identity\_provider\_id: string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

SAMLGroupRule {saml }

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML {attribute\_name, attribute\_value, identity\_provider\_id }

</summary>

attribute\_name: string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessOIDCClaimRule {oidc }

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: OIDC {claim\_name, claim\_value, identity\_provider\_id }

</summary>

claim\_name: string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

ServiceTokenRule {service\_token }

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken {token\_id }

</summary>

token\_id: string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLinkedAppTokenRule {linked\_app\_token }

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: LinkedAppToken {app\_uid }

</summary>

app\_uid: string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

AccessUserRiskScoreRule {user\_risk\_score }

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: UserRiskScore {user\_risk\_score }

</summary>

<details>

<summary>

user\_risk\_score: Array&lt;"low"| "medium"| "high"| "unscored"&gt;

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

AccessCloudflareAccountMemberRule {cloudflare\_account\_member }

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: CloudflareAccountMember {account\_id }

</summary>

account\_id?: string

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

include?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>&gt;

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

GroupRule {group }

Matches an Access group.

</summary>

<details>

<summary>

group: Group {id }

</summary>

id: string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AnyValidServiceTokenRule {any\_valid\_service\_token }

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessAuthContextRule {auth\_context }

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AuthContext {id, ac\_id, identity\_provider\_id }

</summary>

id: string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

AuthenticationMethodRule {auth\_method }

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod {auth\_method }

</summary>

auth\_method: string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AzureGroupRule {azureAD }

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azureAD: AzureAD {id, identity\_provider\_id }

</summary>

id: string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

CertificateRule {certificate }

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessCommonNameRule {common\_name }

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: CommonName {common\_name }

</summary>

common\_name: string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

CountryRule {geo }

Matches a specific country

</summary>

<details>

<summary>

geo: Geo {country\_code }

</summary>

country\_code: string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessDevicePostureRule {device\_posture }

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture {integration\_uid, account\_id }

</summary>

integration\_uid: string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id?: string

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

DomainRule {email\_domain }

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain {domain }

</summary>

domain: string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailListRule {email\_list }

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList {id }

</summary>

id: string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailRule {email }

Matches a specific email.

</summary>

<details>

<summary>

email: Email {email }

</summary>

email: string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EveryoneRule {everyone }

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ExternalEvaluationRule {external\_evaluation }

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation {evaluate\_url, keys\_url }

</summary>

evaluate\_url: string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GitHubOrganizationRule {github-organization }

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

"github-organization": GitHubOrganization {identity\_provider\_id, name, team }

</summary>

identity\_provider\_id: string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team?: string

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GSuiteGroupRule {gsuite }

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite {email, identity\_provider\_id }

</summary>

email: string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLoginMethodRule {login\_method }

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: LoginMethod {id }

</summary>

id: string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

IPListRule {ip\_list }

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList {id }

</summary>

id: string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

IPRule {ip }

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP {ip }

</summary>

ip: string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

OktaGroupRule {okta }

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta {identity\_provider\_id, name }

</summary>

identity\_provider\_id: string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

SAMLGroupRule {saml }

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML {attribute\_name, attribute\_value, identity\_provider\_id }

</summary>

attribute\_name: string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessOIDCClaimRule {oidc }

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: OIDC {claim\_name, claim\_value, identity\_provider\_id }

</summary>

claim\_name: string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

ServiceTokenRule {service\_token }

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken {token\_id }

</summary>

token\_id: string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLinkedAppTokenRule {linked\_app\_token }

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: LinkedAppToken {app\_uid }

</summary>

app\_uid: string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

AccessUserRiskScoreRule {user\_risk\_score }

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: UserRiskScore {user\_risk\_score }

</summary>

<details>

<summary>

user\_risk\_score: Array&lt;"low"| "medium"| "high"| "unscored"&gt;

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

AccessCloudflareAccountMemberRule {cloudflare\_account\_member }

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: CloudflareAccountMember {account\_id }

</summary>

account\_id?: string

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20include">Link to this property</a>

isolation\_required?: boolean

Require this application to be served in an isolated browser for users matching this policy. ‘Client Web Isolation’ must be on for the account in order to use this feature.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20isolation_required">Link to this property</a>

<details>

<summary>

mfa\_config?: MfaConfig {allowed\_authenticators, mfa\_disabled, session\_duration }

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

allowed\_authenticators?: Array&lt;"totp"| "biometrics"| "security\_key"&gt;

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

mfa\_disabled?: boolean

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

session\_duration?: string

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20mfa_config">Link to this property</a>

name?: string

The name of the Access policy.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

purpose\_justification\_prompt?: string

A custom message that will appear on the purpose justification screen.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_prompt">Link to this property</a>

purpose\_justification\_required?: boolean

Require users to enter a justification when they log in to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20purpose_justification_required">Link to this property</a>

<details>

<summary>

require?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>&gt;

Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.

</summary>

One of the following:

<details>

<summary>

GroupRule {group }

Matches an Access group.

</summary>

<details>

<summary>

group: Group {id }

</summary>

id: string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AnyValidServiceTokenRule {any\_valid\_service\_token }

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessAuthContextRule {auth\_context }

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AuthContext {id, ac\_id, identity\_provider\_id }

</summary>

id: string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

AuthenticationMethodRule {auth\_method }

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod {auth\_method }

</summary>

auth\_method: string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AzureGroupRule {azureAD }

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azureAD: AzureAD {id, identity\_provider\_id }

</summary>

id: string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

CertificateRule {certificate }

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessCommonNameRule {common\_name }

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: CommonName {common\_name }

</summary>

common\_name: string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

CountryRule {geo }

Matches a specific country

</summary>

<details>

<summary>

geo: Geo {country\_code }

</summary>

country\_code: string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessDevicePostureRule {device\_posture }

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture {integration\_uid, account\_id }

</summary>

integration\_uid: string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id?: string

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

DomainRule {email\_domain }

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain {domain }

</summary>

domain: string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailListRule {email\_list }

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList {id }

</summary>

id: string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailRule {email }

Matches a specific email.

