---
description: Understand core Cloudflare concepts, set up your account, manage domains, and configure essential platform settings.
title: Cloudflare Fundamentals
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare Fundamentals

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare is one of the world's largest [connectivity cloud networks ↗](https://blog.cloudflare.com/welcome-to-connectivity-cloud). Today, anyone with an Internet presence can have faster and more secure websites and applications thanks to Cloudflare. This includes bloggers, businesses, and even non-profits.

Millions of Internet properties are on Cloudflare, and our network is growing by tens of thousands each day. Cloudflare powers Internet requests for millions of websites and serves 55 million HTTP requests per second on average.

Before you get started, we recommend reviewing [Concepts](https://developers.cloudflare.com/fundamentals/concepts/) to learn about key concepts related to using different Cloudflare products.

## Additional resources

Refer to the list below for additional Cloudflare resources.

- [Cloudflare blog ↗](https://blog.cloudflare.com)
- [Cloudflare's Go library ↗](https://github.com/cloudflare/cloudflare-go)
- [Cloudflare system status ↗](https://www.cloudflarestatus.com/)
- [Cloudflare Radar ↗](https://radar.cloudflare.com)
- [Cloudflare TV ↗](https://cloudflare.tv/schedule)
- [Terraform ↗](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/#page","headline":"Cloudflare Fundamentals","description":"Understand core Cloudflare concepts, set up your account, manage domains, and configure essential platform settings.","url":"https://developers.cloudflare.com/fundamentals/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Create a Cloudflare account, set up member permissions, and explore the Build, Protect &amp; Connect, and Network services available to you.
title: Get started
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Get started

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/get-started/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Before you can begin using Cloudflare products, first [create an account](https://developers.cloudflare.com/fundamentals/account/create-account/). If multiple people manage your Cloudflare account, [set up member permissions](https://developers.cloudflare.com/fundamentals/manage-members/) to control which resources each person can access.

## Learn about Cloudflare's offerings

### Build

**Build** is where developers create and deploy simple sites and full-stack applications on the [Workers compute platform](https://developers.cloudflare.com/workers/), and connect them to storage and database primitives like [KV](https://developers.cloudflare.com/kv/) (key-value data store), [D1](https://developers.cloudflare.com/d1/) (SQL database), [R2](https://developers.cloudflare.com/r2/) (object storage), [Queues](https://developers.cloudflare.com/queues/) (asynchronous messaging), [Durable Objects](https://developers.cloudflare.com/durable-objects/) (stateful coordination), and more.

Our compute, orchestration, AI, storage, media, and security services are integrated, so you can quickly extend existing apps or launch new ones while Cloudflare's global network takes care of infrastructure, scaling, and performance for you.

### Protect & Connect

**Protect & Connect** is where you establish fast and reliable connections between your websites, apps, and users, while protecting them from attackers and unwanted traffic.

Application security and performance focuses on resources available on the public Internet. Manage delivery performance by controlling and speeding up primarily [Layer 7 (Application) traffic](https://developers.cloudflare.com/fundamentals/reference/network-layers/), in addition to managing media such as video and images. Get started by [onboarding a domain](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/).

Zero Trust protects private, internal users/devices and the resources they access. [Get started with Zero Trust](https://developers.cloudflare.com/cloudflare-one/setup/).

Network services extend protection and acceleration to cloud, on-premise, or hybrid networks, and you can also manage network connections and optimize Layer 3 (Network) and 4 (Transport) traffic. Get started with [Magic Transit](https://developers.cloudflare.com/magic-transit/) or [Cloudflare WAN](https://developers.cloudflare.com/cloudflare-wan/) (formerly Magic WAN).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/get-started/#page","headline":"Get started","description":"Create a Cloudflare account, set up member permissions, and explore the Build, Protect & Connect, and Network services available to you.","url":"https://developers.cloudflare.com/fundamentals/get-started/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Manage multiple Cloudflare accounts from a single organization with centralized access control and audit logs.
title: Organizations
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Organizations

Last updated Aug 27, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

An Organization is a top-level container in Cloudflare for managing multiple accounts. It allows administrators to govern accounts, members, and resources from a single location rather than managing each account individually. Organization Super Administrators have implicit access to all accounts within the Organization. This means they do not need explicit membership on each account.

Note

Cloudflare Organizations is currently in public beta. Organizations is actively used in production by Enterprise and MSSP/Distributor customers. Review [current limitations](https://developers.cloudflare.com/fundamentals/organizations/limitations/) before getting started.

## Who is this for?

Organizations is available to **Enterprise customers of any size** and **MSSP/Distributor partners** who manage multiple Cloudflare accounts. Whether you have 5 accounts or 500, Organizations helps you manage them from one dashboard.

Organizations supports two customer types, each with a different structure:

- **[Enterprise Organizations](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/)**: A single-tier structure for businesses managing their own accounts. One Organization contains multiple accounts directly.
- **[MSSP/Distributor Organizations](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/)**: A multi-tier structure for channel partners and managed security service providers (MSSPs). A Distributor Organization contains child MSSP Organizations, each managing their own customer accounts.

Organization type is set at creation and cannot be changed.

### Enterprise hierarchy

```plaintext
Organization
├── Account 1
│   ├── Zone A
│   └── Zone B
├── Account 2
│   ├── Zone C
│   └── Zone D
└── Account 3
    └── Zone E
```

### MSSP/Distributor hierarchy

```plaintext
Distributor Organization
├── MSSP Organization A
│   ├── Sub-Organization A1
│   │   ├── Customer Account 1
│   │   │   ├── Zone A
│   │   │   └── Zone B
│   │   └── Customer Account 2
│   │       └── Zone C
│   └── Customer Account 3
│       └── Zone D
└── MSSP Organization B
    ├── Customer Account 4
    │   └── Zone E
    └── Customer Account 5
        └── Zone F
```

MSSP/Distributor Organizations support up to 5 levels of nested sub-organizations.

## Core features

- **Centralized account management**: Manage all accounts from a single dashboard.
- **Implicit access**: Organization Super Administrators can access any account in the Organization without requiring explicit per-account membership.
- **Aggregate analytics**: View, filter, and download aggregate HTTP analytics across all Organization child accounts.
- **Organization-level membership**: Invite members to the Organization once, granting them access to all child accounts.
- **WAF and Gateway policy sharing**: Create security policies once and share them across accounts in your Organization.
- **IdP federation**: Share a single identity provider configuration across all accounts in your Organization. Refer to [IdP federation](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/idp-federation/) for setup details.
- **API, SDK, and Terraform support**: Manage Organizations programmatically with the [Cloudflare Organizations API](https://developers.cloudflare.com/api/resources/organizations/), SDKs, or Terraform provider. User API Tokens support some Organization operations, but they cannot complete the full Terraform resource lifecycle. Refer to [API authentication](https://developers.cloudflare.com/fundamentals/organizations/limitations/#api-authentication).
- **Enhanced account switcher**: Navigate between accounts with an Organization-aware account switcher in the dashboard.

For a full list of features and limitations specific to each Organization type, refer to the [Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/) or [MSSP/Distributor](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/) guide.

---

- [Organizations for Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/)
- [Organizations for MSSP and Distributors](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/)
- [Policy sharing](https://developers.cloudflare.com/fundamentals/organizations/policy-sharing/)
- [Limitations and troubleshooting](https://developers.cloudflare.com/fundamentals/organizations/limitations/)
- [Set up](https://developers.cloudflare.com/fundamentals/organizations/setup/)
- [Manage members](https://developers.cloudflare.com/fundamentals/organizations/manage-members/)
- [Manage organizations](https://developers.cloudflare.com/fundamentals/organizations/manage-organization/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/organizations/#page","headline":"Organizations","description":"Manage multiple Cloudflare accounts from a single organization with centralized access control and audit logs.","url":"https://developers.cloudflare.com/fundamentals/organizations/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-27","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Set up and manage an Enterprise Organization to manage multiple Cloudflare accounts from a single dashboard.
title: Organizations for Enterprise
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Organizations for Enterprise

Last updated Sep 17, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

Cloudflare Organizations is currently in public beta. Organizations is actively used in production by Enterprise and MSSP/Distributor customers. Review [current limitations](https://developers.cloudflare.com/fundamentals/organizations/limitations/) before getting started.

Organizations provides a single-tier structure for Enterprise customers to manage multiple Cloudflare accounts from one unified dashboard.

## Who is this for?

Organizations is designed for **Enterprise customers of any size** who manage multiple Cloudflare accounts. Whether you have 5 accounts or 500, Organizations helps you manage them from one dashboard.

Common use cases:

- Multi-brand companies managing separate accounts per brand
- Regional operations with accounts per geography
- Business units or subsidiaries with independent accounts
- Development workflows with separate accounts per environment
- Growing companies consolidating account management

Looking for MSSP (Managed Security Service Provider) or Distributor documentation? Refer to [Organizations for MSSP and Distributors](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/).

## Hierarchy structure

Enterprise Organizations use a **single-tier structure**:

```plaintext
Organization
├── Account 1
│   ├── Zone A
│   └── Zone B
├── Account 2
│   ├── Zone C
│   └── Zone D
└── Account 3
    └── Zone E
```

**Key characteristics:**

- One Organization contains multiple accounts
- Each account can contain multiple zones
- All accounts are at the same level (no sub-organizations)
- Organization members have [implicit access](#implicit-access) to all accounts
- Maximum: **500 accounts** and **5,000 zones** per Organization

## Example: Company A

**Company A** is a SaaS company with 12 Cloudflare accounts:

- 3 accounts for different product lines (Product Alpha, Product Beta, Product Gamma)
- 3 environments per product (Development, Staging, Production)
- Each account manages its own zones and configurations

**Before Organizations:**

- Security team manually copies WAF rules to all 12 accounts
- Admins switch between accounts individually
- No unified view of traffic or security events
- Each new admin needs explicit access to all 12 accounts

**With Organizations:**

- Create one Organization containing all 12 accounts
- Security team creates WAF rules once, shares to all production accounts
- Admins see all accounts in one dashboard with the enhanced account switcher
- View aggregate HTTP analytics across all accounts
- New Organization members automatically get access to all 12 accounts
- Use tags to organize accounts by product line and environment

## Set up your Organization

### Prerequisites

Before you create an Organization:

- Your user must have Super Admin role access to an account with an Enterprise plan.
- You (the Organization creator) must have [two-factor authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) or [single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) enabled on your Cloudflare user account. This is a per-user requirement — 2FA/SSO is not an account-level setting.
- You must be a Super Administrator on the accounts you want to assign. You can add accounts of any plan type (eg Enterprise, or Free).
- Each Organization supports a maximum of **500 accounts** and **5,000 zones**. Refer to [Limitations](https://developers.cloudflare.com/fundamentals/organizations/limitations/) for details.
- You may only create a single Organization. You, or another member of your company, must not have already created an Organization.
- Your accounts must not already belong to another Organization.

### Create an Organization

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com).
2. Select **Organizations**.
3. Select **Create organization**.
4. Enter a name for the Organization.
5. Select **Create**.

The Organization overview page displays after creation.

### Assign accounts

After creating an Organization, you can assign existing accounts to manage them centrally. You can add accounts of any plan type (eg Enterprise, or Free) as long as you are a Super Administrator of the account.

1. From the Organization overview, select **Assign an account**.
2. Search for an account name. Only accounts where you are a Super Administrator will appear.
3. Select the account.
4. Select **Assign to organization**.

The assigned account now appears on the Organization overview page. From here, you can view the account, copy its ID, or rename it.

To remove an account from your Organization, contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/).

### Create new accounts

Organization Super Administrators can create up to five Free accounts within an Enterprise Organization.

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and go to **Accounts**. [Go to **Accounts** ↗](https://dash.cloudflare.com/)
2. Select **Create Account**.
3. Enter an account name.
4. For **Organization**, select the destination Organization.
5. Select **Create Account**.

The new account starts on the Free plan. It does not inherit payment methods, plans, subscriptions, or entitlements from the Organization.

API tokens and OAuth access tokens cannot create accounts within an Organization.

## Manage members

### Organization Super Administrator

When you create an Organization, you become the Organization Super Administrator. This role provides [implicit access](#implicit-access) to all accounts in your Organization and allows you to manage memberships at the Organization level.

Note

Organization Super Administrator is the only Organization-level role available today. All Organization members have the same level of access. Additional roles (read-only, billing, audit log) will be available in a future release.

Note

Any Organization Super Administrator can add or remove other Organization Super Administrators at any time.

### Implicit access

Organization members receive **implicit access** to all accounts in the Organization. Implicit access means:

- You do not need explicit membership on each individual account.
- When you go to any account within your Organization, you automatically have Super Administrator permissions on that account.
- Implicit access is granted at the Organization level — you cannot grant implicit access to a subset of accounts.
- Implicit access is equivalent to Super Administrator. There is no read-only implicit access today.

Implicit access is separate from any existing per-account membership. If you were already an explicit member of an account before it was added to the Organization, that existing membership is unaffected.

### Invite members

You can invite additional members to your Organization. Invited members receive implicit Super Administrator access to all accounts in the Organization.

1. From the Organization overview, select **Members**.
2. Select **Invite member**.
3. Enter the email address.
4. Select **Send invitation**.

The user receives an email invitation. After accepting, they have implicit access to all accounts in the Organization.

### Member authentication requirements

All users who will be Organization members must have [two-factor authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) or [single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) enabled on their Cloudflare user account **before** they can accept an Organization invitation. This is a per-user requirement, not an account-level setting.

- If a user does not have 2FA or SSO enabled, they will not be able to accept the invitation.
- Ask the user to enable 2FA or SSO first, then resend the invitation.
- For instructions on enabling 2FA, refer to [Set up 2FA](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/).
- For SSO configuration, refer to [Dashboard SSO](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/).

## Share policies

Organizations allows you to share WAF custom rulesets and Zero Trust Gateway policies (DNS, Network, HTTP, Resolver) across accounts in your Organization. Shared policies are read-only in receiving accounts and automatically stay in sync when updated in the source account.

Organizations also supports [IdP federation](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/idp-federation/), which lets you configure a single identity provider (such as Okta or Entra ID) in one account and share it across all accounts in your Organization. Shared IdP connections are read-only in recipient accounts and are automatically provisioned or removed as accounts join or leave the Organization.

For detailed instructions, refer to [Policy sharing](https://developers.cloudflare.com/fundamentals/organizations/policy-sharing/).

Note

Policy sharing requires the appropriate entitlements. Organizations does not grant access to WAF or Gateway features — your accounts must already have the required Enterprise WAF or Zero Trust Gateway SKUs.

## View aggregate analytics

You can view, filter, and download aggregate HTTP analytics across all accounts in your Organization:

1. From the Organization overview, select **Analytics & Logs**.
2. Use filters to narrow results by date range, account, domain, or other criteria.
3. To export data, select **Download**.

The data includes traffic for proxied hostnames and may be based on a sample. This data does not reflect billable usage.

## Manage your Organization

### Rename your Organization

1. Go to **Organizations** > **Manage Organization**.
2. Next to **Organization name**, select **Rename**.
3. Enter the new name.
4. Select **Rename**.

### Edit customer identification data

1. Go to **Organizations** > **Manage Organization**.
2. Next to **Customer identification data**, select **Edit**.
3. Update the information.
4. Select **Save**.

### View audit logs

Organization audit logs capture user-initiated actions performed by Organization Super Administrators through Organization-level APIs and the dashboard. These logs are separate from account-level audit logs — actions performed within a specific account continue to appear in that account's audit logs.

To view Organization audit logs in the dashboard:

1. Go to **Organizations** > **Manage Organization**.
2. Select **Audit Logs**.

You can also retrieve Organization audit logs via the API:

```bash
GET https://api.cloudflare.com/client/v4/organizations/{organization_id}/logs/audit
```

If you are viewing account-level audit logs and the account belongs to an Organization where you are an Organization Super Administrator, you can select **View Organization Audit Logs** to go to the parent Organization's audit logs.

For more details on audit log structure, filtering, and retention, refer to [Audit Logs — Organization Activity Logs](https://developers.cloudflare.com/fundamentals/account/account-security/audit-logs/#organization-activity-logs).

### API

You can manage Organizations programmatically using the [Cloudflare Organizations API](https://developers.cloudflare.com/api/resources/organizations/). The API supports creating, updating, deleting Organizations, managing members, and assigning accounts.

### Terraform

You can manage Organizations using the [Cloudflare Terraform provider ↗](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs/resources/organization).

Note

To manage Organization resources through their full Terraform lifecycle, configure the provider with a [Global API key](https://developers.cloudflare.com/fundamentals/api/get-started/keys/) and the registered account email. User API Tokens support only some Organization operations. Refer to [API authentication](https://developers.cloudflare.com/fundamentals/organizations/limitations/#api-authentication).

## What you cannot do

### Create sub-organizations

Enterprise Organizations use a flat structure. You cannot create sub-organizations or nested containers. Use **tags** to organize accounts by business unit, region, or environment.

### Move accounts

Accounts cannot be moved between Enterprise Organizations.

If you encounter errors during setup, refer to [Troubleshooting](https://developers.cloudflare.com/fundamentals/organizations/limitations/#troubleshooting).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/#page","headline":"Organizations for Enterprise","description":"Set up and manage an Enterprise Organization to manage multiple Cloudflare accounts from a single dashboard.","url":"https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-17","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Set up and manage an MSSP or Distributor Organization to manage customer accounts and partner sub-organizations.
title: Organizations for MSSP and Distributors
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Organizations for MSSP and Distributors

Last updated Sep 17, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

Cloudflare Organizations is currently in public beta. Organizations is actively used in production by Enterprise and MSSP/Distributor customers. Review [current limitations](https://developers.cloudflare.com/fundamentals/organizations/limitations/) before getting started.

Organizations provides a multi-tier structure for MSSP (Managed Security Service Provider) and Distributor partners to manage customer accounts and create child partner Organizations.

## Who is this for?

Organizations for MSSP and Distributors is designed for:

- **Distributors** managing multiple MSSP partner Organizations
- **MSSPs** managing multiple end-customer accounts
- **Channel partners** providing managed Cloudflare services

Looking for Enterprise documentation? Refer to [Organizations for Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/).

## Hierarchy structure

MSSP/Distributor Organizations use a **multi-tier structure**:

```plaintext
Distributor Organization
├── MSSP Organization A
│   ├── Sub-Organization A1
│   │   ├── Customer Account 1
│   │   │   ├── Zone A
│   │   │   └── Zone B
│   │   └── Customer Account 2
│   │       └── Zone C
│   └── Customer Account 3
│       └── Zone D
├── MSSP Organization B
│   ├── Customer Account 4
│   │   └── Zone E
│   └── Customer Account 5
│       └── Zone F
└── MSSP Organization C
    └── Sub-Organization C1
        └── Customer Account 6
            └── Zone G
```

**Key characteristics:**

- Distributors create and manage child MSSP Organizations
- MSSP Organizations can create up to 5 levels of nested sub-organizations
- Each MSSP Organization manages its own customer accounts
- MSSP Organization members have [implicit access](#implicit-access) to their customer accounts
- Accounts can be moved between MSSP Organizations
- Maximum: **500 accounts** and **5,000 zones** per Organization

## Example: Distributor A

**Distributor A** is a Cloudflare channel partner with 15 MSSP partners:

- Each MSSP partner manages 5-50 end-customer accounts
- Total: 15 MSSP Organizations, 300+ customer accounts

**Distributor A's structure:**

```plaintext
Distributor A Organization
├── Security MSSP
│   ├── Retail Customer 1 (10 zones)
│   ├── Healthcare Customer 2 (25 zones)
│   └── Finance Customer 3 (40 zones)
├── Web Performance MSSP
│   ├── E-commerce Customer 4 (15 zones)
│   └── Media Customer 5 (30 zones)
└── [13 more MSSP Organizations...]
```

**What Distributor A can do:**

- Create new MSSP Organizations for new partners
- Create customer accounts within each MSSP Organization
- Move customer accounts between MSSP Organizations if ownership changes
- View aggregate analytics across all MSSP Organizations
- Share security policies across MSSP Organizations

**What each MSSP can do:**

- Manage their own customer accounts
- Create new customer accounts for new clients
- Invite MSSP team members with implicit access to all customer accounts
- Share WAF and Gateway policies across their customer accounts
- View aggregate analytics across their customer accounts

## Set up your Organization

MSSP/Distributor Organizations cannot be self-serve created by customers. To get started:

1. Contact your **Cloudflare account team** to request an MSSP or Distributor Organization.
2. Cloudflare will create your Organization and assign the initial Organization Super Administrator.
3. The initial Organization Super Administrator must have [two-factor authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) or [single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) enabled on their Cloudflare user account.
4. Once created, the Organization Super Administrator can begin managing the Organization from the [Cloudflare dashboard ↗](https://dash.cloudflare.com).

Note

Organization type (Enterprise vs MSSP/Distributor) is set at creation and cannot be changed. If you need a different type, a new Organization must be created.

### Create child MSSP Organizations

Distributors can create child MSSP partner Organizations. Each MSSP Organization operates independently and manages its own customer accounts.

### Create new accounts

MSSP Organizations can self-serve create new customer accounts within their Organization. Enterprise Organizations can self-serve create up to five Free accounts within their Organization.

### Move accounts between Organizations

Move customer accounts from one MSSP Organization to another when ownership changes or customers switch providers.

## Manage members

Distributor and MSSP Organization Super Administrators can add and manage Organization members directly from the Cloudflare dashboard. No support ticket is required.

### Organization Super Administrator

When your Organization is created, the initial user becomes the Organization Super Administrator. This role provides [implicit access](#implicit-access) to all accounts in your Organization and allows you to manage memberships at the Organization level.

Note

Organization Super Administrator is the only Organization-level role available today. All Organization members have the same level of access. Additional roles (read-only, billing, audit log) will be available in a future release.

Note

Any Organization Super Administrator can add or remove other Organization Super Administrators at any time.

### Implicit access

Organization members receive **implicit access** to all accounts in the Organization. Implicit access means:

- You do not need explicit membership on each individual account.
- When you go to any account within your Organization, you automatically have Super Administrator permissions on that account.
- Implicit access is granted at the Organization level — you cannot grant implicit access to a subset of accounts.
- Implicit access is equivalent to Super Administrator. There is no read-only implicit access today.
- For Distributor Organizations, implicit access applies within each tier — Distributor admins access all child MSSP Organizations and their accounts.

Implicit access is separate from any existing per-account membership. If a user was already an explicit member of an account before it was added to the Organization, that existing membership is unaffected.

### Invite members

You can invite additional members to your Organization. Invited members receive implicit Super Administrator access to all accounts in the Organization.

1. From the Organization overview, select **Members**.
2. Select **Invite member**.
3. Enter the email address.
4. Select **Send invitation**.

The user receives an email invitation. After accepting, they have implicit access to all accounts in the Organization.

### Member authentication requirements

All users who will be Organization members must have [two-factor authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) or [single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) enabled on their Cloudflare user account **before** they can accept an Organization invitation. This is a per-user requirement, not an account-level setting.

- If a user does not have 2FA or SSO enabled, they will not be able to accept the invitation.
- Ask the user to enable 2FA or SSO first, then resend the invitation.
- For instructions on enabling 2FA, refer to [Set up 2FA](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/).
- For SSO configuration, refer to [Dashboard SSO](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/).

## Share policies

Organizations allows you to share WAF custom rulesets and Zero Trust Gateway policies (DNS, Network, HTTP, Resolver) across accounts in your Organization. Shared policies are read-only in receiving accounts and automatically stay in sync when updated in the source account.

For Distributor Organizations, policies can be shared across MSSP Organization boundaries within the same Distributor Organization.

Organizations also supports [IdP federation](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/idp-federation/), which lets you configure a single identity provider (such as Okta or Entra ID) in one account and share it across all accounts in your Organization. Shared IdP connections are read-only in recipient accounts and are automatically provisioned or removed as accounts join or leave the Organization.

For detailed instructions, refer to [Policy sharing](https://developers.cloudflare.com/fundamentals/organizations/policy-sharing/).

Note

Policy sharing requires the appropriate entitlements. Organizations does not grant access to WAF or Gateway features — your accounts must already have the required Enterprise WAF or Zero Trust Gateway SKUs.

## View aggregate analytics

You can view, filter, and download aggregate HTTP analytics across all accounts in your Organization:

1. From the Organization overview, select **Analytics & Logs**.
2. Use filters to narrow results by date range, account, domain, or other criteria.
3. To export data, select **Download**.

The data includes traffic for proxied hostnames and may be based on a sample. This data does not reflect billable usage.

## Manage your Organization

### Rename your Organization

1. Go to **Organizations** > **Manage Organization**.
2. Next to **Organization name**, select **Rename**.
3. Enter the new name.
4. Select **Rename**.

### Edit customer identification data

1. Go to **Organizations** > **Manage Organization**.
2. Next to **Customer identification data**, select **Edit**.
3. Update the information.
4. Select **Save**.

### View audit logs

Organization audit logs capture user-initiated actions performed by Organization Super Administrators through Organization-level APIs and the dashboard. These logs are separate from account-level audit logs — actions performed within a specific account continue to appear in that account's audit logs.

To view Organization audit logs in the dashboard:

1. Go to **Organizations** > **Manage Organization**.
2. Select **Audit Logs**.

You can also retrieve Organization audit logs via the API:

```bash
GET https://api.cloudflare.com/client/v4/organizations/{organization_id}/logs/audit
```

If you are viewing account-level audit logs and the account belongs to an Organization where you are an Organization Super Administrator, you can select **View Organization Audit Logs** to go to the parent Organization's audit logs.

For more details on audit log structure, filtering, and retention, refer to [Audit Logs — Organization Activity Logs](https://developers.cloudflare.com/fundamentals/account/account-security/audit-logs/#organization-activity-logs).

### API

You can manage Organizations programmatically using the [Cloudflare Organizations API](https://developers.cloudflare.com/api/resources/organizations/). The API supports creating, updating, deleting Organizations, managing members, and assigning accounts.

### Terraform

You can manage Organizations using the [Cloudflare Terraform provider ↗](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs/resources/organization).

Note

To manage Organization resources through their full Terraform lifecycle, configure the provider with a [Global API key](https://developers.cloudflare.com/fundamentals/api/get-started/keys/) and the registered account email. User API Tokens support only some Organization operations. Refer to [API authentication](https://developers.cloudflare.com/fundamentals/organizations/limitations/#api-authentication).

If you encounter errors during setup or management, refer to [Troubleshooting](https://developers.cloudflare.com/fundamentals/organizations/limitations/#troubleshooting).

## What you cannot do (today)

### Assign existing accounts

MSSP/Distributor Organizations cannot assign existing accounts. Use account creation to add new accounts to your Organization.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/#page","headline":"Organizations for MSSP and Distributors","description":"Set up and manage an MSSP or Distributor Organization to manage customer accounts and partner sub-organizations.","url":"https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-17","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the current limitations of Cloudflare Organizations and troubleshoot common errors.
title: Limitations and troubleshooting
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Limitations and troubleshooting

Last updated Sep 17, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/limitations/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

Cloudflare Organizations is currently in public beta. Organizations is actively used in production by Enterprise and MSSP/Distributor customers.

The following limitations currently apply to Cloudflare Organizations. For common errors and resolutions, refer to [Troubleshooting](#troubleshooting).

## Account and zone limits

Each Organization supports a maximum of **500 accounts** and **5,000 zones**. This limit applies to both Enterprise and MSSP/Distributor Organizations. These limits may be adjusted as usage patterns are better understood during the beta.

## API authentication

User API Tokens support some Organization operations. They cannot complete the full Terraform resource lifecycle. Full user API Token support for Organization operations is planned. To manage Organization resources with Terraform, configure the Cloudflare provider with a Global API key and the registered account email.

A user API Token may create an Organization. A later Terraform refresh or `terraform plan` may fail when reading the Organization. If the request returns HTTP `403` with error code `10000`, use a Global API key and the account email instead.

API Tokens remain the preferred authentication method for supported operations. A Global API key has full access to the user's Cloudflare resources. Refer to [Global API key limitations](https://developers.cloudflare.com/fundamentals/api/get-started/keys/#limitations).

## Enterprise Organizations

| Limitation | Description |
| --- | --- |
| Organization creation | You must be a Super Administrator of an Enterprise account to create an Organization. |
| Adding accounts | You can add accounts of any plan type (eg Enterprise, or Free) to your Organization. You must have Super Administrator access to the account, and it cannot already belong to another Organization. |
| Account creation | Organization Super Administrators can create up to five Free accounts within their Organization. API tokens and OAuth access tokens cannot create accounts within an Organization. Refer to [Create new accounts](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/#create-new-accounts). |
| Sub-Organizations | Not available. Enterprise Organizations use a flat, single-tier structure. Use tags to organize accounts by business unit, region, or environment. |
| Moving accounts | Accounts cannot be moved between Organizations. |
| Roles | Organization Super Administrator is the only role available. Additional roles (read-only, billing, audit log) will be available in a future release. |
| Organization deletion | To delete an Organization, use the [API](https://developers.cloudflare.com/api/resources/organizations/methods/delete). Dashboard support is not yet available. |
| Account removal | Self-service account removal is not yet available. To remove an account from your Organization, contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/). |

## MSSP/Distributor Organizations

| Limitation | Description |
| --- | --- |
| Organization creation | MSSP/Distributor Organizations are created by Cloudflare. Contact your account team to set up your Organization. |
| Adding existing accounts | Assigning existing accounts is not available for MSSP/Distributor Organizations. Use account creation to add new accounts. |
| Account creation | MSSP Organizations can self-serve create new customer accounts within their Organization. |
| Sub-Organizations | Distributors can create child MSSP Organizations. MSSP/Distributor Organizations support up to 5 levels of nested sub-organizations. |
| Moving accounts | Accounts can be moved between MSSP Organizations within the same Distributor Organization. |
| Roles | Organization Super Administrator is the only role available. Additional roles (read-only, billing, audit log) will be available in a future release. |
| Organization deletion | To delete an Organization, use the [API](https://developers.cloudflare.com/api/resources/organizations/methods/delete). Dashboard support is not yet available. |
| Account removal | Self-service account removal is not yet available. To remove an account from your Organization, contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/). |
| Organization type conversion | Organization type (Enterprise vs MSSP/Distributor) is set at creation and cannot be changed. To switch types, a new Organization must be created. |

## Troubleshooting

You may encounter the following errors when setting up or managing an Organization.

### Organization creation errors

| Error | Description |
| --- | --- |
| Organization management is only available on the Enterprise plan at this time. | You are not a member of any Enterprise accounts. You must be a Super Administrator of at least one Enterprise account to create an Organization. |
| You need a super admin role on an enterprise account to create an Organization. | You are not a Super Administrator of an Enterprise account. Check your role under **Manage Account** > **Members** on your Enterprise account. |
| One or more of your enterprise accounts is already part of an Organization. | Your accounts are already assigned to an Organization. Contact your company administrator to be invited to the existing Organization. |
| You have reached the maximum number of organizations. | Each user can only create one Organization. If you need to manage a second Organization, contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/). |
| An Organization has already been created for accounts associated with your company. Please contact your company administrator. | Every company is limited to one Organization for all business units. Contact your company's Cloudflare administrator to be invited to the existing Organization. |
| You are not eligible to create an Organization because we think there's a problem. Please contact Cloudflare support and we will help you create it. | This rare error may indicate an issue with the internal metadata for one or more of your accounts. Contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/) with your account ID and the error message. |

### Member invitation errors

| Error | Resolution |
| --- | --- |
| Invited member cannot accept the invitation. | The invited user must have [two-factor authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) or [single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) enabled on their Cloudflare user account before they can accept an Organization invitation. This is a per-user requirement, not an account-level setting. Ask the user to enable 2FA or SSO, then resend the invitation. |
| Member does not have access to accounts after accepting. | Organization membership grants implicit access, which may take a few minutes to propagate. If access does not appear after 5 minutes, ask the member to log out and log back in. |

### Account assignment errors

| Error | Resolution |
| --- | --- |
| Account does not appear in the assignment list. | You must be a Super Administrator of the account. Verify your role under **Manage Account** > **Members** on that account. |
| Account cannot be assigned. | The account may already belong to another Organization. Each account can only belong to one Organization. Contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/) if you believe this is incorrect. |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/organizations/limitations/#page","headline":"Limitations and troubleshooting","description":"Review the current limitations of Cloudflare Organizations and troubleshoot common errors.","url":"https://developers.cloudflare.com/fundamentals/organizations/limitations/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-17","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Manage Organization members — refer to the guide for your Organization type.
title: Manage members
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Manage members

Last updated Jul 13, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/manage-members/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Member management is covered within each Organization type guide:

- **[Organizations for Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/#manage-members)** — Invite members, manage Organization Super Administrators, and understand implicit access for Enterprise Organizations.
- **[Organizations for MSSP and Distributors](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/#manage-members)** — Invite members, manage Organization Super Administrators, and understand implicit access for MSSP/Distributor Organizations.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/organizations/manage-members/#page","headline":"Manage members","description":"Manage Organization members — refer to the guide for your Organization type.","url":"https://developers.cloudflare.com/fundamentals/organizations/manage-members/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-13","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Manage your Cloudflare Organization — refer to the guide for your Organization type.
title: Manage organizations
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Manage organizations

Last updated Jul 13, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/manage-organization/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Organization management (rename, edit settings, Terraform) is covered within each Organization type guide:

- **[Organizations for Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/#manage-your-organization)** — Rename, edit customer identification data, and manage with Terraform for Enterprise Organizations.
- **[Organizations for MSSP and Distributors](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/#manage-your-organization)** — Rename, edit customer identification data, and manage with Terraform for MSSP/Distributor Organizations.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/organizations/manage-organization/#page","headline":"Manage organizations","description":"Manage your Cloudflare Organization — refer to the guide for your Organization type.","url":"https://developers.cloudflare.com/fundamentals/organizations/manage-organization/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-13","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Share WAF and Gateway policies across accounts in your Cloudflare Organization.
title: Policy sharing
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Policy sharing

Last updated Sep 10, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/policy-sharing/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

Cloudflare Organizations is currently in public beta. Organizations is actively used in production by Enterprise and MSSP/Distributor customers. Review [current limitations](https://developers.cloudflare.com/fundamentals/organizations/limitations/) before getting started.

Organizations allows you to create security policies in one account and share them across other accounts in your Organization. This ensures consistent security posture across all accounts without manually duplicating configurations.

Policy sharing works the same way for both [Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/) and [MSSP/Distributor](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/) Organizations.

In addition to WAF and Gateway policies, Organizations supports [IdP federation](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/idp-federation/), which lets you configure a single identity provider (such as Okta or Entra ID) in one account and share it across all accounts in your Organization. Shared IdP connections are read-only in recipient accounts and are automatically provisioned or removed as accounts join or leave the Organization.

## Prerequisites

Policy sharing requires the appropriate product entitlements on the accounts involved. Organizations does not grant access to WAF or Gateway features — your accounts must already have the required SKUs.

- **WAF policy sharing** requires Enterprise WAF entitlements on both the source and destination accounts.
- **Gateway policy sharing** requires Zero Trust Gateway entitlements on both the source and destination accounts.

## WAF policy sharing

Create WAF custom rulesets in one account and share them to other accounts within your Organization.

### How it works

1. Create a WAF custom ruleset in a **source account** — this is the account where you author and manage the rules.
2. Share the ruleset to one or more **destination accounts** within your Organization.
3. The shared ruleset appears in the destination accounts as a **read-only** policy.
4. Changes made to the ruleset in the source account automatically propagate to all destination accounts.

### Key behaviors

- **Read-only in destination accounts**: Shared WAF policies cannot be edited in the receiving accounts. To modify the rules, update them in the source account.
- **Source account owns the policy**: If the source account is removed from the Organization, the shared policy is removed from all destination accounts.
- **No cross-Organization sharing**: Policies can only be shared within a single Organization. You cannot share policies between different Organizations.
- **Multiple rulesets**: You can share multiple WAF custom rulesets from the same or different source accounts.

### Share a WAF custom ruleset

1. In the source account, go to **Security** > **WAF** > **Custom rules**.
2. Create or select a custom ruleset.
3. From the ruleset action menu, select **Share**.
4. In the sharing dialog, select one or more destination accounts.
5. Select **Share**.

The shared ruleset now appears in the destination accounts under their WAF custom rules.

## Gateway policy sharing

Share Zero Trust Gateway policies across accounts in your Organization. Gateway policy sharing supports the following policy types:

- **DNS policies** — Filter and block DNS queries.
- **Network policies** — Control network-level traffic.
- **HTTP policies** — Inspect and filter HTTP traffic.
- **Resolver policies** — Customize DNS resolution behavior.

### How it works

1. Create a Gateway policy in a **source account**.
2. Share the policy to one or more **destination accounts** within your Organization.
3. The shared policy appears in the destination accounts as a **read-only** policy.
4. Changes made to the policy in the source account automatically propagate to all destination accounts.

### Key behaviors

- **Read-only in destination accounts**: Shared Gateway policies cannot be edited in the receiving accounts. To modify the policy, update it in the source account.
- **Source account owns the policy**: If the source account is removed from the Organization, the shared policy is removed from all destination accounts.
- **All Gateway policy types supported**: DNS, Network, HTTP, and Resolver policies can all be shared.
- **Zero Trust seat requirements**: Destination accounts must have their own Zero Trust seats and Gateway entitlements.

## Manage shared policies

### View shared policies

From the Organization overview, you can see which policies are shared and to which accounts. Shared policies are marked with a sharing indicator in the destination account's policy list.

### Remove a shared policy

To stop sharing a policy with a destination account:

1. In the source account, go to the shared policy.
2. Select **Manage sharing**.
3. Remove the destination account from the sharing list.

The policy is immediately removed from the destination account.

### Best practices

- **Centralize policy authoring**: Designate one or two accounts as your policy source accounts. This simplifies management and ensures consistency.
- **Use descriptive names**: Name shared policies clearly (for example, "Org-Wide OWASP Rules" or "Global DNS Block List") so destination account admins understand what the policy does.
- **Test before sharing**: Validate policies in the source account before sharing to all destination accounts to avoid unintended blocks or rule conflicts.
- **Monitor shared policy coverage**: Regularly review which accounts have shared policies applied to ensure no accounts are missing critical security rules.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/organizations/policy-sharing/#page","headline":"Policy sharing","description":"Share WAF and Gateway policies across accounts in your Cloudflare Organization.","url":"https://developers.cloudflare.com/fundamentals/organizations/policy-sharing/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-10","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Get started with Cloudflare Organizations — choose the guide for your Organization type.
title: Set up
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Set up

Last updated Jul 13, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/organizations/setup/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Organizations setup varies depending on your Organization type. Choose the guide that matches your use case:

- **[Organizations for Enterprise](https://developers.cloudflare.com/fundamentals/organizations/for-enterprise/)** — For Enterprise customers managing their own accounts. Includes self-serve Organization creation, account assignment, and member management.
- **[Organizations for MSSP and Distributors](https://developers.cloudflare.com/fundamentals/organizations/for-mssp-distributors/)** — For MSSP and Distributor partners managing customer accounts and child Organizations. Includes account creation, sub-org management, and account movement.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/organizations/setup/#page","headline":"Set up","description":"Get started with Cloudflare Organizations — choose the guide for your Organization type.","url":"https://developers.cloudflare.com/fundamentals/organizations/setup/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-13","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Add members to your Cloudflare account and assign roles, scopes, and policies to control their access.
title: Members and permissions
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Members and permissions

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

On any Cloudflare account, you can collaborate by adding members to your account and assigning them access via one or several policies.

Configuring permissions for each member helps prevent accidental changes to your account. For example, you can scope a team member to only manage staging domains, so they do not accidentally modify a production site. Use policies to grant each member the minimum level of access they need.

Every policy has three parts:

1. The actor
2. The role
3. The scope

Refer to the resources below to configure policies to ensure that you can assign only the necessary access permissions to your account members.

## Resources

- [Manage](https://developers.cloudflare.com/fundamentals/manage-members/manage/)
- [Policies](https://developers.cloudflare.com/fundamentals/manage-members/policies/)
- [Roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/)
- [Role scopes](https://developers.cloudflare.com/fundamentals/manage-members/scope/)
- [User Groups](https://developers.cloudflare.com/fundamentals/manage-members/user-groups/)
- [Set up dashboard SSO](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/manage-members/#page","headline":"Members and permissions","description":"Add members to your Cloudflare account and assign roles, scopes, and policies to control their access.","url":"https://developers.cloudflare.com/fundamentals/manage-members/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Configure single sign-on (SSO) for the Cloudflare dashboard using your identity provider to enforce authenticated access for your email domain.
title: Set up dashboard SSO
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Set up dashboard SSO

Last updated Aug 14, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers single sign-on (SSO) for all customers who log in with a custom email domain. By creating a Cloudflare SSO connector, you can enforce SSO to the Cloudflare dashboard with the identity provider (IdP) of your choice. SSO will be enforced for every user in your email domain.

