Schema Profile detections populate these fields after an applicable profile becomes available:
| Field | Type | Source | Meaning | Available in |
|---|---|---|---|---|
cf.schema_validation.learned.violated |
Boolean |
Learned Schema Profile | true when an evaluated request violates the learned profile. |
Security Analytics and Custom Rules |
cf.schema_validation.uploaded.violated |
Boolean |
Uploaded schema | true when an evaluated request violates the supplied schema. |
Security Analytics and Custom Rules |
The following fields identify the names of Schema Profile violations by request location.
| Field | Type | Source | Meaning | Available in |
|---|---|---|---|---|
cf.schema_validation.learned.path.violated_parameters |
Array<String> |
Learned Schema Profile | Names of violating path parameters. | Custom Rules |
cf.schema_validation.learned.query.violated_parameters |
Array<String> |
Learned Schema Profile | Names of violating query parameters. | Custom Rules |
cf.schema_validation.learned.headers.violated_parameters |
Array<String> |
Learned Schema Profile | Names of violating request headers. | Custom Rules |
cf.schema_validation.learned.cookies.violated_parameters |
Array<String> |
Learned Schema Profile | Names of violating cookies. | Custom Rules |
cf.schema_validation.learned.body.violated_parameters |
Array<String> |
Learned Schema Profile | JSON path of a request body violation. | Custom Rules |
cf.schema_validation.uploaded.path.violated_parameters |
Array<String> |
Uploaded schema | Names of violating path parameters. | Custom Rules |
cf.schema_validation.uploaded.query.violated_parameters |
Array<String> |
Uploaded schema | Names of violating query parameters. | Custom Rules |
cf.schema_validation.uploaded.headers.violated_parameters |
Array<String> |
Uploaded schema | Names of violating request headers. | Custom Rules |
cf.schema_validation.uploaded.cookies.violated_parameters |
Array<String> |
Uploaded schema | Names of violating cookies. | Custom Rules |
cf.schema_validation.uploaded.body.violated_parameters |
Array<String> |
Uploaded schema | JSON path of a request body violation. | Custom Rules |
For body violations, the array contains the first detected violation's JSON path. A value of $ identifies the body without a more specific path.
These fields contain URL-decoded query parameter names presented in a request but not declared in the schema.
| Field | Type | Source | Meaning | Available in |
|---|---|---|---|---|
cf.schema_validation.learned.query.undeclared_parameters |
Array<String> |
Learned Schema Profile | Names of query parameters present in the request but not declared in the schema. | Custom Rules |
cf.schema_validation.uploaded.query.undeclared_parameters |
Array<String> |
Uploaded schema | Names of query parameters present in the request but not declared in the schema. | Custom Rules |
Sampled violations in Profile Analysis contain four structured fields that report the first detected violation for the request:
| Field | Type | Meaning |
|---|---|---|
location |
String |
Request component containing the violation: path, query, header, cookie, or body. |
error_class |
String |
Stable, broad category for grouping similar violations. |
error_detail |
String |
Optional specific reason within the error class. |
target |
String |
Optional parameter, header, cookie, or $-prefixed JSON body path associated with the violation. |
The error_class field can have the following values:
| Value | Meaning |
|---|---|
missing_required |
A required parameter, body, or header was absent. |
invalid_type |
A value had the wrong OpenAPI or JSON type. |
invalid_encoding |
Bytes or text did not use the expected encoding. |
invalid_syntax |
Request syntax was invalid, such as malformed JSON. |
invalid_media_type |
A media type did not match the schema. |
unsupported_media_type |
A media type or media type parameter is unsupported. |
duplicate_value |
A value that accepts one entry appeared more than once. |
too_many_values |
A collection contained more values than the validator accepts. |
constraint_violation |
A value violated an OpenAPI or JSON Schema constraint. |
body_size |
The request body could not be validated because of its size or truncation. |
The error_detail field adds context when the error class alone is insufficient. The field is empty when the class, location, and target identify the failure.
Error detail values
| Detail family | Possible values |
|---|---|
| Expected type | expected:array, expected:boolean, expected:integer, expected:null, expected:number, expected:object, expected:string, expected:one_of |
| Encoding and syntax | invalid_utf8, invalid_ascii, invalid_json, invalid_form_urlencoded |
| Media type | invalid_content_type, invalid_media_type, unsupported_media_type_parameter |
| Schema constraint | invalid_length, invalid_object_property_count, invalid_array_item_count, not, all_of, any_of, one_of, invalid_enum_variant, forbidden_value, missing_required_property, number_too_small, number_too_big, number_not_in_range, string_length_not_in_range, different_const_value, multiple_of, pattern_no_match, value_too_deep |
| Format constraint | format_violation:<format>, where <format> identifies the OpenAPI format. Current formats include uuid, email, date-time, date, time, hostname, ipv4, ipv6, uri, uri-reference, iri, iri-reference, int32, int64, uint64, byte, float, and double. |
The target value depends on the violation location:
| Location | Target |
|---|---|
path, query, or cookie |
Parameter name |
header |
Header name, such as content-type |
body |
$-prefixed JSON path, such as $.items[0].quantity |
The target is empty for failures that apply to the entire request body. It can also be empty when Cloudflare cannot safely report a target.
Customers with API Security already have access to Schema Profiles through Schema Learning and Schema Validation. Cloudflare is opening a closed beta to invited Enterprise customers without API Security. Interested customers can contact their account team to express interest. Closed-beta access does not imply future plan availability or pricing.
Cloudflare evaluates requests after the corresponding profile becomes available. The profile must apply to the request operation.
Requests without an applicable profile have Not evaluated status.
For request statuses and investigation steps, refer to Analyze profile detections.