</summary>

<details>

<summary>

email: Email {email }

</summary>

email: string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EveryoneRule {everyone }

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ExternalEvaluationRule {external\_evaluation }

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation {evaluate\_url, keys\_url }

</summary>

evaluate\_url: string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GitHubOrganizationRule {github-organization }

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

"github-organization": GitHubOrganization {identity\_provider\_id, name, team }

</summary>

identity\_provider\_id: string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team?: string

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GSuiteGroupRule {gsuite }

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite {email, identity\_provider\_id }

</summary>

email: string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLoginMethodRule {login\_method }

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: LoginMethod {id }

</summary>

id: string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

IPListRule {ip\_list }

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList {id }

</summary>

id: string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

IPRule {ip }

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP {ip }

</summary>

ip: string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

OktaGroupRule {okta }

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta {identity\_provider\_id, name }

</summary>

identity\_provider\_id: string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

SAMLGroupRule {saml }

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML {attribute\_name, attribute\_value, identity\_provider\_id }

</summary>

attribute\_name: string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessOIDCClaimRule {oidc }

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: OIDC {claim\_name, claim\_value, identity\_provider\_id }

</summary>

claim\_name: string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

ServiceTokenRule {service\_token }

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken {token\_id }

</summary>

token\_id: string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLinkedAppTokenRule {linked\_app\_token }

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: LinkedAppToken {app\_uid }

</summary>

app\_uid: string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

AccessUserRiskScoreRule {user\_risk\_score }

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: UserRiskScore {user\_risk\_score }

</summary>

<details>

<summary>

user\_risk\_score: Array&lt;"low"| "medium"| "high"| "unscored"&gt;

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

AccessCloudflareAccountMemberRule {cloudflare\_account\_member }

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: CloudflareAccountMember {account\_id }

</summary>

account\_id?: string

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20require">Link to this property</a>

session\_duration?: string| null

The amount of time that tokens issued for the application will be valid. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are: ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20session_duration">Link to this property</a>

updated\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_policy%20%3E%20(schema)>)

<details>

<summary>

ApplicationType = "self\_hosted"| "end\_user"| "saas"| 12 more

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"end\_user"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%209">Link to this property</a>

"infrastructure"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2010">Link to this property</a>

"rdp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2011">Link to this property</a>

"mcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2012">Link to this property</a>

"mcp\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2013">Link to this property</a>

"proxy\_endpoint"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)%20%3E%20(member)%2014">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)>)

<details>

<summary>

CORSHeaders {allow\_all\_headers, allow\_all\_methods, allow\_all\_origins, 5 more }

</summary>

allow\_all\_headers?: boolean

Allows all HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_headers">Link to this property</a>

allow\_all\_methods?: boolean

Allows all HTTP request methods.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_methods">Link to this property</a>

allow\_all\_origins?: boolean

Allows all origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_all_origins">Link to this property</a>

allow\_credentials?: boolean

When set to <code>true</code>, includes credentials (cookies, authorization headers, or TLS client certificates) with requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allow_credentials">Link to this property</a>

allowed\_headers?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_headers%20%3E%20(schema)">AllowedHeaders</a>&gt;

Allowed HTTP request headers.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_headers">Link to this property</a>

<details>

<summary>

allowed\_methods?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)">AllowedMethods</a>&gt;

Allowed HTTP request methods.

</summary>

One of the following:

"GET"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"POST"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"HEAD"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"PUT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"DELETE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"CONNECT"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"OPTIONS"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

"TRACE"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%207">Link to this property</a>

"PATCH"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_methods%20%3E%20(schema)%20%3E%20(member)%208">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_methods">Link to this property</a>

allowed\_origins?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_origins%20%3E%20(schema)">AllowedOrigins</a>&gt;

Allowed origins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20allowed_origins">Link to this property</a>

max\_age?: number

The maximum number of seconds the results of a preflight request can be cached.

maximum86400

minimum-1

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)%20%3E%20(property)%20max_age">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)>)

<details>

<summary>

Decision = "allow"| "deny"| "non\_identity"| "bypass"

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

</summary>

One of the following:

"allow"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"deny"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"non\_identity"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"bypass"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)>)

<details>

<summary>

OIDCSaaSApp {access\_token\_lifetime, allow\_pkce\_without\_client\_secret, app\_launcher\_url, 11 more }

</summary>

access\_token\_lifetime?: string

The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

allow\_pkce\_without\_client\_secret?: boolean

If client secret should be required on the token endpoint when authorization\_code\_with\_pkce grant is used.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20allow_pkce_without_client_secret">Link to this property</a>

app\_launcher\_url?: string

The URL where this applications tile redirects users

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20app_launcher_url">Link to this property</a>

<details>

<summary>

auth\_type?: "saml"| "oidc"

Identifier of the authentication protocol used for the saas app. Required for OIDC.

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

client\_id?: string

The application client id

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret?: string

The application client secret, only returned on POST request.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

<details>

<summary>

custom\_claims?: Array&lt;CustomClaim&gt;

</summary>

name?: string

The name of the claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

required?: boolean

If the claim is required when building an OIDC token.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

scope?: "groups"| "profile"| "email"| "openid"

The scope of the claim.

</summary>

One of the following:

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%200">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%202">Link to this property</a>

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20scope">Link to this property</a>

<details>

<summary>

source?: Source {name, name\_by\_idp }

</summary>

name?: string

The name of the IdP claim.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

name\_by\_idp?: Record&lt;string, string&gt;

A mapping from IdP ID to claim name.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_claims">Link to this property</a>

<details>

<summary>

grant\_types?: Array&lt;"authorization\_code"| "authorization\_code\_with\_pkce"| "refresh\_tokens"| 2 more&gt;

The OIDC flows supported by this application

</summary>

One of the following:

"authorization\_code"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"authorization\_code\_with\_pkce"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"refresh\_tokens"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"hybrid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"implicit"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20grant_types">Link to this property</a>

group\_filter\_regex?: string

A regex to filter Cloudflare groups returned in ID token and userinfo endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20group_filter_regex">Link to this property</a>

<details>

<summary>

hybrid\_and\_implicit\_options?: HybridAndImplicitOptions {return\_access\_token\_from\_authorization\_endpoint, return\_id\_token\_from\_authorization\_endpoint }