## Availability

Cloudflare Dashboard SSO is available for free to all plans.

|  | Free | Pro | Business | Enterprise |
| --- | --- | --- | --- | --- |
| Availability | Yes | Yes | Yes | Yes |

## Prerequisites

1. You must control your email domain and be able to add a TXT record to verify this.
   - Public email providers such as `@gmail.com` are not allowed.
   - Every user with that email domain must be an employee in your organization. For example, university domains such as `@harvard.edu` are not allowed because they include student emails.
2. You must be a super administrator and be able to access the Cloudflare API.
3. A Cloudflare Zero Trust organization with any subscription tier (including Free) must be created. To set up a Cloudflare Zero Trust organization, refer to [Create a Cloudflare Zero Trust organization](https://developers.cloudflare.com/cloudflare-one/setup/#2-create-a-zero-trust-organization).

## 1. Set up an IdP

Add an IdP to Cloudflare Zero Trust by following [our detailed instructions](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/).

Once you configure your IdP, make sure you also [test your IdP](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/#test-idps-in-cloudflare-one).

## 2. Register your domain with Cloudflare for SSO

Caution

You must create an [Account API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) with the role `SSO Connector Edit` and store it securely. This acts as a backup plan, allowing you to disable SSO via the API if you are accidentally locked out, such as due to changes in your IdP configuration later.

1. Once you have configured an IdP in Cloudflare One, go to the **Members** page to manage SSO connectors.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. If step 1 was successful, a button to add a new SSO domain will be present. Select the button to begin the process of adding a new SSO domain.

![Screenshot of the SSO connector create modal](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=634,height=305,format=webp/_astro/create_modal.UuyGmCgI.png)

3. Enter your email domain and select **Create** to move to the verification step.

Note

Some top level domains, such as `.edu`, are prohibited from being used as SSO domains.

Using a command line terminal where you have already set the environment variable `CLOUDFLARE_API_TOKEN` to a user or account API token which has the `SSO Connector Edit` permission, run the following command to create an SSO connector. Replace `{account_id}` with your account ID, and `{domain}` with your email domain.

*cURL commandbash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors" \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --json '{"email_domain":"{domain}"}'
```

```json
{
	"success": true,
	"errors": [],
	"messages": [],
	"result": {
		"id": "c3ebcba5c20b42f73e111110d0be67d",
		"enabled": false,
		"email_domain": "cool.cats",
		"verification": {
			"code": "cloudflare_dashboard_sso=111111111",
			"status": "pending"
		},
		"created_on": "2025-09-05T20:35:34Z"
	}
}
```

## 3. Verify domain ownership

If you are unable to change your DNS records right away, the option to verify later is available. The verification process can be manually triggered from the actions menu for that connector in the list.

![Screenshot of the SSO connector create modal](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=636,height=388,format=webp/_astro/verify_modal.DVxZpDs_.png)

Copy the verification code and create a TXT record in your DNS configuration with that value. The record must include all of the text including the `cloudflare_dashboard_sso=` prefix.

Cloudflare will automatically poll this DNS record until it is found or a timeout is reached within two days.

If the verification process fails due to timeout, you can manually reinitiate the polling by selecting **Begin verification** in the actions menu for that connector in the list.

Copy the verification code (for example `cloudflare_dashboard_sso=1111111`) and create a `TXT` record in your DNS configuration with that value. To test that the DNS record was correctly configured, you can use the `dig` command to query your email domain:

```sh
dig cool.cats TXT +short
```

```sh
"cloudflare_dashboard_sso=111111111"
```

The `TXT` record must include the `cloudflare_dashboard_sso=` prefix along with the numerical code.

Cloudflare will automatically poll this DNS record until it is found or a timeout is reached within two days. If verification fails due to timeout, you may manually reinitiate the polling by running the following command:

*cURL commandbash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{sso_connector_id}/begin_verification" \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

Once the verification process has completed or timed out, you will receive an email notification with the verification result.

## 4. Enable dashboard SSO

Caution

Enabling Cloudflare Dashboard SSO for an email domain (for example, `@mycompany.com`) will apply globally to all users with that domain, regardless of which accounts those users have access to. All users will be required to authenticate via the specified identity provider, including users registered on Cloudflare prior to the domain being configured for SSO.

Once the verification process has completed and successfully verified domain ownership, you may enable the connector.

Domains that are associated with an already enabled connector belonging to a different account may not be enabled on a new account until disabled on the old account.

Enable the connector by selecting **Enable** in the Actions menu for that connector in the list.

![Screenshot of the SSO connector enable button](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1226,height=203,format=webp/_astro/verified_domain.B1SGjH_l.png)

Enable the connector by running the following — again, replacing the `{account_id}` value with your account ID, and additionally replacing the `{sso_connector_id}` with the value you obtained from the `id` field in the response to the previous call.

*cURL commandbash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{sso_connector_id}" \
  --request PATCH \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --json '{"enabled": true}'
```

## Test your IdP before enforcement

Before enabling SSO for your domain, verify that your identity provider is configured correctly:

1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Integrations** > **Identity providers**.
2. Find your IdP and select **Test**.
3. Confirm that the test returns a successful authentication result.

If the test fails, review your IdP configuration against the [identity provider setup instructions](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/) before enabling the SSO connector.

### Troubleshoot IdP errors

If you encounter errors during IdP setup or testing, provide the following when [contacting support](https://developers.cloudflare.com/support/contacting-cloudflare-support/):

1. The error message returned by the IdP test.
2. A sanitized [HAR file](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#generate-a-har-file) captured while running the IdP test from the dashboard.

## Limitations

Cloudflare dashboard SSO does not support:

- Users with plus-addressed emails, such as `example+2@domain.com`. If you have users like this added to your Cloudflare organization, they will be unable to login with SSO.
- Adding a separate email-based policy to the Zero Trust SSO application that does not match your SSO domain policy.
- Multiple Zero Trust domain policies. If another domain policy is required, you can create another SSO connector. This will create a second policy for that new domain in your SSO application.
- Deleting the auto-generated Zero Trust `allow email domain` policy. If this policy is deleted, your organization's administrators cannot access the Cloudflare dashboard.

## IdP-initiated SSO

IdP-initiated login is supported for Cloudflare dashboard SSO, with configuration available via your identity provider (IdP).

A step-by-step guide is currently available for Okta, and similar configurations are possible with other identity providers that support custom SSO endpoints.

### Okta

Configure an identity provider (IdP)-initiated single sign-on (SSO) session using Cloudflare Zero Trust and Okta.

#### Prerequisites

1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Access controls** > **Applications** > select your **SSO App**.
2. Select **Configure** to access the application settings.
3. In the **Basic Information** section, copy the **SSO Endpoint URL** and **Access Entity ID or Issuer**. You will need these values for your IdP setup.

#### Configure Okta as the IdP

1. Log in to your [Okta Admin Dashboard ↗](https://login.okta.com/) and go to **Applications** > **Applications**.
2. Select **Create App Integration** to start a new SAML integration to handle the IdP-initiated SSO flow. Note that this is a second, distinct Cloudflare-Okta integration, created separately from the [IdP integration with Zero Trust](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/).
3. In the pop-up, select **SAML 2.0** and select **Next**.
4. Enter a name for the app and select **Next**.
5. In the **Single Sign-On URL** field, paste the **SSO Endpoint URL** [you copied earlier](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#prerequisites-1).
6. In the **Audience URI (SP Entity ID)** field, paste the **Access Entity ID or Issuer** [you copied earlier](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#prerequisites-1).
7. Set the **Name ID Format** to **EmailAddress**.
8. Set the **Application Username** to **Email**.
9. Select **Next** > **Finish** to save the integration.
10. Test the integration by going to your Okta User Dashboard, locating the new app tile, and selecting it to verify the SSO flow.

**(Optional) Enforce single IdP login with instant authentication**

If you use only one IdP (for example, Okta) for Cloudflare SSO and want users to skip the identity provider selection prompt:

1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Access controls** > **Applications** > select your **SSO App**.
2. Go to **Authentication**.
3. Disable **Accept all available identity providers** and ensure only Okta is selected as the login method.
4. Enable **Apply instant authentication** to allow users to skip identity provider selection.

## Bypass dashboard SSO

This section describes how to restore access to the Cloudflare dashboard in case you are unable to login with SSO.

### Option 1: Add a backup IdP

If there is an issue with your SSO IdP provider, you can add an alternate IdP using the API. The following example shows how to add [Cloudflare One-time PIN](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/one-time-pin/) as a login method:

1. [Add](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/create/) one-time PIN login:<details><summary>

   Required API token permissions</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:
   - <code>Access: Organizations, Identity Providers, and Groups Write</code></details>

   *Add an Access identity providerbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/identity_providers" \
   	--request POST \
   	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
   	--json '{
   		"type": "onetimepin",
   		"config": {}
   	}'
   ```


2. [Get](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/list/) the `id` of the `dash_sso` Access application. You can use [`jq` ↗](https://jqlang.github.io/jq/download/) to quickly find the correct application:

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps" \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     | jq '.result[] | select(.type == "dash_sso")'
   ```



```txt
   {
   	"id": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   	"uid": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   	"type": "dash_sso",
   	"name": "SSO App"
   	// ...
   }
```

3. Using the `id` obtained above, [update](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/update/) **SSO App** to accept all identity providers. To avoid overwriting your existing configuration, the PUT request body should contain all fields returned by the previous GET request.<details><summary>

   Required API token permissions</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:
   - <code>Access: Apps and Policies Write</code></details>

   *Update an Access applicationbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps/3537a672-e4d8-4d89-aab9-26cb622918a1" \
   	--request PUT \
   	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
   	--json '{
   		"id": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   		"uid": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   		"type": "dash_sso",
   		"name": "SSO App",
   		"allowed_idps": []
   	}'
   ```



Users will now have the option to log in using a one-time PIN.

### Option 2: Disable dashboard SSO

Caution

Before disabling SSO, make sure you have access to your Cloudflare user email. This will allow you to reset your password in case you get logged out of the Cloudflare dashboard.

1. Navigate to the **Members** page.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. Go to **Settings**.
3. Select the actions menu for the SSO connector in the list and select **Disable**.
4. Type the domain of the connector and click confirm to complete the disable action.

The following API calls will disable SSO enforcement for an account. This action can only be performed by API tokens with the `SSO connectors edit` role or Super Administrators.

1. Get your SSO connector `id`:

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors" \
     --request GET \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
   ```



```txt
   {
   	"result": [
   		{
   			"id": "d616ac82cc7f87153112d75a711c5c3c",
   			"email_domain": "cool.cats",
   			"enabled": true
   			// ...
   		}
   	],
   	"success": true,
   	"errors": [],
   	"messages": []
   }
```

2. Disable the SSO connector:

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{connector_id}" \
     --request PATCH \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     --json '{
       "enabled": false
     }'
   ```



```txt
   {
   	"result": [
   		{
   			"id": "d616ac82cc7f87153112d75a711c5c3c",
   			"email_domain": "cool.cats",
   			"enabled": false
   			// ...
   		}
   	],
   	"success": true,
   	"errors": [],
   	"messages": []
   }
```

Users can now log in using their Cloudflare account email and password. If a user does not have a password, they can use the [forgot password](https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/#forgot-your-password) method on the login page to create one.

## Change your Zero Trust team name

Cloudflare does not allow you to change your team name while a SSO connector is created. To change your team name, you must disable and delete your SSO connector(s).

1. Navigate to the **Members** page.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. Go to **Settings**.
3. Disable all SSO connectors.
4. Delete all SSO connectors.

1. Get all SSO connectors for your account.

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors" \
     --request GET \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
   ```


2. Disable any active SSO connectors using the `id` of each connector from the previous step.

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{connector_id}" \
     --request PATCH \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     --json '{
       "enabled": false
     }'
   ```


3. Delete all SSO connectors using the `id` of each connector from the previous step.

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{connector_id}" \
     --request DELETE \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
   ```



4. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Reusable components** > **Custom pages**.
5. Under **Team domain**, select **Edit** to enter the new team name. Select **Save**.
6. In your identity provider, update your Cloudflare integration with the new team name. For example, if you are using a SAML IdP, you will need to update the Single Sign-on URL and Entity ID to `https://<new-team-name>.cloudflareaccess.com/cdn-cgi/access/callback`.
7. Recreate any deleted SSO connectors using the steps in [Register your domain with Cloudflare for SSO](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#2-register-your-domain-with-cloudflare-for-sso).
8. Follow the verification and enable steps after recreating the SSO connectors.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#page","headline":"Set up dashboard SSO","description":"Configure single sign-on (SSO) for the Cloudflare dashboard using your identity provider to enforce authenticated access for your email domain.","url":"https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"},"keywords":["SSO"]}
```

---

---
description: Add, edit, and remove Cloudflare account members and their permission policies.
title: Manage
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Manage

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/manage/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Granting access to others on your account is done with several sets of data principles:

1. Accounts have Account Members.
2. Account Members have policies.
3. Policies are constructed out of actors, roles, and scopes.

When assigning a new user, you can assign a policy to them directly. If multiple policies are needed, they can be added or revoked at a later time.

Learn how to add new account members, edit or revoke their access, and resend verification emails.

Note

To manage account members, you must have a role of **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

## View account members

To manage account members, you must have a role of **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

To view members using the dashboard:

In the \[Cloudflare dashboard, go to the **Members** page.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

To view members using the API, send a [`GET` request](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/list/).

## Add account members

To manage account members, you must have a role of **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

To add a member to your account:

1. In the Cloudflare dashboard, go to the **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Select **Invite**.
3. Fill out the following information:
   - **Invite members**: Enter one or more email addresses (if multiple, separate addresses with commas).
   - **Scope**: Use a variety of fields to adjust the [scope](https://developers.cloudflare.com/fundamentals/manage-members/roles/) of your roles.
   - **Roles**: Choose one or more [roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/) to assign your members.
4. Select **Continue to summary**.
5. Review the information, then select **Invite**.

Note

If a user already has an account with Cloudflare and you have an Enterprise account, you can also select **Skip email confirmation** to add them to your account without sending an email invitation.

To add a member using the API, send a [`POST` request](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/create/).

## Edit member permissions

To manage account members, you must have a role of **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

To edit member permissions using the dashboard:

1. In the Cloudflare dashboard, go to the **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Select a member record, then select **Edit**.
3. Update the scope and roles of their permissions.
4. Select **Continue to summary**.
5. Review the information, then select **Update**.

To edit member permissions using the API, get a [list of roles](https://developers.cloudflare.com/api/resources/accounts/subresources/roles/methods/list/) available for an account.

Then, send a [`PUT` request](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/update/) to edit their permissions.

*Requestbash*

```bash
curl --request PUT \
  --url https://api.cloudflare.com/client/v4/accounts/{account_id}/members/{member_id} \
  --header 'Authorization: Bearer <API_TOKEN>' \
  --header 'Content-Type: application/json' \
  --data '{
	  "roles": [
	        {
	            "id": "<ROLE_ID1>"
	        },
	        {
	            "id": "<ROLE_ID2>"
	        }
	  	]
		}'
```

## Resend an invitation

If you invited a member to your account but they cannot find the invitation or the invitation expires, you can resend the invitation through the Cloudflare dashboard:

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login) and select your account<sup>[1](#user-content-fn-1)</sup>.
2. Go to **Manage Account** > **Members**.
3. Select a member record where their **Status** is **Invite Pending**.
4. Select **Resend invite**.

## Footnotes

1. To manage account members, you must have a role of **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/). [↩](#user-content-fnref-1)

## Remove account members

To manage account members, you must have a role of **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

To revoke a member's access to your account:

1. In the Cloudflare dashboard, go to the **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Locate an account member and expand their record.
3. Click **Revoke**.
4. Click **Yes, revoke access**.

To revoke a member's access to your account using the API, send a [`DELETE` request](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/delete/).

Note

If you have been invited to an account and want to remove yourself from the account, go to **Manage Account** > **Members**. Under your email address, select **Leave**.

## Super Administrator access

If you are a Super Administrator for an account that has existing domains and you decide to leave the account, you can invite a new Super Administrator who will have access to the same account privileges.

You can delete your user as a Super Administrator, but you cannot delete your account. Other Super Administrators will continue to have access to the appropriate privileges to manage the account, including billing information.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/manage/#page","headline":"Manage","description":"Add, edit, and remove Cloudflare account members and their permission policies.","url":"https://developers.cloudflare.com/fundamentals/manage-members/manage/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how Cloudflare account member policies combine actors, roles, and scopes to define access permissions.
title: Policies
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Policies

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/policies/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Policies define what access a given user has to your account or domains, and are constructed out of three parts:

1. An actor (your user).
2. A `ResourceGroup` (a scope).
3. A `PermissionGroup` (roles).

An account member can have one or several of these policies to represent the most appropriate access. A member’s effective permissions are the union of all policies assigned to them—whether directly, or through group membership.

To increase the usability and flexibility of Cloudflare's role system, changes to the API have been made to expose these underlying data principles and allow users to interact with them.

For example, you may want to assign multiple policies and use scopes to control access to an account where you have a single account with both Production and Staging domains, and a user that should be able see the whole account, purge the production domains, but have the ability to configure the staging domains.

## Manage policies

A set of standard API endpoints is present on every account that allow access to your members, which has recently been enhanced by a list of `resourceGroups` and `PermissionGroups`.

- A `resourceGroup` is a unique identifier for the scope for which a policy applies.
- A `permissionGroup` is a unique identifier for the set of roles that are assigned to a given policy.

Refer to the [API documentation](https://developers.cloudflare.com/api/) for more information.

## Viewing Effective Permissions

Cloudflare supports assigning permissions to members both directly and through [User Groups](https://developers.cloudflare.com/fundamentals/manage-members/user-groups/). A member’s effective permissions are additive; they represent the union of all permissions granted directly to a member and those inherited through a member's group membership.

Note

To understand a member’s full access, check both the **Members** and **User Groups** views:

- The **Members** view shows only the permissions explicitly assigned to the user.
- Permissions inherited through [User Groups](https://developers.cloudflare.com/fundamentals/manage-members/user-groups/) are not shown on the Members page. To see these, go to the Groups tab, find the groups the user belongs to, and review the policies assigned to each group.

Cloudflare is actively working on improvements to consolidate this view in a future update.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/policies/#page","headline":"Policies","description":"Understand how Cloudflare account member policies combine actors, roles, and scopes to define access permissions.","url":"https://developers.cloudflare.com/fundamentals/manage-members/policies/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the account-scoped, domain-scoped, and resource-scoped roles available for Cloudflare account members.
title: Roles
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Roles

Last updated Sep 16, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/roles/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Whenever you [add a new member](https://developers.cloudflare.com/fundamentals/manage-members/manage/) to your account, you can assign policies to those users and make use of the available roles. Roles can only ever be assigned to their given scope and multiple roles can be assigned to a given policy.

## Account-scoped roles

Account-scoped roles apply across an entire Cloudflare account, and through all domains in that account.

| Role | Description |
| --- | --- |
| Administrator | Can access the full account and edit subscriptions. Cannot manage members nor billing profile. |
| Super Administrator - All Privileges | Can edit any Cloudflare setting, make purchases, update billing, manage members, and create account-owned API tokens. Super Administrators can revoke the access of other Super Administrators. |
| Administrator Read Only | Can access the full account in read-only mode. |
| Analytics | Can read Analytics. |
| API Gateway | Grants full access to [API Gateway (including API Shield)](https://developers.cloudflare.com/api-shield/) for all domains in an account. |
| API Gateway Read | Grants read access to [API Gateway (including API Shield)](https://developers.cloudflare.com/api-shield/) for all domains in an account. |
| Application Security Reports Read | Can read Application Security Reports. |
| Audit Logs Viewer | Can view [Audit Logs](https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/). |
| Bot Management (Account-Wide) | Can edit [Bot Management](https://developers.cloudflare.com/bots/plans/bm-subscription/) (including [Super Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/super-bot-fight-mode/)) configurations for all domains in account. |
| Billing | Can edit the account's [billing profile](https://developers.cloudflare.com/billing/get-started/create-billing-profile/) and subscriptions |
| Cache Purge | Can purge the edge cache and allows the reading of zone settings. |
| Cloudflare Access | Can edit [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) and [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/). |
| Cloudflare CASB | Can edit [Cloudflare CASB](https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/). |
| Cloudflare CASB Read | Can read [Cloudflare CASB](https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/). |
| Cloudchamber Admin | Can manage Cloudchamber deployments. |
| Cloudchamber Admin Read Only | Can manage Cloudchamber deployments in read-only mode. |
| Cloudflare DEX | Can edit [Cloudflare DEX](https://developers.cloudflare.com/cloudflare-one/insights/dex/). |
| Cloudflare Gateway | Can edit [Cloudflare Gateway](https://developers.cloudflare.com/cloudflare-one/traffic-policies/) and read [Access](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/). |
| Cloudflare Images | Can access [Cloudflare Images](https://developers.cloudflare.com/images/) data. |
| Cloudflare R2 Admin | Can edit Cloudflare [R2](https://developers.cloudflare.com/r2/) buckets, objects, and associated configurations. |
| Cloudflare R2 Read | Can read Cloudflare [R2](https://developers.cloudflare.com/r2/) buckets, objects, and associated configurations. |
| Cloudflare Stream | Can edit [Cloudflare Stream](https://developers.cloudflare.com/stream/) media. |
| Cloudflare Zero Trust | Can edit [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/). Grants administrator access to all Zero Trust products including Access, Gateway, the Cloudflare One Client, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security. |
| Cloudflare Zero Trust Secure DNS Locations Write | Can view [Gateway DNS locations](https://developers.cloudflare.com/cloudflare-one/networks/resolvers-and-proxies/dns/locations/#secure-dns-locations) and create and edit [secure DNS locations](https://developers.cloudflare.com/cloudflare-one/networks/resolvers-and-proxies/dns/locations/#secure-dns-locations). |
| Cloudflare Zero Trust PII | Can access [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) PII. |
| Cloudflare Zero Trust Read Only | Can access [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) read only mode. |
| Cloudflare Zero Trust Reporting | Can access [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) reporting data. |
| Connectivity Directory Admin | Can view, edit, create, and delete [Workers VPC Services](https://developers.cloudflare.com/workers-vpc/) and bind to [Cloudflare Tunnel](https://developers.cloudflare.com/workers-vpc/configuration/tunnel/). |
| Connectivity Directory Bind | Can read, list, and bind to [Workers VPC Services](https://developers.cloudflare.com/workers-vpc/), as well as read and list [Cloudflare Tunnels](https://developers.cloudflare.com/workers-vpc/configuration/tunnel/). |
| Connectivity Directory Read | Can view [Workers VPC Services](https://developers.cloudflare.com/workers-vpc/) and [Cloudflare Tunnels](https://developers.cloudflare.com/workers-vpc/configuration/tunnel/). |
| DNS | Can edit [DNS records](https://developers.cloudflare.com/dns/manage-dns-records/). |
| Email Configuration Admin | Grants administrator access to Email security. Cannot take actions on emails, or read emails. |
| Email Integration Admin | Grants read and write access to integrations only. |
| Email Security Analyst | Grants analyst access. Can take action on emails and read emails. |
| Email Security Read only | Grants read only access to all of Email security. |
| Email Security Reporting | Grants read access to Email security metrics. |
| Email Security Policy Admin | Grants read access to all settings, and write access to [allow policies](https://developers.cloudflare.com/cloudflare-one/email-security/settings/detection-settings/allow-policies/), [trusted domains](https://developers.cloudflare.com/cloudflare-one/email-security/settings/detection-settings/trusted-domains/), and [blocked senders](https://developers.cloudflare.com/cloudflare-one/email-security/settings/detection-settings/blocked-senders/) |
| Firewall | Can edit [WAF](https://developers.cloudflare.com/waf/), [IP Access rules](https://developers.cloudflare.com/waf/tools/ip-access-rules/), [Zone Lockdown](https://developers.cloudflare.com/waf/tools/zone-lockdown/) settings, [Cache Rules](https://developers.cloudflare.com/cache/how-to/cache-rules/), and [Cache Response Rules](https://developers.cloudflare.com/cache/how-to/cache-response-rules/). |
| HTTP Applications | Grants full access to HTTP Applications. |
| HTTP Applications Read | Grants read-only access to HTTP Applications. |
| Load Balancer | Can edit [Load Balancers](https://developers.cloudflare.com/load-balancing/), Pools, Origins, and Health Checks. |
| Load Balancing Account Read | Can read [Load Balancing](https://developers.cloudflare.com/load-balancing/) resources such as Load Balancers, Monitors, Monitor Groups, Pools, and Health Checks. |
| Log Share | Can edit [Log Share](https://developers.cloudflare.com/logs/) configuration. |
| Log Share Reader | Can read Enterprise [Log Share](https://developers.cloudflare.com/logs/). |
| Magic Network Monitoring | Can view and edit [Network Flow configuration](https://developers.cloudflare.com/network-flow/). |
| Magic Network Monitoring Admin | Can view, edit, create, and delete [Network Flow configuration](https://developers.cloudflare.com/network-flow/). |
| Magic Network Monitoring Read-Only | Can view [Network Flow configuration](https://developers.cloudflare.com/network-flow/). |
| Network Services Write (Magic) | Grants write access to network configurations for Magic services. Magic Tunnel health checks require the Analytics role for non-admin users. |
| Network Services Read (Magic) | Grants read access to network configurations for Magic services. Magic Tunnel health checks require the Analytics role for non-admin users. |
| Minimal Account Access | Can view account, and nothing else. |
| Page Shield | Grants write access to [client-side security](https://developers.cloudflare.com/client-side-security/) (formerly Page Shield) across the whole account. |
| Page Shield Read | Grants read access to [client-side security](https://developers.cloudflare.com/client-side-security/) (formerly Page Shield) across the whole account. |
| Realtime | Grants access to Realtime configuration excluding sensitive data. |
| Realtime Admin | Grants administrator access to Realtime configuration. |
| Hyperdrive Read only | Grants read access to [Hyperdrive](https://developers.cloudflare.com/hyperdrive/) database configuration. |
| Hyperdrive Admin | Grants write access to [Hyperdrive](https://developers.cloudflare.com/hyperdrive/) database configuration. |
| SSL/TLS, Caching, Performance, Page Rules, and Customization | Can edit most Cloudflare settings except for [DNS](https://developers.cloudflare.com/dns/) and [Firewall](https://developers.cloudflare.com/waf/). |
| Secrets Store Admin | Can create, edit, duplicate, delete, and view secrets metadata. Can also [add a Secrets Store binding to a Worker](https://developers.cloudflare.com/secrets-store/integrations/workers/). |
| Secrets Store Deployer | Can view secrets metadata but cannot create, edit, duplicate, nor delete secrets. Can also [add a Secrets Store binding to a Worker](https://developers.cloudflare.com/secrets-store/integrations/workers/). |
| Secrets Store Reporter | Can view secrets metadata. Cannot perform any actions (create, edit, duplicate, delete secrets), nor add a Secrets Store binding to a Worker. |
| Brand Protection | Can access the Brand Protection feature on the API and Cloudflare dashboard. Brand Protection role also gives you access to the Investigate platform. |
| Cloudforce One Admin | Grants write access to [Cloudforce One](https://developers.cloudflare.com/security-center/cloudforce-one/). |
| Cloudforce One Read | Grants read access to [Cloudforce One](https://developers.cloudflare.com/security-center/cloudforce-one/), and cannot create and/or edit RFIs or PIRs. |
| Trust and Safety | Can access trust and safety related services. |
| Turnstile | Grants full access to [Turnstile](https://developers.cloudflare.com/turnstile/). |
| Turnstile Read | Grants read access to [Turnstile](https://developers.cloudflare.com/turnstile/). |
| Vectorize Admin | Can edit [Vectorize](https://developers.cloudflare.com/vectorize/) configurations. |
| Vectorize Read only | Can read [Vectorize](https://developers.cloudflare.com/vectorize/) configurations. |
| Waiting Room Admin | Can edit [Waiting Room](https://developers.cloudflare.com/waiting-room/) configuration. |
| Waiting Room Read | Can read [Waiting Room](https://developers.cloudflare.com/waiting-room/) configuration. |
| Workers Editor | Can use the [Workers Playground](https://developers.cloudflare.com/workers/playground/). |
| Workers Platform Admin | Grants edit and read access to all products typically used as part of Cloudflare's Developer Platform, including [Workers](https://developers.cloudflare.com/workers/), [Pages](https://developers.cloudflare.com/pages/), [Durable Objects](https://developers.cloudflare.com/durable-objects/), [KV](https://developers.cloudflare.com/kv/), [R2](https://developers.cloudflare.com/r2/), Zones, [Zone Analytics](https://developers.cloudflare.com/analytics/account-and-zone-analytics/zone-analytics/) and [Page Rules](https://developers.cloudflare.com/rules/). Cloudflare may add additional read-only permissions to this role as new products are introduced. |
| Workers Platform (Read-only) | Grants read-only access to all products typically used as part of Cloudflare's Developer Platform, including [Workers](https://developers.cloudflare.com/workers/), [Pages](https://developers.cloudflare.com/pages/), [Durable Objects](https://developers.cloudflare.com/durable-objects/), [KV](https://developers.cloudflare.com/kv/), [R2](https://developers.cloudflare.com/r2/), Zones, [Zone Analytics](https://developers.cloudflare.com/analytics/account-and-zone-analytics/zone-analytics/) and [Page Rules](https://developers.cloudflare.com/rules/). Cloudflare may add additional read-only permissions to this role as new products are introduced. |
| Connectivity Directory Read | Can view [Workers VPC Services](https://developers.cloudflare.com/workers-vpc/) and [Cloudflare Tunnels](https://developers.cloudflare.com/workers-vpc/configuration/tunnel/). |
| Connectivity Directory Bind | Can read, list, and bind to [Workers VPC Services](https://developers.cloudflare.com/workers-vpc/), as well as read and list [Cloudflare Tunnels](https://developers.cloudflare.com/workers-vpc/configuration/tunnel/). |
| Connectivity Directory Admin | Can view, edit, create, and delete [Workers VPC Services](https://developers.cloudflare.com/workers-vpc/), including the ability to create VPC Services that bind to [Cloudflare Tunnel](https://developers.cloudflare.com/workers-vpc/configuration/tunnel/). |
| Zaraz Admin | Can edit and publish [Zaraz](https://developers.cloudflare.com/zaraz/) configuration. |
| Zaraz Edit | Can edit [Zaraz](https://developers.cloudflare.com/zaraz/) configuration. |
| Zaraz Read only | Can read [Zaraz](https://developers.cloudflare.com/zaraz/) configuration. |
| Zone Versioning (Account-Wide) | Can view and edit [Zone Versioning](https://developers.cloudflare.com/version-management/) for all domains in account. |
| Zone Versioning Read (Account-Wide) | Can view [Zone Versioning](https://developers.cloudflare.com/version-management/) for all domains in account. |

## Domain-scoped roles

Domain-scoped roles apply for a given domain within an account.

| Role | Description |
| --- | --- |
| AI Crawl Control Read Only | Can read [AI Crawl Control](https://developers.cloudflare.com/ai-crawl-control/) and metrics. |
| Bot Management | Can edit [Bot Management](https://developers.cloudflare.com/bots/plans/bm-subscription/) (including [Super Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/super-bot-fight-mode/)) configurations. |
| Cache Domain Purge | Grants access to [purge the edge cache](https://developers.cloudflare.com/cache/how-to/purge-cache/) for a specific domain and allows the reading of zone settings. |
| Domain Administrator | Grants full access to domains in an account (including [Regional Services](https://developers.cloudflare.com/data-localization/regional-services/) configurations), and read-only access to account-wide [Firewall](https://developers.cloudflare.com/waf/account/managed-rulesets/deploy-dashboard/), [Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/), and [Worker](https://developers.cloudflare.com/workers/) resources. |
| Domain Administrator Read Only | Grants read-only access to domains in an account, as well as account-wide [Firewall](https://developers.cloudflare.com/waf/account/managed-rulesets/deploy-dashboard/), [Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/), and [Worker](https://developers.cloudflare.com/workers/) resources. This role does not currently include read access to [Regional Services](https://developers.cloudflare.com/data-localization/regional-services/) configurations. |
| Domain API Gateway | Grants full access to API Gateway (including [API Shield](https://developers.cloudflare.com/api-shield/)). |
| Domain API Gateway Read | Grants read access to API Gateway (including [API Shield](https://developers.cloudflare.com/api-shield/)). |
| Domain DNS | Grants access to edit [DNS settings](https://developers.cloudflare.com/dns/) for domains in an account. |
| Domain Page Shield | Grants write access to [client-side security](https://developers.cloudflare.com/client-side-security/) for domains in an account. |
| Domain Page Shield Read | Grants read access to [client-side security](https://developers.cloudflare.com/client-side-security/) for domains in an account. |
| Domain Waiting Room Admin | Can edit [waiting rooms](https://developers.cloudflare.com/waiting-room/) configuration. |
| Domain Waiting Room Read | Can read [waiting rooms](https://developers.cloudflare.com/waiting-room/) configuration. |
| Zone Versioning | Grants full access to [Zone Versioning](https://developers.cloudflare.com/version-management/). |
| Zone Versioning Read | Grants read-only access to [Zone Versioning](https://developers.cloudflare.com/version-management/). |

## Resource-scoped roles

Resource-scoped roles apply for a specific resource within an account.

Note

Resource-scoped roles is currently in Beta.

| Role | Description |
| --- | --- |
| Cloudflare Access App Admin | Can edit a specific [Access application](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/) in an account. |
| Cloudflare Access Identity Provider Admin | Can edit a specific [Cloudflare One identity provider (IdP)](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/) in an account. |
| Cloudflare Access Policy Admin | Can edit a specific [Access policy](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) in an account. |
| Cloudflare Access Service Token Admin | Can edit a specific [Access service token](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/) in an account. |
| Access for Infrastructure Target Admin | Can edit a specific [Access for Infrastructure target](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/) in an account. |
| Individual Cloudflare Tunnel instances | Scopes permissions to a specific [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) instance. Refer to [Granular permissions for Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/granular-permissions/) for details. |
| Individual Cloudflare Mesh nodes | Scopes permissions to a specific [Cloudflare Mesh](https://developers.cloudflare.com/mesh/) node. Refer to [Granular permissions for Cloudflare Tunnel and Cloudflare Mesh](https://developers.cloudflare.com/cloudflare-one/networks/connectors/granular-permissions/) for details. |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/roles/#page","headline":"Roles","description":"Review the account-scoped, domain-scoped, and resource-scoped roles available for Cloudflare account members.","url":"https://developers.cloudflare.com/fundamentals/manage-members/roles/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-16","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Choose account, domain, or resource-level scopes to control where Cloudflare member permissions apply.
title: Role scopes
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Role scopes

Last updated Sep 16, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/scope/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Scopes are one of three constituent parts of a policy that allows granting of access to users.

To allow for flexible combinations of access to users, Cloudflare currently has account-level scopes, domain scopes, and resource-specific scopes. Each scope is associated with a different set of [roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/).

- **Account scope:** Use when the member needs access across the entire account, for example, billing or account-level settings.
- **Specific domains:** Use when the member should only manage certain domains, for example, a developer who works on staging domains but should not modify production.
- **Domain groups:** Use when you have related domains that share the same access needs, for example, all production domains.
- **Specific resources:** Use when access should be limited to individual resources.

---

## Choose the scope of roles

Each policy has a limitation of a single scope, but you can assign multiple policies to a given user.

You can choose the scope of a policy when you [add a member](https://developers.cloudflare.com/fundamentals/manage-members/manage/).

### Account scope

If you want the member to have a policy that applies across your account, use the following combination of fields.

| Field | Value |
| --- | --- |
| Operator | *Include* |
| Type | *All domains* |

Note

You can only assign [account-scoped roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/#account-scoped-roles) as part of these types of policies

### Specific domains

If you want the member to have a policy that applies to a specific domain, use the following combination of fields. When applying these roles to this policy, only domain-scoped roles can be used.

| Field | Value |
| --- | --- |
| Operator | *Include* |
| Type | *A specific domain* |
| Name | *A specific domain* |

### Domain groups

If you have a set of domains that are all categorized similarly (e.g. all of your sensitive/production domains, all domains around a given project or geography), you can pre-assign them into a domain group and then create policies that provide access to all domains within this group.

#### Create group

To create a domain group:

1. In the Cloudflare dashboard, go to the **Settings** > **Lists** page. (You must be logged in as a **Super Administrator** and have a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/)). [Go to **Configurations** ↗](https://dash.cloudflare.com/?to=/:account/configurations)
2. For **Domain Group Manager**, select **Create**.
3. Create your domain group:
   1. Select the domains to include.
   2. Add a **Name**.
   3. Select **Create**.

You can also edit and delete these groups as needed.

#### Use group

To assign a member permissions to a domain group, use the following combination of fields:

| Field | Value |
| --- | --- |
| Operator | *Include* |
| Type | *Domain Group* |
| Name | *Example Group* |

Note

With Domain Groups, you can only assign [domain-scoped roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/#domain-scoped-roles) to these members.

### Specific resources

If you want the member to have a policy that applies to a specific resource, use the following combination of fields.

| Field | Value |
| --- | --- |
| Operator | *Include* |
| Type | *Granular* |
| Product | *Product Name* |
| Resource | *Specific Resource* |

#### Available scopes

You can assign the following resource-specific scopes to members:

| Scope | Description |
| --- | --- |
| Individual Access applications | Grant access to manage a specific [Access application](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/). |
| Individual Access identity providers (IdPs) | Grant access to manage a specific [Cloudflare One identity provider (IdP)](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/). |
| Individual Access policies | Grant access to manage a specific [Access policy](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/). |
| Individual Access service tokens | Grant access to manage a specific [Access service token](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/). |
| Individual Access infrastructure targets | Grant access to manage a specific [Access for Infrastructure target](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/). |
| Individual Cloudflare Tunnel instances | Grant access to manage a specific [Cloudflare Tunnel](https://developers.cloudflare.com/tunnel/) instance. |
| Individual Cloudflare Mesh nodes | Grant access to manage a specific [Cloudflare Mesh](https://developers.cloudflare.com/mesh/) node. |

Note

When using scopes for specific resources, you can only assign [resource-scoped roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/#resource-scoped-roles) to these members.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/scope/#page","headline":"Role scopes","description":"Choose account, domain, or resource-level scopes to control where Cloudflare member permissions apply.","url":"https://developers.cloudflare.com/fundamentals/manage-members/scope/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-16","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Create and manage Cloudflare User Groups to assign shared permission policies to multiple account members.
title: User Groups
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# User Groups

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/user-groups/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

User Groups are a collection of [account members](https://developers.cloudflare.com/fundamentals/manage-members/) that are treated equally from an access control perspective. User Groups can be assigned permission policies, with individual members in the group receiving all permissions of the roles assigned to the User Group. If users also have individually assigned permissions, then their effective permissions are the union of all of their individual permissions, plus the permissions for all of the User Groups they are a member of.

Note

User Group permissions are inherited by each member of the group but are not currently reflected in the role field on the **Members** page. To view a member’s full set of permissions, check both:

- The **Members** page for any directly assigned policies
- The **Groups** tab to identify which groups the member belongs to, and the policies applied to those groups

Cloudflare is actively working on improving this experience to make inherited and direct permissions easier to view.

## Create a User Group manually

1. In the Cloudflare dashboard, go to the **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Select the **Groups** tab.
3. Select **Create a Group** and enter a name and description for your new group.
4. Select **Create group** to confirm your changes. The **Group members** tab displays.
5. Select **Add members**.
6. Select the relevant members you want to include in the group and select **Add to Group**.

### Assign a Permission Policy

With your Group created, you can now add a [Permission Policy](https://developers.cloudflare.com/fundamentals/manage-members/policies/) to your Group.

1. In the **Groups** tab under **Permission policies**, select **Add a Policy**.
2. Specify the scope and permissions you want applied to the members of the group.
3. Select **Create Policy** to apply it to the group.

Using the role identifiers from the previous section, you can create a permission policy for your group.

`export ADMIN_ROLE='...' # id field from admin or desired role entry from permission_groups API response`

*Example requestcurl*

```curl
$ cat <<-PAYLOAD | curl -XPUT  -H "Authorization: Bearer $AOT" -H "Content-type: application/json" --data-binary @- https://api.cloudflare.com/client/v4/accounts/$ACCT/iam/user_groups/$PUSHED_GROUP  | jq .
{
    "policies": [
        {
            "access": "allow",
            "permission_groups": [{"id": "$ADMIN_ROLE"}],
            "resource_groups": [{
                "scope": {
                    "key": "com.cloudflare.api.account.$ACCT",
                    "objects": [{"key":"*"}]
                }
            }]
        }
    ]
}
PAYLOAD
```

**Reset a policy to an empty state**

If you made a mistake while creating the group policy or need to reset the policy to an empty state, send another PUT request to the group API with an empty policy array to overwrite with your new policy.