</summary>

return\_access\_token\_from\_authorization\_endpoint?: boolean

If an Access Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_access_token_from_authorization_endpoint">Link to this property</a>

return\_id\_token\_from\_authorization\_endpoint?: boolean

If an ID Token should be returned from the OIDC Authorization endpoint

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options%20%3E%20(property)%20return_id_token_from_authorization_endpoint">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20hybrid_and_implicit_options">Link to this property</a>

public\_key?: string

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

redirect\_uris?: Array&lt;string&gt;

The permitted URL’s for Cloudflare to return Authorization codes and Access/ID tokens

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20redirect_uris">Link to this property</a>

<details>

<summary>

refresh\_token\_options?: RefreshTokenOptions {lifetime }

</summary>

lifetime?: string

How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options%20%3E%20(property)%20lifetime">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20refresh_token_options">Link to this property</a>

<details>

<summary>

scopes?: Array&lt;"openid"| "groups"| "email"| "profile"&gt;

Define the user information shared with access, “offline\_access” scope will be automatically enabled if refresh tokens are enabled

</summary>

One of the following:

"openid"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"groups"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"profile"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20oidc_saas_app%20%3E%20(schema)>)

<details>

<summary>

SaaSAppNameIDFormat = "id"| "email"

The format of the name identifier sent to the SaaS application.

</summary>

One of the following:

"id"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"email"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)>)

<details>

<summary>

SAMLSaaSApp {auth\_type, consumer\_service\_url, custom\_attributes, 8 more }

</summary>

<details>

<summary>

auth\_type?: "saml"| "oidc"

Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is “saml”

</summary>

One of the following:

"saml"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%200">Link to this property</a>

"oidc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20auth_type">Link to this property</a>

consumer\_service\_url?: string

The service provider’s endpoint that is responsible for receiving and parsing a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20consumer_service_url">Link to this property</a>

<details>

<summary>

custom\_attributes?: Array&lt;CustomAttribute&gt;

</summary>

friendly\_name?: string

The SAML FriendlyName of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20friendly_name">Link to this property</a>

name?: string

The name of the attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_format?: "urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"| "urn:oasis:names:tc:SAML:2.0:attrname-format:basic"| "urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

A globally unique name for an identity or service provider.

</summary>

One of the following:

"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%200">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:basic"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%201">Link to this property</a>

"urn:oasis:names:tc:SAML:2.0:attrname-format:uri"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20name_format">Link to this property</a>

required?: boolean

If the attribute is required when building a SAML assertion.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

<details>

<summary>

source?: Source {name, name\_by\_idp }

</summary>

name?: string

The name of the IdP attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

name\_by\_idp?: Array&lt;NameByIdP&gt;

A mapping from IdP ID to attribute name.

</summary>

idp\_id?: string

The UID of the IdP.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20idp_id">Link to this property</a>

source\_name?: string

The name of the IdP provided attribute.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp%20%3E%20(items)%20%3E%20(property)%20source_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20name_by_idp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20custom_attributes">Link to this property</a>

default\_relay\_state?: string

The URL that the user will be redirected to after a successful login for IDP initiated logins.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20default_relay_state">Link to this property</a>

idp\_entity\_id?: string

The unique identifier for your SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20idp_entity_id">Link to this property</a>

name\_id\_format?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saas_app_name_id_format%20%3E%20(schema)">SaaSAppNameIDFormat</a>

The format of the name identifier sent to the SaaS application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_format">Link to this property</a>

name\_id\_transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms an application’s user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the <code>name_id_format</code> setting.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20name_id_transform_jsonata">Link to this property</a>

public\_key?: string

The Access public certificate that will be used to verify your identity.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20public_key">Link to this property</a>

saml\_attribute\_transform\_jsonata?: string

A \[JSONata] (<a href="https://jsonata.org/">https://jsonata.org/</a>) expression that transforms an application’s user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml\_attributes or oidc\_fields of the identity provider used to authenticate. The output of this expression must be a JSON object.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20saml_attribute_transform_jsonata">Link to this property</a>

sp\_entity\_id?: string

A globally unique name for an identity or service provider.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sp_entity_id">Link to this property</a>

sso\_endpoint?: string

The endpoint where your SaaS application will send login requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)%20%3E%20(property)%20sso_endpoint">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20saml_saas_app%20%3E%20(schema)>)

<details>

<summary>

SCIMConfigAuthenticationHTTPBasic {password, scheme, user }

Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.

</summary>

password: string

Password used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20password">Link to this property</a>

scheme: "httpbasic"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

user: string

User name used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)%20%3E%20(property)%20user">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_http_basic%20%3E%20(schema)>)

<details>

<summary>

SCIMConfigAuthenticationOAuthBearerToken {token, scheme }

Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.

</summary>

token: string

Token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20token">Link to this property</a>

scheme: "oauthbearertoken"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth_bearer_token%20%3E%20(schema)>)

<details>

<summary>

SCIMConfigAuthenticationOauth2 {authorization\_url, client\_id, client\_secret, 3 more }

Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.

</summary>

authorization\_url: string

URL used to generate the auth code used during token generation.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20authorization_url">Link to this property</a>

client\_id: string

Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_id">Link to this property</a>

client\_secret: string

Secret used to authenticate when generating a token for authenticating with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20client_secret">Link to this property</a>

scheme: "oauth2"

The authentication scheme to use when making SCIM requests to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scheme">Link to this property</a>

token\_url: string

URL used to generate the token used to authenticate with the remote SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20token_url">Link to this property</a>

scopes?: Array&lt;string&gt;

The authorization scopes to request when generating the token used to authenticate with the remove SCIM service.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)%20%3E%20(property)%20scopes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_authentication_oauth2%20%3E%20(schema)>)

<details>

<summary>

SCIMConfigMapping {schema, enabled, filter, 3 more }

Transformations and filters applied to resources before they are provisioned in the remote SCIM service.

</summary>

schema: string

Which SCIM resource type this mapping applies to.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

enabled?: boolean

Whether or not this mapping is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

filter?: string

A <a href="https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2">SCIM filter expression</a> that matches resources that should be provisioned to this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

<details>

<summary>

operations?: Operations {create, delete, update }

Whether or not this mapping applies to creates, updates, or deletes.

</summary>

create?: boolean

Whether or not this mapping applies to create (POST) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20create">Link to this property</a>

delete?: boolean

Whether or not this mapping applies to DELETE operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20delete">Link to this property</a>

update?: boolean

Whether or not this mapping applies to update (PATCH/PUT) operations.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations%20%3E%20(property)%20update">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20operations">Link to this property</a>

<details>

<summary>

strictness?: "strict"| "passthrough"

The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.

</summary>

One of the following:

"strict"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%200">Link to this property</a>

"passthrough"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20strictness">Link to this property</a>

transform\_jsonata?: string

A <a href="https://jsonata.org/">JSONata</a> expression that transforms the resource before provisioning it in the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)%20%3E%20(property)%20transform_jsonata">Link to this property</a>

</details>

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20scim_config_mapping%20%3E%20(schema)>)

SelfHostedDomains = string

A domain that Access will secure.

[Link to this property](<#(resource)%20zero_trust.access.applications%20%3E%20(model)%20self_hosted_domains%20%3E%20(schema)>)

<details>

<summary>

ApplicationListResponse = EndUserApplication {oauth\_configuration, type, user\_populations, 7 more } | SelfHostedApplication {domain, type, id, 31 more } | SaaSApplication {id, allowed\_idps, app\_launcher\_visible, 10 more } | 11 more

</summary>

One of the following:

<details>

<summary>

EndUserApplication {oauth\_configuration, type, user\_populations, 7 more }

</summary>

<details>

<summary>

oauth\_configuration: OAuthConfiguration {dynamic\_client\_registration, enabled, grant }

**Beta:** Optional configuration for managing an OAuth authorization flow controlled by Access. When set, Access will act as the OAuth authorization server for this application. Only compatible with OAuth clients that support <a href="https://datatracker.ietf.org/doc/html/rfc8707">RFC 8707</a> (Resource Indicators for OAuth 2.0). This feature is currently in beta.

</summary>

<details>

<summary>

dynamic\_client\_registration?: DynamicClientRegistration {allow\_any\_on\_localhost, allow\_any\_on\_loopback, allowed\_uris, enabled }

Settings for OAuth dynamic client registration.

</summary>

allow\_any\_on\_localhost?: boolean

Allows any client with redirect URIs on localhost.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_localhost">Link to this property</a>

allow\_any\_on\_loopback?: boolean

Allows any client with redirect URIs on 127.0.0.1.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_loopback">Link to this property</a>

allowed\_uris?: Array&lt;string&gt;

The URIs that are allowed as redirect URIs for dynamically registered clients. HTTP and HTTPS paths may end in <code>/*</code> to match all sub-paths. Custom-scheme URIs must be explicitly configured and match exactly.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allowed_uris">Link to this property</a>

enabled?: boolean

Whether dynamic client registration is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration">Link to this property</a>

enabled?: true

Managed OAuth is required for end user applications and cannot be disabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

grant?: Grant {access\_token\_lifetime, session\_duration }

Settings for OAuth grant behavior.

</summary>

access\_token\_lifetime?: string

The lifetime of the access token. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

session\_duration?: string

The duration of the OAuth session. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20oauth_configuration">Link to this property</a>

<details>

<summary>

type: "self\_hosted"| "end\_user"| "saas"| 12 more

The application type.

</summary>

One of the following:

"self\_hosted"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

"end\_user"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

"saas"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%202">Link to this property</a>

"ssh"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%203">Link to this property</a>

"vnc"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%204">Link to this property</a>

"app\_launcher"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%205">Link to this property</a>

"warp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%206">Link to this property</a>

"biso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%207">Link to this property</a>

"bookmark"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%208">Link to this property</a>

"dash\_sso"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%209">Link to this property</a>

"infrastructure"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2010">Link to this property</a>

"rdp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2011">Link to this property</a>

"mcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2012">Link to this property</a>

"mcp\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2013">Link to this property</a>

"proxy\_endpoint"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type%20%3E%20(member)%2014">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

user\_populations: Array&lt;string&gt;

The single user population associated with this application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20user_populations">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20id">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20allowed_idps">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20aud">Link to this property</a>

<details>

<summary>

destinations?: Array&lt;AccessEndUserPublicDestination {uri, overrides, type } | AccessEndUserWorkerDestination {type, worker\_id, overrides } | AccessEndUserPreviewWorkerDestination {type, worker\_id, overrides } | 2 more&gt;

Public hostname and Workers destinations secured by Access.

</summary>

One of the following:

<details>

<summary>

AccessEndUserPublicDestination {uri, overrides, type }

</summary>

uri: string

The public hostname and optional path to secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20uri">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides">Link to this property</a>

type?: "public"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

AccessEndUserWorkerDestination {type, worker\_id, overrides }

</summary>

type: "worker"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

worker\_id: string

The ID of the Cloudflare Worker to secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

AccessEndUserPreviewWorkerDestination {type, worker\_id, overrides }

</summary>

type: "preview\_worker"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

worker\_id: string

The ID of the Cloudflare Worker whose previews to secure.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

AccessEndUserAllWorkersDestination {type, overrides }

</summary>

type: "all\_workers"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

AccessEndUserAllPreviewWorkersDestination {type, overrides }

</summary>

type: "all\_preview\_workers"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20destinations">Link to this property</a>

domain?: string

The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20domain">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20name">Link to this property</a>

Deprecatedself\_hosted\_domains?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20self_hosted_domains%20%3E%20(schema)">SelfHostedDomains</a>&gt;

List of public domains that Access will secure. This field is deprecated in favor of <code>destinations</code> and will be supported until **November 21, 2025.** If <code>destinations</code> are provided, then <code>self_hosted_domains</code> will be ignored.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200%20%3E%20(property)%20self_hosted_domains">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

SelfHostedApplication {domain, type, id, 31 more }

</summary>

domain: string

The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20domain">Link to this property</a>

type: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_type%20%3E%20(schema)">ApplicationType</a>

The application type.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

id?: string

UUID.