```curl
$ cat <<-PAYLOAD | curl -XPUT  -H "Authorization: Bearer $AOT" -H "Content-type: application/json" --data-binary @- https://api.cloudflare.com/client/v4/accounts/$ACCT/iam/user_groups/$PUSHED_GROUP  | jq .
{
    "policies": []
}
PAYLOAD
```

## Create a User Group with SCIM

Customers with the SCIM integration configured can sync User Groups from an upstream identity provider to Cloudflare. Cloudflare's SCIM integration requires one external application per account.

Note

If you use the [Cloudflare dashboard SCIM integration](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/), you can sync Groups from an upstream Identity Provider. This allows you to centralize user and group management at your identity provider.

Note that when managing User Groups via SCIM:

- You cannot change the name, members, or delete the group manually from the Cloudflare dashboard or API.
- The integration requires one external SCIM application per Cloudflare account.
- Cloudflare does not currently support updating user profile fields ( `firstName`, `lastName`, or `email`) via SCIM. If those attributes change in your IdP, they will not be updated in Cloudflare. These values are only set during initial provisioning.

To set up a user group with SCIM, refer to the [Provisioning with SCIM guide](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/).

### Set up permissions for User Groups

After a user group is created either manually in Cloudflare dashboard or through SCIM integration the final step is to attach permissions to it.

1. Go to **Manage members** > **Members** > **User groups**.
2. Select the user group you want to attach permissions to.
3. Select the **Permission policies** tab and select **Add policy**.
4. Choose the scope and role that you want to apply to the policy.
5. Select **Save** to apply the policy.

Before you begin, confirm the groups that were created internally or have been pushed to Cloudflare by using the command below.

**1. Get user groups**

*Example requestcurl*

```curl
$ curl -X GET -H "Authorization: Bearer $AOT" https://api.cloudflare.com/client/v4/accounts/$ACCT/iam/user_groups | jq .
```

*Example responsecurl*

```curl
{
    "errors": [],
    "messages": [],
    "result": [
        {
            "created_on": "2025-01-24T15:31:36.759979Z",
            "id": "f234f49f66df4db8864c5189fe78c87f",
            "modified_on": "2025-01-24T15:35:50.151764Z",
            "name": "My Cool Demo Group",
            "status": "V"
        },
        {
            "created_on": "2025-01-16T20:43:01.019311Z",
            "id": "7148c1e4d9f247f5b6dcd3ef20f998f9",
            "modified_on": "2025-01-16T20:44:07.627233Z",
            "name": "My Cool Demo Group, now with policies!",
            "policies": [
                {
                    "access": "allow",
                    "created_on": "2025-01-16T20:44:07.627233Z",
                    "id": "8d82cf8c15c64e07a4bee58e00d80bca",
                    "modified_on": "2025-01-16T20:44:07.627233Z",
                    "permission_groups": [
                        {
                            "created_on": "2023-06-21T18:58:29.907496Z",
                            "id": "a1a099e3256942259bfde18c688b67d5",
                            "meta": {
                                "description": "Grants write access to Page Shield for domain",
                                "editable": "false",
                                "label": "domain_page_shield",
                                "scopes": "com.cloudflare.api.account.zone"
                            },
                            "modified_on": "2023-06-21T18:58:29.907496Z",
                            "name": "Domain Page Shield",
                            "permissions": ["dev note: snipped for length"],
                            "status": "V"
                        }
                    ],
                    "resource_groups": [
                        {
                            "created_on": "2025-01-16T20:44:07.627233Z",
                            "modified_on": "2025-01-16T20:44:07.627233Z",
                            "scope": {
                                "key": "com.cloudflare.api.account.a3324a084cd290080b563ab39c91545a",
                                "objects": [
                                    {
                                        "key": "*"
                                    }
                                ]
                            }
                        }
                    ],
                    "status": "V"
                }
            ],
            "status": "V"
        }
    ],
    "result_info": {
        "count": 2,
        "page": 1,
        "per_page": 100,
        "total_count": 2,
        "total_pages": 1
    },
    "success": true
}
```

**2. Make a query against the resource ID**

Locate the tag of the group you pushed from the IdP and use it to make a direct query against its resource ID:

`export PUSHED_GROUP='...' # Pull this value from the "id" json field in the group list response`

*Example requestcurl*

```curl
$ curl -XGET -H "Authorization: Bearer $AOT" https://api.cloudflare.com/client/v4/accounts/$ACCT/iam/user_groups/$PUSHED_GROUP | jq .
```

The response for this should have the group name that was specified in the identity provider with no attached policies.

**3. Review available permission groups**

Before you modify the group's policies, review the available permission groups (roles) on the account by querying its API.

*Example requestcurl*

```curl
$ curl -XGET -H "Authorization: Bearer $DEMO_AOT" https://api.cloudflare.com/client/v4/accounts/$ACCT/iam/permission_groups | jq .
```

*Example responsecurl*

```curl
{
  "result": [
    {
      "id": "1a0fc8bdeae24387b64d5b8de1ad052a",
      "name": "Administrator Read Only",
      "status": "V",
      "meta": {
        "description": "Can access the full account in read-only mode.",
        "editable": "false",
        "label": "admin_readonly",
        "scopes": "com.cloudflare.api.account"
      },
      "created_on": "2020-07-06T12:19:13.099114Z",
      "modified_on": "2020-10-13T11:18:00.208228Z"
    },
    {
      "id": "ce2c69b09baf4ca38223910a8b7e07a9",
      "name": "Administrator",
      "status": "V",
      "meta": {
        "description": "Can access the full account, except for membership management and billing.",
        "editable": "false",
        "label": "admin",
        "scopes": "com.cloudflare.api.account"
      },
      "created_on": "2020-07-06T12:19:13.099114Z",
      "modified_on": "2020-10-13T11:18:00.208228Z"
    }
  ],
  "success": true,
  "errors": [],
  "messages": []
}
```

Note

These permission groups are from our staging environment and tags will not function in your production deployment.

## Inspect Group Members

To verify the IdP synchronized the group and user members pushed in the SCIM operation, query the Group Members API.

*Example requestcurl*

```curl
$ curl -XGET -H "Authorization: Bearer $DEMO_AOT" https://api.cloudflare.com/client/v4/accounts/$ACCT/iam/user_groups/$PUSHED_GROUP/members | jq .
```

*Example responsecurl*

```curl
{
  "result": [
    {
      "id": "a4366a09c43a0b0c4606dc5528472bb6",
      "email": "luke.skywalker@rebelalliance.net"
    },
    {
      "id": "0329c17f6c13f5202dc38d2036efb1a9",
      "email": "arya.stark@winterfell.place"
    }
  ],
  "result_info": {
    "page": 1,
    "per_page": 100,
    "total_pages": 1,
    "count": 2,
    "total_count": 2
  },
  "success": true,
  "errors": [],
  "messages": []
}
```

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/user-groups/#page","headline":"User Groups","description":"Create and manage Cloudflare User Groups to assign shared permission policies to multiple account members.","url":"https://developers.cloudflare.com/fundamentals/manage-members/user-groups/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Manage your Cloudflare user profile, including login, 2FA, email, password, and account settings.
title: User profiles
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# User profiles

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Each user has a profile that contains several settings, such as [Communication preferences](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#notifications) and [Language preferences](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#language).

To access your profile, select the user icon and then **My Profile** from any page within the [Cloudflare dashboard ↗](https://dash.cloudflare.com).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/#page","headline":"User profiles","description":"Manage your Cloudflare user profile, including login, 2FA, email, password, and account settings.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Set up and manage two-factor authentication on your Cloudflare account using security keys, TOTP apps, or email.
title: Two-factor authentication
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Two-factor authentication

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

We recommend that all Cloudflare user account holders enable two-factor authentication (2FA) to keep your accounts secure. 

2FA can only be enabled successfully on an account with a [verified email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/). If you do not verify your email address first, you may lock yourself out of your account.

Caution

Super Administrators can turn on **2FA Enforcement** to require all members to enable 2FA. If you are not a Super Administrator, you will be forced to turn on 2FA prior to accepting the invitation to join a Cloudflare account as a member.

To enable two-factor authentication for your Cloudflare login:

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login).
2. Under the **My Profile** dropdown, select **My Profile**.
3. Select **Authentication**. 
4. Select **Add** next to [Mobile App Authentication](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#configure-totp-mobile-application-authentication) or [Security Key Authentication](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#configure-security-key-authentication-for-two-factor-cloudflare-login), or **Enable** next to [Email Authentication](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#configure-email-two-factor-authentication).

Note

Cloudflare recommends that users enable at least two different 2FA factors, as well as safely store [backup codes](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#regenerate-backup-codes)) to prevent lockouts.

## Configure security key authentication for two-factor Cloudflare login

Caution

Security keys only work with browsers that support the WebAuthn protocol.

A security key provides phishing-resistant multifactor authentication to your Cloudflare account using a built-in authenticator (Apple Touch ID, Android fingerprint, or Windows Hello) or an external hardware key (like [YubiKey ↗](https://www.yubico.com/works-with-yubikey/catalog/cloudflare/)) that connects to your computer through USB-A, USB-C, NFC, or Bluetooth.

Cloudflare recommends configuring multiple security keys. With multiple keys, you can still use 2FA if the primary key is unavailable or if you are working on a different device.

After [enabling 2FA on your Cloudflare account](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#configure-totp-mobile-application-authentication), you can select **Manage** to configure 2FA security key authentication.

### Built-in authenticators

You can configure a built-in authenticator such as Apple Touch ID, Android fingerprint, or Windows Hello.

1. In **Security Key Authentication**, select **Add**.
2. On the **Add a Security Key**, enter your Cloudflare password and select **Next**.
3. Interact with your built-in authenticator to add it to your Cloudflare account.
4. Enter a name for the built-in authenticator. If this is the initial setup, you will be prompted to generate backup codes. If not, skip to Step 8.
5. Enter your Cloudflare password.
6. Select **Next** to review your backup codes. Backup codes can be used to access your user account without your mobile device.
7. Select **Download**, **Print**, or **Copy** to save your backup codes in a secure location.
8. Select **Next** to finish the configuration.

### Security keys

You can configure a security key, such as a Yubikey, to use with your account. Before you begin, ensure your hardware security key is configured and plugged in.

On a Windows device, you may need to set up Windows Hello or register your security key to your Microsoft account. Review the Windows documentation for more details.

1. Once your security key is plugged in, go to **Profile** > **Authentication**.
2. From **Two-Factor Authentication**, select **Set up**.
3. From **Security Key Authentication**, select **Add**.
4. Enter your Cloudflare password on the **Add a Security Key** screen, then select **Next**.
5. Interact with your security key to add it to your Cloudflare account. Ensure that the dialog is for the security key setup. If the Windows Hello dialog appears on a Windows device, select **Cancel**. The security key dialog box will then appear. Depending on your system, you may be required to register a PIN for the security key.
6. Enter a name for the security key. If this is the initial setup, you will be prompted to generate backup codes. If not, skip to Step 8.
7. Enter your Cloudflare password.
8. Select **Next** to review your backup codes. Backup codes can be used to access your user account without your mobile device.
9. Select **Download**, **Print**, or **Copy** to save your backup codes in a secure location.
10. Select **Next** to finish the configuration.

## Configure TOTP mobile application authentication

Time-based one-time password (TOTP) authentication works by using an authenticatior app, such as Google Authenticator or Microsoft Authenticator, which generates a secret code shared between the app and a website. When you log in to the website, you enter your username, password, and the secret code generated from the authenticator app. The secret code is only valid for a short period of time, about 30 to 60 seconds, before a new code is generated.

1. Once your security key is plugged in, go to **Profile** > **Authentication**.
2. From **Two-Factor Authentication**, select **Set up**.
3. Under **Mobile App Authentication**, select **Add**.
4. Scan the QR code with your mobile device and enter the code from your authenticator application.
5. Enter your Cloudflare password, then select **Next**. If you cannot scan the QR code, select **Can't scan QR code, Follow alternative steps** to configure your authenticator application manually.

![You can enable 2FA by scanning a QR code with your mobile device.](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=467,height=856,format=webp/_astro/2FA_scan_QR_code.t5BNYUYn.png)

6. Enter your Cloudflare password again.
7. Select **Next** to review your backup codes. You can use backup codes to access your account without your mobile device.
8. Select **Download**, **Print**, or **Copy** to save your backup codes in a secure location.

Note

To avoid being locked out of your account, be sure to generate and save your recovery codes. If you forget your password and cannot receive the reset code or lose access to your phone with the authenticator app, you can use the recovery codes to access your account.

You can regenerate your backup codes at any time using the Cloudflare dashboard.

9. Select **Next** on the backup code page to complete the recovery code setup.

### Reconfigure TOTP mobile application authentication

You may need to reconfigure your mobile application authentication if you join a new organization or lose access to your mobile device. When you reconfigure your mobile application authentication, your previous TOTP codes are invalid.

Note

Reconfiguring TOTP mobile application authentication does not turn off 2FA.

To reconfigure, follow [Steps 1-7](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#configure-totp-mobile-application-authentication) as detailed above.

## Configure email two factor authentication

Email 2FA works by sending you a TOTP code to your email address. This is a good option particularly if you are concerned about losing a hardware based key.

1. Navigate to **User Profile**, then **Authentication**.
2. Under **Two-Factor Authentication**, select **Set up**.
3. Under **Email Authentication**, select **Enable**.
4. You will be prompted to enter your password twice, and then be shown recovery codes. Save these somewhere safe like a password manager.

## Regenerate backup codes

Each backup code is one-time use only, but you can always request a new set of backup codes using the Cloudflare dashboard. This is useful if you have lost access to or used all of your previous backup codes.

Note

Regenerating your backup codes will invalidate your previous codes.

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select **My Profile**.
3. Select **Authentication**.
4. For **Two-Factor Authentication**, select **Manage**.
5. For **Backup codes**, select **Regenerate** to generate and save a new set of two-factor backup codes.

## Disable two-factor authentication for your Cloudflare account

To disable 2FA for your Cloudflare account, you must delete all security keys and TOTP authenticators from your account.

Note

If you are not the Super Administrator of an organization with **2FA Enforcement** enabled, you may not have permission to disable 2FA.

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select **Profile**.
3. Select the **Authentication**.
   - To remove your security key:
     1. Select **Edit** in the **Security Key Authentication** card. A drop-down menu shows more details about your security key.
     2. Select **Delete**.
     3. Enter your Cloudflare password, then select **Remove**.
   - To remove your TOTP mobile application authentication:
     1. Select **Delete method** in the **Mobile App Authentication** card.
     2. Enter your Cloudflare password, authenticator application code, or a recovery code, then select **Disable**.

![how to disable your TOTP mobile application authentication.](https://developerdocsgifs.cloudflaretraining.com/resampled_5fps_disable_mobile_auth_v2_final.gif)

## Use a backup code

If you lose access to a mobile device, security key, or authentication code, you can solve these issues by using a backup code or retrieving a backup code from your preferred authentication app.

Refer to Google's documentation to [transfer Google Authenticator codes from one Android device to another ↗](https://support.google.com/accounts/answer/1066447?co=GENIE.Platform%3DAndroid&hl=en&oco=0).

When setting up 2FA, you should have saved your backup codes in a secure location. To restore lost access using a Cloudflare backup code:

1. Retrieve the backup code from where you stored it.
2. Go to the [Cloudflare login page ↗](https://dash.cloudflare.com/login), enter your username and password and select **Log in**. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
3. You should see a page titled **Two-Factor Authentication**
   - If it has a text box, enter one of your backup codes and select **Log in**.
   - If instead you see "Insert your security key and touch it", cancel any prompts from your browser that appear and select **try another authentication method or backup code**. Proceed to enter one of your backup codes and select **Log in**.

Note

Once you use a backup code, it becomes invalid.

## Related resources

- [Google Authentication documentation ↗](https://support.google.com/accounts/answer/1066447?hl=en&ref_topic=2954345&co=GENIE.Platform%3DiOS&oco=0)
- [YubiKey documentation ↗](https://www.yubico.com/works-with-yubikey/catalog/cloudflare/)
- [Set up multi-user accounts on Cloudflare](https://developers.cloudflare.com/fundamentals/manage-members/)
- [Account recovery](https://developers.cloudflare.com/fundamentals/user-profiles/account-recovery/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#page","headline":"Two-factor authentication","description":"Set up and manage two-factor authentication on your Cloudflare account using security keys, TOTP apps, or email.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/2fa/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Regain access to your Cloudflare account when you have lost your 2FA device and backup codes.
title: Account recovery
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Account recovery

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/account-recovery/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If you do not have access to your 2FA account or backup codes and cannot currently generate a 2FA code, use a verified device that you have logged in from before to request a temporary access code.

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login). [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. On the **Two-Factor Authentication** page, select **Try recovery** on **Lost all 2FA devices and backup codes?**.
3. Select **Begin recovery**.
4. An access code will be sent to the email address associated with your Cloudflare account.
5. Enter the temporary access code into the Cloudflare Dashboard and select **Verify email**.
6. Select **Verify device**. This checks whether you are using a device that has previously logged into your account.

If you see **Device verified**, you will receive an email within 3-5 days with instructions to regain access to your account. It is important to note this process cannot be expedited, so you will need to wait until that email arrives before you can proceed.

If you see **Device verification failed**, you may be able to try again considering the following:

- If you clear your cookies often or are logging in from a different IP address, you have wiped Cloudflare's memory of your device and will need to use a different device to verify.
- Your browser may be set to clear cookies on exit or after browser or OS upgrades. This interferes with the device verification process.
- You may be using anti-malware or other software that automatically clears your browser cookies and makes your device unregognizable by Cloudflare's Dashboard.

If you are still unable to verify your device, follow the instructions to *Request manual verification* on the **Device verification failed** page.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/account-recovery/#page","headline":"Account recovery","description":"Regain access to your Cloudflare account when you have lost your 2FA device and backup codes.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/account-recovery/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to change your email address or password associated with your account.
title: Email address and password
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Email address and password

Last updated Sep 8, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Change email address

Note

You cannot change your email address if your administrator has [enabled single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) or if you did not successfully verify the original email address.

For example, if the email address was entered incorrectly or is a non-working email address, you will need to create a new account with a working email address and [move domains](https://developers.cloudflare.com/fundamentals/manage-domains/move-domain/).

To change the email address associated with your Cloudflare account:

1. Go to your [Profile ↗](https://dash.cloudflare.com/?to=/:account/profile).
2. Select your account.
3. In the Email Address panel, select **Change Email Address**.
4. In the dialog, enter your new email address in **New email** and **Confirm email**.
5. Enter your current password.
6. Select **Save**.

Billing and notification email addresses must be updated separately

The process above will update your user profile email, but you may have specified separate emails to receive [billing invoices](https://developers.cloudflare.com/billing/manage/invoices/#turn-on-invoice-emails-from-cloudflare) and other types of [notifications](https://developers.cloudflare.com/notifications/get-started/#edit-a-notification). You will also need to update those email addresses if you want to receive those emails at your new address.

## Change password

Note

If your administrator has [enabled Single sign-on (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/), you cannot change your **Authentication** settings.

To change your Cloudflare password:

1. Go to your [Profile ↗](https://dash.cloudflare.com/?to=/:account/profile).
2. Select your account.
3. Select **Authentication**.
4. On **Password**, select **Change Password**.
5. Change your password and select **Save**.

For added account security, consider changing your [API tokens](https://developers.cloudflare.com/fundamentals/api/how-to/roll-token/) as well.

## Forgot your email address

Note

If you are an Enterprise customer and forgot the email address associated with your account, contact your account team.

If you forget the email address associated with your application:

1. Go to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login) and select **Forgot your email?**.
2. Enter your domain name.
3. Cloudflare will send an email to the email address associated with your domain name. If you do not receive an email within 20 minutes, check your spam folder. The message will be sent from `no-reply@cloudflare.com` or `noreply@notify.cloudflare.com`.

## Forgot your password

You must be logged out of the Cloudflare dashboard to view the **Forgot your password?** option.

If you forget the password associated with your email address:

1. Go to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login) and select **Forgot your password?**.
2. Enter your email address.
3. Cloudflare will send an email with instructions to reset your password. If you do not receive an email within 20 minutes, check your spam folder. The message will be sent from `no-reply@cloudflare.com` or `noreply@notify.cloudflare.com`.

Note

This process does not affect your account or share your email address with anyone.

If you still cannot access the email address associated with your Cloudflare account, you may need to [move your domain to another account](https://developers.cloudflare.com/fundamentals/manage-domains/move-domain/).

Cloudflare requires these steps to prevent account hijacking.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/#page","headline":"Email address and password","description":"Learn how to change your email address or password associated with your account.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-08","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Customize your Cloudflare dashboard language, appearance, timezone, and notification preferences.
title: Profile settings
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Profile settings

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

From your Profile, you can modify settings that affect the Cloudflare dashboard.

## Language

Change the language used throughout the Cloudflare dashboard.

1. Log in to the Cloudflare dashboard.

[Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)

2. Go to **Profile**.
3. From **Settings** > **Language**, select a language.

Your dashboard will update to the new language automatically.

## Dashboard appearance

Adjust how the Cloudflare dashboard appears on your device.

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **Profile**.
3. From **Settings** > **Dashboard appearance**, choose a value:
   - **Dark**: Defaults to darker colors.
   - **Light**: Defaults to lighter colors.
   - **Use system setting**: Defaults to the option used on your device.

Your dashboard display will update to the new appearance setting automatically.

## Notifications

Choose the type of notifications you receive from Cloudflare, such as marketing announcements or insights about your domain.

To update the communication preferences for your profile (which requires a [verified email address)](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/):

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **Profile**.
3. Select **Notifications**.
4. Choose the categories of notifications you want to receive. Your choices are saved automatically.

Note

All email notifications from Cloudflare are sent from [noreply@notify.cloudflare.com](mailto:noreply@notify.cloudflare.com). If you are not receiving emails from Cloudflare, you may have marked Cloudflare as spam.

To continue receiving emails, make sure Cloudflare is added as a trusted sender.

Refer to [Cloudflare Notifications](https://developers.cloudflare.com/notifications/) to receive information about your account, such denial-of-service attacks or server issues.

## Timezone

Choose to set the timezone in the Cloudflare dashboard as Coordinated Universal Time (UTC) or your browser or system's timezone.

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select your **Profile**.
3. Select **Set Timezone** and choose either **Standard (UTC)** or **Local (CST)**.

The page reloads to apply the new setting.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#page","headline":"Profile settings","description":"Customize your Cloudflare dashboard language, appearance, timezone, and notification preferences.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Permanently delete your Cloudflare user profile and remove all associated domains and billing information.
title: Delete your Cloudflare account
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Delete your Cloudflare account

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/delete-account/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

These steps do not apply to accounts under contract. Contact your account team for more information.

## Who can delete their account

If your account uses [Single-Sign On (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/), your super administrator may need to delete your account on your behalf.

If your account does not use SSO, you can delete your account on your own.

## Prerequisites

Before Cloudflare can cancel your account and delete your personal information, you will need to follow the process below for each domain associated with your Cloudflare account:

- [Cancel your subscriptions or add-on services](https://developers.cloudflare.com/billing/manage/cancel-subscription/)
- [Remove your domain from Cloudflare](https://developers.cloudflare.com/fundamentals/manage-domains/remove-domain/)
- [Remove Cloudflare nameservers at your domain registrar](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/)
- [Disable auto-renew for your Registrar domain(s)](https://developers.cloudflare.com/registrar/account-options/renew-domains#set-up-automatic-renewals)
- If you are using a Cloudflare [CNAME setup](https://developers.cloudflare.com/dns/zone-setups/partial-setup/), [update your DNS records](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/#edit-dns-records) at your DNS provider to point to your website IPs or hostnames instead of Cloudflare.
- [Delete payment information](https://developers.cloudflare.com/billing/get-started/update-billing-info/#delete-a-payment-method)
- (*Optional*) [Download a copy of your invoices](https://developers.cloudflare.com/billing/manage/invoices/#download-invoice). Once deleted, the invoices will no longer be accessible and cannot be re-sent to you.

## Delete your Cloudflare account

When you sign up for Cloudflare, we create a user profile for you and an account named `youremail@example.com's account`, and your user profile is the admin for the newly create account. Your user profile is where you manage preferences like your password or language, while your account is where you'll manage Cloudflare product configurations.

Note

Your user profile can be invited to other Cloudflare accounts, so you may have access to more than one account.

When you delete your profile, the account associated with your profile and any accounts where you are the last active member will also be deleted. Deleting your account is permanent. Any accounts where you are the primary owner will also be deleted and any other users on those accounts will be removed.

After you delete your profile, you can use the email address with your profile to create a new account. In most cases, your email should be freed up to be used in a new signup right away. However, this may not be the same for users who have a lock on their account (for legal purposes).

All domains, subscriptions, and billing information on your account will be removed from Cloudflare.

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select **My Profile**.
3. Select **Delete this user**.
4. Select **Delete user**.
5. Follow the prompts to finish deleting your account.

Note

Cloudflare will purge your personal information within a year of a deletion request unless required to retain it for legal obligations (such as ongoing abuse investigations or pending litigation). Refer to the [Cloudflare Data Processing Addendum ↗](https://www.cloudflare.com/cloudflare-customer-dpa/) for further information about the deletion of personal information following the cancellation of your account.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/delete-account/#page","headline":"Delete your Cloudflare account","description":"Permanently delete your Cloudflare user profile and remove all associated domains and billing information.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/delete-account/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Sign in to the Cloudflare dashboard using email and password, SSO, or social login with Apple, Google, or GitHub.
title: Log in to Cloudflare
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Log in to Cloudflare

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/login/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Go to the Cloudflare dashboard and choose your [sign-in option](#sign-in-options).

[Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)

## Sign-in options

Cloudflare offers the following sign-in options:

### Email and password

Enter your email address and password.

### Single Sign-On (SSO)

If your admin has enabled [enabled SSO](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/), enter your email address.

### Social login

Social login allows you to sign in with a trusted 3rd party sign in service such as Apple, Google, or GitHub. Social login is only available for accounts with a verified email address, or accounts that signed up via social login initially. If you have additionally configured two-factor authentication on your account, that will be presented in addition to any login and two-factor authentication provided by the social login provider.

Note

If you log in to your Cloudflare user account with Single Sign-On (SSO), you will not be able to use social login.

Caution

If you use social login to sign in, your user profile will not have a password associated with it at first. Some operations, such as enabling 2-Factor Authentication or creating API tokens, require setting a password.

To set a password, go to [Forgot Password ↗](https://dash.cloudflare.com/forgot-password) in the Cloudflare dashboard, paste your email address, and click **Send**. You will receive an email with instructions to set your password. Once created, use your email and the new password to log in.

#### Sign in with Apple

- **Same Cloudflare account email as Apple ID**: You can sign in with either your email and password or sign in with Apple.
- **Different Cloudflare account email as Apple ID**: This option creates a new Cloudflare account. If you want to log in to an existing account, [change your email address](https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/) to match the one used for your Apple ID.

If you chose to share your email when creating a Cloudflare account with Apple ID and want to set a password and obtain an API key, go to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login) login page and select **Forgot your password?** to trigger a password reset email.

If you have chosen to hide your email when creating a Cloudflare account with Apple ID, resetting your password will not work. You can use the suggested workaround below:

1. [Add a new member to your account](https://developers.cloudflare.com/fundamentals/manage-members/manage/#add-account-members) using your secondary email address.
2. [Register a new Cloudflare account](https://developers.cloudflare.com/fundamentals/account/create-account/) with your secondary email address and set a password.
3. Access the Cloudflare dashboard with the new user and password to obtain an API key.

Changing your Cloudflare account email address will unlink the login credentials with the Apple ID from your Cloudflare account. If you attempt to log in using the same Apple ID after the email is changed, you will create a new Cloudflare account.

If you created your Cloudflare account using Apple Relay and decide to change your Apple ID or email address, you will be unable to retrieve the Cloudflare account and all login options will be permanently lost.

#### Sign in with Google

- **A Cloudflare account has already been created with your Google account's email**: This option is unavailable at this time, but we are working on the capability to link and unlink social login providers to your Cloudflare account.
- If you select **Sign in with Google** with an email that does not already have a Cloudflare account associated with it, Cloudflare will create a new account and allow you to sign in using **Sign in with Google** option moving forward.

#### Sign in with GitHub

- Sign in with GitHub uses the [Primary email address ↗](https://docs.github.com/en/account-and-profile/how-tos/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/changing-your-primary-email-address) which is set on your GitHub account. If you change your primary email address in GitHub, you will not be able to log into your Cloudflare account using GitHub social login.
- If you select **Sign in with GitHub** with an email that does not already have a Cloudflare account associated with it, Cloudflare will create a new account and allow you to sign in using **Sign in with GitHub** option moving forward.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/login/#page","headline":"Log in to Cloudflare","description":"Sign in to the Cloudflare dashboard using email and password, SSO, or social login with Apple, Google, or GitHub.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/login/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Cloudflare's Multi-Factor Email Authentication prevents unauthorized access by sending one-time codes to your email.
title: Multi-Factor Email Authentication
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Multi-Factor Email Authentication

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/multi-factor-email-authentication/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Overview

Cloudflare uses a Multi-Factor Email Authentication (MFA) method for increased account security. MFA prevents customer account takeovers when attackers gain unauthorized access to an account due to an exposed or easily guessed password.

Cloudflare will challenge any login attempt if the user provides the correct credentials from an unrecognized IP address.

![Cloudflare will send an email when your account is logged into from an unknown IP address.](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1026,height=502,format=webp/_astro/hc-import-account_access_email.CGeKtgax.png)

Cloudflare challenges the login by sending a one-time code that expires in 30 minutes to the email that we have on file for the account. Once the correct code is provided through the dashboard, your IP will be recorded and further login attempts from that IP address will not be challenged for 90 days.

![When your account is logged into from an unknown IP address, you have to enter an authentication token from an email sent to your email address on file.](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=702,height=426,format=webp/_astro/hc-import-login_authentication.B7wAaxsz.png)

Note

Email MFA can only be disabled by enabling [two-factor authentication](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/)

## Troubleshoot MFA

Cloudflare emails are sometimes flagged as spam by the recipient's email service. If you are expecting an authentication token, you should check the spam folder for any Cloudflare emails and configure a filter to allow Cloudflare emails from *[no-reply@notify.cloudflare.com](mailto:no-reply@notify.cloudflare.com)*\_**.**\_

Other times, emails are rejected by the recipient email service. Cloudflare will try again it will flag your email address after several attempts and no further emails will be sent.

If you still do not receive an email after ensuring your email service is not flagging Cloudflare, contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/).

---

## Related resources

- [Secure user access with two-factor authentication](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/multi-factor-email-authentication/#page","headline":"Multi-Factor Email Authentication","description":"Cloudflare's Multi-Factor Email Authentication prevents unauthorized access by sending one-time codes to your email.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/multi-factor-email-authentication/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Confirm the email address on your Cloudflare account to unlock dashboard features like adding members and updating preferences.
title: Verify email address
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Verify email address

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

For security reasons, Cloudflare attempts to verify the email address associated with your account. You cannot perform certain tasks within the Cloudflare dashboard -- for example, [adding a new member](https://developers.cloudflare.com/fundamentals/manage-members/manage/#add-account-members), [changing your email address](https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/#change-email-address) or [updating your communication preferences](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#notifications) -- without verifying your email.

## When creating your account

When you first [create an account](https://developers.cloudflare.com/fundamentals/account/create-account/), Cloudflare automatically sends a message to the email address you provided for your account.

To verify your email:

1. Log in to your email provider and find your recent message from Cloudflare. If you cannot find the message, check your Spam folder.
2. Go to the link in the email.
3. Log in to Cloudflare to verify the email address associated with your account.

Note

If someone else used your email to sign up for a Cloudflare account, you can remove this account by going to our [unintended registration ↗](https://dash.cloudflare.com/unintended-registration) page and entering the information at the end of your confirmation email.

## Resend verification emails

If you cannot find your verification email or your email has expired, request another verification email:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile**.
3. For **Email Address**, select **Send verification email** (if this option is not available, your email has already been verified).

## Verification issues

If you experience issues with your verification link, you might have already verified your email address.

To check your verification:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile**.
3. For **Email Address**, your email address will have `(verified)` added after it.

If your email is still not verified, try clicking the verification link in a different browser or a private window.

If this still does not work, try [resending](#resend-verification-emails) the verification email to get a new verification link.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/#page","headline":"Verify email address","description":"Confirm the email address on your Cloudflare account to unlock dashboard features like adding members and updating preferences.","url":"https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Add, configure, and manage your domains (zones) on Cloudflare, including DNS setup, subdomains, and SSL certificates.
title: Domains
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Domains

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

A *domain* or *domain name* (also known as a *zone*) is the location of a website or application, or what an end user types into their browser to get to your website (`example.com`).

## Get a domain name

You can purchase domain names for your website from a variety of places. Cloudflare offers an at-cost registrar service to [purchase new domain names](https://developers.cloudflare.com/registrar/get-started/register-domain/) or [transfer existing domain names](https://developers.cloudflare.com/registrar/get-started/transfer-domain-to-cloudflare/).

Refer to [Account and domain management best practices](https://developers.cloudflare.com/fundamentals/reference/best-practices/) for a detailed list of ways to protect your account and domain.

## Host your domain

A web host keeps your website online so visitors can reach it via the domain name.

Cloudflare does not offer web hosting for most websites, though you can deploy and host JAMstack sites with [Cloudflare Pages](https://developers.cloudflare.com/pages/).

## Add a domain to Cloudflare

For help onboarding a domain to Cloudflare's CDN, refer to our [setup guide](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/).

You will need to [update your domain's nameservers](https://developers.cloudflare.com/dns/zone-setups/full-setup/) and [proxy](https://developers.cloudflare.com/dns/proxy-status/) your web traffic to benefit from caching, DDoS protection, Argo Smart Routing, and other [application security and performance products](https://developers.cloudflare.com/directory/?product-group=Application+performance%2CApplication+security).

## Get free SSL certificates

Cloudflare offers free, unshared, publicly trusted [Universal SSL certificates](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/) to all Cloudflare domains.

## Manage subdomains

For more details about subdomains (`www.example.com` or `blog.example.com`), refer to [Manage subdomains](https://developers.cloudflare.com/fundamentals/manage-domains/manage-subdomains/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/#page","headline":"Domains","description":"Add, configure, and manage your domains (zones) on Cloudflare, including DNS setup, subdomains, and SSL certificates.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: To add multiple sites to Cloudflare at once and more efficiently, you can do so via the Cloudflare API.
title: Add multiple sites via automation
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Add multiple sites via automation

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/add-multiple-sites-automation/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

To add multiple sites to Cloudflare at once and more efficiently, you can do so via the Cloudflare API.

Adding multiple sites can be useful when you:

- Have multiple domains mapping back to a single, canonical domain (common for domains in different countries - such as `.com.au`, `.co.uk` - that you want protected by Cloudflare).
- Are a [partner ↗](https://www.cloudflare.com/partners/), agency, or IT consultancy, and manage multiple domains on behalf of your customers.
- Are moving an existing set of sites over to Cloudflare.

Using the API will allow you to add multiple sites quickly and efficiently, especially if you are already familiar with [how to change your nameservers](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/) or [add a DNS record](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/).

This tutorial assumes domains will be added using a [primary DNS setup (full)](https://developers.cloudflare.com/dns/zone-setups/full-setup/).

---

## Prerequisites

To add multiple sites to Cloudflare via automation, you need:

- An existing [Cloudflare account](https://developers.cloudflare.com/fundamentals/account/create-account/).
- Command line with `curl`
- A Cloudflare [API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) with one of the following permissions:
  - Zone-level `Administrator`
  - Zone-level `Zone: Edit` and `DNS: Edit`
  - Account-level `Domain Administrator`
- To have disabled [DNSSEC](https://developers.cloudflare.com/dns/concepts/#dnssec) for each domain at your registrar (where you bought your domain name).<details><summary>

  Provider-specific DNSSEC instructions</summary>

This is not an exhaustive list, but the following links may be helpful:
  - <a href="https://support.dnsimple.com/articles/cloudflare-ds-record/">DNSimple ↗</a>
  - <a href="https://support.domaindiscount24.com/hc/articles/4409759478161">Domaindiscount24 ↗</a>
  - <a href="https://help.dreamhost.com/hc/en-us/articles/219539467">DreamHost ↗</a>
  - <a href="https://www.dynadot.com/help/question/set-DNSSEC">Dynadot ↗</a>
  - <a href="https://support.enom.com/support/solutions/articles/201000065386">Enom ↗</a>
  - <a href="https://docs.gandi.net/en/domain_names/advanced_users/dnssec.html">Gandi ↗</a>
  - <a href="https://www.godaddy.com/help/add-a-ds-record-23865">GoDaddy ↗</a>
  - <a href="https://www.hostinger.com/support/3667267-how-to-use-dnssec-records-at-hostinger/">Hostinger ↗</a>
  - <a href="https://support.hover.com/support/solutions/articles/201000064716">Hover ↗</a>
  - <a href="https://faq.infomaniak.com/2187">Infomaniak ↗</a>
  - <a href="https://www.inmotionhosting.com/support/edu/cpanel/enable-dnssec-cloudflare/">InMotion Hosting ↗</a>
  - <a href="https://kb.inwx.com/en-us/3-nameserver/131">INWX ↗</a>
  - <a href="https://joker.com/faq/books/jokercom-faq-en/page/dnssec">Joker.com ↗</a>
  - <a href="https://www.name.com/support/articles/205439058-managing-dnssec">Name.com ↗</a>
  - <a href="https://www.namecheap.com/support/knowledgebase/article.aspx/9722/2232/managing-dnssec-for-domains-pointed-to-custom-dns/">Namecheap ↗</a>
  - <a href="https://support.nameisp.com/knowledgebase/dns">NameISP ↗</a>
  - <a href="https://www.namesilo.com/support/v2/articles/domain-manager/ds-records">Namesilo ↗</a>
  - <a href="https://help.ovhcloud.com/csm/en-dns-secure-domain-dnssec?id=kb_article_view&amp;sysparm_article=KB0051637">OVH ↗</a>
  - <a href="https://support.squarespace.com/hc/articles/4404183898125-Nameservers-and-DNSSEC-for-Squarespace-managed-domains#toc-dnssec">Squarespace ↗</a>
  - <a href="https://registro.br/tecnologia/dnssec/?secao=tutoriais-dns">Registro.br ↗</a>
  - <a href="https://kb.porkbun.com/article/93-how-to-install-dnssec">Porkbun ↗</a> (do not fill out **keyData**)
  - <a href="https://www.transip.eu/knowledgebase/150-secure-domains-custom-nameservers-dnssec/">TransIP ↗</a></details>

Note

  If your previous provider allows you to add DNSKEY records on the zone apex and use these records in responses to DNS queries, refer to this [migration tutorial](https://developers.cloudflare.com/dns/dnssec/dnssec-active-migration/) to learn how to migrate a zone with DNSSEC enabled.

---

## 1. Add domains

1. Create a list of domains you want to add, each on a separate line (newline separated), stored in a file such as `domains.txt`.
2. Create a bash script `add-multiple-zones.sh` and add the following. Add `domains.txt` to the same directory or update its path accordingly.

```bash
  for domain in $(cat domains.txt); do
    printf "Adding ${domain}:\n"

    curl https://api.cloudflare.com/client/v4/zones \
    --header "Authorization: Bearer <API_TOKEN>" \
    --header "Content-Type: application/json" \
    --data '{
      "account": {
        "id":"<ACCOUNT_ID>"
      },
      "name": "'"$domain"'",
      "type": "full"
    }'

    printf "\n\n"
  done
```

3. Open the command line and run:

```sh
bash add-multiple-zones.sh
```

Caution

There are limitations on the number of domains you can add at a time. Refer to [limitations](#limitations) for details.

After adding a domain, it will be in a [`Pending Nameserver Update`](https://developers.cloudflare.com/dns/zone-setups/reference/domain-status/) state.

### Additional options

#### jq

[`jq` ↗](https://jqlang.github.io/jq/) is a command-line tool that parses and beautifies JSON outputs.

This tool is a requirement to complete any additional option steps in this tutorial.

```sh
echo '{"foo":{"bar":"foo","testing":"hello"}}' | jq .
```

Refer to `jq` [documentation ↗](https://jqlang.github.io/jq/manual/#basic-filters) for more information.

#### Quick scan

Cloudflare offers a [quick scan](https://developers.cloudflare.com/dns/zone-setups/reference/dns-quick-scan/) that helps populate a zone's DNS records. This scan is a best effort attempt based on a predefined list of commonly used record names and types.

This API call requires the domain ID. This can be found in the following locations:

- [Create Zone](https://developers.cloudflare.com/api/resources/zones/methods/create/#Request)
- [List Zones](https://developers.cloudflare.com/api/resources/zones/methods/list/)

Using `jq` with the first option above, modify your script `add-multiple-zones.sh` to extract the domain ID and run a subsequent API call to quick scan DNS records.

```js
  for domain in $(cat domains.txt); do
    printf "Adding ${domain}:\n"

    add_output=`curl https://api.cloudflare.com/client/v4/zones \
      --header "Authorization: Bearer <API_TOKEN>" \
      --header "Content-Type: application/json" \
      --data '{
        "account": {
          "id":"<ACCOUNT_ID>"
        },
        "name": "'"$domain"'",
        "type": "full"
      }'`

    echo $add_output | jq .

    domain_id=`echo $add_output | jq -r .result.id`

    printf "\n\n"
    printf "DNS quick scanning ${domain}:\n"

    scan_output=`curl --request POST https://api.cloudflare.com/client/v4/zones/$domain_id/dns_records/scan \
      --header "X-Auth-Email: <EMAIL>" \
      --header "X-Auth-Key: <API_KEY>"`

    echo $scan_output | jq .

  done
```

## 2. Update nameservers

For each domain to become active on Cloudflare, it must be activated in either [Full setup](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/) or [Partial setup](https://developers.cloudflare.com/dns/zone-setups/partial-setup/setup/). The following script will output a list containing the nameservers associated with each domain.

You can find your zones nameservers in the following locations:

- [Create Zone](https://developers.cloudflare.com/api/resources/zones/methods/create/#Request)
- [Zone Details](https://developers.cloudflare.com/api/resources/zones/methods/get/)

1. Modify your script `add-multiple-zones.sh` to print a CSV with data from the `Create Zone` JSON response.

```js
  for domain in $(cat domains.txt); do
    printf "Adding ${domain}:\n"

    add_output=`curl https://api.cloudflare.com/client/v4/zones \
      --header "Authorization: Bearer <API_TOKEN>" \
      --header "Content-Type: application/json" \
      --data '{
        "account": {
          "id": "<ACCOUNT_ID>"
        },
        "name": "'"$domain"'",
        "type": "full"
      }'`

    # Create csv of nameservers
    echo $add_output | jq -r '[.result.name,.result.id,.result.name_servers[]] | @csv' >> /tmp/domain_nameservers.csv

    domain_id=`echo $add_output | jq -r .result.id`

    printf "\n\n"
    printf "DNS quick scanning ${domain}:\n"

    scan_output=`curl --request POST https://api.cloudflare.com/client/v4/zones/$domain_id/dns_records/scan \
      --header "X-Auth-Email: <EMAIL>" \
      --header "X-Auth-Key: <API_KEY>"`

    echo $scan_output | jq .

  done

  printf "name_servers are saved in /tmp/domain_nameservers"
  cat /tmp/domain_nameservers.csv
```

| ID | ZONE | NAME SERVERS |
| --- | --- | --- |
| \<ZONE\_ID> | `example.com` | `arya.ns.cloudflare.com`, `tim.ns.cloudflare.com` |

2. Use the values in the **NAME SERVERS** column to [update the nameservers](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/#34-update-your-registrar) at the registrar of each domain.

---

## Limitations

There are limitations on the number of domains you can add at a time - specifically, you can only sign up a maximum of 25 domains every 10 minutes.

In addition, if you have over 50 domains and, of those domains, more are pending than active, you will be blocked from adding more. We recommend waiting until your pending sites have been activated before adding more.

## Common issues

If any errors were returned in this process, the domain may not be registered (or only just registered), be a subdomain, or be otherwise invalid. For more details, refer to [Cannot add domain](https://developers.cloudflare.com/dns/zone-setups/troubleshooting/cannot-add-domain/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/add-multiple-sites-automation/#page","headline":"Add multiple sites via automation","description":"To add multiple sites to Cloudflare at once and more efficiently, you can do so via the Cloudflare API.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/add-multiple-sites-automation/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to onboard your domain to Cloudflare, to speed up and protect your website or application.
title: Onboard a domain
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Onboard a domain

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

After you onboard your domain, Cloudflare will act as the [reverse proxy](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-reverse-proxy) and [DNS provider](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-dns-provider) for your site.

This guide applies to existing domains that were purchased from another provider, and will use a [full DNS setup](https://developers.cloudflare.com/dns/zone-setups/full-setup), which is the most common configuration. To set this up, you will have to complete a few steps at Cloudflare, but also update some settings at your domain registrar<sup>[1](#user-content-fn-1)</sup>, and at your previous DNS provider (if you were using one).

Cloudflare Registrar

If you need a new domain, you can [buy one from Cloudflare](https://developers.cloudflare.com/registrar/get-started/register-domain/) without markup fees. We will complete the rest of this setup for you.

## 1. Add your domain

1. Log in to the Cloudflare dashboard. [Go to **Domains** ↗](https://dash.cloudflare.com/?to=/:account/domains/overview)
2. Select **Onboard a domain**.
3. Enter your website's apex domain (for example, `example.com`), choose how you would like to add your DNS records, and select **Continue**.

   Note

   If Cloudflare is unable to identify your domain as a registered domain, make sure you are using an existing [top-level domain ↗](https://www.cloudflare.com/learning/dns/top-level-domain/) ( `.com`, `.net`, `.biz`, or others).

   Cloudflare requires your apex domain to be one level below a valid TLD defined in the [Public Suffix List (PSL) ↗](https://github.com/publicsuffix/list/blob/master/public_suffix_list.dat). For instance, `example.com` is valid but `level2.example.com`<sup>[2](#user-content-fn-2)</sup> or `example.home` are not.
4. Select a [plan ↗](https://www.cloudflare.com/plans/#compare-features).

## 2. Review DNS records

Your DNS records must be accurate for your domain to work properly. If you don't know what DNS records are, consider the video below for a quick explanation.

1. Since the quick scan is not guaranteed to find all existing DNS records, you need to review your records, paying special attention to the following:
   - [Zone apex records ( `example.com`)](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-zone-apex/)<details><summary>

     More about zone apex records</summary>

Zone apex refers to the domain or subdomain that you are <a href="https://developers.cloudflare.com/dns/concepts/#zone">adding to Cloudflare</a>.

     Usually, the zone apex record makes your domain accessible by visitors. In this case, the necessary record type (<a href="https://developers.cloudflare.com/dns/manage-dns-records/reference/dns-record-types/#ip-address-resolution">A, AAAA, or CNAME</a>) and its content will depend on the provider that <a href="https://developers.cloudflare.com/fundamentals/manage-domains/#host-your-domain">hosts</a> your website or application.

     If you are using Cloudflare Workers, refer to <a href="https://developers.cloudflare.com/workers/configuration/routing/custom-domains/">Custom domains</a>.

     If you are using other providers, look for their guidance on how to connect domains managed on external DNS services. Then, make sure you have the records required by your hosting provider on your <a href="https://developers.cloudflare.com/dns/manage-dns-records/#dns-records-table">DNS records table</a> at Cloudflare.</details>

   - [Subdomain records ( `www.example.com` or `blog.example.com`)](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-subdomain/)<details><summary>

     More about subdomain records</summary>

Most subdomains serve a specific purpose within the overall context of your website. For example, <code>blog.example.com</code> might be your blog, <code>support.example.com</code> could be your customer help portal, and <code>store.example.com</code> would be your e-commerce site.

     Even if you do not require specific subdomains, you might want to set up at least a subdomain record on <code>www</code>. It will usually point to the same content as what you have on the apex domain (<code>example.com</code>) or use a <a href="https://developers.cloudflare.com/fundamentals/manage-domains/manage-subdomains/#redirect-a-subdomain-to-the-apex-domain">redirect</a>. Having a subdomain DNS record on <code>www</code> helps guarantee that a visitor who types <code>www.</code> in front of your domain address can still find your website or application.</details>

   - [Email records](https://developers.cloudflare.com/dns/manage-dns-records/how-to/email-records/)<details><summary>

     More about email records</summary>

Depending on your business needs, you can configure DNS records so that you can use your domain to receive emails, receive and send emails from your domain, or prevent others from sending emails on your behalf (spoofing).

     Below are some examples of what those DNS records might look like. The exact values for your DNS mail records depend on your email provider. If you have issues, review the <a href="https://developers.cloudflare.com/dns/troubleshooting/email-issues/">Troubleshooting</a> and contact your email service provider to confirm your DNS records are correct.

     | Type | Name | Content | Proxy status | TTL |
     | --- | --- | --- | --- | --- |
     | A | <code>mail</code> | <code>192.0.2.1</code> | DNS Only | Auto |
     | MX | <code>example.com</code> | <code>5 john.mx.example-server.test</code> | DNS Only | Auto |
     | TXT | <code>_dmarc</code> | <code>"v=DMARC1; p=reject; sp=...</code> | DNS Only | Auto |
     | TXT | <code>*._domainkey</code> | <code>"v=DKIM1; k=rsa; p=..."</code> | DNS Only | Auto |
     | TXT | <code>example.com</code> | <code>"v=spf1 ip4:..."</code> | DNS Only | Auto |</details>

Note

   If you activate your domain on Cloudflare *without* setting up the correct DNS records for your domain, your visitors may experience [DNS\_PROBE\_FINISHED\_NXDOMAIN](https://developers.cloudflare.com/dns/troubleshooting/dns-probe-finished-nxdomain/) errors.
2. If you find any missing records, [manually add](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/) those records.
3. Depending on your site setup, you may want to adjust the [proxy status](https://developers.cloudflare.com/dns/proxy-status/) for certain `A`, `AAAA`, or `CNAME` records. Each record has a proxy status toggle:
   - **Proxied** (orange cloud): web traffic goes through the Cloudflare network, which provides caching, DDoS protection, and other security features.
   - **DNS only** (gray cloud): Cloudflare returns the DNS record value but does not proxy traffic. Use this for CNAME records that verify your domain for third-party services.
4. Select **Continue**.

## 3. Update nameservers

Your domain will be assigned two authoritative Cloudflare nameservers. Nameservers are specialized servers that store your domain's DNS records and "answer" requests from browsers by providing the specific IP address needed to connect to your website.

Usually, you need to add these nameservers at your registrar. Refer to [Update nameservers](https://developers.cloudflare.com/dns/nameservers/update-nameservers/) for more information.

<details>

<summary>

Provider-specific instructions

</summary>

This is not an exhaustive list of provider-specific instructions, but the following links may be helpful:

- <a href="https://www.ionos.com/help/domains/using-your-own-name-servers/using-your-own-name-servers-for-a-domain/">Ionos ↗</a>
- <a href="https://help.101domain.com/kb/managing-name-server-records">101Domain ↗</a>
- <a href="https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-name-servers-glue-records.html#domain-name-servers-glue-records-adding-changing">Amazon ↗</a>
- <a href="https://help.blacknight.com/hc/articles/4413036322321-How-do-I-change-the-nameservers-for-my-domain">Blacknight ↗</a>
- <a href="https://www.bluehost.com/help/article/custom-nameservers">BlueHost ↗</a>
- <a href="https://directnic.com/knowledge/article/33:how%2Bdo%2Bi%2Bmodify%2Bname%2Bservers%2Bfor%2Bmy%2Bdomain%2Bname%253F">DirectNIC ↗</a>
- <a href="http://www.dnsmadeeasy.com/support/faq/">DNSMadeEasy ↗</a>
- <a href="https://www.domain.com/help/article/domain-management-how-to-update-nameservers">Domain.com ↗</a>
- <a href="https://www.dotster.com/help/article/domain-management-how-to-update-nameservers">Dotster ↗</a>
- <a href="https://help.dreamhost.com/hc/en-us/articles/360038897151">DreamHost ↗</a>
- <a href="https://kb.easydns.com/knowledge/settingchanging-nameservers/">EasyDNS ↗</a>
- <a href="https://help.enom.com/hc/en-us/articles/115000486451-Nameservers-NS">Enom ↗</a>
- <a href="https://www.fastdomain.com/hosting/help/transfer_client_start">Fast Domain ↗</a>
- <a href="https://billing.flokinet.is/index.php?rp=/knowledgebase/57/Nameserver-and-DNS-records.html">FlokiNET ↗</a>
- <a href="https://docs.gandi.net/en/domain_names/common_operations/changing_nameservers.html">Gandi ↗</a>
- <a href="https://www.godaddy.com/help/change-nameservers-for-your-domain-names-664">GoDaddy ↗</a>
- <a href="https://www.hostgator.com/help/article/changing-name-servers">HostGator ↗</a>
- <a href="https://hostico.ro/docs/setarea-nameserverelor-din-contul-de-client-hostico/">Hostico ↗</a>
- <a href="https://my.hostmonster.com/cgi/help/222">HostMonster ↗</a>
- <a href="https://support.hover.com/support/solutions/articles/201000064742-changing-your-domain-nameservers">Hover ↗</a>
- <a href="https://faq.internetbs.net/hc/en-gb/articles/4516921367837-How-to-update-Nameservers-for-a-domain">Internetdbs ↗</a>
- <a href="https://www.ipage.com/help/article/domain-management-how-to-update-nameservers">iPage ↗</a>
- <a href="https://support.melbourneit.au/docs/how-do-i-manage-my-dns-on-cpanel">MelbourneIT ↗</a>
- <a href="https://support.moniker.com/hc/en-gb/articles/10101271418653-How-to-update-Nameservers-for-a-domain">Moniker ↗</a>
- <a href="https://www.name.com/support/articles/205934457-registering-custom-nameservers">Name.com ↗</a>
- <a href="https://www.namecheap.com/support/knowledgebase/article.aspx/767/10/how-can-i-change-the-nameservers-for-my-domain">Namecheap ↗</a>
- <a href="https://www.networksolutions.com/manage-it/edit-nameservers.jsp">Network Solutions ↗</a>
- <a href="https://docs.ovh.com/gb/en/domains/web_hosting_general_information_about_dns_servers/#step-2-edit-your-domains-dns-servers">OVH ↗</a>
- <a href="https://kb.porkbun.com/article/22-how-to-change-your-nameservers">Porkbun ↗</a>
- <a href="https://support.rackspace.com/how-to/rackspace-name-servers/">Rackspace ↗</a>
- <a href="https://www.register.com/knowledge">Register ↗</a>
- <a href="https://support.squarespace.com/hc/articles/4404183898125-Nameservers-and-DNSSEC-for-Squarespace-managed-domains#toc-open-the-domain-s-advanced-settings">Squarespace ↗</a>
- <a href="https://kb.site5.com/dns-2/custom-nameservers/">Site5 ↗</a>
- <a href="https://cloud.ibm.com/docs/dns?topic=dns-add-edit-or-delete-custom-name-servers-for-a-domain">Softlayer ↗</a>
- <a href="https://helpcenter.yola.com/hc/articles/360012492660-Changing-your-name-servers">Yola ↗</a>

</details>

DNSSEC

If your domain uses [DNSSEC](https://developers.cloudflare.com/dns/dnssec/), you must turn it off at your registrar before changing nameservers. Changing nameservers while DNSSEC is active can cause your domain to become unreachable. You can [re-enable DNSSEC through Cloudflare](https://developers.cloudflare.com/dns/dnssec/#enable-dnssec) after your domain is active.

## 4. Complete SSL/TLS setup

To prevent insecure connections and visitor browser errors, review your [SSL/TLS certificates](https://developers.cloudflare.com/ssl/get-started/). Many Cloudflare services will automatically protect and speed up your web traffic after your nameservers are updated and your DNS records are proxied. For further guidance, refer to [Proxy status](https://developers.cloudflare.com/dns/proxy-status/).

If you encounter unexpected results when changing your nameservers, refer to the [DNS Full Setup troubleshooting](https://developers.cloudflare.com/dns/zone-setups/full-setup/troubleshooting/).

## Further options

### Other DNS setups

- To use Cloudflare as a reverse proxy but maintain your DNS provider, refer to [partial setup](https://developers.cloudflare.com/dns/zone-setups/partial-setup/).
- To use one or more DNS providers, refer to [DNS Zone transfers](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/).
- Enterprise customers can onboard lower-level subdomains using [Subdomain setup](https://developers.cloudflare.com/dns/zone-setups/subdomain-setup/).

### Minimize downtime

- If your domain is particularly sensitive to downtime, review our suggestions to [minimize downtime](https://developers.cloudflare.com/fundamentals/performance/minimize-downtime/).

## Footnotes

1. The provider you purchased your domain from [↩](#user-content-fnref-1)
2. Enterprise customers can onboard these using [Subdomain setup](https://developers.cloudflare.com/dns/zone-setups/subdomain-setup/). [↩](#user-content-fnref-2)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/add-site/#page","headline":"Onboard a domain","description":"Learn how to onboard your domain to Cloudflare, to speed up and protect your website or application.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/add-site/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Version Management allows you to safely test, deploy, and roll back changes to your zone configurations. By default, Version Management is not enabled on a zone.
title: Change your domain version
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Change your domain version

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/domain-version/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

[Version Management](https://developers.cloudflare.com/version-management/) is available for Enterprise customers and allows you to safely test, deploy, and roll back changes to your zone configurations.

## Enable versioning

By default, Version Management is not enabled on a zone.

To enable [Version Management ↗](https://dash.cloudflare.com/?to=/:account/:zone/versioning):

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select your account and zone.
3. Go to **Version Management**.
4. Select **Enable versioning**.

Note

If you cannot enable Version Management, make sure your zone, account, and user meet the [requirements](https://developers.cloudflare.com/version-management/#requirements).

## (Optional) Create additional environments

Once you [enable](https://developers.cloudflare.com/version-management/how-to/enable/) Version Management, Cloudflare will automatically create:

- **Version Zero**, think about this as the configuration of your current zone. Once default environments are created, Version Zero is automatically deployed to them, guaranteeing no disruption in your live traffic. This Version is also permanently editable. In case you decide to disable Zone Versioning, Version Zero will become your zone again.
- **Global Configuration**, you can find all the configurations here that are not supported by Version Management.

Important

Any changes made to the **Global Configuration** will immediately apply to your zone and all versions of your zone, affecting live traffic.

On the Environments page, you can create default environments for **Production**, **Staging**, and **Development**.

These environments each serve a specific purpose and are accessed differently:

- **Development**: Meant to validate that changes work correctly. The default [traffic filters](https://developers.cloudflare.com/version-management/reference/traffic-filters/) are that the `cf.zone.name` matches your zone name, the `Edge Server IP` is a specific value, and the request contains a cookie with `development=true`.
- **Staging**: Meant to test changes before sending them to **Production**. The default [traffic filters](https://developers.cloudflare.com/version-management/reference/traffic-filters/) are that the `cf.zone.name` matches your zone name and the `Edge Server IP` is a specific value.
- **Production**: Meant to hold all configurations applied to your zone. You cannot edit the [traffic filters](https://developers.cloudflare.com/version-management/reference/traffic-filters/) - which are just that the `cf.zone.name` is equal to your zone's name - and cannot delete this environment. This environment has a read-only check enabled, so versions promoted to this environment will become read-only as well.

Based on your organization's needs, you may need to create additional environments to test and roll out changes.

  

For more details, refer to [Create environment](https://developers.cloudflare.com/version-management/how-to/environments/#create-environment).

## Update configurations

Before making changes, make sure you are inside the correct version of your zone.

To change between different versions of your zone:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select your account and a domain that has version management. The Global Configuration of your domain will load.
3. Go to the product or feature you wish to modify.
   - **If the product or feature is available for versioning**: The last version you were working on will load.
   - **If the product or feature is NOT available for versioning**: Your Global Configuration will load, and any changes you make will impact live traffic.
4. Ensure that the configuration or version displayed in the domain summary bar is the one you would like to work on. If not, select the version in the domain summary bar to open the version switcher.

Note

If you are on a product that is not available for versioning, you will not be able to switch to another version, and can only make changes under your Global Configuration.

The Domain Summary is accessible from all pages and allows you to quickly switch between versions and domains.

![Switch between versions of your configuration](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1688,height=934,format=webp/_astro/configurable-versions.BsHb-j9S.png)

From within a version, you can update configurations just as you would with your normal zone configurations. Any changes are saved automatically.

## Test version

Once you have made changes to a version, apply that version to your lowest-ranked environment.

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select your account and zone.
3. Go to **Version Management**.
4. Go to **Environments**.
5. On your lowest-ranked environment, use the **Version** dropdown to select your desired version.

To test your version, send requests to that environment that match the pattern specified in its [traffic filters](https://developers.cloudflare.com/version-management/reference/traffic-filters/).

For more details about what happens to these requests, refer to the version's [metrics](https://developers.cloudflare.com/version-management/how-to/versions/#view-metrics).

## Promote version

Next, [promote](https://developers.cloudflare.com/version-management/how-to/environments/#change-environment-version) your version through your different environments.

To promote a version:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select your account and zone.
3. Go to **Version Management**.
4. Select **Environments**.
5. On the environment in which you tested the version, select **Promote**. This option will only be available if the lower-ranked environment has a different version than the higher-ranked environment.

Promoting a version to a read-only environment will make the version permanently read-only.

After promoting to each environment, test the new version in your new environment.

## Repeat

For new changes to your zone, [create a new version](https://developers.cloudflare.com/version-management/how-to/versions/#create-version) and repeat this process.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/domain-version/#page","headline":"Change your domain version","description":"Version Management allows you to safely test, deploy, and roll back changes to your zone configurations. By default, Version Management is not enabled on a zone.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/domain-version/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Create subdomains, set up redirects between subdomains and apex domains, and configure SSL/TLS for subdomains on Cloudflare.
title: Manage subdomains
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Manage subdomains

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/manage-subdomains/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Once you have [added your domain to Cloudflare](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/) and [updated your nameservers](https://developers.cloudflare.com/dns/zone-setups/full-setup/), you also might want to set up a subdomain.

Most subdomains serve a specific purpose within the overall context of your website. For example, `blog.example.com` might be your blog, `support.example.com` could be your customer help portal, and `store.example.com` would be your e-commerce site.

## Create a subdomain

If you have already added a subdomain at your host, create a corresponding [DNS A or CNAME record](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/) for that subdomain (`blog`, `store`).

## Set up redirects

### Redirect a subdomain to the apex domain

Sometimes, you might want all traffic to a subdomain (`www.example.com`) to actually go to your apex domain (`example.com`).

1. Create a [proxied DNS A record](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/) for your subdomain. This record can point to any IP address since all traffic will be redirected prior to reaching the address.

   | **Type** | **Name** | **IPv4 address** | **Proxy status** |
   | --- | --- | --- | --- |
   | A | `www` | `192.0.2.1` | Proxied |
2. Create a [Single Redirect](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/create-dashboard/) to forward traffic from your subdomain to your apex domain.

**When incoming requests match**

Using the Expression Editor:  
`(http.request.full_uri contains "www.example.com")`

**Then**

- **Type:** *Dynamic*
- **Expression:** `concat("https://","example.com",http.request.uri.path)`
- **Status code:** *301*

### Redirect the apex domain to a subdomain

Sometimes, you might want all traffic to your apex domain (`example.com`) to actually go to a subdomain (`www.example.com`).

1. If you have already added that subdomain at your host, create a corresponding [DNS A or CNAME record](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/) for that subdomain.
2. Create a proxied DNS A record for your apex domain. This record can point to any IP address since all traffic will be redirected prior to reaching the address.

   | **Type** | **Name** | **IPv4 address** | **Proxy status** |
   | --- | --- | --- | --- |
   | A | `@` | `192.0.2.1` | Proxied |
3. Create a [Single Redirect](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/create-dashboard/) to forward traffic from your apex domain to your subdomain.

**When incoming requests match**

Using the Expression Editor:  
`(lower(http.host) eq "example.com")`

**Then**

- **Type:** *Dynamic*
- **Expression:** `concat("https://","www.example.com",http.request.uri.path)`
- **Status code:** *301*

## SSL/TLS for subdomains

If your main domain is using Cloudflare's [Universal SSL certificate](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/), that certificate also covers all first-level subdomains (`blog.example.com`).

For deeper subdomains (`dev.blog.example.com`), use a [different type of certificate](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/limitations/#full-setup).

Proxy status

Cloudflare can only serve an SSL/TLS certificate for a DNS record when you set the record's [proxy status](https://developers.cloudflare.com/dns/proxy-status/) to **Proxied**. If you do not do this, the origin server your record points to will be responsible for supporting SSL/TLS connections.

## Customize subdomain behavior

If you want to customize Cloudflare settings for individual subdomains, your approach will vary depending on your plan.

Enterprise customers can set up custom settings and access for a specific subdomain within Cloudflare with [Subdomain support](https://developers.cloudflare.com/dns/zone-setups/subdomain-setup/).

All other customers can set up subdomain-specific [Configuration Rules](https://developers.cloudflare.com/rules/configuration-rules/) or [Page Rules](https://developers.cloudflare.com/rules/page-rules/) to alter Cloudflare settings.

If you want a subdomain's DNS settings managed totally outside of Cloudflare — meaning this subdomain can be managed by individuals without access to your Cloudflare account — refer to [Delegating subdomains outside of Cloudflare](https://developers.cloudflare.com/dns/manage-dns-records/how-to/subdomains-outside-cloudflare/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/manage-subdomains/#page","headline":"Manage subdomains","description":"Create subdomains, set up redirects between subdomains and apex domains, and configure SSL/TLS for subdomains on Cloudflare.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/manage-subdomains/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to transfer a domain between Cloudflare accounts, including requirements, DNS settings, and SSL/TLS certificate management for seamless migration.
title: Move a domain between Cloudflare accounts
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Move a domain between Cloudflare accounts

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/move-domain/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

You will have to move or transfer domains from one Cloudflare account to another if you:

- Manage a multi-user organization and need to segment domain access by user.
- Receive a `Cloudflare is already hosting under a different account` error.
- Lose access to your email address or Cloudflare account (though you can also use the [backup codes](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/#use-a-backup-code) if you have two-factor authentication enabled).
- Registered a Cloudflare account with a typo in your email.

Caution

If your domain is registered with Cloudflare Registrar, you need to submit a manual request to transfer the domain and its registration to a new account.

Refer to [Transfer a Cloudflare Registrar domain registration between accounts](https://developers.cloudflare.com/registrar/account-options/inter-account-transfer/) to complete this process.

## Requirements

To transfer a domain from one Cloudflare account to another, you will need:

- Access to your domain registrar. If your domain is using Cloudflare Registrar, refer to [Transfer a Cloudflare Registrar domain registration between accounts](https://developers.cloudflare.com/registrar/account-options/inter-account-transfer/).
- At least one Cloudflare account associated with the domain.

## Transfer your domain

Caution

Before transferring an active Cloudflare domain to another Cloudflare account, you must remove any [DNSSEC configurations](https://developers.cloudflare.com/dns/dnssec/) and [add-ons or subscriptions](https://developers.cloudflare.com/billing/manage/cancel-subscription/).

We also recommend [exporting](https://developers.cloudflare.com/dns/manage-dns-records/how-to/import-and-export/#export-records) the DNS records of your zone while it is in the previous account. Then, you can [import](https://developers.cloudflare.com/dns/manage-dns-records/how-to/import-and-export/#import-records) the correct DNS records into the new account. If you miss this step, Cloudflare will import your proxied DNS records, which might cause your domain to experience a [1000 error](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/).

If you still have access to your previous Cloudflare account, you can copy over the Cloudflare account settings manually. You must reissue [SSL/TLS certificates](#issue-new-certificates) and [recreate and validate DNS records](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/) when transferring domains between Cloudflare accounts.

If you lose access to the email address associated with your Cloudflare account and do not have backup codes, you will need to manually transfer your domain to a new Cloudflare account associated with a different email address.

The domain transfer process depends on your DNS settings. If Cloudflare is your authoritative DNS provider (that is, your domain nameservers point to Cloudflare), you must:

1. [Create a new Cloudflare account](https://developers.cloudflare.com/fundamentals/account/create-account/) or log in to an existing Cloudflare account.
2. [Add the domain](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/) to the account (as if you were adding it for the first time).
3. Log in to your domain registrar account and [update the nameservers](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/) to the provided Cloudflare nameservers.
4. Finalize the nameserver update by selecting your domain in the dashboard > **Overview** > **Re-check now**.

Once the Cloudflare network recognizes the nameserver change, the domain in the new account will be marked as **Active**. While the domain in the new account is **Pending**, it cannot proxy traffic through Cloudflare and the origin IP addresses will be returned until the domain is marked as **Active**.

In the old account, the domain will be marked as **Moved Away**. After seven days in **Moved Away** status, the domain will be marked as **Deleted**. After seven days in the **Deleted** status, the domain will be permanently removed.

For more information, refer to [Zone status](https://developers.cloudflare.com/dns/zone-setups/reference/domain-status/).

## Issue new certificates

SSL/TLS certificates associated with your previous Cloudflare account will not be transferred to your new account. If your site requires an SSL/TLS certificate prior to domain transfer, refer to [Minimize downtime](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/enable-universal-ssl/#minimize-downtime).

If you were using [custom certificates](https://developers.cloudflare.com/ssl/edge-certificates/custom-certificates/), you will need to delete them from the previous zone and upload them to the new zone. You can upload the certificates while the new zone is in **Pending** status - if you do so, once you upload the certificates, they will have a [**Holding Deployment**](https://developers.cloudflare.com/ssl/reference/certificate-statuses/#custom-certificates) status and will become active once the zone is active.

You can order an [advanced certificate](https://developers.cloudflare.com/ssl/edge-certificates/advanced-certificate-manager/) prior to transferring your domain. ACM certificates will automatically deploy to active domains.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/move-domain/#page","headline":"Move a domain between Cloudflare accounts","description":"Learn how to transfer a domain between Cloudflare accounts, including requirements, DNS settings, and SSL/TLS certificate management for seamless migration.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/move-domain/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Temporarily pause Cloudflare on your domain to send traffic directly to your origin server for troubleshooting.
title: Pause Cloudflare
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Pause Cloudflare

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/pause-cloudflare/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

To troubleshoot your site, you can pause Cloudflare globally. This will send traffic directly to your origin web server instead of Cloudflare's reverse proxy. Paused domains also cannot use Cloudflare services like [Rules](https://developers.cloudflare.com/rules/), [WAF](https://developers.cloudflare.com/waf/), and [SSL/TLS certificates](https://developers.cloudflare.com/ssl/edge-certificates/). Consider turning on [Development Mode](https://developers.cloudflare.com/fundamentals/manage-domains/pause-cloudflare/#enable-development-mode) to bypass caching while preserving protection.

1. In the Cloudflare dashboard, go to the **Account home** page and select your account and domain. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Within **Overview**, choose **Advanced Actions** > **Pause Cloudflare on Site**.

The process of pausing Cloudflare takes five minutes or less. This approach is preferable to [changing nameservers](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/), which can cause propagation delays of several hours.

Note

Disabling a zone does not impact Spectrum applications.

---

## Alternatives to global pause

### Disable proxy on DNS records

Instead of pausing Cloudflare globally, you can disable the proxy on individual records:

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and select your account and domain.
2. Go to **DNS** > **Records**. Choose the record and select **Edit**.
3. Toggle **Proxy Status** to **Off**.

Adjusting the proxy status will prevent that record from using Cloudflare services like [Rules](https://developers.cloudflare.com/rules/), [WAF](https://developers.cloudflare.com/waf/), and [SSL/TLS certificates](https://developers.cloudflare.com/ssl/edge-certificates/).

### Enable Development Mode

To troubleshoot caching issues, you could [enable Development Mode](https://developers.cloudflare.com/cache/reference/development-mode/). This will bypass Cloudflare's cache while still preserving Cloudflare services like [Rules](https://developers.cloudflare.com/rules/), [WAF](https://developers.cloudflare.com/waf/), and [SSL/TLS certificates](https://developers.cloudflare.com/ssl/edge-certificates/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/pause-cloudflare/#page","headline":"Pause Cloudflare","description":"Temporarily pause Cloudflare on your domain to send traffic directly to your origin server for troubleshooting.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/pause-cloudflare/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Set up domain redirects in Cloudflare to forward traffic from an alias domain to your primary domain using DNS records and redirect rules.
title: Redirect one domain to another
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Redirect one domain to another

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/redirect-domain/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If you have an alias domain that only forwards traffic to another domain (that is, the domain does not have an associated origin server of its own), you can set up redirects directly within Cloudflare.

1. [Add](https://developers.cloudflare.com/fundamentals/manage-domains/#add-a-domain-to-cloudflare) your alias domain (for example, `previous.com`) to Cloudflare.
2. Make sure that your alias domain has a proxied [DNS A or CNAME record](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/) that properly resolves DNS queries. You may also want to include a subdomain DNS record for `www`.

   Use the IP address `192.0.2.1` for the `A` record. This address does not route traffic to an origin server but allows Cloudflare to apply rules, redirects, and Workers to incoming traffic. The equivalent IP address for an `AAAA` record is `100::`.

   | **Type** | **Name** | **IPv4 address** | **Proxy status** |
   | --- | --- | --- | --- |
   | A | `@` | `192.0.2.1` | Proxied |
   | A | `www` | `192.0.2.1` | Proxied |
3. Use [Redirect rules](https://developers.cloudflare.com/rules/url-forwarding/) to forward traffic from your alias domain to your other domain.

This example will redirect all requests for `smallshop.example.com` to a different hostname using HTTPS, keeping the original path and query string.

**When incoming requests match**

- **Field:** *Hostname*
- **Operator:** *equals*
- **Value:** `smallshop.example.com`

If you are using the Expression Editor, enter the following expression:  
`(http.host eq "smallshop.example.com")`

**Then**

- **Type:** *Dynamic*
- **Expression:** `concat("https://globalstore.example.net", http.request.uri.path)`
- **Status code:** *301*
- **Preserve query string:** Enabled

For example, the redirect rule would perform the following redirects:

| Request URL | Target URL | Status code |
| --- | --- | --- |
| `http://smallshop.example.com/` | `https://globalstore.example.net/` | `301` |
| `http://smallshop.example.com/admin/?logged_out=true` | `https://globalstore.example.net/admin/?logged_out=true` | `301` |
| `https://smallshop.example.com/?all_items=1` | `https://globalstore.example.net/?all_items=1` | `301` |
| `http://example.com/about/` | (unchanged) | n/a |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/redirect-domain/#page","headline":"Redirect one domain to another","description":"Set up domain redirects in Cloudflare to forward traffic from an alias domain to your primary domain using DNS records and redirect rules.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/redirect-domain/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Remove a domain from your Cloudflare account, including required steps for DNS, subscriptions, and registrar settings.
title: Remove a domain
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Remove a domain

Last updated Sep 8, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/remove-domain/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Consider the following sections on how you can remove domains from Cloudflare. Removing your domain cancels all active subscriptions on that domain, which will not be refunded per our [billing policy](https://developers.cloudflare.com/billing/understand/billing-policy/). If you add this domain back to Cloudflare later, you will need to re-purchase all subscriptions. Removing your domain from Cloudflare does not change your domain registration.

## Before removing your domain

If you experience website issues, we recommend [temporarily pausing Cloudflare](https://developers.cloudflare.com/fundamentals/manage-domains/pause-cloudflare/) to evaluate your website's performance.

If you have an Enterprise plan, you need to [change the zone plan](https://developers.cloudflare.com/billing/manage/change-plan/#change-plan-type) to **Free**.

If you need to re-add the domain in a different account, make sure the current settings have been saved. For example, you may [Import and export DNS records](https://developers.cloudflare.com/dns/manage-dns-records/how-to/import-and-export/).

Note

If you have just added a domain and have not configured its plan yet, the domain is in the `Initializing (Finish setup)` status and cannot be deleted. At this step you'll need to select a plan for this domain: the status will then change to `Pending` and you can then delete the domain. Please also note that domains in the `Initializing (Finish setup)` or `Pending` statuses will [automatically be deleted after 28 days](https://developers.cloudflare.com/dns/zone-setups/reference/domain-status/#initializing-finish-setup) if they do not activate.

### Actions outside of Cloudflare

- When you remove a domain from Cloudflare, it also prevents your domain from using Cloudflare for DNS resolution. To avoid DNS errors, update your nameservers at your domain registrar to use nameservers not owned by Cloudflare.
  - Refer to [Check if your nameservers are pointing to Cloudflare](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/#35-verify-changes) to confirm that your nameservers no longer point to Cloudflare.
- At your registrar, make sure you do not have a **DS** DNS record. This record enables [DNSSEC](https://developers.cloudflare.com/dns/dnssec/) and could prevent your DNS records from being changed.

### Actions within Cloudflare

- [Cancel active add-on subscriptions](https://developers.cloudflare.com/billing/manage/cancel-subscription/).
- [Delete all the Logpush jobs for that domain](https://developers.cloudflare.com/logs/logpush/examples/example-logpush-curl/#optional---delete-a-job)
- If you use Cloudflare Registrar:
  - [Disable domain auto-renewal](https://developers.cloudflare.com/registrar/account-options/renew-domains/) or [transfer your domain out of Cloudflare](https://developers.cloudflare.com/registrar/account-options/transfer-out-from-cloudflare/).
  - If the domain has already expired, it will be automatically removed from your account. Refer to [What happens when a domain expires?](https://developers.cloudflare.com/registrar/faq/#what-happens-when-a-domain-expires)
  - If the domain has not yet expired you can likely request deletion. Refer to [Delete a domain registration](https://developers.cloudflare.com/registrar/account-options/domain-management/#delete-a-domain-registration)
  - If enabled, disable DNSSEC. In your domain dashboard, go to **DNS** > **Settings**. Within **DNSSEC**, select **Disable DNSSEC**. Select **Confirm**.

## Remove a domain activated in Cloudflare

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com) and select your domain. [Go to **Overview** ↗](https://dash.cloudflare.com/?to=/:account/:zone/)
2. On the domain **Overview** page, find **Advanced Actions** and then select **Remove from Cloudflare**.

   Note

   If you are using an Enterprise domain, [change your domain plan](https://developers.cloudflare.com/billing/manage/change-plan/#change-plan-type) to **Free**, which will give you access to **Remove from Cloudflare**.  
     
   If this does not work, contact your account team.
3. Select **Confirm**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/remove-domain/#page","headline":"Remove a domain","description":"Remove a domain from your Cloudflare account, including required steps for DNS, subscriptions, and registrar settings.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/remove-domain/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-08","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Star up to ten frequently used domains per account in the Cloudflare dashboard for quick access.
title: Star domains
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Star domains

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-domains/star-zones/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

For quick access to commonly configured domains (also known as "zones"), star up to ten domains per account in the Cloudflare dashboard.

## Star a domain

To star a domain:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com).
2. Select your account and domain.
3. On the website **Overview**, select **Star**.

![Star domain on the Overview page of the website](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=972,height=367,format=webp/_astro/star-domain.CroUMQQh.png)

## Filter to starred domains

To view only starred domains in your account:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com).
2. Select your account.
3. On the account **Home**, select **Starred**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-domains/star-zones/#page","headline":"Star domains","description":"Star up to ten frequently used domains per account in the Cloudflare dashboard for quick access.","url":"https://developers.cloudflare.com/fundamentals/manage-domains/star-zones/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Create and integrate with Cloudflare using OAuth
title: OAuth Applications on Cloudflare
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# OAuth Applications on Cloudflare

Last updated Aug 14, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/oauth/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Availability

|  | Free | Pro | Business | Enterprise |
| --- | --- | --- | --- | --- |
| Availability | Yes | Yes | Yes | Yes |

OAuth allows third-party applications to securely access Cloudflare resources without requiring users to share long-lived API tokens. As an industry-standard protocol for authorization, OAuth 2.0 enables applications to obtain limited access to user accounts on an HTTP service.

[Learn more about OAuth ↗](https://www.cloudflare.com/learning/access-management/what-is-oauth/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/oauth/#page","headline":"OAuth Applications on Cloudflare","description":"Create and integrate with Cloudflare using OAuth","url":"https://developers.cloudflare.com/fundamentals/oauth/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn more about what it means to authorize a third-party application on Cloudflare
title: Authorizing an application
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Authorizing an application

Last updated Aug 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/oauth/authorizing-an-application/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Overview

When you authorize a third-party OAuth application, you grant it permission to access specific Cloudflare resources on your behalf. Cloudflare provides tools to view, manage, and revoke these authorizations at any time.

## Authorize a third-party application

When a third-party application requests access to your Cloudflare account, you will see a consent screen that displays:

- **Application name and logo**: The name and branding of the requesting application
- **Publisher domain**: The domain and verification status of the application publisher
- **Account selection**: Choose which Cloudflare account(s) the application can access
- **Requested permissions**: After selecting the account(s) the application may access, the specific scopes the application is requesting will be displayed before consent is complete. You can also decline optional permissions. To finish the authorization process, review the permissions the application is requesting and select “**Authorize**”

Each shield icon indicates who owns the application and whether its domain ownership is verified:

- **Green filled shield**: Cloudflare owns and manages the application.
- **Blue outlined shield**: A third-party application with verified ownership of its domain.
- **Amber filled shield**: A third-party application without verified ownership of a domain.

Domain verification only confirms that the application owner controls the displayed domain.

### Edit optional permissions

All requested permissions are selected by default. You can turn off optional permissions, but required permissions remain selected. Select **Read only** to include only optional scopes with read access, or **Full access** to include all optional scopes. If the client has no permissions configured as optional, editing controls do not appear.

1. In **Additional access**, select **Edit Permissions**.
2. Turn permissions on or off individually or by category.
3. Select **Authorize** to grant required and selected optional permissions.

## View and revoke authorized applications

Application authorizations may be viewed and revoked at any time from the profile page on the Cloudflare dashboard.

1. Log in to the Cloudflare dashboard.
2. [Go to **Manage OAuth authorizations** ↗](https://dash.cloudflare.com/?to=/profile/access-management/authorization)
3. View the list of applications you have authorized.
   - If you wish to revoke access to an application, select the “Revoke” button for that row

## Account administrator controls

If an account is not available for selection during the consent flow, it may be due to an administrator of that account disabling access to account resources via OAuth.

Account administrators can restrict OAuth applications from accessing account resources via **Manage Account** > **Members > Settings > Public OAuth App access**.

Caution

This will not prevent existing authorizations account members may already have in place, and will only prevent new authorizations from accessing account resources.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/oauth/authorizing-an-application/#page","headline":"Authorizing an application","description":"Learn more about what it means to authorize a third-party application on Cloudflare","url":"https://developers.cloudflare.com/fundamentals/oauth/authorizing-an-application/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Create an OAuth client that can access Cloudflare API resources on behalf of users.
title: Create your OAuth client
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Create your OAuth client

Last updated Aug 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/oauth/create-an-oauth-client/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Prerequisites

To create an OAuth client, you must have one of these roles for the associated account: Super Administrator, Administrator, or OAuth Client Write.

1. Log in to the Cloudflare dashboard.
2. Select your account.
3. Go to **Manage Account** > **OAuth clients**.
4. Select **Create client**.
5. Enter the required configuration details:
   - Client name
   - Response type
   - Grant type
   - Token authentication method
   - Redirect URLs
6. Optional: Add non-required fields.
7. Select **Continue** and define the scopes required for your client.
8. Optional: In **Choose optional scopes**, turn off **Required** for each scope you want to make optional. All scopes are required by default.
9. Select **Create client**.
10. Save your **Client ID** and **Client Secret** in a secure location.

[Go to **OAuth clients** ↗](https://dash.cloudflare.com/?to=/:account/oauth-clients)

To create OAuth clients with the Cloudflare API, create an API token with the `OAuth Clients Write` permission.