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

allow\_authenticate\_via\_warp?: boolean

When set to true, users can authenticate to this application using their WARP session. When set to false this application will always require direct IdP authentication. This setting always overrides the organization setting for WARP authentication.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allow_authenticate_via_warp">Link to this property</a>

allow\_iframe?: boolean

Enables loading application content in an iFrame.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allow_iframe">Link to this property</a>

allowed\_idps?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20allowed_idps%20%3E%20(schema)">AllowedIdPs</a>&gt;

The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20allowed_idps">Link to this property</a>

app\_launcher\_visible?: boolean

Displays the application in the App Launcher.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20app_launcher_visible">Link to this property</a>

aud?: string

Audience tag.

maxLength64

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20aud">Link to this property</a>

auto\_redirect\_to\_identity?: boolean

When set to <code>true</code>, users skip the identity provider selection step during login. You must specify only one identity provider in allowed\_idps.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20auto_redirect_to_identity">Link to this property</a>

cors\_headers?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20cors_headers%20%3E%20(schema)">CORSHeaders</a> {allow\_all\_headers, allow\_all\_methods, allow\_all\_origins, 5 more }

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20cors_headers">Link to this property</a>

custom\_deny\_message?: string

The custom error message shown to a user when they are denied access to the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_deny_message">Link to this property</a>

custom\_deny\_url?: string

The custom URL a user is redirected to when they are denied access to the application when failing identity-based rules.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_deny_url">Link to this property</a>

custom\_non\_identity\_deny\_url?: string

The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_non_identity_deny_url">Link to this property</a>

custom\_pages?: Array&lt;string&gt;

The custom pages that will be displayed when applicable for this application

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20custom_pages">Link to this property</a>

<details>

<summary>

destinations?: Array&lt;PublicDestination {overrides, type, uri } | PrivateDestination {cidr, hostname, l4\_protocol, 3 more } | ViaMcpServerPortalDestination {mcp\_server\_id, type } | 4 more&gt;

List of destinations secured by Access. This supersedes <code>self_hosted_domains</code> to allow for more flexibility in defining different types of domains. If <code>destinations</code> are provided, then <code>self_hosted_domains</code> will be ignored.

</summary>

One of the following:

<details>

<summary>

PublicDestination {overrides, type, uri }

A public hostname that Access will secure. Public destinations support sub-domain and path. Wildcard ’\*’ can be used in the definition.

</summary>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20overrides">Link to this property</a>

type?: "public"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20type">Link to this property</a>

uri?: string

The URI of the destination. Public destinations’ URIs can include a domain and path with <a href="https://developers.cloudflare.com/cloudflare-one/policies/access/app-paths/">wildcards</a>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200%20%3E%20(property)%20uri">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%200">Link to this property</a>

<details>

<summary>

PrivateDestination {cidr, hostname, l4\_protocol, 3 more }

</summary>

cidr?: string

The CIDR range of the destination. Single IPs will be computed as /32.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20cidr">Link to this property</a>

hostname?: string

The hostname of the destination. Matches a valid SNI served by an HTTPS origin.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20hostname">Link to this property</a>

<details>

<summary>

l4\_protocol?: "tcp"| "udp"

The L4 protocol of the destination. When omitted, both UDP and TCP traffic will match.

</summary>

One of the following:

"tcp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20l4_protocol%20%3E%20(member)%200">Link to this property</a>

"udp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20l4_protocol%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20l4_protocol">Link to this property</a>

port\_range?: string

The port range of the destination. Can be a single port or a range of ports. When omitted, all ports will match.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20port_range">Link to this property</a>

type?: "private"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

vnet\_id?: string

The VNET ID to match the destination. When omitted, all VNETs will match.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201%20%3E%20(property)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

<details>

<summary>

ViaMcpServerPortalDestination {mcp\_server\_id, type }

A MCP server id configured in ai-controls. Access will secure the MCP server if accessed through a MCP portal.

</summary>

mcp\_server\_id?: string

The MCP server id configured in ai-controls.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20mcp_server_id">Link to this property</a>

type?: "via\_mcp\_server\_portal"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

WorkerDestination {type, worker\_id, overrides }

A specific Cloudflare Worker that Access will secure. All requests routed to the specified Worker, including its preview deployments, will be protected. The <code>preview_worker</code> and <code>public</code> destination types takes precedence, so you can create separate applications to override the policies for the Worker’s previews or specific paths.

</summary>

type: "worker"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20type">Link to this property</a>

worker\_id: string

The ID of the Cloudflare Worker to protect with Access.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%203">Link to this property</a>

<details>

<summary>

PreviewWorkerDestination {type, worker\_id, overrides }

A specific Cloudflare Worker whose preview deployments Access will secure. Only requests routed to the preview deployments of the specified Worker will be protected. The <code>public</code> destination type takes precedence, so you can create separate applications to override the policies for specific paths.

</summary>

type: "preview\_worker"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20type">Link to this property</a>

worker\_id: string

The ID of the Cloudflare Worker whose preview deployments to protect with Access.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20worker_id">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%204">Link to this property</a>

<details>

<summary>

AllWorkersDestination {type, overrides }

Protects all Cloudflare Workers on the account with Access, including their preview deployments. At most one destination of this type can exist per account. The <code>worker</code>, <code>preview_worker</code>, <code>all_preview_workers</code>, and <code>public</code> destination types take precedence, so you can create separate applications to override the policies for specific Workers, their previews, or specific paths.

</summary>

type: "all\_workers"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%205">Link to this property</a>

<details>

<summary>

AllPreviewWorkersDestination {type, overrides }

Protects the preview deployments of all Cloudflare Workers on the account with Access. At most one destination of this type can exist per account. The <code>worker</code>, <code>preview_worker</code>, and <code>public</code> destination types take precedence, so you can create separate applications to override the policies for specific Workers, their previews, or specific paths.

</summary>

type: "all\_preview\_workers"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20type">Link to this property</a>

<details>

<summary>

overrides?: Array&lt;Override&gt;

Rules that override how Access handles requests to this destination. Each rule can make a matching path public, bypassing Access authentication. Overrides are supported for public destinations and Worker destinations.

</summary>

behavior: "public"

The behavior to apply to matching requests.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20behavior">Link to this property</a>

path\_pattern: string

The request path pattern to match. Wildcards (<code>*</code>) are supported, but each path segment may have at most one wildcard. Unlike the <code>uri</code> in public destinations, override path patterns do not implicitly cover subpaths; to do that, use a wildcard.

maxLength512

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20overrides%20%3E%20(items)%20%3E%20(property)%20path_pattern">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206%20%3E%20(property)%20overrides">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations%20%3E%20(items)%20%3E%20(variant)%206">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destinations">Link to this property</a>

eager\_redirect\_cookie\_setting?: boolean

Preemptively sets the Access session cookie on every hostname in a multi-hostname self-hosted application during the initial redirect chain, rather than setting it lazily on first visit. Defaults to true. Set to false to disable the eager redirect cookie behavior.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20eager_redirect_cookie_setting">Link to this property</a>

enable\_binding\_cookie?: boolean

Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20enable_binding_cookie">Link to this property</a>

http\_only\_cookie\_attribute?: boolean

Enables the HttpOnly cookie attribute, which increases security against XSS attacks.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20http_only_cookie_attribute">Link to this property</a>

logo\_url?: string

The image URL for the logo shown in the App Launcher dashboard.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20logo_url">Link to this property</a>

<details>

<summary>

mfa\_config?: MfaConfig {allowed\_authenticators, mfa\_disabled, session\_duration }

Configures multi-factor authentication (MFA) settings.

</summary>

<details>

<summary>

allowed\_authenticators?: Array&lt;"totp"| "biometrics"| "security\_key"&gt;

Lists the MFA methods that users can authenticate with.

</summary>

One of the following:

"totp"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"biometrics"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"security\_key"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20allowed_authenticators">Link to this property</a>

mfa\_disabled?: boolean

Indicates whether to disable MFA for this resource. This option is available at the application and policy level.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20mfa_disabled">Link to this property</a>

session\_duration?: string

Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:<code>5m</code> or <code>24h</code>.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20mfa_config">Link to this property</a>

name?: string

The name of the application.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20name">Link to this property</a>

<details>

<summary>

oauth\_configuration?: OAuthConfiguration {dynamic\_client\_registration, enabled, grant }

**Beta:** Optional configuration for managing an OAuth authorization flow controlled by Access. When set, Access will act as the OAuth authorization server for this application. Only compatible with OAuth clients that support <a href="https://datatracker.ietf.org/doc/html/rfc8707">RFC 8707</a> (Resource Indicators for OAuth 2.0). This feature is currently in beta.

</summary>

<details>

<summary>

dynamic\_client\_registration?: DynamicClientRegistration {allow\_any\_on\_localhost, allow\_any\_on\_loopback, allowed\_uris, enabled }

Settings for OAuth dynamic client registration.

</summary>

allow\_any\_on\_localhost?: boolean

Allows any client with redirect URIs on localhost.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_localhost">Link to this property</a>

allow\_any\_on\_loopback?: boolean

Allows any client with redirect URIs on 127.0.0.1.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allow_any_on_loopback">Link to this property</a>

allowed\_uris?: Array&lt;string&gt;

The URIs that are allowed as redirect URIs for dynamically registered clients. HTTP and HTTPS paths may end in <code>/*</code> to match all sub-paths. Custom-scheme URIs must be explicitly configured and match exactly.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20allowed_uris">Link to this property</a>

enabled?: boolean

Whether dynamic client registration is enabled.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration%20%3E%20(property)%20enabled">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20dynamic_client_registration">Link to this property</a>

enabled?: boolean

Whether the OAuth configuration is enabled for this application. When set to <code>false</code>, Access will not handle OAuth for this application. Defaults to <code>true</code> if omitted.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20enabled">Link to this property</a>

<details>

<summary>

grant?: Grant {access\_token\_lifetime, session\_duration }

Settings for OAuth grant behavior.

</summary>

access\_token\_lifetime?: string

The lifetime of the access token. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20access_token_lifetime">Link to this property</a>

session\_duration?: string

The duration of the OAuth session. Must be in the format <code>300ms</code> or <code>2h45m</code>. Valid time units are ns, us (or µs), ms, s, m, h.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant%20%3E%20(property)%20session_duration">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration%20%3E%20(property)%20grant">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20oauth_configuration">Link to this property</a>

options\_preflight\_bypass?: boolean

Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors\_headers is set.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20options_preflight_bypass">Link to this property</a>

path\_cookie\_attribute?: boolean

Enables cookie paths to scope an application’s JWT to the application path. If disabled, the JWT will scope to the hostname by default

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20path_cookie_attribute">Link to this property</a>

<details>

<summary>

policies?: Array&lt;Policy&gt;

</summary>

id?: string

The UUID of the policy

maxLength36

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

account\_id?: string

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20account_id">Link to this property</a>

<details>

<summary>

approval\_groups?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)">ApprovalGroup</a> {approvals\_needed, email\_addresses, email\_list\_uuid } &gt;

Administrators who can approve a temporary authentication request.

</summary>

approvals\_needed: number

The number of approvals needed to obtain access.

minimum0

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20approvals_needed">Link to this property</a>

email\_addresses?: Array&lt;string&gt;

A list of emails that can approve the access request.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_addresses">Link to this property</a>

email\_list\_uuid?: string

The UUID of an re-usable email list.

<a href="#(resource)%20zero_trust.access.policies%20%3E%20(model)%20approval_group%20%3E%20(schema)%20%3E%20(property)%20email_list_uuid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20approval_groups">Link to this property</a>

approval\_required?: boolean

Requires the user to request access from an administrator at the start of each session.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20approval_required">Link to this property</a>

<details>

<summary>

connection\_rules?: ConnectionRules {rdp }

The rules that define how users may connect to targets secured by your application.

</summary>

<details>

<summary>

rdp?: RDP {allowed\_clipboard\_local\_to\_remote\_formats, allowed\_clipboard\_remote\_to\_local\_formats }

The RDP-specific rules that define clipboard behavior for RDP connections.

</summary>

<details>

<summary>

allowed\_clipboard\_local\_to\_remote\_formats?: Array&lt;"text"| "file"&gt;

Clipboard formats allowed when copying from local machine to remote RDP session.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_local_to_remote_formats">Link to this property</a>

<details>

<summary>

allowed\_clipboard\_remote\_to\_local\_formats?: Array&lt;"text"| "file"&gt;

Clipboard formats allowed when copying from remote RDP session to local machine.

</summary>

One of the following:

"text"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"file"

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp%20%3E%20(property)%20allowed_clipboard_remote_to_local_formats">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules%20%3E%20(property)%20rdp">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20connection_rules">Link to this property</a>

created\_at?: string

formatdate-time

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

decision?: <a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications%20%3E%20(model)%20decision%20%3E%20(schema)">Decision</a>

The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20decision">Link to this property</a>

<details>

<summary>

exclude?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>&gt;

Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.