```bash
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/oauth_clients" \
	-H "Content-Type: application/json" \
	-H "Authorization: Bearer $API_TOKEN" \
	-d '{
		"client_name": "Cloudflare OAuth Client",
		"grant_types": ["authorization_code"],
		"redirect_uris": ["https://example.com/oauth/callback"],
		"scopes": ["workers-platform.read", "workers-platform.write"],
		"optional_scopes": ["workers-platform.read"],
		"post_logout_redirect_uris": ["https://example.com/logout"],
		"response_types": ["code"],
		"token_endpoint_auth_method": "client_secret_basic",
		"logo_uri": "https://example.com/logo.png",
		"policy_uri": "https://example.com/policy",
		"tos_uri": "https://example.com/tos",
		"client_uri": "https://example.com",
		"allowed_cors_origins": ["https://example.com"]
	}'
```

Note

After you create an OAuth client, Cloudflare displays the client secret if the client requires one. Copy it to a secure location. You cannot view the secret again after you leave the page. If you lose the secret, rotate it to get a new one.

## Select scopes

OAuth scope names correspond to Cloudflare API token permission names. Use the Cloudflare API documentation to identify the permissions your client needs.

When you create or edit an OAuth client, select at least one scope. All selected scopes are required by default.

In **Choose optional scopes**, turn off **Required** for each scope you want to make optional.

Required scopes must be granted on the consent screen, while optional scopes can be declined by the user.

Fetch the available scopes from the API. Use the scope ID when you create a client through the API.

```bash
curl "https://api.cloudflare.com/client/v4/oauth/scopes" \
	-H "Content-Type: application/json" \
	-H "Authorization: Bearer $API_TOKEN"
```

To mark scopes as optional, include them in the `optional_scopes` of the request. This must be a subset of the `scopes` for the client. Optional scopes may be declined by the user during authorization.

## Supported OAuth flows

Cloudflare OAuth clients support the OAuth 2.0 Authorization Code flow.

Cloudflare does not support Client Credentials, Implicit, Resource Owner Password Credentials, Device Authorization, or other OAuth grant types for third-party clients.

### Choose a flow

Use the following guidance to choose an OAuth flow:

| Client type | Flow | Token endpoint authentication | PKCE |
| --- | --- | --- | --- |
| Server-side web app or backend service | Authorization Code with a client secret | `client_secret_basic` or `client_secret_post` | Optional/not required |
| Browser-based, mobile, desktop, or CLI app | Authorization Code with PKCE | `none` | Required, `S256` |

### Client secret

The Authorization Code flow is intended for secure server-side applications that can protect a client secret from exposure.

- **Use when:** Your OAuth client is a server-side web application or backend service.
- **How it works:** Your client redirects the user to the authorization page. After authorization, Cloudflare returns an authorization code to your backend. Your backend exchanges the code and client secret for an access token.
- **Security note:** Never expose your client secret in client-side code or embed it in mobile client binaries.

### PKCE

Proof Key for Code Exchange (PKCE) extends the Authorization Code flow for public clients, such as mobile or single-page apps, where a client secret cannot be securely stored.

- **Use when:** Your OAuth client is a single-page, mobile, desktop, or CLI application.
- **How it works:** Your application generates a unique code verifier and code challenge for every login request instead of using a static client secret.
- **Security note:** Clients that use PKCE do not need a client secret.

## Private and public clients

New OAuth clients default to private visibility. Private clients can only be authorized by members of the parent Cloudflare account. Public clients allow authorization from any Cloudflare user.

Before you make a client public, complete the required actions and populate the required fields.

### Required fields

- Client name
- Logo
- Client URL
- Scopes

### Required actions

OAuth clients must complete [domain verification](#client-url-domain-ownership-verification) for the client URL before they can be made public.

### Promote a client to public

Caution

Setting a client's visibility to public is permanent. You cannot change the visibility back to private.

1. Go to **Manage Account** > **OAuth clients**.
2. Open the action menu for your client.
3. Select **Change Visibility**.

[Go to **OAuth clients** ↗](https://dash.cloudflare.com/?to=/:account/oauth-clients)

```bash
curl -X PATCH "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/oauth_clients/$CLIENT_ID" \
	-H "Content-Type: application/json" \
	-H "Authorization: Bearer $API_TOKEN" \
	-d '{ "visibility": "public" }'
```

## Client URL domain ownership verification

Cloudflare requires client URL domain ownership verification before a client can become public. If your client is only for private use by members of the account, domain ownership verification is not required.

Caution

After Cloudflare verifies domain ownership, you cannot change the domain of the client URL. You can still update the route for that domain.

Copy the verification code and create a `TXT` record in your DNS configuration with that value. The record must include all text, including the `cloudflare_oauth_client_publisher=` prefix.

Cloudflare polls this DNS record until it is found or until the request times out after two days.

### Restart verification

If the verification process times out, select **Restart verification** in the client action menu.

To restart a failed or timed out verification, send a `PATCH` request with the existing `client_uri` unchanged.

```bash
curl -X PATCH "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/oauth_clients/$CLIENT_ID" \
	-H "Content-Type: application/json" \
	-H "Authorization: Bearer $API_TOKEN" \
	-d '{ "client_uri": "https://example.com" }'
```

## Rotate client secrets

Each client can have two secrets. This lets you create a new secret, update your client to use the new secret, and delete the old secret.

1. Go to **Manage Account** > **OAuth clients**.
2. Open the action menu for your client.
3. Select **Rotate client secret**.
4. Save the new secret in a secure location.
5. After your client uses the new secret, delete the old secret.

[Go to **OAuth clients** ↗](https://dash.cloudflare.com/?to=/:account/oauth-clients)

To check whether a client is in the middle of a secret rotation, look for `has_rotated_secret` in the `GET` response. If the value is `true`, delete the old secret before you create another secret.

#### Create a new secret

```bash
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/oauth_clients/$CLIENT_ID/rotate_secret" \
	-H "Content-Type: application/json" \
	-H "Authorization: Bearer $API_TOKEN"
```

#### Delete the old secret

```bash
curl -X DELETE "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/oauth_clients/$CLIENT_ID/rotate_secret" \
	-H "Content-Type: application/json" \
	-H "Authorization: Bearer $API_TOKEN"
```

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/oauth/create-an-oauth-client/#page","headline":"Create your OAuth client","description":"Create an OAuth client that can access Cloudflare API resources on behalf of users.","url":"https://developers.cloudflare.com/fundamentals/oauth/create-an-oauth-client/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: After registering an application, use these endpoints to integrate your OAuth client with Cloudflare.
title: Integrate your OAuth client with Cloudflare
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Integrate your OAuth client with Cloudflare

Last updated Jun 3, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/oauth/integrate-with-cloudflare/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

After [registering an application](https://developers.cloudflare.com/fundamentals/oauth/create-an-oauth-client/), use these endpoints to integrate your OAuth client with Cloudflare.

- Jwks: `https://dash.cloudflare.com/.well-known/jwks.json`
- Open ID config: `https://dash.cloudflare.com/.well-known/openid-configuration`
- Authorization: `https://dash.cloudflare.com/oauth2/auth`
- Token: `https://dash.cloudflare.com/oauth2/token`
- Revoke: `https://dash.cloudflare.com/oauth2/revoke`
- Session logout: `https://dash.cloudflare.com/oauth2/logout`
- User info: `https://dash.cloudflare.com/oauth2/userinfo`

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/oauth/integrate-with-cloudflare/#page","headline":"Integrate your OAuth client with Cloudflare","description":"After registering an application, use these endpoints to integrate your OAuth client with Cloudflare.","url":"https://developers.cloudflare.com/fundamentals/oauth/integrate-with-cloudflare/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-06-03","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Set an abuse contact email address on your Cloudflare account to receive communications about potential abuse on your websites.
title: Add abuse contact
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Add abuse contact

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/abuse-contact/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Enter an abuse contact email address to ensure you are receiving communications regarding potential abuse on your websites.

To update your abuse contact email address:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com) and select your account.
2. Go to **Manage Account** > **Configurations**.
3. For **Abuse report contact email address**, select **Change email address**.
4. Enter and confirm your new email and select **Save**.

If you choose not to provide an abuse contact email address, communication about abuse will be directed to one of the Super Administrators on your account.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/abuse-contact/#page","headline":"Add abuse contact","description":"Set an abuse contact email address on your Cloudflare account to receive communications about potential abuse on your websites.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/abuse-contact/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Use Cloudflare Audit Logs v2 to track user-initiated and system-initiated actions across your account via the dashboard, API, or Logpush.
title: Audit Logs - version 2
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Audit Logs - version 2

Last updated Sep 14, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/audit-logs/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare Audit Logs are account-based. All user-initiated actions are recorded automatically across both the Cloudflare API and dashboard. System-initiated logs are also captured to reflect actions taken automatically by Cloudflare systems, such as configuration updates, background processes, or internal policy enforcement.

When a user-initiated action triggers additional automated behavior, corresponding system-initiated logs will be generated. In some cases, user-initiated logs include additional enrichments that provide more context about what was changed, offering deeper visibility into the full lifecycle of the action.

When an action occurs, it is streamed through Cloudflare's audit logging pipeline and stored. This ensures consistent visibility into activity across all products.

For more detailed information about how the user-initiated actions are logged automatically, refer to the [Cloudflare Blog ↗](https://blog.cloudflare.com/introducing-automatic-audit-logs/).

Note

A transition plan from Audit Logs v1 to Audit Logs v2 will be communicated in due course.

## Key features

Audit Logs (version 2) provide a unified and standardized system for tracking and recording actions across Cloudflare products. This system enhances transparency and accountability by offering comprehensive insights into user-initiated and system-initiated activities within your Cloudflare environment.

- **Standardized logging**: Audit logs are automatically generated in a consistent format across all Cloudflare services, ensuring uniformity and eliminating inconsistencies.
- **Expanded product coverage**: Audit Logs covers \~95% of Cloudflare products, capturing actions from key endpoints, such as `/accounts`, `/zones`, `/user`, and `/memberships` APIs.
- **Granular filtering**: Uniformly formatted logs allow for precise filtering by actions, actors, methods, and resources, facilitating efficient investigations.
- **Enhanced context and transparency**: Each log entry includes detailed context, such as the authentication method used, the interface (API or dashboard) through which the action was performed, and mappings to Cloudflare Ray IDs for improved traceability.
- **Comprehensive activity capture**: Audit Logs records create, update, and delete actions across all supported products. Selective logging of `GET` requests for sensitive read operations is planned for a future release.

## Retention

- Audit logs are retained for 18 months before being deleted. No additional setup is required.
- In the Audit Logs v2 UI, queries are limited to the most recent 90 days for performance reasons. To access the full 18 months of data, use the API or [Logpush](https://developers.cloudflare.com/logs/logpush/).
- Enterprise customers can use [Logpush](https://developers.cloudflare.com/logs/logpush/) to store audit logs beyond 18 months.

Note

Approximately 30 days of logs from the Beta period (back to \~February 8, 2026) are available at GA. These Beta logs will expire on \~April 9, 2026. Logs generated after GA will be retained for the full 18 months. Older logs remain available in Audit Logs v1.

## Customer Metadata Boundary

Audit Logs v2 supports [Customer Metadata Boundary (CMB)](https://developers.cloudflare.com/data-localization/metadata-boundary/). The account-level CMB preference automatically applies to Audit Logs v2. For example, if you select `eu`, Audit Logs v2 uses the EU metadata boundary. You do not need to configure Audit Logs separately.

To configure CMB in the Cloudflare dashboard or via the `/accounts/{account_id}/logs/control/cmb/config` API, refer to [Get started with Customer Metadata Boundary](https://developers.cloudflare.com/data-localization/metadata-boundary/get-started/). CMB is part of the Data Localization Suite. Contact your account team if CMB is not enabled for your account.

## Access Audit Logs

You can retrieve audit logs using the Cloudflare dashboard, the API, or Logpush.

### API

Audit Logs are available through the Cloudflare API. To retrieve audit logs, use the following endpoint:

```bash
https://api.cloudflare.com/client/v4/accounts/{account_id}/logs/audit
```

Below is an example request to retrieve audit logs for a certain period of time along with its corresponding response. Replace the example values in the URL with your actual values:

- `account_id`: Your Cloudflare account identifier.
- `since` (required): Start date for the audit log retrieval. Accepts `yyyy-mm-dd` (interpreted as UTC) or RFC3339 timestamp ( `yyyy-mm-ddTHH:MM:SSZ`).
- `before` (required): End date for the audit log retrieval. Same format as `since`.

```bash
GET https://api.cloudflare.com/client/v4/accounts/1234567890abcdef/logs/audit?since=2025-03-01T00:00:00Z&before=2025-03-26T23:59:59Z
```

*Example responsejson*

```json
{
	"result": [
		{
			"action": "zone.settings.change",
			"actor": {
				"email": "user@example.com",
				"id": "0987654321abcdef"
			},
			"ip": "192.0.2.1",
			"method": "PUT",
			"interface": "dashboard",
			"resources": [
				{
					"resource_id": "zone123",
					"resource_type": "zone"
				}
			],
			"timestamp": "2025-03-15T14:25:37Z"
		}
		// Additional log entries
	],
	"success": true,
	"errors": [],
	"messages": []
}
```

For more information refer to the [API documentation ↗](<https://developers.cloudflare.com/api/resources/accounts/subresources/logs/subresources/audit/methods/list/#(params)%20default%20%3E%20(param)%20since%20%3E%20(schema)>).

### Dashboard

To access audit logs in the Cloudflare dashboard, go to **Manage Account** > **Audit Logs**.

[Go to **Audit logs** ↗](https://dash.cloudflare.com/?to=/:account/audit-log)

Note

The Audit Logs v2 is shown by default. You can switch between Audit Logs v2 and v1 as needed.

#### Account analytics

The account-level Audit Logs v2 dashboard includes analytics for the selected time range. The **Actions over time** chart separates successful and failed actions. The summary cards show **Total actions**, **Unique actors**, **Products impacted**, and **Failure rate**.

Select a summary card to view more details:

- **Total actions**: Action types and authentication methods
- **Unique actors**: Actors with the most actions
- **Products impacted**: Products with the most actions
- **Failure rate**: Failed actions and their HTTP status codes

To focus the analytics and audit log table on a value, select **Filter** or **Exclude** from a detail panel. The analytics, table, filters, and time range remain synchronized.

Note

Account analytics are available for account-level audit logs. They are not available for organization-level audit logs.

### Logpush

Note

For customers who already have a Logpush job set up for Audit Logs v1, note that a separate Logpush job must be configured for [Audit Logs v2](https://developers.cloudflare.com/logs/logpush/logpush-job/datasets/account/audit_logs_v2/) (dataset). We will communicate the timeline for when Logpush Audit Logs v1 will be deprecated and turned off.

To create a Logpush job:

1. In the Cloudflare dashboard, go to the **Logpush** page. [Go to **Logpush** ↗](https://dash.cloudflare.com/?to=/:account/logs)
2. Select **Create a Logpush job**.
3. In **Select a destination**, select the destination of your choice and add the destination details.
4. In the datasets section, select the [Audit Logs v2 dataset](https://developers.cloudflare.com/logs/logpush/logpush-job/datasets/account/audit_logs_v2/). Audit Logs v2 is an account-based dataset.
5. Once you are done configuring your logpush job, select **Submit**.

## Resource History

Resource History shows what changed on every configuration modification captured in Audit Logs. For any audit log entry, you can see the sequence of previous changes to the same resource and view a side-by-side diff of what was modified.

Resource History is available in the Cloudflare dashboard and via the Audit Logs API. It uses the audit log entries you already have. There is no additional configuration, no backend recapture, and no changes to how audit logs are generated.

### What Resource History gives you

For any audit log entry, Resource History retrieves every other audit log entry for the same resource, ordered chronologically. You can then pick an earlier entry from that history to see exactly which fields changed between the two.

### Use Resource History in the dashboard

1. Go to **Manage Account** > **Audit Logs**.
2. Open any audit log entry.
3. Select the **History** tab to see the full history for the resource that entry describes.
4. In the history view, select any earlier entry to see a side-by-side diff of the fields that changed between it and the current entry.

When Resource History cannot identify the underlying resource (for example, for certain system-initiated events), the dashboard shows an empty state indicating that change history is not available for that entry.

### Use Resource History via the API

You can retrieve the change history for any audit log entry using the History endpoint. Given the `id` of a source audit log entry, the endpoint derives identifying filters from that entry and returns matching audit log entries within a date window you specify.

For account-scoped audit logs, use:

```bash
GET https://api.cloudflare.com/client/v4/accounts/{account_id}/logs/audit/{id}/history
```

For organization-scoped audit logs, use:

```bash
GET https://api.cloudflare.com/client/v4/organizations/{organization_id}/logs/audit/{id}/history
```

The `{id}` path parameter is the `id` of the source audit log entry whose resource history you want to retrieve.

Required API token permissions

At least one of the following [token permissions](https://developers.cloudflare.com/fundamentals/api/reference/permissions/) is required:

- `Account Settings Read`
- `Account Settings Write`

The endpoint requires three query parameters:

- `action_time` (required): RFC3339 timestamp of the source audit log entry's action time. Provide the `action.time` value from the audit log identified by `{id}`. This narrows the source-entry lookup window.
- `since` (required): Limits returned results to entries newer than this date. Accepts a date string ( `2024-10-30`, interpreted as UTC) or an RFC3339 timestamp.
- `before` (required): Limits returned results to entries older than this date. Same format as `since`.

Optional query parameters:

- `direction`: `desc` (default) or `asc`.
- `limit`: Number of entries to return per page. Default `100`.
- `cursor`: Pagination cursor from a previous response's `result_info.cursor`.

<details>

<summary>

Required API token permissions

</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:

- <code>Account Settings Write</code>
- <code>Account Settings Read</code>

</details>

*Get resource change history from an account audit log entry (Version 2)bash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/logs/audit/$ID/history" \
	--request GET \
	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

Each entry in `result` has the same shape as an entry returned by the Audit Logs list endpoint. Results are paginated using the `cursor` value in `result_info`.

The `result_info.history_status` field indicates the quality of resource identification used to build the history:

- `exact`: The source entry contained a resource URI, so the history was built from an exact resource match.
- `approximate`: The source entry did not contain a resource URI, so the history was built from an approximate match (other resources of the same product and type). The dashboard surfaces this state with a warning banner.
- `unavailable`: The source entry did not contain enough information to identify the resource. `result` is empty. This can happen for certain system-initiated events.

Resource History reflects the audit log entries currently retained by Audit Logs v2 (refer to [Retention](#retention)). Entries older than the retention window are not returned. Resource History is a query-time capability and is not exposed as additional fields in the `audit_logs_v2` Logpush dataset.

## Audit Log structure

Cloudflare's audit logs offer a detailed view of activity across your environment by capturing both the source of actions and the context in which they occur. These logs are categorized by who initiated the action (user or system) and whether the activity occurred within a specific account or spanned multiple accounts under the same user profile. This structure enables flexible filtering, investigation, and compliance monitoring.

### Initiation type

Audit logs can be initiated either by users or the system. Understanding the type of actor involved helps in identifying the source and intent of actions.

#### User initiated Audit Logs

Track actions initiated by users through Cloudflare interfaces, including the dashboard and API. These logs capture who or what performed the action. They also record when it occurred and which resource was affected. User-initiated actions can have four actor types:

- `actor_type="user"`: Action was performed by an individual user.
- `actor_type="cloudflare_admin"`: Action was performed by Cloudflare.
- `actor_type="account"`: Action was performed using an account API token. Refer to the [Account API tokens](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/) documentation for more information.
- `actor_type="delegated_service"`: Action was performed by a Cloudflare service acting on a user's behalf. The log does not identify the initiating user.

#### System initiated Audit Logs

Record changes made automatically by Cloudflare systems, without direct user input. These logs provide visibility into internal processes, automated tasks, and security events. Some entries may include associated user context for traceability (`actor_type="system"`).

### Activity Scope

#### Account Activity Logs

Contain events scoped to a single Cloudflare account. These logs are filterable by `account ID` and reflect actions within that account only. You can optionally filter events further using the `resource_scope` field, which specifies whether the resource is associated with a user, an account, or a zone (`resource_scope ="user"`, `resource_scope ="accounts"`, or `resource_scope ="zones"`).

#### User Profile Activity Logs

Reflect actions associated with a user's login (email) across multiple accounts. These logs enable cross-account tracking and can be filtered by `user ID` or `email`. They are visible on any account the user had access to at the time of the activity. User Profile Activity Logs can be filtered using `resource_scope ="user"`.

The `GET /memberships` endpoint supports cross-account access. To query memberships, use the parameter `resource_scope=memberships`.

#### Organization Activity Logs

Contain events scoped to specific [Cloudflare Organizations](https://developers.cloudflare.com/fundamentals/organizations/). These logs capture user-initiated actions performed by Org Admins through organization-level APIs.

Note

Cloudflare Organizations is Enterprise-only and currently in public beta.

You can retrieve Organization audit logs using either the API or the Cloudflare dashboard.

##### API access

Retrievable via the Audit Logs v2 API:

```bash
GET https://api.cloudflare.com/client/v4/organizations/{organization_id}/logs/audit
```

##### Dashboard access

To access organization audit logs in the Cloudflare dashboard, go to **Organizations** > *(select your organization)* > **Manage Organization** > **Audit Logs**.

If you are viewing account-level audit logs and the account belongs to an organization where you are an Organization Super Administrator, you can navigate to the parent organization's audit logs using the **View Organization Audit Logs** button.

Note

Organization-level audit logs are separate from account-level audit logs. Actions performed within a specific account continue to be available via the account-level Audit Logs UI, Audit Logs v2 API, and Logpush.

This release covers user-initiated actions only. Support for system-initiated actions and Logpush for organizations will be added in future releases.

## Example how to query Audit Logs

Use the following example to get a list of audit logs for a Cloudflare account.

<details>

<summary>

Required API token permissions

</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:

- <code>Account Settings Write</code>
- <code>Account Settings Read</code>

</details>

*Get account audit logs (Version 2)bash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/logs/audit" \
	--request GET \
	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

*Example responsejson*

```json
{
	"errors": [
		{
			"message": "message"
		}
	],
	"result": [
		{
			"account": {
				"id": "4bb334f7c94c4a29a045f03944f072e5",
				"name": "Example Account"
			},
			"action": {
				"description": "Add Member",
				"result": "success",
				"time": "2024-04-26T17:31:07Z",
				"type": "create"
			},
			"actor": {
				"id": "f6b5de0326bb5182b8a4840ee01ec774",
				"context": "dash",
				"email": "alice@example.com",
				"ip_address": "198.41.129.166",
				"token_id": "token_id",
				"token_name": "token_name",
				"type": "user"
			},
			"raw": {
				"cf_ray_id": "8e9b1c60ef9e1c9a",
				"method": "POST",
				"status_code": 200,
				"uri": "/accounts/4bb334f7c94c4a29a045f03944f072e5/members",
				"user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Safari/605.1.15"
			},
			"resource": {
				"id": "id",
				"product": "members",
				"request": {},
				"response": {},
				"scope": {},
				"type": "type"
			},
			"zone": {
				"id": "id",
				"name": "example.com"
			}
		}
	],
	"result_info": {
		"count": "1",
		"cursor": "ASqdKd7dKgxh-aZ8bm0mZos1BtW4BdEqifCzNkEeGRzi_5SN_-362Y8sF-C1TRn60_6rd3z2dIajf9EAPyQ_NmIeAMkacmaJPXipqvP7PLU4t72wyqBeJfjmjdE="
	},
	"success": true
}
```

## Common terms and definitions

### Actor

The actor represents who or what performed the action. Its identity attributes depend on the actor type. These attributes can include a user ID, email address, and IP address. Actor types include `user`, `account`, `cloudflare_admin`, `delegated_service`, or `system`. An actor can also include the context used to initiate the action:

- `api`: The action was performed through the API. The specific credential type was not recorded.
- `api_key`: The action was authenticated with a Cloudflare Global API Key.
- `api_token`: The action was authenticated with an API token.
- `dash`: The action was performed through the Cloudflare dashboard.
- `oauth`: The action was authenticated with an OAuth token.
- `origin_ca_key`: The action was authenticated with an Origin CA key.

### Action

The action field captures the nature of the event and whether it was successful. It includes a high-level type (e.g., `create`, `update`, `delete`), a specific description (such as `SSO_LOGIN`), the timestamp of when the action occurred, and the result (`success` or `failure`).

`view` actions correspond to `GET` requests. These are defined in the schema but not currently captured in Audit Logs. Selective `GET` logging for sensitive read operations is planned for a future release.

### Account

This field refers to the Cloudflare account under which the action was executed. It includes a unique account ID and a human-readable account name to help associate activity with a customer environment.

### Resource

The resource identifies the object impacted by the action. It includes the resource type, the unique resource ID, the scope (`user`, `account`, or `zone`), and optionally the product associated with the change.

### Audit Log ID

This is a unique identifier for the log record itself. It can be used for deduplication, correlation, or referencing specific actions during investigations.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/audit-logs/#page","headline":"Audit Logs - version 2","description":"Use Cloudflare Audit Logs v2 to track user-initiated and system-initiated actions across your account via the dashboard, API, or Logpush.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/audit-logs/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Grant your Cloudflare Account Team temporary editing access to your account for migrations or sensitive configuration changes.
title: Allow Cloudflare access
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Allow Cloudflare access

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/cloudflare-access/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Occasionally, you may want to allow edit access to your Account Team. A typical use case might be migrating a complex or sensitive domain over to Cloudflare.

By default, Cloudflare does not have edit access to your account.

To enable editing access by your Account Team:

1. In the Cloudflare dashboard, go to the **Configurations** page. (You must be logged in as a **Super Administrator**). [Go to **Configurations** ↗](https://dash.cloudflare.com/?to=/:account/configurations)
2. For **Editing Permission**, switch the toggle to **On**.
3. Select a duration.
4. Click **Approve**.

Note

In an emergency, Cloudflare Support can override your **Editing Permissions** and make updates to your account, but your Super Administrator will receive an email and the action will be recorded in your [Audit Logs](https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/) with an **Action** of **Break glass**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/cloudflare-access/#page","headline":"Allow Cloudflare access","description":"Grant your Cloudflare Account Team temporary editing access to your account for migrations or sensitive configuration changes.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/cloudflare-access/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Configure single sign-on (SSO) for the Cloudflare dashboard using your identity provider to enforce authenticated access for your email domain.
title: Set up dashboard SSO
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Set up dashboard SSO

Last updated Aug 14, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers single sign-on (SSO) for all customers who log in with a custom email domain. By creating a Cloudflare SSO connector, you can enforce SSO to the Cloudflare dashboard with the identity provider (IdP) of your choice. SSO will be enforced for every user in your email domain.

## Availability

Cloudflare Dashboard SSO is available for free to all plans.

|  | Free | Pro | Business | Enterprise |
| --- | --- | --- | --- | --- |
| Availability | Yes | Yes | Yes | Yes |

## Prerequisites

1. You must control your email domain and be able to add a TXT record to verify this.
   - Public email providers such as `@gmail.com` are not allowed.
   - Every user with that email domain must be an employee in your organization. For example, university domains such as `@harvard.edu` are not allowed because they include student emails.
2. You must be a super administrator and be able to access the Cloudflare API.
3. A Cloudflare Zero Trust organization with any subscription tier (including Free) must be created. To set up a Cloudflare Zero Trust organization, refer to [Create a Cloudflare Zero Trust organization](https://developers.cloudflare.com/cloudflare-one/setup/#2-create-a-zero-trust-organization).

## 1. Set up an IdP

Add an IdP to Cloudflare Zero Trust by following [our detailed instructions](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/).

Once you configure your IdP, make sure you also [test your IdP](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/#test-idps-in-cloudflare-one).

## 2. Register your domain with Cloudflare for SSO

Caution

You must create an [Account API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) with the role `SSO Connector Edit` and store it securely. This acts as a backup plan, allowing you to disable SSO via the API if you are accidentally locked out, such as due to changes in your IdP configuration later.

1. Once you have configured an IdP in Cloudflare One, go to the **Members** page to manage SSO connectors.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. If step 1 was successful, a button to add a new SSO domain will be present. Select the button to begin the process of adding a new SSO domain.

![Screenshot of the SSO connector create modal](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=634,height=305,format=webp/_astro/create_modal.UuyGmCgI.png)

3. Enter your email domain and select **Create** to move to the verification step.

Note

Some top level domains, such as `.edu`, are prohibited from being used as SSO domains.

Using a command line terminal where you have already set the environment variable `CLOUDFLARE_API_TOKEN` to a user or account API token which has the `SSO Connector Edit` permission, run the following command to create an SSO connector. Replace `{account_id}` with your account ID, and `{domain}` with your email domain.

*cURL commandbash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors" \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --json '{"email_domain":"{domain}"}'
```

```json
{
	"success": true,
	"errors": [],
	"messages": [],
	"result": {
		"id": "c3ebcba5c20b42f73e111110d0be67d",
		"enabled": false,
		"email_domain": "cool.cats",
		"verification": {
			"code": "cloudflare_dashboard_sso=111111111",
			"status": "pending"
		},
		"created_on": "2025-09-05T20:35:34Z"
	}
}
```

## 3. Verify domain ownership

If you are unable to change your DNS records right away, the option to verify later is available. The verification process can be manually triggered from the actions menu for that connector in the list.

![Screenshot of the SSO connector create modal](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=636,height=388,format=webp/_astro/verify_modal.DVxZpDs_.png)

Copy the verification code and create a TXT record in your DNS configuration with that value. The record must include all of the text including the `cloudflare_dashboard_sso=` prefix.

Cloudflare will automatically poll this DNS record until it is found or a timeout is reached within two days.

If the verification process fails due to timeout, you can manually reinitiate the polling by selecting **Begin verification** in the actions menu for that connector in the list.

Copy the verification code (for example `cloudflare_dashboard_sso=1111111`) and create a `TXT` record in your DNS configuration with that value. To test that the DNS record was correctly configured, you can use the `dig` command to query your email domain:

```sh
dig cool.cats TXT +short
```

```sh
"cloudflare_dashboard_sso=111111111"
```

The `TXT` record must include the `cloudflare_dashboard_sso=` prefix along with the numerical code.

Cloudflare will automatically poll this DNS record until it is found or a timeout is reached within two days. If verification fails due to timeout, you may manually reinitiate the polling by running the following command:

*cURL commandbash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{sso_connector_id}/begin_verification" \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

Once the verification process has completed or timed out, you will receive an email notification with the verification result.

## 4. Enable dashboard SSO

Caution

Enabling Cloudflare Dashboard SSO for an email domain (for example, `@mycompany.com`) will apply globally to all users with that domain, regardless of which accounts those users have access to. All users will be required to authenticate via the specified identity provider, including users registered on Cloudflare prior to the domain being configured for SSO.

Once the verification process has completed and successfully verified domain ownership, you may enable the connector.

Domains that are associated with an already enabled connector belonging to a different account may not be enabled on a new account until disabled on the old account.

Enable the connector by selecting **Enable** in the Actions menu for that connector in the list.

![Screenshot of the SSO connector enable button](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1226,height=203,format=webp/_astro/verified_domain.B1SGjH_l.png)

Enable the connector by running the following — again, replacing the `{account_id}` value with your account ID, and additionally replacing the `{sso_connector_id}` with the value you obtained from the `id` field in the response to the previous call.

*cURL commandbash*

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{sso_connector_id}" \
  --request PATCH \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --json '{"enabled": true}'
```

## Test your IdP before enforcement

Before enabling SSO for your domain, verify that your identity provider is configured correctly:

1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Integrations** > **Identity providers**.
2. Find your IdP and select **Test**.
3. Confirm that the test returns a successful authentication result.

If the test fails, review your IdP configuration against the [identity provider setup instructions](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/) before enabling the SSO connector.

### Troubleshoot IdP errors

If you encounter errors during IdP setup or testing, provide the following when [contacting support](https://developers.cloudflare.com/support/contacting-cloudflare-support/):

1. The error message returned by the IdP test.
2. A sanitized [HAR file](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#generate-a-har-file) captured while running the IdP test from the dashboard.

## Limitations

Cloudflare dashboard SSO does not support:

- Users with plus-addressed emails, such as `example+2@domain.com`. If you have users like this added to your Cloudflare organization, they will be unable to login with SSO.
- Adding a separate email-based policy to the Zero Trust SSO application that does not match your SSO domain policy.
- Multiple Zero Trust domain policies. If another domain policy is required, you can create another SSO connector. This will create a second policy for that new domain in your SSO application.
- Deleting the auto-generated Zero Trust `allow email domain` policy. If this policy is deleted, your organization's administrators cannot access the Cloudflare dashboard.

## IdP-initiated SSO

IdP-initiated login is supported for Cloudflare dashboard SSO, with configuration available via your identity provider (IdP).

A step-by-step guide is currently available for Okta, and similar configurations are possible with other identity providers that support custom SSO endpoints.

### Okta

Configure an identity provider (IdP)-initiated single sign-on (SSO) session using Cloudflare Zero Trust and Okta.

#### Prerequisites

1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Access controls** > **Applications** > select your **SSO App**.
2. Select **Configure** to access the application settings.
3. In the **Basic Information** section, copy the **SSO Endpoint URL** and **Access Entity ID or Issuer**. You will need these values for your IdP setup.

#### Configure Okta as the IdP

1. Log in to your [Okta Admin Dashboard ↗](https://login.okta.com/) and go to **Applications** > **Applications**.
2. Select **Create App Integration** to start a new SAML integration to handle the IdP-initiated SSO flow. Note that this is a second, distinct Cloudflare-Okta integration, created separately from the [IdP integration with Zero Trust](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/).
3. In the pop-up, select **SAML 2.0** and select **Next**.
4. Enter a name for the app and select **Next**.
5. In the **Single Sign-On URL** field, paste the **SSO Endpoint URL** [you copied earlier](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#prerequisites-1).
6. In the **Audience URI (SP Entity ID)** field, paste the **Access Entity ID or Issuer** [you copied earlier](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#prerequisites-1).
7. Set the **Name ID Format** to **EmailAddress**.
8. Set the **Application Username** to **Email**.
9. Select **Next** > **Finish** to save the integration.
10. Test the integration by going to your Okta User Dashboard, locating the new app tile, and selecting it to verify the SSO flow.

**(Optional) Enforce single IdP login with instant authentication**

If you use only one IdP (for example, Okta) for Cloudflare SSO and want users to skip the identity provider selection prompt:

1. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Access controls** > **Applications** > select your **SSO App**.
2. Go to **Authentication**.
3. Disable **Accept all available identity providers** and ensure only Okta is selected as the login method.
4. Enable **Apply instant authentication** to allow users to skip identity provider selection.

## Bypass dashboard SSO

This section describes how to restore access to the Cloudflare dashboard in case you are unable to login with SSO.

### Option 1: Add a backup IdP

If there is an issue with your SSO IdP provider, you can add an alternate IdP using the API. The following example shows how to add [Cloudflare One-time PIN](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/one-time-pin/) as a login method:

1. [Add](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/create/) one-time PIN login:<details><summary>

   Required API token permissions</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:
   - <code>Access: Organizations, Identity Providers, and Groups Write</code></details>

   *Add an Access identity providerbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/identity_providers" \
   	--request POST \
   	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
   	--json '{
   		"type": "onetimepin",
   		"config": {}
   	}'
   ```


2. [Get](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/list/) the `id` of the `dash_sso` Access application. You can use [`jq` ↗](https://jqlang.github.io/jq/download/) to quickly find the correct application:

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps" \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     | jq '.result[] | select(.type == "dash_sso")'
   ```



```txt
   {
   	"id": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   	"uid": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   	"type": "dash_sso",
   	"name": "SSO App"
   	// ...
   }
```

3. Using the `id` obtained above, [update](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/update/) **SSO App** to accept all identity providers. To avoid overwriting your existing configuration, the PUT request body should contain all fields returned by the previous GET request.<details><summary>

   Required API token permissions</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:
   - <code>Access: Apps and Policies Write</code></details>

   *Update an Access applicationbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps/3537a672-e4d8-4d89-aab9-26cb622918a1" \
   	--request PUT \
   	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
   	--json '{
   		"id": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   		"uid": "3537a672-e4d8-4d89-aab9-26cb622918a1",
   		"type": "dash_sso",
   		"name": "SSO App",
   		"allowed_idps": []
   	}'
   ```



Users will now have the option to log in using a one-time PIN.

### Option 2: Disable dashboard SSO

Caution

Before disabling SSO, make sure you have access to your Cloudflare user email. This will allow you to reset your password in case you get logged out of the Cloudflare dashboard.

1. Navigate to the **Members** page.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. Go to **Settings**.
3. Select the actions menu for the SSO connector in the list and select **Disable**.
4. Type the domain of the connector and click confirm to complete the disable action.

The following API calls will disable SSO enforcement for an account. This action can only be performed by API tokens with the `SSO connectors edit` role or Super Administrators.

1. Get your SSO connector `id`:

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors" \
     --request GET \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
   ```



```txt
   {
   	"result": [
   		{
   			"id": "d616ac82cc7f87153112d75a711c5c3c",
   			"email_domain": "cool.cats",
   			"enabled": true
   			// ...
   		}
   	],
   	"success": true,
   	"errors": [],
   	"messages": []
   }
```

2. Disable the SSO connector:

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{connector_id}" \
     --request PATCH \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     --json '{
       "enabled": false
     }'
   ```



```txt
   {
   	"result": [
   		{
   			"id": "d616ac82cc7f87153112d75a711c5c3c",
   			"email_domain": "cool.cats",
   			"enabled": false
   			// ...
   		}
   	],
   	"success": true,
   	"errors": [],
   	"messages": []
   }
```

Users can now log in using their Cloudflare account email and password. If a user does not have a password, they can use the [forgot password](https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/#forgot-your-password) method on the login page to create one.

## Change your Zero Trust team name

Cloudflare does not allow you to change your team name while a SSO connector is created. To change your team name, you must disable and delete your SSO connector(s).

1. Navigate to the **Members** page.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. Go to **Settings**.
3. Disable all SSO connectors.
4. Delete all SSO connectors.

1. Get all SSO connectors for your account.

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors" \
     --request GET \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
   ```


2. Disable any active SSO connectors using the `id` of each connector from the previous step.

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{connector_id}" \
     --request PATCH \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
     --json '{
       "enabled": false
     }'
   ```


3. Delete all SSO connectors using the `id` of each connector from the previous step.

   *cURL commandbash*

   

   ```bash
   curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/sso_connectors/{connector_id}" \
     --request DELETE \
     --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
   ```



4. In the [Cloudflare dashboard ↗](https://dash.cloudflare.com/), go to **Zero Trust** > **Reusable components** > **Custom pages**.
5. Under **Team domain**, select **Edit** to enter the new team name. Select **Save**.
6. In your identity provider, update your Cloudflare integration with the new team name. For example, if you are using a SAML IdP, you will need to update the Single Sign-on URL and Entity ID to `https://<new-team-name>.cloudflareaccess.com/cdn-cgi/access/callback`.
7. Recreate any deleted SSO connectors using the steps in [Register your domain with Cloudflare for SSO](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#2-register-your-domain-with-cloudflare-for-sso).
8. Follow the verification and enable steps after recreating the SSO connectors.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/#page","headline":"Set up dashboard SSO","description":"Configure single sign-on (SSO) for the Cloudflare dashboard using your identity provider to enforce authenticated access for your email domain.","url":"https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"},"keywords":["SSO"]}
```

---

---
description: Cloudflare checks your password against known data breaches at login and prompts you to reset it if a match is found.
title: Leaked Password Notifications
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Leaked Password Notifications

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/leaked-password-notifications/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare automatically checks if your password has been compromised when you log in to the Cloudflare dashboard. Every time you log in to your account, we will securely verify through threat intelligence sources to confirm if your password has been leaked in a past data breach.

Refer to the [blog post ↗](https://blog.cloudflare.com/helping-keep-customers-safe-with-leaked-password-notification/) for more information on how Cloudflare checks for leaked credentials.

Note

Cloudflare does not have additional information about the specific breach or Internet service that potentially lost your password.

Popular online tools such as [Have I Been Pwned ↗](https://haveibeenpwned.com/) can help you better understand where your external accounts were attacked. If you reused this password in other systems, it is recommended that you reset it in those as well.

If your password is found in a data breach, we will email you information on how to reset your password and prompt you to do so in the Cloudflare dashboard.

Your first three login attempts will warn you of the need to reset your password. After three attempts, you will be required to reset your password to log in to Cloudflare.

Users leveraging [Single Sign-On (SSO)](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/) or [two-factor authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) will not be subject to these requirements given the higher level of security provided by those features.

We encourage you to enable two-factor authentication to secure your account.

Cloudflare account Super Administrators can also require that [all members enable 2FA](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/). This functionality can be enabled by going to **Manage Account** > **Members** in the Cloudflare dashboard.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/leaked-password-notifications/#page","headline":"Leaked Password Notifications","description":"Cloudflare checks your password against known data breaches at login and prompts you to reset it if a match is found.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/leaked-password-notifications/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: View and revoke active login sessions associated with your Cloudflare account to maintain account security.
title: Manage active sessions
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Manage active sessions

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/manage-active-sessions/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

In the Cloudflare dashboard, you can view a list of active sessions associated with your email address.

Each time your email is used to log in to your Cloudflare account, a session begins. The Cloudflare dashboard provides session information including if the device is currently viewing the dashboard, the IP address, location, device type, browser type, and last active login.

If you notice any suspicious activity, you can also revoke any active sessions.

Note

By default, the session timeout for the Cloudflare dashboard is 72 hours without any activity.

Some customers can also enforce single-sign on (SSO) by [adding a Dashboard SSO application](https://developers.cloudflare.com/fundamentals/manage-members/dashboard-sso/).

## View active sessions

To view the active sessions associated with your email address:

1. In the Cloudflare dashboard, go to the **Account home** page. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile** > **Sessions**.

## Revoke active sessions

When there is more than one active session associated with your email account, you can revoke any session that is not the current session.

To revoke a session:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile** > **Sessions**.
3. On a specific section, click **Revoke**.
4. You will be prompted to enter your password before revoking the session.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/manage-active-sessions/#page","headline":"Manage active sessions","description":"View and revoke active login sessions associated with your Cloudflare account to maintain account security.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/manage-active-sessions/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review Cloudflare Audit Logs v1 to track account activity through the dashboard or API.
title: Review audit logs - v1
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Review audit logs - v1

Last updated Apr 22, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

Audit Logs version 2 is available. Refer to the [Audit Logs v2 documentation](https://developers.cloudflare.com/fundamentals/account/account-security/audit-logs/) for more details.

Audit logs summarize the history of changes made within your Cloudflare account. Audit logs include account level actions like login, as well as zone configuration changes.

Audit Logs are available on all plan types and are captured for both individual users and for multi-user organizations.

Note

Most beta features will not appear in audit logs until they are out of beta.

## Access audit logs

### Using the dashboard

To access audit logs in the Cloudflare dashboard:

In the Cloudflare dashboard, go to the **Audit Logs** page.

[Go to **Audit logs** ↗](https://dash.cloudflare.com/?to=/:account/audit-log)

You can search these audit logs by user email or domain and filter by date range. To download audit logs, click **Download CSV**.

Note

Depending on the volume of data, the export of large amounts of events from Audit Logs might fail with errors. We always recommend using Cloudflare [Logpush](https://developers.cloudflare.com/logs/logpush/) to make sure Audit Logs are always available and stored externally.

### Using the API

To get audit logs from the Cloudflare API, send a [GET request](https://developers.cloudflare.com/api/resources/audit_logs/methods/list/).

We recommending using the API for downloading historical audit log data.

To maintain Audit Logs query performance, the Audit Logs API was modified on 2019-06-30 to return records with a maximum age of 18 months.

## Retention

Audit Logs are retained for 18 months before being deleted. Enterprise customers can use [Logpush](https://developers.cloudflare.com/logs/logpush/) to store Audit Logs for longer periods of time.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/#page","headline":"Review audit logs - v1","description":"Review Cloudflare Audit Logs v1 to track account activity through the dashboard or API.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-22","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Provision users and groups into your Cloudflare account using the SCIM protocol with Okta, Microsoft Entra, or Authentik.
title: SCIM provisioning
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# SCIM provisioning

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare supports bulk provisioning of users into the Cloudflare dashboard by using the System for Cross-domain Identity Management (SCIM) protocol. This allows you to connect an external identity provider (IdP) to Cloudflare, quickly onboard and manage user permissions. Currently, SCIM provisioning has been integrated with Okta, Microsoft Entra, and Authentik.

Note

This section covers SCIM provisioning for the Cloudflare dashboard. If you need to provision SCIM for Cloudflare Zero Trust, refer to [Zero Trust SCIM provisioning](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/scim/).

## Objectives

Once the SCIM provisioning is enabled:

- A Cloudflare account can receive user group provisioning from the identity provider.
- Members of each user group can be assigned one or more [policies](https://developers.cloudflare.com/fundamentals/manage-members/policies/). Each policy defines one or more [roles ↗](https://developers.cloudflare.com/fundamentals/manage-members/roles/) applied to all group members thereof.
- Members can belong to multiple user groups, and each group can also be configured with different policies.
- Policies provisioned via SCIM can coexist with policies configured via the [traditional setup](https://developers.cloudflare.com/fundamentals/manage-members/manage/#edit-member-permissions).

## Expected behaviors

Expectations for user lifecycle management with SCIM:

| Expected Cloudflare dash behavior | Identity provider action |
| --- | --- |
| User is added to account as member | Assign the user to a SCIM application. They will be assigned the Minimal Account Access role so that their dash experience is not broken. |
| User is removed from account as member | Unassign the user from the SCIM application. |
| Add role to user | Add the user to a group in the IdP which is pushed via SCIM. They must also be assigned to the SCIM application and exist as an account member. |
| Remove role from user | Remove the user from the corresponding group in the IdP. |
| Retain user in account but with no permissions | Remove the user from all role groups but leave them assigned to the SCIM application. They will be an account member with only the role Minimal Account Access. |

Note

Dashboard SCIM handles group membership and user account lifecycle through separate services. Removing a user from a SCIM group updates their group membership in Cloudflare but has no effect on their account membership. Account membership removal requires the identity provider to send `active: false` in a `PATCH /Users` or `PUT /Users` request. Ensure your IdP is configured with the `active` attribute mapping. For Microsoft Entra ID, refer to [Provision with Microsoft Entra](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/entra/).

## Limitations

- If a user is the only Super Administrator on an Enterprise account, they will not be deprovisioned.
- It is possible to unintentionally remove all account Super Administrators by misconfiguring SCIM groups. Refer to [SCIM troubleshooting](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/troubleshooting/) for more information.
- SCIM group names cannot begin with the reserved prefix `CF`.

## Prerequisites

- Cloudflare dashboard SCIM provisioning is only available to Enterprise customers using Okta, Microsoft Entra, or Authentik.
- You must be a Super Administrator for the initial setup.
- In the identity provider, you must have the ability to create applications and groups.

---

## Gather the required data

To start, you will need to collect a couple of pieces of data from Cloudflare and set these aside for later use.

### Get the Account ID

The account ID can be found via dashboard or API. For more information, refer to [Find account and zone IDs](https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/).

### Create an API token

1. [Create an API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) with the following permissions:

   | Type | Item | Permission |
   | --- | --- | --- |
   | Account | SCIM Provisioning | Edit |

   Note

   Account API tokens are recommended for SCIM Provisioning. User owned API tokens, while supported, may result in a broken SCIM connection in the event when the user's policies are revoked from the SCIM integration, or the [API access](https://developers.cloudflare.com/fundamentals/api/how-to/control-api-access/) is unexpectedly disabled. Learn more about [Account API tokens](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/).
2. Under **Account Resources**, select the specific account to include or exclude from the dropdown menu, if applicable.
3. Select **Continue to summary**.
4. Validate the permissions and select **Create Token**.
5. Copy the token value.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/#page","headline":"SCIM provisioning","description":"Provision users and groups into your Cloudflare account using the SCIM protocol with Okta, Microsoft Entra, or Authentik.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Configure Authentik as a SCIM identity provider to provision users and groups into your Cloudflare account.
title: Provision with Authentik
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Provision with Authentik

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/authentik/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

**Important Update:** Cloudflare now supports native User Groups for enhanced access control. This new feature replaces the previous method of directly assigning Cloudflare roles based on IdP group mappings (identified by the pattern `CF-<accountID> - <Role Name>`), which is deprecated as of June 2nd, 2025. SCIM Virtual Groups will reach end-of-life on December 2, 2025. Update your SCIM configurations using the instructions below to utilize User Groups for seamless provisioning.

Once you have [gathered the required data](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/#gather-the-required-data), the following steps will be required to finish the provisioning with Authentik.

## Set up your Authentik SCIM provider

1. In the Authentik Admin interface, go to **Applications** > **Providers**.
2. Select **Create** and choose **SCIM Provider**.
3. Name your provider (for example, `Cloudflare SCIM`).
4. In **URL**, enter: `https://api.cloudflare.com/client/v4/accounts/<accountID>/scim/v2`, substituting `<accountID>` for your [Cloudflare Account ID](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/#get-the-account-id).
5. In **Token**, Paste the SCIM provisioning API token.
6. (Optional) Adjust the **User filtering** and **Group filtering** settings to control which users and groups are synchronized.
7. Select **Finish** to create the provider.

## Create an Authentik application

1. In the Authentik Admin interface, go to **Applications** > **Applications**.
2. Select **Create**.
3. Name your application (for example, `Cloudflare Dashboard`).
4. In **Provider**, select the SCIM provider you created in the previous step.
5. Select **Create** to save the application.

## Configure user and group sync in Authentik

Note

The **Update User Attributes** option is not supported.

1. In the Authentik Admin interface, go to **Directory** > **Groups**.
2. Create or select the groups you want to synchronize with Cloudflare. Ensure the users you want to provision are members of these groups.
3. Return to **Applications** > **Providers** and select your SCIM provider.
4. Under **Backchannel Providers**, verify that your SCIM provider is correctly linked to the application.
5. To trigger a manual sync, select **Sync** from the provider page. Authentik will also perform automatic periodic syncs based on your configured schedule.

## Verify the integration

To verify the integration:

1. In Authentik, go to **Applications** > **Providers**, select your SCIM provider, and review the **Sync status** section for any errors.
2. In the Cloudflare dashboard, go to **Manage Account** > **Members** > **User Groups** to view the synchronized groups.
3. Check the Audit Logs in the Cloudflare dashboard by going to **Manage Account** > **Audit Log**.

## Assign policies to user groups

After users and groups are synchronized, you can assign [policies](https://developers.cloudflare.com/fundamentals/manage-members/policies/) to user groups:

1. In the Cloudflare dashboard, go to **Manage Account** > **Members** > **User Groups**.

[Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)

2. Select the group you want to configure.
3. Assign the appropriate policies to define the [roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/) for group members.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/authentik/#page","headline":"Provision with Authentik","description":"Configure Authentik as a SCIM identity provider to provision users and groups into your Cloudflare account.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/authentik/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Configure Microsoft Entra as a SCIM identity provider to provision users and groups into your Cloudflare account.
title: Provision with Microsoft Entra
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Provision with Microsoft Entra

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/entra/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

**Important Update:** Cloudflare now supports native User Groups for enhanced access control. This new feature replaces the previous method of directly assigning Cloudflare roles based on IdP group mappings (identified by the pattern `CF-<accountID> - <Role Name>`), which is deprecated as of June 2nd, 2025. SCIM Virtual Groups will reach end-of-life on December 2, 2025. Update your SCIM configurations using the instructions below to utilize User Groups for seamless provisioning.

Once you have [gathered the required data](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/#gather-the-required-data), the following steps will be required to finish the provisioning with Entra.

## Set up the Enterprise application

1. Go to the Entra admin center and select **Applications** > **Enterprise Applications**.
2. In the Microsoft Entra Gallery, select **New application** > **Create your own application**, then choose a name.
3. Select **Integrate any other application you don't find in the gallery (Non-gallery)**.
4. **Create** an application.

## Provision the Enterprise application

1. Inside the newly created application under **Manage** from the sidebar menu, select **Provisioning**.
2. Select **New configuration** and enter the **Tenant URL**: `https://api.cloudflare.com/client/v4/accounts/<ACCOUNT_ID>/scim/v2`. Replace `<ACCOUNT_ID>` with your own account ID.
3. Paste the SCIM provisioning API token value as **Secret token**.
4. Select **Test Connection** then **Save** the configuration.

## Configure user and group synchronization

1. Navigate to the newly created application under **Manage** from the sidebar menu, select **Users and groups**.
2. [Assign users and groups to the application ↗](https://learn.microsoft.com/entra/identity/enterprise-apps/assign-user-or-group-access-portal).
3. After the users are assigned, navigate to **Provisioning** on the sidebar menu and select **Start Provisioning**.

Note

To successfully synchronize the group details into Cloudflare the `User Principal Name` (of `Identity`) and `Email` (of `Contact Information`) fields of each user must be identical. Values are case-sensitive, and the User Principal Name can only contain alphanumeric characters. Learn more about [how to create, invite, and delete users ↗](https://learn.microsoft.com/entra/fundamentals/how-to-create-delete-users).

4. To validate which users and groups have been synchronized, navigate to **Provisioning logs** on the sidebar menu. You can also [review the Cloudflare Audit Logs](https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/).

Read-only group

If the Entra group shares the same name of an existing Cloudflare user group, the Cloudflare user group will become read-only after the provisioning.

5. To grant permissions to users and groups at Cloudflare, refer to [Roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/) and [Policies](https://developers.cloudflare.com/fundamentals/manage-members/policies/).

## (Optional) Automate Cloudflare's SCIM integration

Cloudflare's SCIM integration requires one external application per account. Customers with multiple accounts may want to automate part of the setup to save time and reduce the amount of time spent in the Entra administrative UI.

The initial setup of creating the non-gallery applications and adding the provisioning URL and API key are scriptable via API, but the rest of the setup is dependent on your specific need and IDP configuration.

**1. Get an access token**

Get an Entra access token. Note that the example below is using the Azure CLI.

```plaintext
# Using azure-cli
az login
az account get-access-token --resource https://graph.microsoft.com

(payload with accessToken returned)
```

**2. Create a new application via template.**

The template ID 8adf8e6e-67b2-4cf2-a259-e3dc5476c621 is the suggested template to create non-gallery apps in the Entra docs. Replace `<accessToken>` and `displayName` with your values.

*Example requestcurl*

```curl
curl -X POST 'https://graph.microsoft.com/v1.0/applicationTemplates/8adf8e6e-67b2-4cf2-a259-e3dc5476c621/instantiate' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: Bearer <accessToken>' \
  --data-raw '{
    "displayName": "Entra API create application test"
}'
```

*Example responsecurl*

```curl
{
  "@odata.context": "https://graph.microsoft.com/v1.0/$metadata#microsoft.graph.applicationServicePrincipal",
  "application": {
    "id": "343a8552-f9d9-471c-b677-d37062117cc8", //
    "appId": "03d8207b-e837-4be9-b4e6-180492eb3b61",
    "applicationTemplateId": "8adf8e6e-67b2-4cf2-a259-e3dc5476c621",
    "createdDateTime": "2025-01-30T00:37:44Z",
    "deletedDateTime": null,
    "displayName": "Entra API create application test",
    "description": null,
    // ... snipped rest of large application payload
  },
  "servicePrincipal": {
    "id": "a8cb133d-f841-4eb9-8bc9-c8e9e8c0d417", // Note this ID for the subsequent request
    "deletedDateTime": null,
    "accountEnabled": true,
    "appId": "03d8207b-e837-4be9-b4e6-180492eb3b61",
    "applicationTemplateId": "8adf8e6e-67b2-4cf2-a259-e3dc5476c621",
    "appDisplayName": "Entra API create application test",
	// ...snipped rest of JSON payload
}
}
```

**3. Create a provisioning job**

To enable provisioning, you will also need to create a job. Note the SERVICE\_PRINCIPAL\_ID in the previous request will be used in the request below. The SCIM templateId is an Entra provided template.

*Example requestcurl*

```curl
curl -X POST 'https://graph.microsoft.com/v1.0/servicePrincipals/<SERVICE_PRINCIPAL_ID>/synchronization/jobs' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: Bearer <accessToken>' \
  --data-raw '{
    "templateId": "scim"
}'
```

*Example responsecurl*

```curl
{
  "@odata.context": "https://graph.microsoft.com/v1.0/$metadata#servicePrincipals('a8cb133d-f841-4eb9-8bc9-c8e9e8c0d417')/synchronization/jobs/$entity",
  "id": "scim.5b223a2cc249463bbd9a791550f11c76.03d8207b-e837-4be9-b4e6-180492eb3b61",
  "templateId": "scim",
  "schedule": {
    "expiration": null,
    "interval": "PT40M",
    "state": "Disabled"
  },
}
// ... snipped rest of JSON payload
```

**4. Configure the SCIM provisioning URL and API token**

Next, configure the Tenant URL (Cloudflare SCIM endpoint) and API token (SCIM Provisioning API Token).

Replace `<accessToken>`, `<ACCOUNT_ID>`, `<SCIM_PROVISIONING_API_TOKEN_VALUE>` with your values.

*Example requestcurl*

```curl
--header 'Content-Type: application/json' \
  --header 'Authorization: Bearer <accessToken>' \
  --data-raw '{
  "value": [
    {
      "key": "BaseAddress",
      "value": "https://api.cloudflare.com/client/v4/accounts/<ACCOUNT_ID>/scim/v2"
    },
    {
      "key": "SecretToken",
      "value": "<SCIM_PROVISIONING_API_TOKEN_VALUE>"
    }
  ]
}'
```

After completing the tasks above, the next steps in Entra include:

- Additional group/provisioning configuration
- Test and save after updating the config.
- Provisioning after configuration is complete

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/entra/#page","headline":"Provision with Microsoft Entra","description":"Configure Microsoft Entra as a SCIM identity provider to provision users and groups into your Cloudflare account.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/entra/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Configure Okta as a SCIM identity provider to provision users and groups into your Cloudflare account.
title: Provision with Okta
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Provision with Okta

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/okta/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

**Important Update:** Cloudflare now supports native User Groups for enhanced access control. This new feature replaces the previous method of directly assigning Cloudflare roles based on IdP group mappings (identified by the pattern `CF-<accountID> - <Role Name>`), which is deprecated as of June 2nd, 2025. SCIM Virtual Groups will reach end-of-life on December 2, 2025. Update your SCIM configurations using the instructions below to utilize User Groups for seamless provisioning.

Once you have [gathered the required data](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/#gather-the-required-data), the following steps will be required to finish the provisioning with Okta.

## Set up your Okta SCIM application

1. In the Okta dashboard, go to **Applications** > **Applications**.
2. Select **Browse App Catalog**.
3. Locate and select **SCIM 2.0 Test App (OAuth Bearer Token)**.
4. Select **Add Integration** and name your integration.
5. Enable the following options:
   - **Do not display application icon to users**
   - **Do not display application icon in the Okta Mobile App**
6. Disable **Automatically log in when user lands on login page**.
7. Select **Next**, then select **Done**.

## Integrate the Cloudflare API

Note

The **Update User Attributes** option is not supported.

1. In your integration page, go to **Provisioning** > **Configure API Integration**.
2. Enable **Enable API Integration**.
3. In SCIM 2.0 Base URL, enter: `https://api.cloudflare.com/client/v4/accounts/<accountID>/scim/v2`, substituting `accountID` for your [Cloudflare Account ID](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/#get-the-account-id).
4. In the **OAuth Bearer Token** field, enter your API token value.
5. Deselect **Import Groups**.

## Configure user & group sync in Okta

1. In **Provisioning to App**, select **Edit**.
2. Enable **Create Users** and **Deactivate Users**. Select **Save**.
3. Select **Done**.
4. In the Assignments tab, add the users you want to synchronize with Cloudflare dashboard. You can add users in batches by assigning a group. If a user is removed from the application assignment via either direct user assignment or removed from the group that was assigned to the app, this will trigger a deprovisioning event from Okta to Cloudflare.
5. In the Push Groups tab, add the Okta groups you want to synchronize with Cloudflare dashboard. View these Okta groups in the dashboard under Manage Account > Manage members > Members > User Groups.

To verify the integration, select **View Logs** in the Okta SCIM application, and check the Audit Logs in the Cloudflare dashboard by navigating to **Manage Account** > **Audit Log**.

This will provision all of the users in the group(s) affected to your Cloudflare account with "minimal account access."

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/okta/#page","headline":"Provision with Okta","description":"Configure Okta as a SCIM identity provider to provision users and groups into your Cloudflare account.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/okta/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Restore Super Administrator access and resolve common SCIM provisioning issues on your Cloudflare account.
title: SCIM troubleshooting
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# SCIM troubleshooting

Last updated Jul 14, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/troubleshooting/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Restore Super Administrator after group misconfiguration

If you have removed all Super Administrators mistakenly, you can restore the role to account member(s) using the Account API Token you created for SCIM provisioning.

First, fetch a list of account members and find the member ID for the user you want to restore Super Admin to via [list members](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/list/).

```curl
curl -X GET "https://api.cloudflare.com/client/v4/accounts/{account_id}/members" \
  -H "Authorization: Bearer YOUR_SCIM_AOT" \
  -H "Content-Type: application/json"
```

Then restore the Super Admin role to that member via [update member](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/update/)

```curl
curl -X PUT "https://api.cloudflare.com/client/v4/accounts/{account_id}/members/{member_id}" \
  -H "Authorization: Bearer YOUR_SCIM_AOT" \
  -H "Content-Type: application/json" \
  -d '{
    "roles": [
      {
        "id": "33666b9c79b9a5273fc7344ff42f953d"
      }
    ]
  }'
```

The value `33666b9c79b9a5273fc7344ff42f953d` is the role ID of Super Administrator.

## Update email domains after onboarding

We currently **do not** support updating email domains for users. This means that any SCIM `PATCH`/`PUT` operations that change email domains will be rejected. We recommend not using the email as the matching attribute if email domains are expected to change, and restarting provisioning manually.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/troubleshooting/#page","headline":"SCIM troubleshooting","description":"Restore Super Administrator access and resolve common SCIM provisioning issues on your Cloudflare account.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/troubleshooting/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: If you observe suspicious activity within your Cloudflare account, secure your account with these steps.
title: Secure compromised account
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Secure compromised account

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/secure-a-compromised-account/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If you observe suspicious activity within your Cloudflare account, secure your account with these steps.

## Step 1 - Change your password

For more guidance on changing your password, refer to [Change email address or password](https://developers.cloudflare.com/fundamentals/user-profiles/change-password-or-email/).

## Step 2 - Revoke active account sessions

When there is more than one active session associated with your email account, you can revoke any session that is not the current session.

To revoke a session:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile** > **Sessions**.
3. On a specific section, click **Revoke**.
4. You will be prompted to enter your password before revoking the session.

## Step 3 - Enable Two-Factor Authentication (2FA)

To prevent future compromises, make sure that you have [Two-Factor Authentication (2FA)](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) enabled on your account.

## Step 4 - Change API keys and tokens

### API keys

If your API key might be compromised, change your API key:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile** > **API Tokens**.
3. In the **API Keys** section, find your key.
4. Select **Change**.

### API tokens

If your token is lost or compromised, you can either create a new token or roll your token to generate a new secret. Rolling your API token into a new one will invalidate the previous token, but the access and permissions will be the same as the previous API token. The new token uses the [scannable format](https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/), which allows credential scanning tools to detect leaked tokens.

To roll your API token:

1. Go to **My Profile** > **API Tokens**. [Go to **API Tokens** ↗](https://dash.cloudflare.com/profile/api-tokens)
2. Next to the API token you want to roll, select the **three dot icon** > **Roll**.
3. Select **Confirm** to generate a new API token.

## Step 5 - Review the audit log

To access audit logs in the Cloudflare dashboard:

In the Cloudflare dashboard, go to the **Audit Logs** page.

[Go to **Audit logs** ↗](https://dash.cloudflare.com/?to=/:account/audit-log)

You can search these audit logs by user email or domain and filter by date range. To download audit logs, click **Download CSV**.

Note

Depending on the volume of data, the export of large amounts of events from Audit Logs might fail with errors. We always recommend using Cloudflare [Logpush](https://developers.cloudflare.com/logs/logpush/) to make sure Audit Logs are always available and stored externally.

If you notice any settings were changed, you should undo those changes.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/secure-a-compromised-account/#page","headline":"Secure compromised account","description":"If you observe suspicious activity within your Cloudflare account, secure your account with these steps.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/secure-a-compromised-account/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Prevent other teams from adding your active Cloudflare zones to a different account by enabling zone holds.
title: Zone holds
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Zone holds

Last updated Aug 14, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/account-security/zone-holds/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Zone holds prevent other teams in your organization from adding zones that are already active in another account.

For example, you might already have an active Cloudflare zone for `example.com`. If another team does not realize this, they could add and activate `example.com` in another Cloudflare account, which may cause downtimes or security issues until the original zone could be re-activated.

Note

Zone holds are enabled by default for all Enterprise zones.

## Availability

|  | Free | Pro | Business | Enterprise |
| --- | --- | --- | --- | --- |
| Availability | No | No | No | Yes |

## Enable zone holds

When you enable a zone hold, no one else can [add your zone](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/) to their Cloudflare account. If they attempt to, they will receive the following message:

*The zone name provided is subject to a hold which disallows the creation of this zone. Please contact the domain owner to have this hold removed.*

To enable a zone hold:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com).
2. Select your account and zone.
3. On the zone homepage, go to **Quick Actions**.
4. For **Zone Hold**, switch the toggle to **On**.

You also have the option to **Also prevent subdomains**, which prevents anyone in your organization from creating subdomains or custom hostnames related to your zone.

## Release zone holds

You may want to temporarily release a zone hold to allow another team to [register a subdomain](https://developers.cloudflare.com/dns/zone-setups/subdomain-setup/) in a separate Cloudflare account, such as `docs.example.com`.

To release a zone hold:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com).
2. Select your account and zone.
3. On the zone homepage, go to **Quick Actions**.
4. For **Zone Hold**, switch the toggle to **Off**.
5. Choose the length of your release.
6. Select **Release hold**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/account-security/zone-holds/#page","headline":"Zone holds","description":"Prevent other teams from adding your active Cloudflare zones to a different account by enabling zone holds.","url":"https://developers.cloudflare.com/fundamentals/account/account-security/zone-holds/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Add or replace a Super Administrator on your Cloudflare account when someone leaves or loses access.
title: Change Super Administrator
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Change Super Administrator

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/change-super-admin/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If you or someone in your organization leaves or loses access to email, you can add another Super Administrator using any other Super Administrator on your Account with a [verified email ↗](https://developers.cloudflare.com/fundamentals/account/verify-email-address/) address.

First, [add a member](https://developers.cloudflare.com/fundamentals/manage-members/manage/) to your account and assign the **Super Administrator** role.

Then, if needed, remove the previous Super Administrator.

Note

Cloudflare recommends having more than one user as Super Administrators for your accounts, so that if you are unable to login with your credentials for any reason, there is another one you can use to manage your domains.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/change-super-admin/#page","headline":"Change Super Administrator","description":"Add or replace a Super Administrator on your Cloudflare account when someone leaves or loses access.","url":"https://developers.cloudflare.com/fundamentals/account/change-super-admin/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to create a new Cloudflare account.
title: Create account
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Create account

Last updated Sep 17, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/create-account/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

To create your first Cloudflare account:

1. Go to the [Sign up page ↗](https://dash.cloudflare.com/sign-up).
2. Enter your **Email** and **Password**.
3. Select **Create Account**.

Once you create your account, Cloudflare will automatically send an email to your address to [verify that email address](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

## Create an additional Free account

Existing users can create additional Free accounts in the dashboard or with the API.

### Eligibility

The following requirements apply to Free account creation:

- Your Cloudflare user must be active and at least seven days old.
- You must have the Super Administrator role on an existing account.
- You can create up to five additional Free accounts.

### Create an account in the dashboard

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and go to **Accounts**. [Go to **Accounts** ↗](https://dash.cloudflare.com/)
2. Select **Create Account**.
3. Enter an account name.
4. Select **Create Account**.

### Create an account with the API

Use a user-owned API token or OAuth access token. Account-owned API tokens cannot create accounts.

A user-owned API token requires the **User Details Read** permission. An OAuth access token requires the `user-details.read` scope.

Set the `standalone` field to `true` and omit `unit`. Every Free account creation request requires exactly one valid `Idempotency-Key` header. Reuse the same key when retrying the same request.

Set `CLOUDFLARE_API_TOKEN` to a user-owned API token. Set `IDEMPOTENCY_KEY` to a unique value for this account creation request.

```bash
curl "https://api.cloudflare.com/client/v4/accounts" \
	--request POST \
	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
	--header "Content-Type: application/json" \
	--header "Idempotency-Key: $IDEMPOTENCY_KEY" \
	--data '{"name":"Example account","type":"standard","standalone":true}'
```

Set `CLOUDFLARE_OAUTH_TOKEN` to an OAuth access token. Set `IDEMPOTENCY_KEY` to a unique value for this account creation request.

```bash
curl "https://api.cloudflare.com/client/v4/accounts" \
	--request POST \
	--header "Authorization: Bearer $CLOUDFLARE_OAUTH_TOKEN" \
	--header "Content-Type: application/json" \
	--header "Idempotency-Key: $IDEMPOTENCY_KEY" \
	--data '{"name":"Example account","type":"standard","standalone":true}'
```

For the complete request schema, refer to [Create Account](https://developers.cloudflare.com/api/resources/accounts/methods/create/).

### Resolve account creation errors

Use the error message to resolve common account creation failures:

| Error | Resolution |
| --- | --- |
| Your user is less than seven days old. | Wait until the user is at least seven days old. |
| You are not a Super Administrator. | Confirm that you have the Super Administrator role on an existing account. |
| You reached an account creation limit. | Use an existing account or contact your account team. |
| Account creation is temporarily unavailable. | Retry the request later with the same idempotency key. |
| The idempotency key was used for a different request. | Use a new key for the new request. Reuse the original key only for an identical retry. |
| Your user is suspended. | Contact [Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/). |

## Account name

Your account name defaults to `<<YOUR_EMAIL_ADDRESS>>'s Account`.

You may want to customize the name of this account, either to help specify its purpose or to help associate it with multiple accounts.

To change your account name:

1. In the Cloudflare dashboard, go to the **Configurations** page. [Go to **Configurations** ↗](https://dash.cloudflare.com/?to=/:account/configurations)
2. For **Account Name**, select **Change Name**.
3. Enter a new account name.
4. Select **Save**.

## Best practices

If you are creating an account for your team or a business, we recommend choosing an email alias or distribution list for your **Email**, such as `cloudflare@example.com`.

This email address is the main point of contact for your Cloudflare billing, usage notifications, and account recovery.

Refer to [Account and domain management best practices](https://developers.cloudflare.com/fundamentals/reference/best-practices/) for a detailed list of ways to protect your account and domain.

Once you [set up an account](https://developers.cloudflare.com/fundamentals/account/), you have several ways to interact with Cloudflare.

## Interact with Cloudflare

If you prefer working without code, you can manage your account and domain settings through the [Cloudflare dashboard ↗](https://dash.cloudflare.com/login).

Note

If your domain was added to Cloudflare by a hosting partner, manage your DNS records via the hosting partner.

For those who prefer to interact with Cloudflare programmatically, you can use several methods:

| Resource | Docs | Description |
| --- | --- | --- |
| [Cloudflare API](https://developers.cloudflare.com/fundamentals/api/) | [API docs](https://developers.cloudflare.com/api/) | RESTful API based on HTTPS requests and JSON responses. |
| [Terraform ↗](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs) | [Terraform docs](https://developers.cloudflare.com/terraform/) | Configure Cloudflare using HashiCorp's Infrastructure as Code tool, Terraform. |
| [cloudflare-go ↗](https://github.com/cloudflare/cloudflare-go) | [README ↗](https://github.com/cloudflare/cloudflare-go#readme) | The official Go library for the Cloudflare API. |
| [cloudflare-typescript ↗](https://github.com/cloudflare/cloudflare-typescript) | [README ↗](https://github.com/cloudflare/cloudflare-typescript#readme) | The official TypeScript library for the Cloudflare API. |
| [cloudflare-python ↗](https://github.com/cloudflare/cloudflare-python) | [README ↗](https://github.com/cloudflare/cloudflare-python#readme) | The official Python library for the Cloudflare API. |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/create-account/#page","headline":"Create account","description":"Learn how to create a new Cloudflare account.","url":"https://developers.cloudflare.com/fundamentals/account/create-account/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-17","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Locate your Cloudflare account ID and zone ID in the dashboard for use with the API.
title: Find account and zone IDs
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Find account and zone IDs

Last updated Aug 3, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Once you [set up a new account](https://developers.cloudflare.com/fundamentals/account/) and [add your domain](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/) to Cloudflare, you may need access to your zone and account IDs for API operations.

## Copy your account ID

1. Open the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Select **Search** (or press `CMD/CTRL + K` from any page).
3. Enter `Copy account ID` and select the result to copy.![Search results showing the Copy account ID command](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=600,height=199,format=webp/_astro/quick-search-account-id.n1JgrcIV.png)

## Copy your zone ID

1. In the Cloudflare dashboard, select the domain you want the zone ID for. [Go to **Domains** ↗](https://dash.cloudflare.com/?to=/:account/domains/overview)
2. On the domain **Overview** page, locate the **API** section towards the bottom of the page.![Domain Overview page with the API section highlighted](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=600,height=709,format=webp/_astro/dash-overview-api-highlighted.uHQaRqfT.png)
3. Select the copy button next to **Zone ID**. You can also copy **Account ID** from this section.

## Find account ID in Workers & Pages

You can also find your account ID from the **Workers & Pages** section of your account.

1. In the Cloudflare dashboard, go to **Workers & Pages**. [Go to **Workers & Pages** ↗](https://dash.cloudflare.com/?to=/:account/workers-and-pages)
2. Locate the **Account Details** section.
3. Select the copy button next to **Account ID**.![Workers \& Pages Overview page with the Account ID section highlighted](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=600,height=262,format=webp/_astro/workers-account-id.BndMHhMr.png)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/#page","headline":"Find account and zone IDs","description":"Locate your Cloudflare account ID and zone ID in the dashboard for use with the API.","url":"https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-03","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn what account API tokens are, when to use them, and what they currently work with
title: Account API tokens
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Account API tokens

Last updated Sep 2, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

While user tokens act on behalf of a particular user and inherit a subset of that user's permissions, account API tokens allow you to set up durable integrations that can act as service principals with their own specific set of permissions. This approach is ideal for scenarios like CI/CD, or building integrations with external services like SIEMs where it is important that the integration continues working, even long after the user who configured the integration may have left your organization altogether. User tokens are better for ad hoc tasks like scripting, where acting as the user is ideal and durability is less of a concern.

New account API tokens use the `cfat_` prefixed [scannable format](https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/), which allows credential scanning tools to detect leaked tokens.

## Create an account owned token

Note

Creating or updating an account owned token requires Super Administrator permission on the account

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com).
2. Go to **Manage Account** > **Account API Tokens**.
3. Select **Create Token** and fill in the token name, permissions, and the optional expiration date for the token.
4. Select **Continue to summary** and review the details.
5. Select **Create Token**.

Alternatively, you can create a token using the [account API token creation API](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/create/).

Refer to the [blog post ↗](https://blog.cloudflare.com/account-owned-tokens-automated-actions-zaraz/) for more information.

## Compatibility matrix

Account API tokens are generally available for all accounts. Some services may not support account API tokens yet. Refer to the compatibility matrix below for the latest status.

| Product | Compatibility |
| --- | --- |
| Access | ✅ |
| Account Analytics | ✅ |
| Account Management | ✅ |
| AI Gateway | ✅ |
| API Shield | ✅ |
| Argo | ✅ |
| Billing | ✅ |
| Browser Run | ✅ |
| Bulk Redirects | ✅ |
| Cache | ✅ |
| Tiered Cache | ✅ |
| Client-side security (formerly Page Shield) | ✅ |
| Cloud Connector | ✅ |
| Configuration Rules | ✅ |
| Custom Lists | ✅ |
| Custom Pages | ✅ |
| D1 | ✅ |
| Data Loss Prevention | ✅ |
| Digital Experience Monitoring | ✅ |
| Distributed Web | ✅ |
| DNS | ✅ |
| Durable Objects | ✅ |
| Email Relay | ✅ |
| Secure Web Gateway | ✅ |
| Healthchecks | ✅ |
| Hyperdrive | ✅ |
| Images | ✅ |
| Intel Data Platform | ❌ |
| Load Balancing | ✅ |
| Log Explorer | ✅ |
| Network Flow | ✅ |
| Magic Transit | ✅ |
| Cloudflare WAN | ✅ |
| Managed Rules | ✅ |
| Network Error Logging | ✅ |
| Page Rules | ❌ |
| Pages | ✅ |
| R2 | ✅ |
| Radar | ✅ |
| Registrar | ❌ |
| Rulesets | ✅ |
| Spectrum | ✅ |
| Speed | ✅ |
| SSL/TLS | ✅ |
| Stream | ✅ |
| Super Bot Fight Mode | ❌ |
| Trace | ✅ |
| Tunnels | ✅ |
| Turnstile | ❌ |
| Vectorize | ✅ |
| Waiting Room | ✅ |
| Workers | ✅ |
| Workers AI | ✅ |
| Workers KV | ✅ |
| Workers Observability | ✅ |
| Workers Queues | ✅ |
| Workflows | ✅ |
| Zaraz | ✅ |
| Zero Trust Client Platform | ❌ |
| Zero Trust Devices and Services | ✅ |
| Zone/Domain Management | ✅ |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/#page","headline":"Account API tokens","description":"Learn what account API tokens are, when to use them, and what they currently work with","url":"https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-02","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Retrieve or change your Cloudflare Origin CA key used to authenticate Origin CA certificate API requests.
title: Get Origin CA keys
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Get Origin CA keys

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/get-started/ca-keys/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Deprecated

Origin CA keys (Service Keys) are deprecated and will be removed on September 30, 2026. Use an [API Token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) with `Zone`-`SSL and Certificates`-`Edit` permissions instead. For more information, refer to [API deprecations](https://developers.cloudflare.com/fundamentals/api/reference/deprecations/).

Origin CA keys are often used as the value of header `X-AUTH-USER-SERVICE-KEY` when interacting with [Origin CA certificates](https://developers.cloudflare.com/ssl/origin-configuration/origin-ca/) API. It is also used by [Keyless SSL](https://developers.cloudflare.com/ssl/keyless-ssl/) key server.

The key value always starts with `v1.0-`.

## Limitations

- Changing the Origin CA key is not recorded by [Audit Logs](https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/).
- Each time you view the Origin CA key, it will be presented as a different value. All these different values are **simultaneously valid** until you click the `Change` button, which immediately invalidates all previously generated values.
- Origin CA keys have access to every account the user has access to.

## View/Change your Origin CA keys

To retrieve your Origin CA keys:

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com). [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **User Profile** > **API Tokens**.
3. In the **API Keys** section, select `Origin CA Key`.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/get-started/ca-keys/#page","headline":"Get Origin CA keys","description":"Retrieve or change your Cloudflare Origin CA key used to authenticate Origin CA certificate API requests.","url":"https://developers.cloudflare.com/fundamentals/api/get-started/ca-keys/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to create a token to perform actions using the Cloudflare API.
title: Create API token
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Create API token

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Prerequisite

Before you begin, [find your zone and account IDs](https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/).

1. Determine if you want a user token or an [Account API token](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/). Use Account API tokens if you prefer service tokens that are not associated with users and your [desired API endpoints are compatible](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/#compatibility-matrix).
2. From the [Cloudflare dashboard ↗](https://dash.cloudflare.com/profile/api-tokens/), go to **My Profile** > **API Tokens** for user tokens. For Account Tokens, go to **Manage Account** > **API Tokens**.
3. Select **Create Token**.
4. Select a template from the available [API token templates](https://developers.cloudflare.com/fundamentals/api/reference/template/) or create a custom token. The following example uses the **Edit zone DNS** template.
5. Add or edit the token name to describe why or how the token is used. Templates are prefilled with a token name and permissions.![Token template overview screen](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1677,height=1328,format=webp/_astro/template-customize.Bt5BDoKm.png)
6. Modify the token's permissions. After selecting a permissions group (*Account*, *User*, or *Zone*), choose what level of access to grant the token. Most groups offer `Edit` or `Read` options. `Edit` is full CRUDL (create, read, update, delete, list) access, while `Read` is the read permission and list where appropriate. Refer to the [available token permissions](https://developers.cloudflare.com/fundamentals/api/reference/permissions/) for more information.
7. Select which resources the token is authorized to access. For example, granting `Zone DNS Read` access to a zone `example.com` will allow the token to read DNS records only for that specific zone. Any other zone will return an error for DNS record reads operations. Any other operation on that zone will also return an error.
8. (Optional) Restrict how a token is used in the **Client IP Address Filtering** and **TTL (time to live)** fields.
9. Select **Continue to summary**.
10. Review the token summary. Select **Edit token** to make adjustments. You can also edit a token after creation.

![Token summary screen displaying the resources and permissions selected](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1202,height=884,format=webp/_astro/token-summary.BFSJoL8C.png)

11. Select **Create Token** to generate the token's secret.
12. Copy the secret to a secure place.

Warning

The token secret is **only shown once**. Do not store the secret in plaintext where others can access it. Anyone with this token can perform the authorized actions against the resources that the token has access to.

![Token creation completion screen displaying your API token and the curl command to test your token](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1204,height=940,format=webp/_astro/token-complete.Dg4S1W72.png)

The token secret page also includes an example command to test the token. Use the `/user/tokens/verify` endpoint to fetch the current status of the given token.