</summary>

One of the following:

<details>

<summary>

GroupRule {group }

Matches an Access group.

</summary>

<details>

<summary>

group: Group {id }

</summary>

id: string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AnyValidServiceTokenRule {any\_valid\_service\_token }

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessAuthContextRule {auth\_context }

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AuthContext {id, ac\_id, identity\_provider\_id }

</summary>

id: string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

AuthenticationMethodRule {auth\_method }

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod {auth\_method }

</summary>

auth\_method: string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AzureGroupRule {azureAD }

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azureAD: AzureAD {id, identity\_provider\_id }

</summary>

id: string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

CertificateRule {certificate }

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessCommonNameRule {common\_name }

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: CommonName {common\_name }

</summary>

common\_name: string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

CountryRule {geo }

Matches a specific country

</summary>

<details>

<summary>

geo: Geo {country\_code }

</summary>

country\_code: string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessDevicePostureRule {device\_posture }

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture {integration\_uid, account\_id }

</summary>

integration\_uid: string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id?: string

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

DomainRule {email\_domain }

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain {domain }

</summary>

domain: string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailListRule {email\_list }

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList {id }

</summary>

id: string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailRule {email }

Matches a specific email.

</summary>

<details>

<summary>

email: Email {email }

</summary>

email: string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EveryoneRule {everyone }

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ExternalEvaluationRule {external\_evaluation }

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation {evaluate\_url, keys\_url }

</summary>

evaluate\_url: string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GitHubOrganizationRule {github-organization }

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

"github-organization": GitHubOrganization {identity\_provider\_id, name, team }

</summary>

identity\_provider\_id: string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team?: string

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GSuiteGroupRule {gsuite }

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite {email, identity\_provider\_id }

</summary>

email: string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLoginMethodRule {login\_method }

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: LoginMethod {id }

</summary>

id: string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

IPListRule {ip\_list }

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList {id }

</summary>

id: string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

IPRule {ip }

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP {ip }

</summary>

ip: string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

OktaGroupRule {okta }

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta {identity\_provider\_id, name }

</summary>

identity\_provider\_id: string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

SAMLGroupRule {saml }

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML {attribute\_name, attribute\_value, identity\_provider\_id }

</summary>

attribute\_name: string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

identity\_provider\_id: string

The ID of your SAML identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessOIDCClaimRule {oidc }

Matches an OIDC claim. Requires an OIDC identity provider.

</summary>

<details>

<summary>

oidc: OIDC {claim\_name, claim\_value, identity\_provider\_id }

</summary>

claim\_name: string

The name of the OIDC claim.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_name">Link to this property</a>

claim\_value: string

The OIDC claim value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20claim_value">Link to this property</a>

identity\_provider\_id: string

The ID of your OIDC identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021%20%3E%20(property)%20oidc">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2021">Link to this property</a>

<details>

<summary>

ServiceTokenRule {service\_token }

Matches a specific Access Service Token

</summary>

<details>

<summary>

service\_token: ServiceToken {token\_id }

</summary>

token\_id: string

The ID of a Service Token.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token%20%3E%20(property)%20token_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)%20%3E%20(property)%20service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLinkedAppTokenRule {linked\_app\_token }

Matches OAuth 2.0 access tokens issued by the specified Access OIDC SaaS application. Only compatible with non\_identity and bypass decisions.

</summary>

<details>

<summary>

linked\_app\_token: LinkedAppToken {app\_uid }

</summary>

app\_uid: string

The ID of an Access OIDC SaaS application

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token%20%3E%20(property)%20app_uid">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023%20%3E%20(property)%20linked_app_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2023">Link to this property</a>

<details>

<summary>

AccessUserRiskScoreRule {user\_risk\_score }

Matches a user’s risk score.

</summary>

<details>

<summary>

user\_risk\_score: UserRiskScore {user\_risk\_score }

</summary>

<details>

<summary>

user\_risk\_score: Array&lt;"low"| "medium"| "high"| "unscored"&gt;

A list of risk score levels to match. Values can be low, medium, high, or unscored.

</summary>

One of the following:

"low"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"medium"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"high"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"unscored"

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024%20%3E%20(property)%20user_risk_score">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2024">Link to this property</a>

<details>

<summary>

AccessCloudflareAccountMemberRule {cloudflare\_account\_member }

Matches users who are members of a specific Cloudflare account. Requires a Cloudflare identity provider.

</summary>

<details>

<summary>

cloudflare\_account\_member: CloudflareAccountMember {account\_id }

</summary>

account\_id?: string

Identifier.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025%20%3E%20(property)%20cloudflare_account_member">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2025">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications%20%3E%20(model)%20application_list_response%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20policies%20%3E%20(items)%20%3E%20(property)%20exclude">Link to this property</a>

<details>

<summary>

include?: Array&lt;<a href="https://developers.cloudflare.com/api/typescript/resources/zero_trust#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)">AccessRule</a>&gt;

Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

</summary>

One of the following:

<details>

<summary>

GroupRule {group }

Matches an Access group.

</summary>

<details>

<summary>

group: Group {id }

</summary>

id: string

The ID of a previously created Access group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)%20%3E%20(property)%20group">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AnyValidServiceTokenRule {any\_valid\_service\_token }

Matches any valid Access Service Token

</summary>

any\_valid\_service\_token: AnyValidServiceToken

An empty object which matches on all service tokens.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)%20%3E%20(property)%20any_valid_service_token">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20any_valid_service_token_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessAuthContextRule {auth\_context }

Matches an Azure Authentication Context. Requires an Azure identity provider.

</summary>

<details>

<summary>

auth\_context: AuthContext {id, ac\_id, identity\_provider\_id }

</summary>

id: string

The ID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20id">Link to this property</a>

ac\_id: string

The ACID of an Authentication context.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20ac_id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202%20%3E%20(property)%20auth_context">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%202">Link to this property</a>

<details>

<summary>

AuthenticationMethodRule {auth\_method }

Enforce different MFA options

</summary>

<details>

<summary>

auth\_method: AuthMethod {auth\_method }

</summary>

auth\_method: string

The type of authentication method <a href="https://datatracker.ietf.org/doc/html/rfc8176#section-2">https://datatracker.ietf.org/doc/html/rfc8176#section-2</a>.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)%20%3E%20(property)%20auth_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20authentication_method_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AzureGroupRule {azureAD }

Matches an Azure group. Requires an Azure identity provider.