```bash
curl "https://api.cloudflare.com/client/v4/user/tokens/verify" \
--header "Authorization: Bearer <API_TOKEN>"
```

The result:

```json
{
	"result": {
		"id": "100bf38cc8393103870917dd535e0628",
		"status": "active"
	},
	"success": true,
	"errors": [],
	"messages": [
		{
			"code": 10000,
			"message": "This API Token is valid and active",
			"type": null
		}
	]
}
```

New API tokens use the `cfut_` prefixed [scannable format](https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/), which allows credential scanning tools to detect leaked tokens.

With this you have successfully created an API token and can start working with the Cloudflare API. After creating your first API token, you can create additional API tokens [via the API](https://developers.cloudflare.com/fundamentals/api/how-to/create-via-api/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/get-started/create-token/#page","headline":"Create API token","description":"Learn how to create a token to perform actions using the Cloudflare API.","url":"https://developers.cloudflare.com/fundamentals/api/get-started/create-token/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Retrieve or change your Cloudflare Global API key, a legacy authentication method with full account access.
title: Get Global API key (legacy)
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Get Global API key (legacy)

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/get-started/keys/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Global API key is the previous authorization scheme for interacting with the Cloudflare API. When possible, use [API tokens](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) instead of Global API key.

New and rolled Global API Keys use the `cfk_` prefixed [scannable format](https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/), which allows credential scanning tools to detect leaked keys.

Note

Global API key is only available after the [account email address is verified](https://developers.cloudflare.com/fundamentals/user-profiles/verify-email-address/).

## Limitations

Global API key has multiple limitations when compared to API tokens:

- **Access to all Cloudflare resources** - Global API key has access to all of a user's resources. This makes it impossible to safely use Global API key to access non-production resources when a user also has access to production resources.
- **Full permissions** - Similarly, Global API key has the exact same permissions as the user, which means if the user can delete zones or change DNS records, so can the Global API key.
- **Limited to one per user** - Only one Global API key can be provisioned per user. This complicates using Cloudflare's API in production systems where maintaining two secrets for accessing the API is important in the case one needs to be rolled.
- **Lack of advanced limits on usage** - API tokens can be limited to specific time windows and expire or be limited to use from specific IP ranges.

For these reasons, Global API key is not recommended for new customers. Current customers using Global API key are encouraged to migrate and use API tokens instead.

## View your Global API key

To retrieve your Global API key:

1. In the Cloudflare dashboard and select **User Profile** > **API Tokens**. [Go to **Account API tokens** ↗](https://dash.cloudflare.com/?to=/:account/api-tokens)
2. In the **API Keys** section, click `View` button of **Global API Key**.

## Change your Global API key

If your API key might be compromised, change your API key:

1. Log in to the Cloudflare dashboard. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. Go to **My Profile** > **API Tokens**.
3. In the **API Keys** section, find your key.
4. Select **Change**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/get-started/keys/#page","headline":"Get Global API key (legacy)","description":"Retrieve or change your Cloudflare Global API key, a legacy authentication method with full account access.","url":"https://developers.cloudflare.com/fundamentals/api/get-started/keys/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Scannable API credential formats and leaked token detection.
title: Token formats
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Token formats

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare API credentials use a prefixed, scannable format that makes them identifiable by credential scanning tools. Each credential type has a distinct prefix followed by 40 characters and a checksum.

| Credential type | Description | Format |
| --- | --- | --- |
| Global API Key | Global key tied to your user account (full access) | `cfk_[40 characters][checksum]` |
| User API Token | Scoped token you create for specific permissions | `cfut_[40 characters][checksum]` |
| Account API Token | Token owned by the account, not tied to a specific user | `cfat_[40 characters][checksum]` |

Existing tokens continue to work. Every new token you create or [roll](https://developers.cloudflare.com/fundamentals/api/how-to/roll-token/) uses the scannable format automatically.

## Leaked token detection

The prefixed format and checksum allow credential scanning tools to detect leaked Cloudflare tokens with high confidence. Cloudflare partners with credential scanning providers to proactively find your leaked tokens and revoke them before they can be used maliciously.

### GitHub Secret Scanning

Cloudflare participates in [GitHub's Secret Scanning program ↗](https://docs.github.com/en/code-security/secret-scanning/introduction/about-secret-scanning). GitHub scans every commit for Cloudflare API credentials in both public and private repositories.

- **Public repositories** — When GitHub detects a leaked Cloudflare token, it verifies the token using the checksum and sends Cloudflare a webhook. Cloudflare automatically revokes the token and notifies you by email so you can generate a replacement.
- **Private repositories** — GitHub notifies you about any leaked Cloudflare tokens so you can rotate them.

## Pre-2026 formats

Tokens created before the scannable format was introduced use unprefixed strings. These tokens continue to work. Cloudflare scans for and revokes leaked tokens in both the old and new formats.

| Credential type | Old format |
| --- | --- |
| Global API Key | 37–45 character lowercase hex string |
| User API Token | 40-character alphanumeric string |
| Account API Token | 40-character alphanumeric string |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/#page","headline":"Token formats","description":"Scannable API credential formats and leaked token detection.","url":"https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Generate Cloudflare API tokens with pre-configured permissions using template URLs. Learn how to create and customize template URLs for any use case.
title: API token template URLs
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# API token template URLs

Last updated Jan 14, 2025|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Use template URLs to generate Cloudflare API tokens with pre-configured permissions. Template URLs allow you to share token requirements with users without manually selecting permissions in the dashboard.

Template URLs use query parameters to pre-fill the API token creation page in the Cloudflare dashboard. When a user opens a template URL, the dashboard automatically configures the specified permissions and settings.

Cloudflare supports template URLs for both [user API tokens](#user-token-url-format) and [account API tokens](#account-token-url-format). For more information on the difference between these token types, refer to [Account API tokens](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/).

Note

Template URLs only pre-fill the token creation form. Users must still complete the token creation process in the dashboard.

## User token URL format

User token template URLs open the token creation form at the user profile level (`/profile/api-tokens`). Tokens created this way are owned by the user.

The basic template URL structure is:

```txt
https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=[ENCODED_PERMISSIONS]&accountId=*&zoneId=all&name=[TOKEN_NAME]
```

### URL components

| Parameter | Required | Description |
| --- | --- | --- |
| `permissionGroupKeys` | Yes | URL-encoded JSON array of permission objects |
| `accountId` | Yes | Account scope (use `*` for all accounts) |
| `zoneId` | Yes | Zone scope (use `all` for all zones) |
| `name` | No | Pre-filled token name |

## Account token URL format

Account token template URLs open the token creation form at the account level. Tokens created this way are owned by the account (service principal tokens) and are not tied to any individual user. Creating account tokens requires Super Administrator or Administrator permissions.

The basic template URL structure is:

```txt
https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=[ENCODED_PERMISSIONS]&name=[TOKEN_NAME]
```

The `:account` segment is a placeholder. When a user opens the URL, the dashboard prompts them to select an account if they have access to more than one.

### URL components

| Parameter | Required | Description |
| --- | --- | --- |
| `permissionGroupKeys` | Yes | URL-encoded JSON array of permission objects |
| `name` | No | Pre-filled token name |

Note

Account token template URLs do not use `accountId` or `zoneId` parameters. Resource scoping for account tokens is configured during token creation in the dashboard.

## Permission format

Both user token and account token template URLs use the same permission encoding. Permissions are encoded as a JSON array with the following structure:

```json
[{ "key": "permission_name", "type": "read|edit|revoke|run|purge" }]
```

### Permission types

| Type | Description |
| --- | --- |
| `read` | Read-only access |
| `edit` | Full access (create, read, update, delete) |
| `revoke` | Revoke permissions |
| `run` | Execute permissions |
| `purge` | Purge permissions |

## Create custom templates

### 1. Identify required permissions

List the permissions your use case needs. Refer to the [permission reference](#permission-reference) table.

### 2. Create the permission JSON

Format your permissions as a JSON array:

```json
[
	{ "key": "dns", "type": "edit" },
	{ "key": "analytics", "type": "read" }
]
```

### 3. URL-encode the JSON

Use a URL encoder to convert the JSON string:

```text
%5B%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22analytics%22%2C%22type%22%3A%22read%22%7D%5D
```

### 4. Build the complete URL

For a **user token**, combine all components into the final template URL:

```txt
https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=[ENCODED_JSON]&accountId=*&zoneId=all&name=Custom%20Token
```

For an **account token**, use the account-level path instead:

```txt
https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=[ENCODED_JSON]&name=Custom%20Token
```

## Permission reference

Use this table to find permission keys for your custom templates.

### Account permissions

| Permission key | Description | Common use cases |
| --- | --- | --- |
| `account_analytics` | Account analytics | Reporting, monitoring |
| `account_api_tokens` | API token management | Token automation |
| `account_settings` | Account configuration | Account management |
| `billing` | Billing information | Cost tracking, invoicing |
| `workers_scripts` | Workers scripts | Serverless functions |
| `workers_kv_storage` | Workers KV storage | Data storage |
| `workers_routes` | Workers routes | Traffic routing |
| `workers_r2` | R2 storage | Object storage |
| `d1` | D1 database | SQL databases |
| `queues` | Queues | Message queuing |
| `page` | Cloudflare Pages | Page deployments |
| `stream` | Stream | Video streaming |
| `images` | Images | Image optimization |
| `logs` | Logs | Log management |

### Zone permissions

| Permission key | Description | Common use cases |
| --- | --- | --- |
| `dns` | DNS records | Domain management |
| `zone` | Zone management | Domain configuration |
| `zone_settings` | Zone settings | Zone configuration |
| `analytics` | Zone analytics | Performance monitoring |
| `firewall_services` | Firewall rules | Security management |
| `page_rules` | Page rules | Traffic control |
| `cache` | Cache purging | Content updates |
| `ssl_and_certificates` | SSL/TLS certificates | Certificate management |

### Access permissions

| Permission key | Description | Common use cases |
| --- | --- | --- |
| `access` | Access applications | Zero Trust apps |
| `access_acct` | Access organizations | Identity management |
| `access_audit_log` | Access audit logs | Compliance, security |
| `access_custom_page` | Custom pages | Branding, user experience |
| `teams` | Zero Trust | Gateway, CASB, DLP |

## Common permission templates

Use these ready-to-use template URLs for common scenarios. Each example provides both a user token URL and an account token URL.

### DNS management

Create tokens for DNS record management.

#### User token

| Use case | Template URL |
| --- | --- |
| DNS read-only | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=DNS%20Read%20Token` |
| DNS read/write | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22edit%22%7D%5D&accountId=%2A&zoneId=all&name=DNS%20Management%20Token` |

#### Account token

| Use case | Template URL |
| --- | --- |
| DNS read-only | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22read%22%7D%5D&name=DNS%20Read%20Token` |
| DNS read/write | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22dns%22%2C%22type%22%3A%22edit%22%7D%5D&name=DNS%20Management%20Token` |

### Workers development

Create tokens for Workers, KV storage, and related services.

#### User token

| Use case | Template URL |
| --- | --- |
| Workers scripts only | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22workers_scripts%22%2C%22type%22%3A%22edit%22%7D%5D&accountId=%2A&zoneId=all&name=Workers%20Scripts%20Token` |
| Workers full access | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22workers_scripts%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22workers_kv_storage%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22workers_routes%22%2C%22type%22%3A%22edit%22%7D%5D&accountId=%2A&zoneId=all&name=Workers%20Full%20Access%20Token` |

#### Account token

| Use case | Template URL |
| --- | --- |
| Workers scripts only | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22workers_scripts%22%2C%22type%22%3A%22edit%22%7D%5D&name=Workers%20Scripts%20Token` |
| Workers full access | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22workers_scripts%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22workers_kv_storage%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22workers_routes%22%2C%22type%22%3A%22edit%22%7D%5D&name=Workers%20Full%20Access%20Token` |

### Analytics and monitoring

Create tokens for accessing analytics and logs.

#### User token

| Use case | Template URL |
| --- | --- |
| Account analytics | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22account_analytics%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Account%20Analytics%20Token` |
| Zone analytics | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22analytics%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Zone%20Analytics%20Token` |

#### Account token

| Use case | Template URL |
| --- | --- |
| Account analytics | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22account_analytics%22%2C%22type%22%3A%22read%22%7D%5D&name=Account%20Analytics%20Token` |
| Zone analytics | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22analytics%22%2C%22type%22%3A%22read%22%7D%5D&name=Zone%20Analytics%20Token` |

### Zero Trust administration

Create tokens for Cloudflare Zero Trust management.

#### User token

| Use case | Template URL |
| --- | --- |
| Access applications read | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22access%22%2C%22type%22%3A%22read%22%7D%5D&accountId=%2A&zoneId=all&name=Access%20Read%20Token` |
| Access full management | `https://dash.cloudflare.com/profile/api-tokens?permissionGroupKeys=%5B%7B%22key%22%3A%22access%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22access_acct%22%2C%22type%22%3A%22edit%22%7D%5D&accountId=%2A&zoneId=all&name=Access%20Management%20Token` |

#### Account token

| Use case | Template URL |
| --- | --- |
| Access applications read | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22access%22%2C%22type%22%3A%22read%22%7D%5D&name=Access%20Read%20Token` |
| Access full management | `https://dash.cloudflare.com/?to=/:account/api-tokens&permissionGroupKeys=%5B%7B%22key%22%3A%22access%22%2C%22type%22%3A%22edit%22%7D%2C%7B%22key%22%3A%22access_acct%22%2C%22type%22%3A%22edit%22%7D%5D&name=Access%20Management%20Token` |

## Best practices

Follow these guidelines when creating and sharing template URLs.

- Principle of least privilege: Only request the minimum permissions necessary for your use case. This reduces security risks if a token is compromised.
- Use descriptive token names: Include clear, descriptive names in your template URLs to help users understand the token's purpose.
- Document token usage: Provide clear documentation about what each token is used for and how to revoke it when no longer needed.
- Regular token rotation: Encourage users to regularly rotate tokens and review permissions.
- Test before sharing: Always test template URLs in a staging environment before sharing them with users.

## Troubleshooting

Review the list of common issues and solutions.

| Issue | Solution |
| --- | --- |
| URL does not pre-fill permissions | Verify the JSON is properly URL-encoded |
| Permissions are missing | Check permission keys in the reference table |
| Token name does not appear | Ensure the name parameter is URL-encoded |
| Access denied error | Verify the user has required permissions in their account |

Additionally, review the checklist before sharing a template URL.

- All permission keys are correct
- JSON syntax is valid
- URL encoding is proper
- Token name is descriptive
- Permissions follow least privilege principle

## Related resources

- [API token permissions](https://developers.cloudflare.com/fundamentals/api/reference/permissions/)
- [Create API tokens](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/)
- [Account API tokens](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/)
- [API authentication](https://developers.cloudflare.com/fundamentals/api/how-to/make-api-calls/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/#page","headline":"API token template URLs","description":"Generate Cloudflare API tokens with pre-configured permissions using template URLs. Learn how to create and customize template URLs for any use case.","url":"https://developers.cloudflare.com/fundamentals/api/how-to/account-owned-token-template/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2025-01-14","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Restrict Cloudflare API access at the account or member level using Enterprise account controls.
title: Control API Access
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Control API Access

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/how-to/control-api-access/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Super administrators of an Enterprise account are capable of selectively scoping the API access. API access can be restricted for the entire account or only for specified account members.

Note that the feature does not disable API calls not related to the Enterprise account.

## Account-level access control

To restrict the API access for the entire account:

1. In the Cloudflare dashboard, go to the **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Locate the **Enable API Access** section and then update the setting.

## Member-level access control

Note

Member-level settings will override the account-level setting. If a specific member has API access enabled whereas the account has the access disabled, that member can still call APIs related to the Enterprise account.

To restrict the API access for a specific member:

1. In the Cloudflare dashboard, go to the **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Click on the member to expand and choose the intended **API Access**. If `Account Default`, then it follows the account level setting.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/how-to/control-api-access/#page","headline":"Control API Access","description":"Restrict Cloudflare API access at the account or member level using Enterprise account controls.","url":"https://developers.cloudflare.com/fundamentals/api/how-to/control-api-access/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to create API tokens via Cloudflare's API. Follow steps to define access policies, set restrictions, and generate tokens securely.
title: Create tokens via API
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Create tokens via API

Last updated Aug 11, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/how-to/create-via-api/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Generate new API tokens on the fly via the API. Before you can do this, you must create an API token in the Cloudflare dashboard that can create subsequent tokens.

Note

To create user-owned API tokens, use the [**Create additional tokens**](https://developers.cloudflare.com/fundamentals/api/reference/template/) template. The **User** > **API Tokens** > **Edit** permission is not available in any other template or in the Custom Token builder.

## Generating the initial token

Before you can use the API, you need to [generate an initial token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) via the Cloudflare dashboard. The required permission depends on the API operation. To grant users access to an account as members, create a token with **Account** > **Account Settings** > **Edit**. To create account-owned API tokens, create a token with **Account** > **Account API Tokens** > **Edit**. To create user-owned API tokens, use the **Create additional tokens** template.

Warning

The token secret is **only shown once**. Do not store the secret in plaintext where others can access it. Anyone with this token can perform the authorized actions against the resources that the token has access to.

### Recommendations

When using the **Create additional tokens** template, Cloudflare highly recommends that you do not grant other permissions to the token. Make sure you safeguard the new token because it can create tokens with access to any of a user's resources.

Cloudflare also recommends limiting the use of the token via client IP address filtering or TTL to reduce the potential for abuse in the event that the token is compromised. Refer to [Restrict token use](https://developers.cloudflare.com/fundamentals/api/how-to/restrict-tokens/) for more information.

## Creating API tokens with the API

You can create a user owned token or account owned token to use with the API. Refer to the [user owned token](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/create/) or the [account owned token](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/create/) API schema docs for more information.

To create a token:

1. Define the policy.
2. Define the restrictions.
3. Create the token.

### 1. Define the Access Policy

An Access Policy defines what resources the token can act on and what permissions the token has to those resources. This process is similar to how you [create tokens in the Cloudflare dashboard](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/).

Each token can contain multiple policies.

```json
[
	{
		"id": "f267e341f3dd4697bd3b9f71dd96247f",
		"effect": "allow",
		"resources": {
			"com.cloudflare.api.account.zone.eb78d65290b24279ba6f44721b3ea3c4": "*",
			"com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
		},
		"permission_groups": [
			{
				"id": "c8fed203ed3043cba015a93ad1616f1f",
				"name": "Zone Read"
			},
			{
				"id": "82e64a83756745bbbb1c9c2701bf816b",
				"name": "DNS Read"
			}
		]
	}
]
```

| Field | Description |
| --- | --- |
| `id` | Unique read-only identifier for the policy generated after creation. |
| `effect` | Defines whether this policy is allowing or denying access. If only creating one policy, use `allow`. The evaluation order for policies is as follows: 1. Explicit `DENY` Policies; 2. Explicit `ALLOW` Policies; 3. Implicit `DENY ALL`. |
| `resources` | Defines what resources are allowed to be configured. |
| `permission_groups` | Defines what permissions the policy grants to the included resources. |

#### Resources

API token policies support three resource types: `User`, `Account`, and `Zone`.

Note

Fetch each object's ID by calling the appropriate `GET <object>` API. Refer to [User](https://developers.cloudflare.com/api/resources/user/methods/get/), [Account](https://developers.cloudflare.com/api/resources/accounts/methods/list/), and [Zone](https://developers.cloudflare.com/api/resources/zones/methods/list/) documentation for more details.

##### Account

Include a single account or all accounts in a token policy.

- A **single account** is denoted as: `"com.cloudflare.api.account.<ACCOUNT_ID>": "*"`.
- **All accounts** is denoted as: `"com.cloudflare.api.account.*": "*"`

##### Zone

Include a **single zone**, **all zones in an account**, or **all zones in all accounts** in a token policy.

- A **single zone** is denoted as: `"com.cloudflare.api.account.zone.<ZONE_ID>": "*"`
- **All Zones in an account** are denoted as: `"com.cloudflare.api.account.<ACCOUNT_ID>": {"com.cloudflare.api.account.zone.*": "*"}`
- **All zones in all accounts** is denoted as: `"com.cloudflare.api.account.zone.*": "*"`

##### User

For user resources, you can only reference yourself, which is denoted as:`"com.cloudflare.api.user.<USER_TAG>": "*"`

#### Permission groups

Add permission groups to the API token by specifying their `id` values. We recommend using `id` as the key for interacting with Cloudflare APIs; the permission `name` is cosmetic and subject to change. Permission groups are scoped to specific resources (user, account, or zone), so a permission group in a policy will only apply to the resource type it is scoped for.

To fetch all available permission groups and their IDs, use the [List permission groups](https://developers.cloudflare.com/api/resources/user/subresources/tokens/subresources/permission_groups/methods/list/) endpoint:

<details>

<summary>

Required API token permissions

</summary>

At least one of the following <a href="https://developers.cloudflare.com/fundamentals/api/reference/permissions/">token permissions</a> is required:

- <code>API Tokens Write</code>
- <code>API Tokens Read</code>

</details>

*List Token Permission Groupsbash*

```bash
curl "https://api.cloudflare.com/client/v4/user/tokens/permission_groups" \
	--request GET \
	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

```json
{
  "result": [
    {
      "id": "19637fbb73d242c0a92845d8db0b95b1",
      "name": "AI Crawl Control Read",
      "description": "Grants access to reading AI Crawl Control",
      "scopes": [
        "com.cloudflare.api.account.zone"
      ]
    },
    {
      "id": "1ba6ab4cacdb454b913bbb93e1b8cb8c",
      "name": "AI Crawl Control Write",
      "description": "Grants access to reading and editing AI Crawl Control",
      "scopes": [
        "com.cloudflare.api.account.zone"
      ]
    },
    // (...)
	]
}
```

### 2. Define the restrictions

Set up any limitations on how the token can be used. API tokens allow restrictions for client IP address filtering and TTLs. Refer to [Restrict token use](https://developers.cloudflare.com/fundamentals/api/how-to/restrict-tokens/) for more information.

When defining TTLs, you can set the time at which a token becomes active with `not_before` and the time when it expires with `expires_on`. Both of these fields take UTC timestamps in the following format: `"2018-07-01T05:20:00Z"`.

Limit usage of a token by client IP address filters with the following object:

```json
{
	"request.ip": {
		"in": ["199.27.128.0/21", "2400:cb00::/32"],
		"not_in": ["199.27.128.0/21", "2400:cb00::/32"]
	}
}
```

Each parameter in the `in` and `not_in` objects must be in CIDR notation. For example, use `192.168.0.1/32` to specify a single IP address.

### 3. Create the token

Combine the previous information to create a token as in the following example:

```bash
curl "https://api.cloudflare.com/client/v4/accounts/{account_id}/tokens" \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
  "name": "readonly token",
  "policies": [
    {
      "effect": "allow",
      "resources": {
        "com.cloudflare.api.account.zone.eb78d65290b24279ba6f44721b3ea3c4": "*",
        "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
      },
      "permission_groups": [
        {
          "id": "c8fed203ed3043cba015a93ad1616f1f",
          "name": "Zone Read"
        },
        {
          "id": "82e64a83756745bbbb1c9c2701bf816b",
          "name": "DNS Read"
        }
      ]
    }
  ],
  "not_before": "2020-04-01T05:20:00Z",
  "expires_on": "2020-04-10T00:00:00Z",
  "condition": {
    "request.ip": {
      "in": [
        "199.27.128.0/21",
        "2400:cb00::/32"
      ],
      "not_in": [
        "199.27.128.1/32"
      ]
    }
  }
}'
```

```bash
curl "https://api.cloudflare.com/client/v4/user/tokens" \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
  "name": "readonly token",
  "policies": [
    {
      "effect": "allow",
      "resources": {
        "com.cloudflare.api.account.zone.eb78d65290b24279ba6f44721b3ea3c4": "*",
        "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
      },
      "permission_groups": [
        {
          "id": "c8fed203ed3043cba015a93ad1616f1f",
          "name": "Zone Read"
        },
        {
          "id": "82e64a83756745bbbb1c9c2701bf816b",
          "name": "DNS Read"
        }
      ]
    }
  ],
  "not_before": "2020-04-01T05:20:00Z",
  "expires_on": "2020-04-10T00:00:00Z",
  "condition": {
    "request.ip": {
      "in": [
        "199.27.128.0/21",
        "2400:cb00::/32"
      ],
      "not_in": [
        "199.27.128.1/32"
      ]
    }
  }
}'
```

```bash
curl "https://api.cloudflare.com/client/v4/user/tokens" \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
  "name": "readonly token",
  "policies": [
    {
      "effect": "allow",
      "resources": {
        "com.cloudflare.api.account.zone.eb78d65290b24279ba6f44721b3ea3c4": "*",
        "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
      },
      "permission_groups": [
        {
          "id": "c8fed203ed3043cba015a93ad1616f1f",
          "name": "Zone Read"
        },
        {
          "id": "82e64a83756745bbbb1c9c2701bf816b",
          "name": "DNS Read"
        }
      ]
    }
  ],
  "not_before": "2020-04-01T05:20:00Z",
  "expires_on": "2020-04-10T00:00:00Z",
  "condition": {
    "request.ip": {
      "in": [
        "199.27.128.0/21",
        "2400:cb00::/32"
      ],
      "not_in": [
        "199.27.128.1/32"
      ]
    }
  }
}'
```

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/how-to/create-via-api/#page","headline":"Create tokens via API","description":"Learn how to create API tokens via Cloudflare's API. Follow steps to define access policies, set restrictions, and generate tokens securely.","url":"https://developers.cloudflare.com/fundamentals/api/how-to/create-via-api/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-11","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to make API calls using Cloudflare's API with step-by-step instructions for Windows, including using curl and PowerShell, and handling JSON.
title: Make API calls
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Make API calls

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/how-to/make-api-calls/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Once you [create your API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/), all API requests are authorized in the same way. Cloudflare uses the [RFC standard ↗](https://tools.ietf.org/html/rfc6750#section-2.1) `Authorization: Bearer <API_TOKEN>` interface. An example request is shown below.

```bash
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID" \
--header "Authorization: Bearer YQSn-xWAQiiEh9qM58wZNnyQS7FUdoqGIUAbrh7T"
```

Never send or store your API token secret in plaintext. Also be sure not to check it into code repositories, especially public ones.

Consider defining [environment variables](#environment-variables) for the zone or account ID, as well as for authentication credentials (for example, the API token).

To format JSON output for readability in the command line, you can use a tool like `jq`, a command-line JSON processor. For more information on obtaining and installing `jq`, refer to [Download jq ↗](https://stedolan.github.io/jq/download/).

The following example will format the curl JSON output using `jq`:

```bash
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID" \
--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" | jq .
```

## Using Cloudflare's APIs

Every Cloudflare API element is fixed to a version number. The latest version is Version 4. The stable base URL for all Version 4 HTTPS endpoints is: `https://api.cloudflare.com/client/v4/`

For specific guidance on making API calls, refer to the following resources:

- The product's [Developer Docs section](https://developers.cloudflare.com/directory/) for how-to guides.
- [API schema docs](https://developers.cloudflare.com/api/) for request and response payloads for each endpoint.
- The first-party libraries for [Go ↗](https://github.com/cloudflare/cloudflare-go), [TypeScript ↗](https://github.com/cloudflare/cloudflare-typescript), [Python ↗](https://github.com/cloudflare/cloudflare-python), or [HashiCorp's Terraform ↗](https://github.com/cloudflare/terraform-provider-cloudflare).

## Query parameters

Several Cloudflare endpoints have optional query parameters to filter incoming results, such as [List Zones](https://developers.cloudflare.com/api/resources/zones/methods/list/).

When adding those query parameters, make sure you enclose the URL in double quotes `""` (just like the header values), or the API call might error.

```bash
curl "https://api.cloudflare.com/client/v4/zones?account.id=$ACCOUNT_ID" \
--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

You can enclose strings using either single quotes (`''`) or double quotes (`""`). However, using single quotes prevents variable substitution in shells like `bash`. In the previous example, this would mean that the `$ACCOUNT_ID` and `$CLOUDFLARE_API_TOKEN` [environment variables](#environment-variables) would not be replaced with their values.

### Pagination

Sometimes there will be too many results to display via the default page size, for example you might receive the following:

```txt
"count": 1,
"page": 1,
"per_page": 20,
"total_count": 200,
```

Two query parameter options exist, which can be combined to paginate across the results.

- `page=x` enables you to select a specific page.
- `per_page=xx` enables you to adjust the number of results displayed on a page. If you select too many, you may get a timeout.

An example might be `https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records?per_page=100&page=2`.

Other options are:

- `order`: Select the attribute to order by.
- `direction`: Either `ASC` (ascending order) or `DESC` (descending order).

The available options will be listed at the end of the `result_info` of all endpoints in the [API documentation](https://developers.cloudflare.com/api/).

## Making API calls on Windows

Recent versions of Windows 10 and 11 [already include the curl tool ↗](https://curl.se/windows/microsoft.html) used in the developer documentation's API examples. If you are using a different Windows version, refer to [Windows downloads ↗](https://curl.se/windows/) in the curl website for more information on obtaining and installing this tool.

### Using a Command Prompt window

To use the Cloudflare API with curl on a Command Prompt window, you must use double quotes (`"`) as string delimiters.

A typical `PATCH` request will be similar to the following:

```txt
C:\>curl --request PATCH "https://api.cloudflare.com/client/v4/user/invites/{id}" --header "X-Auth-Email: <EMAIL>" --header "X-Auth-Key: <API_KEY>" --data "{""status"": ""accepted""}"
```

To escape a double quote character in a request body (for example, a body specified with `-d` or `--data` in a `POST`/`PATCH` request), prepend it with another double quote (`"`) or a backslash (`\`) character.

To break a single command in two or more lines, use `^` as the line continuation character at the end of a line:

```txt
C:\>curl --request PATCH ^
"https://api.cloudflare.com/client/v4/user/invites/{id}" ^
--header "X-Auth-Email: <EMAIL>" ^
--header "X-Auth-Key: <API_KEY>" ^
--data "{""status"": ""accepted""}"
```

### Using PowerShell

Note

Cloudflare recommends that you use the most recent stable or preview version of PowerShell. For more information, refer to [Installing PowerShell on Windows ↗](https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-windows).

PowerShell has specific cmdlets (`Invoke-RestMethod` and `ConvertFrom-Json`) for making REST API calls and handling JSON responses. The syntax for these cmdlets is different from the curl examples provided in the developer documentation.

The following example uses the `Invoke-RestMethod` cmdlet:

```powershell
Invoke-RestMethod -URI "https://api.cloudflare.com/client/v4/zones/$Env:ZONE_ID/ssl/certificate_packs?ssl_status=all" -Method 'GET' -Headers @{'X-Auth-Email'=$Env:CLOUDFLARE_EMAIL;'X-Auth-Key'=$Env:CLOUDFLARE_API_KEY}
```

```txt
result      : {@{id=78411cfa-5727-4dc1-8d4a-773d01f17c7c; type=universal; hosts=System.Object[];
              primary_certificate=c173c8a1-9724-4e96-a748-2c4494186098; status=active; certificates=System.Object[];
              created_on=2022-12-09T23:11:06.010263Z; validity_days=90; validation_method=txt;
              certificate_authority=lets_encrypt}}
result_info : @{page=1; per_page=20; total_pages=1; count=1; total_count=1}
success     : True
errors      : {}
messages    : {}
```

The command assumes that the environment variables `ZONE_ID`, `CLOUDFLARE_EMAIL`, and `CLOUDFLARE_API_KEY` have been previously defined. For more information, refer to [Environment variables](#environment-variables).

By default, the output will only contain the first level of the JSON object hierarchy (in the above example, the content of objects such as `hosts` and `certificates` is not shown). To show additional levels and format the output like the `jq` tool, you can use the `ConvertFrom-Json` cmdlet specifying the desired maximum depth (by default, `2`):

```powershell
Invoke-RestMethod -URI "https://api.cloudflare.com/client/v4/zones/$Env:ZONE_ID/ssl/certificate_packs?ssl_status=all" -Method 'GET' -Headers @{'X-Auth-Email'=$Env:CLOUDFLARE_EMAIL;'X-Auth-Key'=$Env:CLOUDFLARE_API_KEY} | ConvertTo-Json -Depth 5
```

```json
{
	"result": [
		{
			"id": "78411cfa-5727-4dc1-8d4a-773d01f17c7c",
			"type": "universal",
			"hosts": ["*.example.com", "example.com"],
			"primary_certificate": "c173c8a1-9724-4e96-a748-2c4494186098",
			"status": "active",
			"certificates": [
				{
					"id": "c173c8a1-9724-4e96-a748-2c4494186098",
					"hosts": ["*.example.com", "example.com"],
					"issuer": "LetsEncrypt",
					"signature": "ECDSAWithSHA384",
					"status": "active",
					"bundle_method": "ubiquitous",
					"zone_id": "<ZONE_ID>",
					"uploaded_on": "2023-02-02T11:20:25.403338Z",
					"modified_on": "2022-12-08T00:26:15.577555Z",
					"expires_on": "2023-03-07T23:26:12.000000Z",
					"priority": null
				}
			],
			"created_on": "2022-12-09T23:11:06.010263Z",
			"validity_days": 90,
			"validation_method": "txt",
			"certificate_authority": "lets_encrypt"
		}
	]
	// (...)
}
```

ConvertFrom-Json handling of DateTime values

The `ConvertTo-Json` cmdlet tries to convert strings formatted as timestamps to DateTime values, according to the exact format in the string. For details on this behavior, refer to the notes in the [ConvertFrom-Json ↗](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/convertfrom-json#notes) documentation.

You can also use the curl tool in PowerShell. However, in PowerShell `curl` is an alias to the `Invoke-WebRequest` cmdlet, which supports a different syntax from the usual curl tool. To use curl, enter `curl.exe` instead.

A typical `PATCH` request with curl will be similar to the following:

```powershell
curl.exe --request PATCH "https://api.cloudflare.com/client/v4/user/invites/{id}" --header "Authorization: Bearer $Env:CLOUDFLARE_API_TOKEN" --data '{\"status\": \"accepted\"}'
```

To escape a double quote (`"`) character in a request body (specified with `-d` or `--data`), prepend it with another double quote (`"`) or a backslash (`\`). You must escape double quotes even when using single quotes (`'`) as string delimiters.

To break a single command in two or more lines, use a backtick (`` ` ``) character as the line continuation character at the end of a line:

```powershell
curl.exe --request PATCH `
"https://api.cloudflare.com/client/v4/user/invites/{id}" `
--header "X-Auth-Email: $Env:CLOUDFLARE_EMAIL" `
--header "X-Auth-Key: $Env:CLOUDFLARE_API_KEY" `
--data '{\"status\": \"accepted\"}'
```

## Environment variables

You can define environment variables for values that repeat between commands, such as the zone or account ID. The lifetime of an environment variable can be the current shell session, all future sessions of the current user, or even all future sessions of all users on the machine you are defining them.

You can also use environment variables for keeping authentication credentials (API token, API key, and email) and reusing them in different commands. However, make sure you define these values in the smallest possible scope (either the current shell session only or all new sessions for the current user).

The procedure for setting and referencing environment variables depends on your platform and shell.

### Define an environment variable

To define a `ZONE_ID` environment variable for the current shell session, run the following command:

```sh
export ZONE_ID='f2ea6707005a4da1af1b431202e96ac5'
```

To define the variable for all new shell sessions for the current user, add the command above at the end of your shell configuration file (for example, `~/.bashrc` for the `bash` shell and `~/.zshrc` for the `zsh` shell).

To define a `ZONE_ID` environment variable for the current PowerShell session, run the following command:

```powershell
$Env:ZONE_ID='f2ea6707005a4da1af1b431202e96ac5'
```

To define the environment variable for all new PowerShell sessions of the current user, set the variable in your PowerShell profile. You can get the path to your PowerShell profile by running `echo $PROFILE`.

Alternatively, set the variable for all new PowerShell sessions of the current user using the `SetEnvironmentVariable()` method of the `System.Environment` class. For example:

```powershell
[Environment]::SetEnvironmentVariable("ZONE_ID", "f2ea6707005a4da1af1b431202e96ac5", "User")
```

Running this command will not affect the current session. You will need to close and start a new PowerShell session.

To define a `ZONE_ID` environment variable for the current Command Prompt session, run the following command:

```txt
set ZONE_ID=f2ea6707005a4da1af1b431202e96ac5
```

To define an environment variable for all future Command Prompt sessions of the current user, run the following command:

```txt
setx ZONE_ID f2ea6707005a4da1af1b431202e96ac5
```

Running this command will not affect the current window. You will need to either run the `set` command or close and start a new Command Prompt window.

### Reference an environment variable

When referencing an environment variable in a command, add a `$` prefix to the variable name (for example, `$ZONE_ID`). Make sure that the full string referencing the variable is either unquoted (if it does not contain spaces) or enclosed in double quotes (`""`).

For example:

```sh
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID" \
--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

When referencing an environment variable in a command, add an `$Env:` prefix to the variable name (for example, `$Env:ZONE_ID`). Make sure that the full string referencing the variable is either unquoted or enclosed in double quotes (`""`).