</summary>

<details>

<summary>

azureAD: AzureAD {id, identity\_provider\_id }

</summary>

id: string

The ID of an Azure group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20id">Link to this property</a>

identity\_provider\_id: string

The ID of your Azure identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)%20%3E%20(property)%20azureAD">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20azure_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

CertificateRule {certificate }

Matches any valid client certificate.

</summary>

certificate: Certificate

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)%20%3E%20(property)%20certificate">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20certificate_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessCommonNameRule {common\_name }

Matches a specific common name.

</summary>

<details>

<summary>

common\_name: CommonName {common\_name }

</summary>

common\_name: string

The common name to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206%20%3E%20(property)%20common_name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%206">Link to this property</a>

<details>

<summary>

CountryRule {geo }

Matches a specific country

</summary>

<details>

<summary>

geo: Geo {country\_code }

</summary>

country\_code: string

The country code that should be matched.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo%20%3E%20(property)%20country_code">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)%20%3E%20(property)%20geo">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20country_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessDevicePostureRule {device\_posture }

Enforces a device posture rule has run successfully

</summary>

<details>

<summary>

device\_posture: DevicePosture {integration\_uid, account\_id }

</summary>

integration\_uid: string

The ID of a device posture integration.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20integration_uid">Link to this property</a>

account\_id?: string

The ID of the account that owns the device posture integration.

maxLength32

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture%20%3E%20(property)%20account_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)%20%3E%20(property)%20device_posture">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_device_posture_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

DomainRule {email\_domain }

Match an entire email domain.

</summary>

<details>

<summary>

email\_domain: EmailDomain {domain }

</summary>

domain: string

The email domain to match.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain%20%3E%20(property)%20domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)%20%3E%20(property)%20email_domain">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20domain_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailListRule {email\_list }

Matches an email address from a list.

</summary>

<details>

<summary>

email\_list: EmailList {id }

</summary>

id: string

The ID of a previously created email list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)%20%3E%20(property)%20email_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EmailRule {email }

Matches a specific email.

</summary>

<details>

<summary>

email: Email {email }

</summary>

email: string

The email of the user.

formatemail

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)%20%3E%20(property)%20email">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20email_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

EveryoneRule {everyone }

Matches everyone.

</summary>

everyone: Everyone

An empty object which matches on all users.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)%20%3E%20(property)%20everyone">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20everyone_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

ExternalEvaluationRule {external\_evaluation }

Create Allow or Block policies which evaluate the user based on custom criteria.

</summary>

<details>

<summary>

external\_evaluation: ExternalEvaluation {evaluate\_url, keys\_url }

</summary>

evaluate\_url: string

The API endpoint containing your business logic.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20evaluate_url">Link to this property</a>

keys\_url: string

The API endpoint containing the key that Access uses to verify that the response came from your API.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation%20%3E%20(property)%20keys_url">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)%20%3E%20(property)%20external_evaluation">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20external_evaluation_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GitHubOrganizationRule {github-organization }

Matches a Github organization. Requires a Github identity provider.

</summary>

<details>

<summary>

"github-organization": GitHubOrganization {identity\_provider\_id, name, team }

</summary>

identity\_provider\_id: string

The ID of your Github identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the organization.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20name">Link to this property</a>

team?: string

The name of the team

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization%20%3E%20(property)%20team">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)%20%3E%20(property)%20github-organization">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20github_organization_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

GSuiteGroupRule {gsuite }

Matches a group in Google Workspace. Requires a Google Workspace identity provider.

</summary>

<details>

<summary>

gsuite: GSuite {email, identity\_provider\_id }

</summary>

email: string

The email of the Google Workspace group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20email">Link to this property</a>

identity\_provider\_id: string

The ID of your Google Workspace identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite%20%3E%20(property)%20identity_provider_id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)%20%3E%20(property)%20gsuite">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20gsuite_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

AccessLoginMethodRule {login\_method }

Matches a specific identity provider id.

</summary>

<details>

<summary>

login\_method: LoginMethod {id }

</summary>

id: string

The ID of an identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016%20%3E%20(property)%20login_method">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20access_rule%20%3E%20(schema)%20%3E%20(variant)%2016">Link to this property</a>

<details>

<summary>

IPListRule {ip\_list }

Matches an IP address from a list.

</summary>

<details>

<summary>

ip\_list: IPList {id }

</summary>

id: string

The ID of a previously created IP list.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list%20%3E%20(property)%20id">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)%20%3E%20(property)%20ip_list">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_list_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

IPRule {ip }

Matches an IP address block.

</summary>

<details>

<summary>

ip: IP {ip }

</summary>

ip: string

An IPv4 or IPv6 CIDR block.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)%20%3E%20(property)%20ip">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20ip_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

OktaGroupRule {okta }

Matches an Okta group. Requires an Okta identity provider.

</summary>

<details>

<summary>

okta: Okta {identity\_provider\_id, name }

</summary>

identity\_provider\_id: string

The ID of your Okta identity provider.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20identity_provider_id">Link to this property</a>

name: string

The name of the Okta group.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)%20%3E%20(property)%20okta">Link to this property</a>

</details>

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20okta_group_rule%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

SAMLGroupRule {saml }

Matches a SAML group. Requires a SAML identity provider.

</summary>

<details>

<summary>

saml: SAML {attribute\_name, attribute\_value, identity\_provider\_id }

</summary>

attribute\_name: string

The name of the SAML attribute.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_name">Link to this property</a>

attribute\_value: string

The SAML attribute value to look for.

<a href="#(resource)%20zero_trust.access.applications.policies%20%3E%20(model)%20saml_group_rule%20%3E%20(schema)%20%3E%20(property)%20saml%20%3E%20(property)%20attribute_value">Link to this property</a>

</details>

</details>

</details>

</details>

</details>

</details>

<!-- Cloudflare Markdown for Agents: incomplete conversion; source HTML truncated at the conversion size limit -->