For example:

```powershell
Invoke-RestMethod -URI "https://api.cloudflare.com/client/v4/zones/$Env:ZONE_ID" -Method 'GET' -Headers @{'Authorization'="Bearer $Env:CLOUDFLARE_API_TOKEN"}
```

When referencing an environment variable in a command, enclose the variable name in `%` characters (for example, `%ZONE_ID%`).

For example:

```txt
curl "https://api.cloudflare.com/client/v4/zones/%ZONE_ID%" --header "Authorization: Bearer %CLOUDFLARE_API_TOKEN%"
```

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/how-to/make-api-calls/#page","headline":"Make API calls","description":"Learn how to make API calls using Cloudflare's API with step-by-step instructions for Windows, including using curl and PowerShell, and handling JSON.","url":"https://developers.cloudflare.com/fundamentals/api/how-to/make-api-calls/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Limit Cloudflare API token usage by client IP address filtering and time-to-live (TTL) constraints.
title: Restrict tokens
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Restrict tokens

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/how-to/restrict-tokens/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

API tokens can be restricted at runtime in two ways:

- [Client IP address range filtering](#client-ip-address-range-filtering)
- [Time To Live (TTL) constraints](#time-to-live-ttl-constraints)

## Client IP address range filtering

Client IP address restrictions control which IP addresses can make API requests with this token. By default, if no filtering is applied, all IP addresses can use the token. Once an `Is in` rule is applied, the token can only be used from the defined IP addresses. Define ranges with [CIDR notation ↗](https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing#CIDR_notation). To allow an IP range with exceptions, define `Is not in` to exempt specific IPs or smaller ranges.

![IP Address filtering options](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1802,height=442,format=webp/_astro/ip-filter.DbEuurVj.png)

Note

Client IP address range filtering is not applied to the [Verify Token ↗](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/verify/) endpoint.

## Time to live (TTL) constraints

By default, tokens do not expire and are long lived. Defining a TTL sets when a token starts being valid and when a token is no longer valid. This is often referred to as `notBefore` and `notAfter`. Setting these timestamps limits the lifetime of the token to the defined period. Not setting the start date or `notBefore` means the token is active as soon as it is created. Not setting the end date or `notAfter` means the token does not expire.

Note

Dates selected are defined as 00:00 UTC of that day. For finer grained time selection, use the [API](https://developers.cloudflare.com/fundamentals/api/).

![Time to Live selection calendar](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1280,height=836,format=webp/_astro/ttl.6XWjuAt_.png)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/how-to/restrict-tokens/#page","headline":"Restrict tokens","description":"Limit Cloudflare API token usage by client IP address filtering and time-to-live (TTL) constraints.","url":"https://developers.cloudflare.com/fundamentals/api/how-to/restrict-tokens/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Regenerate Cloudflare API token secrets to rotate credentials and maintain account security.
title: Roll tokens
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Roll tokens

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/how-to/roll-token/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If your token is lost or compromised, you can either create a new token or roll your token to generate a new secret. Rolling your API token into a new one will invalidate the previous token, but the access and permissions will be the same as the previous API token. The new token uses the [scannable format](https://developers.cloudflare.com/fundamentals/api/get-started/token-formats/), which allows credential scanning tools to detect leaked tokens.

To roll your API token:

1. Go to **My Profile** > **API Tokens**. [Go to **API Tokens** ↗](https://dash.cloudflare.com/profile/api-tokens)
2. Next to the API token you want to roll, select the **three dot icon** > **Roll**.
3. Select **Confirm** to generate a new API token.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/how-to/roll-token/#page","headline":"Roll tokens","description":"Regenerate Cloudflare API token secrets to rotate credentials and maintain account security.","url":"https://developers.cloudflare.com/fundamentals/api/how-to/roll-token/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Track Cloudflare API deprecations, removal timelines, and replacement endpoints.
title: API deprecations
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# API deprecations

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/reference/deprecations/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare occasionally makes updates to our APIs that result in behavior changes or deprecations. When this happens, we will communicate when the API will no longer be available and whether there will be a replacement.

Note

Subscribe to all API deprecation posts via [RSS](https://developers.cloudflare.com/fundamentals/api/reference/deprecations/index.xml).

[Subscribe to RSS](https://developers.cloudflare.com/fundamentals/api/reference/deprecations/index.xml)

## 2026-07-27

**Zone Settings Batch API**

Deprecation date: April 23, 2025

End of life date: March 31, 2027

**Update:** This deprecation's end of life date has been extended to March 31, 2027 (previously September 15, 2026).

The Zone Settings Batch API endpoints, which read and edit multiple zone settings in a single request, are deprecated and will reach their end of life on March 31, 2027. Use the per-setting endpoints to read and edit individual zone settings instead.

Deprecated APIs:

- `GET /zones/{zone_id}/settings`
- `PATCH /zones/{zone_id}/settings`

Replacements:

- [Get zone setting](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/get/) — `GET /zones/{zone_id}/settings/{setting_id}`
- [Edit zone setting](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/edit/) — `PATCH /zones/{zone_id}/settings/{setting_id}`

Integrations that read or edit multiple settings in a single call must migrate to per-setting requests before March 31, 2027 to ensure uninterrupted service. After this date, the batch endpoints will no longer be available.

## 2026-07-27

**Foundation DNS boolean setting**

Deprecation date: July 27, 2026

End of life date: November 23, 2026

The `foundation_dns` boolean is deprecated in the [DNS settings endpoints](https://developers.cloudflare.com/api/resources/dns/subresources/settings/) for zone settings and account defaults. Use `nameservers.type: "cloudflare.advanced"` to configure Advanced Nameservers instead.

Affected endpoints:

- [`/zones/{zone_id}/dns_settings`](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/)
- [`/accounts/{account_id}/dns_settings`](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/)

Beginning October 26, 2026, the DNS settings API will gradually represent Advanced Nameservers with `nameservers.type: "cloudflare.advanced"`. This rollout is expected to take seven days. Before the rollout reaches an account, the API will continue to return `nameservers.type: "cloudflare.standard"` for Advanced Nameservers. The API will accept `nameservers.type: "cloudflare.advanced"` in `PATCH` requests for entitled accounts throughout the rollout.

The `foundation_dns` boolean remains available as a compatibility alias during this transition. You can continue to read and write it. If a `PATCH` request includes both values, they must match. The API will reject conflicting values.

Beginning November 23, 2026, the DNS settings API will no longer return or accept `foundation_dns`. This rollout is expected to take seven days. `PATCH` requests that include `foundation_dns` will be rejected. Update clients that treat `nameservers.type` as a closed enum to recognize the `"cloudflare.advanced"` value, and update clients that read or write `foundation_dns` before the end-of-life date. This API change does not change your Foundation DNS subscription or whether Advanced Nameservers are enabled on your zones. It does not require a zone migration.

## 2026-07-22

**Account name 65-character limit**

Enforcement date: September 27, 2026

Account names will be limited to a maximum of 65 characters across all account creation and update APIs. This limit applies to all accounts, including organization accounts. Currently, the account update API (`PUT /accounts/{account_id}`) already enforces this limit, while the account create API (`POST /accounts`) silently truncates names up to 120 bytes. This mismatch can result in accounts that are created successfully but cannot later be renamed. After September 27, 2026, the create API will reject names longer than 65 characters with an HTTP `400` error.

Affected APIs:

- `POST /accounts` — Create account
- `PUT /accounts/{account_id}` — Update account (already enforced)

After the enforcement date, integrations that create accounts with names longer than 65 characters must truncate or shorten the name before sending the request to ensure uninterrupted service.

## 2026-07-21

**Account Roles API**

Deprecation date: July 21, 2026

The [Account Roles API](https://developers.cloudflare.com/api/resources/accounts/subresources/roles/) only returns account-level roles today, and is deprecated in favor of the [Permission Groups API](https://developers.cloudflare.com/api/resources/iam/subresources/permission_groups/). The Permission Groups API is the supported way to enumerate account, zone, and resource-level roles that can be granted to account members.

Deprecated APIs:

- `GET /accounts/{account_id}/roles` — List roles
- `GET /accounts/{account_id}/roles/{role_id}` — Role details

Replacements:

- `GET /accounts/{account_id}/iam/permission_groups` — List account permission groups
- `GET /accounts/{account_id}/iam/permission_groups/{permission_group_id}` — Permission group details

The response schema differs from the legacy Roles response:

- The legacy `Role` response includes a top-level `description` and a `permissions` object keyed by resource type with edit/read flags.
- The `PermissionGroup` response replaces those with a `meta` object containing `label` and `scopes`. Individual permissions are not returned as part of the permission group.

Additional notes:

- Integrations migrating to the Permission Groups API must obtain Permission Group IDs from that API and use them in the Account Members API policies request shape. Integrations that persist legacy Role IDs will need to remap their assignments.
- Both endpoints use the standard Cloudflare response envelope, so pagination and error-handling do not change.
- The new API supports the [API Token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) authorization scheme. The legacy Email + API Key authorization scheme is provided for backwards compatibility.
- The affected terraform resource is the `cloudflare_account_role` data source. You will need to migrate to the `cloudflare_account_permission_group` data source.

## 2026-07-15

**Workers KV: Legacy Namespace Routes**

Deprecation date: July 15, 2026

End of life date: October 15, 2026

The legacy Workers KV API routes under `/accounts/{account_id}/workers/namespaces/*` are deprecated in favor of the [Workers KV API](https://developers.cloudflare.com/api/resources/kv/) routes under `/accounts/{account_id}/storage/kv/namespaces/*`.

The legacy and replacement routes are interchangeable. They accept the same request parameters and return the same response payloads. To migrate, update the URL path from `/workers/namespaces/` to `/storage/kv/namespaces/`.

Deprecated APIs:

- `GET` and `POST /accounts/{account_id}/workers/namespaces` (list and create namespaces)
- `GET`, `PUT`, and `DELETE /accounts/{account_id}/workers/namespaces/{namespace_id}` (get, rename, and remove a namespace)
- `GET /accounts/{account_id}/workers/namespaces/{namespace_id}/keys` (list keys)
- `GET /accounts/{account_id}/workers/namespaces/{namespace_id}/metadata/{key_name}` (read key metadata)
- `GET`, `PUT`, and `DELETE /accounts/{account_id}/workers/namespaces/{namespace_id}/values/{key_name}` (read, write, and delete key-value pairs)

Replacements:

Update the URL path from `/workers/namespaces/` to `/storage/kv/namespaces/` in each endpoint.

- `GET` and `POST /accounts/{account_id}/storage/kv/namespaces` (list and create namespaces)
- `GET`, `PUT`, and `DELETE /accounts/{account_id}/storage/kv/namespaces/{namespace_id}` (get, rename, and remove a namespace)
- `GET /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/keys` (list keys)
- `GET /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/metadata/{key_name}` (read key metadata)
- `GET`, `PUT`, and `DELETE /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name}` (read, write, and delete key-value pairs)

After October 15, 2026, requests to the legacy `/accounts/{account_id}/workers/namespaces/*` routes will no longer be supported. Update integrations to use the documented Workers KV API endpoints before that date to ensure uninterrupted service.

## 2026-07-09

**Zero Trust Networks Route Endpoints and Cloudflare Tunnel Connections Field**

Deprecation date: July 9, 2026

End of life date: October 5, 2026

Two related changes to the [Zero Trust Networks API](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/) and [Cloudflare Tunnel API](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/) take effect on October 5, 2026.

**Route endpoints**

The CIDR-encoded route endpoints are deprecated in favor of the standard, `route_id`-based endpoints that already exist today.

Deprecated APIs:

- `POST /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded}`
- `PATCH /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded}`
- `DELETE /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded}`

Replacements:

- `POST /accounts/{account_id}/teamnet/routes`
- `PATCH /accounts/{account_id}/teamnet/routes/{route_id}`
- `DELETE /accounts/{account_id}/teamnet/routes/{route_id}`

**Cloudflare Tunnel and Cloudflare Mesh connections**

The `connections` array is removed from list and get responses for Cloudflare Tunnel and Cloudflare Mesh nodes (the `cfd_tunnel` and `warp_connector` API resources). Query the dedicated connections endpoint instead of reading the field off the tunnel or node object.

Affected APIs:

- `GET /accounts/{account_id}/cfd_tunnel`
- `GET /accounts/{account_id}/cfd_tunnel/{tunnel_id}`
- `GET /accounts/{account_id}/warp_connector`
- `GET /accounts/{account_id}/warp_connector/{tunnel_id}`

Replacements:

- `GET /accounts/{account_id}/cfd_tunnel/{tunnel_id}/connections`
- `GET /accounts/{account_id}/warp_connector/{tunnel_id}/connections`

For full migration guidance, including `curl` examples and `cloudflared` and Terraform notes, refer to the [Cloudflare Tunnel changelog](https://developers.cloudflare.com/changelog/2026-07-09-tunnel-routes-and-connections-api-changes/).

## 2026-07-08

**AMP/SXG API and Rules**

Deprecation date: September 18, 2025

End of life date: June 23, 2026

The AMP/SXG features have reached end of life. There will be no replacement functionality. The zone settings API endpoints and sxg [Configuration Rule setting](https://developers.cloudflare.com/rules/configuration-rules/settings/) should no longer be used.

Deprecated APIs:

- `GET /zones/{zone_id}/amp/sxg`
- `PUT /zones/{zone_id}/amp/sxg`

Deprecated Configuration Rule setting:

- `sxg`

The Dashboard UI will no longer show references to AMP or the sxg setting. Users can remove the sxg parameter from their rulesets by using the [rulesets API](https://developers.cloudflare.com/ruleset-engine/rulesets-api/update-rule/). Terraform deprecation will follow later, and users should remove references to the `sxg` parameter from their [terraform](https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs/resources/ruleset#sxg-1).

## 2026-06-29

**Legacy Registrar Domain Management API**

Deprecation date: April 10, 2026

End of life date: September 27, 2026

The legacy Registrar domain management endpoints are deprecated and will reach their end of life on September 27, 2026. These endpoints have been replaced by the new [Registrar API](https://developers.cloudflare.com/api/resources/registrar/), which provides domain search, availability checking, and registration capabilities.

Deprecated APIs:

- `GET /accounts/{account_id}/registrar/domains` — List domains
- `GET /accounts/{account_id}/registrar/domains/{domain_name}` — Get domain
- `PUT /accounts/{account_id}/registrar/domains/{domain_name}` — Update domain

Replacement: [Registrar API](https://developers.cloudflare.com/api/resources/registrar/)

- [Search for available domains](https://developers.cloudflare.com/api/resources/registrar/methods/search/) — `GET /accounts/{account_id}/registrar/domain-search`
- [Check domain availability](https://developers.cloudflare.com/api/resources/registrar/methods/check/) — `POST /accounts/{account_id}/registrar/domain-check`
- [List registrations](https://developers.cloudflare.com/api/resources/registrar/subresources/registrations/methods/list/) — `GET /accounts/{account_id}/registrar/registrations`
- [Create registration](https://developers.cloudflare.com/api/resources/registrar/subresources/registrations/methods/create/) — `POST /accounts/{account_id}/registrar/registrations`

Customers and integrations using the legacy domain management endpoints must migrate to the new Registrar API before September 27, 2026 to ensure uninterrupted service. After this date, the legacy endpoints will no longer be available.

## 2026-05-13

**Gateway Audit SSH rules**

Deprecation date: November 3, 2025

End of life date: July 15, 2026

The Gateway Audit SSH action for [network policies](https://developers.cloudflare.com/cloudflare-one/traffic-policies/network-policies/) is deprecated and will be fully removed on July 15, 2026. [SSH with Access for Infrastructure](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/) is the replacement for managing and auditing SSH access.

Creating new Gateway rules with `action: "audit_ssh"` via the dashboard was disabled in December 2024. Creating new rules via the API and Terraform was disabled on November 3, 2025. Editing existing rules via the dashboard, API, and Terraform was disabled on January 15, 2026. On July 15, 2026, all remaining Audit SSH rules will stop working.

Deprecated APIs:

- `POST /accounts/{account_id}/gateway/rules` — creating rules with `action: "audit_ssh"` is no longer accepted
- `PUT /accounts/{account_id}/gateway/rules/{rule_id}` — editing rules with `action: "audit_ssh"` is no longer accepted

Replacement: [SSH with Access for Infrastructure](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/)

## 2026-03-19

**Service Key Authentication**

Deprecation date: March 19, 2026

End of life date: September 30, 2026

Service Key authentication for the Cloudflare API is deprecated and will be removed on September 30, 2026. [API Tokens](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) are capable of providing all functionality of Service Keys, with additional support for fine-grained permission scoping, expiration, and IP address restrictions.

Deprecated behavior:

- Authenticating API requests using the `X-Auth-User-Service-Key` header.
- Generating new Service Keys via the Cloudflare dashboard or API. The ability to generate new Service Keys from the Dashboard will be removed soon.

Replacement:

- [Create an API Token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) with the appropriate permissions for your use case. API Tokens support fine-grained scoping, expiration, and revocation.

Users of `cloudflared` should ensure they are running a version from November 2022 or later, which uses API Tokens instead of Service Keys. Users of [origin-ca-issuer](https://github.com/cloudflare/origin-ca-issuer) should update to a version that supports API Token authentication.

## 2026-01-23

**DNS Record Type Updates via API**

Deprecation date: January 23, 2026

End of life date: June 30, 2026

Changing the type of an existing DNS record via the API is deprecated and will no longer be supported after June 30, 2026.

Changing a DNS record's type is not a natural update operation and typically also requires changing the record's content. Updates to attributes such as name, TTL, or content are common and safe, but changing the record type introduces additional validation complexity and consistency risks.

To align with correct DNS semantics and reduce operational risk, Cloudflare is deprecating support for in-place DNS record type changes. This behavior already exists in the Terraform v5 provider, where record type changes result in a delete and recreate operation rather than an update.

Deprecated behavior:

- Using the [DNS Records API](https://developers.cloudflare.com/api/resources/dns/subresources/records/) to change the type of an existing record.

Replacement behavior:

- [Delete the existing DNS record](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/delete/) and [Create a new DNS record](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/create/) with the desired type and content.

  `DELETE /zones/{zone_id}/dns_records/{dns_record_id}`

  `POST /zones/{zone_id}/dns_records`
- Use the [Batch DNS records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/batch/) API to perform both operations in a single request.

  `POST /zones/{zone_id}/dns_records/batch`

Customers and integrations that rely on in-place record type updates must migrate to a delete-and-recreate workflow before June 30, 2026 to ensure uninterrupted service. After this date, attempts to change a record's type via update operations will no longer be supported.

## 2025-12-09

**Authoritative DNS and DNS Firewall Legacy Analytics**

Deprecation date: December 9, 2025

End of life date: December 1, 2026

The following REST APIs are deprecated and will reach their end of life on December 1, 2026.

- [DNS Analytics API](https://developers.cloudflare.com/api/resources/dns/subresources/analytics/)
- [DNS Firewall Analytics API](https://developers.cloudflare.com/api/resources/dns_firewall/subresources/analytics/)

All existing functionality is fully supported by Cloudflare's GraphQL Analytics API, which provides improved performance, flexibility, and long-term support. Integrations using the REST API need to be migrated to the new GraphQL API before December 1, 2026 in order to ensure uninterrupted service.

Deprecated APIs:

- `GET/zones/{zone_id}/dns_analytics/` (DNS Analytics API)
- `GET/accounts/{account_id}/dns_firewall/{dns_firewall_id}/dns_analytics/report` (DNS Firewall Analytics API)

Replacements:

- [GraphQL API for DNS Analytics](https://developers.cloudflare.com/dns/additional-options/analytics/#explore-with-the-api)
- [GraphQL API for DNS Firewall Analytics](https://developers.cloudflare.com/dns/dns-firewall/analytics/#graphql)

## 2025-11-11

**Zero Trust Devices**

End of life date: November 11, 2025

We are changing the definition of Devices. Devices are going to represent the real-world machines while the relation between Users and Devices will be represented by a new concept - Registrations.

As a result multiple fields are moving from Devices to Registrations and we are deprecating the endpoints listed below.

The deprecated endpoints are not supported on accounts with [multi-user mode](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/windows-multiuser/) enabled.

Deprecated API:

- `GET /accounts/{account_id}/devices`
- `GET /accounts/{account_id}/devices/{device_id}`
- `GET /accounts/{account_id}/devices/{device_id}/override_codes`
- `POST /accounts/{account_id}/devices/revoke`
- `POST /accounts/{account_id}/devices/unrevoke`

Replacement:

- `GET /accounts/{account_id}/devices/physical-devices`
- `GET /accounts/{account_id}/devices/physical-devices/{device_id}`
- `GET /accounts/{account_id}/devices/registrations`
- `GET /accounts/{account_id}/devices/registrations/{registration_id}`
- `GET /accounts/{account_id}/devices/registrations/{registration_id}/override_codes`
- `POST /accounts/{account_id}/devices/registrations/revoke`
- `POST /accounts/{account_id}/devices/registrations/unrevoke`

## 2025-11-03

**Cloudflare Mirage**

Deprecation date: November 2025

End of life date: January 2026

Following on from the [deprecation of Cloudflare Mirage](https://developers.cloudflare.com/speed/optimization/images/mirage/), the following API endpoints that manage Mirage settings are now deprecated and will be sunsetted in January 2026.

Deprecated APIs:

- `GET /zones/{zone_id}/settings/mirage`
- `PATCH /zones/{zone_id}/settings/mirage`

Affected APIs:

- `GET /zones/{zone_id}/pagerules/settings` - Mirage will be removed from available settings.
- `POST /zones/{zone_id}/pagerules` - Mirage parameter will be removed.
- `PATCH /zones/{zone_id}/pagerules/{rule_id}` - Mirage parameter will be removed.
- `PUT /zones/{zone_id}/pagerules/{rule_id}` - Mirage parameter will be removed.
- `GET /zones/{zone_id}/rulesets/{ruleset_id}` - Mirage parameter in `set_config` action will be removed.
- `GET /zones/{zone_id}/rulesets/{ruleset_id}/versions/{version_id}` - Mirage parameter in `set_config` action will be removed.
- `POST /zones/{zone_id}/rulesets` - Mirage parameter in `set_config` action will be removed.
- `PUT /zones/{zone_id}/rulesets/{ruleset_id}` - Mirage parameter in `set_config` action will be removed.
- `POST /zones/{zone_id}/rulesets/{ruleset_id}/rules` - Mirage parameter in `set_config` action will be removed.
- `PATCH /zones/{zone_id}/rulesets/{ruleset_id}/rules/{rule_id}` - Mirage parameter in `set_config` action will be removed.
- `GET /accounts/{account_id}/rulesets/{ruleset_id}` - Mirage parameter in `set_config` action will be removed.
- `GET /accounts/{account_id}/rulesets/{ruleset_id}/versions/{version_id}` - Mirage parameter in `set_config` action will be removed.
- `POST /accounts/{account_id}/rulesets` - Mirage parameter in `set_config` action will be removed.
- `PUT /accounts/{account_id}/rulesets/{ruleset_id}` - Mirage parameter in `set_config` action will be removed.
- `POST /accounts/{account_id}/rulesets/{ruleset_id}/rules` - Mirage parameter in `set_config` action will be removed.
- `PATCH /accounts/{account_id}/rulesets/{ruleset_id}/rules/{rule_id}` - Mirage parameter in `set_config` action will be removed.

## 2025-10-15

**Cloudflare Radar: Summary and Timeseries Groups Endpoints**

Deprecation date: October 15, 2025

End of life date: April 15, 2026

The Radar API currently has multiple summary and timeseries groups endpoints per dataset (for example, `/radar/http/summary/device_type` and `/radar/http/timeseries_groups/device_type`), which share nearly identical parameters and schema. To simplify the API and improve maintainability, these endpoints will be replaced with parameterized endpoints using a `{dimension}` path parameter.

Deprecated APIs:

- `GET /radar/http/summary/device_type`
- `GET /radar/http/summary/bot_class`
- `GET /radar/http/timeseries_groups/device_type`
- `GET /radar/http/timeseries_groups/bot_class`
- Other similar summary and timeseries groups endpoints for the following datasets: AI Bots, AI Inference, AS112, DNS, Email Routing, Email security, HTTP, Layer 3 Attacks, Layer 7 Attacks, Leaked Credential Checks

Replacements:

- `GET /radar/http/summary/{dimension}`
- `GET /radar/http/timeseries_groups/{dimension}`
- ...

Here, `{dimension}` is a required path parameter listing all available dimensions for the dataset.

For users calling the API directly (not via the Cloudflare SDK), no action is required. For users using the SDK, we recommend updating to the new operations to ensure compatibility after the operations are removed.

## 2025-07-01

**Cloudflare Radar: Verified Bots APIs**

Deprecation date: July 1, 2025

End of life date: January 1, 2026

The Radar Verified Bots API is now deprecated and will be replaced by the new Bots API.

Deprecated APIs:

- `GET /radar/verified_bots/top/bots`
- `GET /radar/verified_bots/top/categories`

Replacements:

- `GET /radar/bots/summary/bot`
- `GET /radar/bots/summary/category`

## 2025-07-01

**Cloudflare DWeb Resolver**

Deprecation date: July 1, 2025

The Cloudflare DWeb Resolver experiment is ending.

Deprecated APIs:

- DoH resolver on resolver.cloudflare-eth.com

## 2025-06-15

**Firewall Rules API and Filters API**

Deprecation date: June 15, 2025

The Firewall Rules API and the Filters API are deprecated, since Firewall Rules was deprecated in favor of [WAF custom rules](https://developers.cloudflare.com/waf/custom-rules/). Refer to [Firewall Rules upgrade](https://developers.cloudflare.com/waf/reference/legacy/firewall-rules-upgrade/) for more information about this change.

Deprecated APIs:

- `GET /zones/:zone_id/firewall/rules`
- `POST /zones/:zone_id/firewall/rules`
- `PATCH /zones/:zone_id/firewall/rules`
- `PUT /zones/:zone_id/firewall/rules`
- `DELETE /zones/:zone_id/firewall/rules`
- `GET /zones/:zone_id/firewall/rules/:rule_id`
- `PATCH /zones/:zone_id/firewall/rules/:rule_id`
- `PUT /zones/:zone_id/firewall/rules/:rule_id`
- `DELETE /zones/:zone_id/firewall/rules/:rule_id`
- `GET /zones/:zone_id/filters`
- `POST /zones/:zone_id/filters`
- `PUT /zones/:zone_id/filters`
- `DELETE /zones/:zone_id/filters`
- `GET /zones/:zone_id/filters/:filter_id`
- `PUT /zones/:zone_id/filters/:filter_id`
- `DELETE /zones/:zone_id/filters/:filter_id`

Replacement: [WAF custom rules](https://developers.cloudflare.com/waf/custom-rules/)

## 2025-06-15

**WAF managed rules APIs (previous version)**

Deprecation date: June 15, 2025

The APIs for managing WAF managed rules (previous version) — namely for managing packages, rule groups, rules, and overrides — are deprecated in favor of using the [Rulesets API](https://developers.cloudflare.com/ruleset-engine/rulesets-api/) for managing the new version of [WAF Managed Rules](https://developers.cloudflare.com/waf/managed-rules/). Refer to [WAF Managed Rules upgrade](https://developers.cloudflare.com/waf/reference/legacy/old-waf-managed-rules/upgrade/) for more information about this change.

Deprecated APIs:

- `GET /zones/:zone_id/firewall/waf/packages`
- `GET /zones/:zone_id/firewall/waf/packages/:package_id`
- `PATCH /zones/:zone_id/firewall/waf/packages/:package_id`
- `GET /zones/:zone_id/firewall/waf/packages/:package_id/groups`
- `GET /zones/:zone_id/firewall/waf/packages/:package_id/groups/:group_id`
- `PATCH /zones/:zone_id/firewall/waf/packages/:package_id/groups/:group_id`
- `GET /zones/:zone_id/firewall/waf/packages/:package_id/rules`
- `GET /zones/:zone_id/firewall/waf/packages/:package_id/rules/:rule_id`
- `PATCH /zones/:zone_id/firewall/waf/packages/:package_id/rules/:rule_id`
- `GET /zones/:zone_id/firewall/waf/overrides`
- `POST /zones/:zone_id/firewall/waf/overrides`
- `GET /zones/:zone_id/firewall/waf/overrides/:override_id`
- `PUT /zones/:zone_id/firewall/waf/overrides/:override_id`
- `DELETE /zones/:zone_id/firewall/waf/overrides/:override_id`

Replacement: [WAF Managed Rules](https://developers.cloudflare.com/waf/managed-rules/) (new version)

## 2025-06-15

**Rate Limiting API (previous version)**

Deprecation date: June 15, 2025

The Rate Limiting API is deprecated, in favor of using the [Rulesets API](https://developers.cloudflare.com/ruleset-engine/rulesets-api/) for managing the new [rate limiting rules](https://developers.cloudflare.com/waf/rate-limiting-rules/). Refer to [Rate limiting (previous version) upgrade](https://developers.cloudflare.com/waf/reference/legacy/old-rate-limiting/upgrade/) for more information about this change.

Deprecated API:

- `GET /zones/:zone_id/rate_limits`
- `POST /zones/:zone_id/rate_limits`
- `GET /zones/:zone_id/rate_limits/:rate_limit_id`
- `PUT /zones/:zone_id/rate_limits/:rate_limit_id`
- `DELETE /zones/:zone_id/rate_limits/:rate_limit_id`

Replacement: [Rate limiting rules](https://developers.cloudflare.com/waf/rate-limiting-rules/) (new version)

## 2025-06-08

**Zone Setting: cname\_flattening**

Deprecation date: June 8, 2025

The Zone Settings API endpoints for managing zone-level CNAME flattening are deprecated. Instead, use the [Show DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/methods/get/) and [Update DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/methods/edit/) endpoints to manage this setting.

Changes via the old endpoints will be reflected in the new ones, and vice versa, so there is no need to migrate existing zones. However, future API calls must use DNS Settings instead of the Zone Settings endpoints.

Note that, with the deprecated zone setting, values `"off"` and `"apex"` have the same behavior. These are represented as `{"flatten_all_cnames": false}` in the new API. The zone setting `"on"` corresponds to `{"flatten_all_cnames": true}` in the new API.

Affected APIs:

- `GET /zones/:zone_id/settings`
- `PATCH /zones/:zone_id/settings`

Deprecated APIs:

- `GET /zones/:zone_id/settings/cname_flattening`
- `PATCH /zones/:zone_id/settings/cname_flattening`

## 2025-03-23

**Eligible Zones For Account Custom Nameservers**

Deprecation date: March 23, 2025

Users can now add custom nameservers that are not part of a zone managed within their account. As a result, any zone is eligible for custom nameservers, regardless of whether it is managed by Cloudflare. Given this change, an endpoint to check for eligible zones is no longer relevant and is therefore being deprecated.

Deprecated APIs:

- `GET /accounts/:account_id/custom_ns/availability`

## 2025-03-20

**Cloudflare Radar: Attack top industry and vertical endpoints**

Deprecation date: March 20, 2025

End of life date: September 20, 2025

The `/top/industry` and `/top/vertical` attack endpoints are now deprecated and will be replaced by the corresponding summary endpoints.

Affected APIs:

- `GET /radar/attacks/layer3/top/industry`
- `GET /radar/attacks/layer3/top/vertical`
- `GET /radar/attacks/layer7/top/industry`
- `GET /radar/attacks/layer7/top/vertical`

Replacements:

- `GET /radar/attacks/layer3/summary/industry`
- `GET /radar/attacks/layer3/summary/vertical`
- `GET /radar/attacks/layer7/summary/industry`
- `GET /radar/attacks/layer7/summary/vertical`

## 2025-03-17

**Security Center: Security level and Threat Score are now automated**

Change date: March 17, 2025

Cloudflare now combines the IP address threat signal with threshold and botnet data, no longer requiring you to set a sensitivity level. Users will no longer be able to set Security level via the Cloudflare dashboard. However, users can still rely on the existing API or Terraform configuration to set a Security level.

If you are using threat score in rule expressions, you should review those expressions to make sure the rule still triggers when appropriate. Cloudflare will audit and migrate your configuration in the future to update any references to threat score. If you are using the Rulesets API or Terraform to push your configuration, you should review your scripts and pipelines before the end of Q1 2026 to prevent issues.

## 2025-03-14

**Account Settings: default\_nameservers and use\_account\_custom\_ns\_by\_default**

Deprecation date: March 14, 2025

The fields `"default_nameservers"` and `"use_account_custom_ns_by_default"` within the `"settings"` object of accounts are deprecated. Instead, use the [Show DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/methods/get/) and [Update DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/methods/edit/) endpoints to manage this setting. This setting is available in the new API as `.zone_defaults.nameservers.type`, with allowed values `"cloudflare.standard"`, `"cloudflare.standard.random"`, `"custom.account"` and `"custom.tenant"`.

Changes via the old endpoints will be reflected in the new ones, and vice versa, so there is no need to migrate existing zones. However, future API calls must use DNS Settings instead of the Accounts endpoints.

Affected APIs:

- `GET /accounts`
- `POST /accounts`
- `GET /accounts/:account_id`
- `PUT /accounts/:account_id`

## 2025-03-11

**Cloudflare Radar: Layer 7 attack magnitude parameter**

Deprecation date: March 11, 2025

End of life date: June 11, 2025

The layer 7 attack `magnitude` query parameter, which allows you to define attack magnitude by total requests mitigated (`MITIGATED_REQUESTS`) or total zones attacked (`AFFECTED_ZONES`), is deprecated. Moving forward, Cloudflare Radar will only support defining layer 7 attack magnitude based on the total number of mitigated requests.

Affected API:

`GET /radar/attacks/layer7/top/attacks`

Replacement:

Users should stop using the `magnitude` parameter, as the default behavior already uses `MITIGATED_REQUESTS`.

## 2025-02-21

**DNS Records API: Changes to Filter Parameters**

Deprecation date: February 21, 2025

The following URL parameters for filtering DNS records are deprecated:

- `name=contains:value` Instead, use the supported `name.contains=value` syntax.
- `name=starts_with:value` Instead, use the supported `name.startswith=value` syntax.
- `name=ends_with:value` Instead, use the supported `name.endswith=value` syntax.
- `name=one,two,three` (searching for one of multiple possible names, separated by commas) Instead, make multiple requests, one for each possible `name`. Alternatively, if only querying the `name` field, the `?match=any&name=one&name=two&name=three` syntax can be used instead. This syntax has an extended deprecation date of May 23, 2025.
- `content=contains:value` Instead, use the supported `content.contains=value` syntax.
- `content=starts_with:value` Instead, use the supported `content.startswith=value` syntax.
- `content=ends_with:value` Instead, use the supported `content.endswith=value` syntax.
- `content=one,two,three` (searching for one of multiple possible contents, separated by commas) Instead, make multiple requests, one for each possible `content`. Alternatively, if only querying the `content` field, the `?match=any&content=one&content=two&content=three` syntax can be used instead. This syntax has an extended deprecation date of May 23, 2025.
- `type=contains:value` Searching for substrings of a type name will no longer be supported. Instead, please search for an exact type name, such as `type=CNAME`. If the input value is a free-text search from a human user, consider using the `search` parameter instead.

None of the parameters being deprecated were ever officially supported per our API documentation.

Affected APIs:

- `GET /zones/:zone_id/dns_records`

## 2024-12-09

**Access applications: self\_hosted\_domains**

Deprecation date: November 21, 2025

The `self_hosted_domains` field for [Access applications](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/update/) is deprecated in favor of `destinations` to allow for more flexibility in defining different types of domains.

Before:

```json
{
  // ...
  "self_hosted_domains": ["foo.example.com", "bar.example.com"]
}
```

After:

```json
{
  // ...
  "destinations": [
    {
      "type": "public",
      "uri": "foo.example.com"
    },
    {
      "type": "public",
      "uri": "bar.example.com"
    }
  ]
}
```

The API will accept both fields until the deprecation date. If `self_hosted_domains` are provided, then they will be interpreted as `public` destinations. However, if `destinations` are provided, then `self_hosted_domains` will be ignored even if provided.

Additionally, the API will continue to return `self_hosted_domains` until the deprecation date. The field will contain the URIs of the subset of destinations that have type `public`.

Affected APIs:

- `GET /accounts/:account_id/access/apps`
- `POST /accounts/:account_id/access/apps`
- `GET /accounts/:account_id/access/apps/:app_id`
- `PUT /accounts/:account_id/access/apps/:app_id`
- `GET /zones/:zone_id/access/apps`
- `POST /zones/:zone_id/access/apps`
- `GET /zones/:zone_id/access/apps/:app_id`
- `PUT /zones/:zone_id/access/apps/:app_id`

## 2024-11-30

**Zone information in individual DNS records**

Deprecation date: November 30, 2024

Currently, each individual DNS record returned by the API contains information about the zone it is on, specifically the zone ID and name.

```json
{
  "result": [
    {
      // ...
      "zone_id": "ab922473c42f4e50819d7c1c9b81b16b",
      "zone_name": "example.com"
    }
  ],
  // ...
}
```

This information is redundant because both affected API routes are already within the zone scope. In particular, the zone ID will already be known to any user of these routes because it appears in the URL. The zone name can be retrieved by making a `GET` request to `/zones/:zone_id` if it is necessary.

After November 30th, 2024, Cloudflare will stop including the `zone_id` and `zone_name` fields on individual DNS records in API responses. These fields are currently ignored when sent to the API as part of a request body, so no changes to request bodies are required.

Modified API:

- `GET /zones/:zone_id/dns_records`
- `POST /zones/:zone_id/dns_records`
- `GET /zones/:zone_id/dns_records/:dns_record_id`
- `PATCH /zones/:zone_id/dns_records/:dns_record_id`
- `PUT /zones/:zone_id/dns_records/:dns_record_id`

## 2024-10-01

**DNS Records: Error chains for DNS validation errors**

Deprecation date: October 1, 2024

Cloudflare is making a minor change to the representation of certain errors when creating DNS records. Currently, when the DNS record to be created is invalid, an error similar to the following may be returned:

```txt
{
  "result": null,
  "success": false,
  "errors": [
    {
      "code": 1004,
      "message": "DNS Validation Error",
      "error_chain": [
        {
          "code": 9999,
          "message": "This is an example."
        }
      ]
    }
  ],
  "messages": []
}
```

After October 1st, 2024, the `error_chain` will be omitted, returning the root cause directly without wrapping it in another "DNS Validation Error" error:

```txt
{
  "result": null,
  "success": false,
  "errors": [
    {
      "code": 9999,
      "message": "This is an example."
    }
  ],
  "messages": []
}
```

## 2024-09-13

**Legacy DNS Settings Endpoints**

Deprecation date: September 13, 2024

The dedicated endpoints for DNS settings `use_apex_ns` and `secondary_overrides` are being deprecated.

Instead, use the [Show DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/methods/get/) and [Update DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/methods/edit/) endpoints to manage these settings.

- Instead of the `.../use_apex_ns` endpoint, use the `multi_provider` field.
- Instead of the `.../secondary_overrides` endpoint, use the `secondary_overrides` field.

Deprecated APIs:

- `GET /zones/:zone_id/dns_settings/use_apex_ns`
- `PATCH /zones/:zone_id/dns_settings/use_apex_ns`
- `GET /zones/:zone_id/dns_settings/secondary_overrides`
- `PATCH /zones/:zone_id/dns_settings/secondary_overrides`

## 2024-08-15

**Brotli**

Deprecation date: August 15, 2024

The Brotli setting and its API endpoints are deprecated. Brotli compression is available for all non-Enterprise zones, and it will be extended to Enterprise zones in the coming year.

Deprecated APIs:

- `GET /zones/:zone_id/settings/brotli`
- `PATCH /zones/:zone_id/settings/brotli`

Enterprise customers can override Cloudflare's default compression behavior using [Compression Rules](https://developers.cloudflare.com/rules/compression-rules/).

## 2024-08-05

**Auto Minify**

Deprecation date: August 5, 2024

The Auto Minify API endpoints are deprecated since the Auto Minify feature was deprecated.

Deprecated APIs:

- `GET /zones/:zone_id/settings/minify`
- `PATCH /zones/:zone_id/settings/minify`

## 2024-07-14

**DNS Records: 'locked' Field**

Deprecation date: July 14, 2024

The `"locked"` field of DNS records in API responses is unused and has been guaranteed to always be `false` for more than a year. This deprecation means that the field will be omitted from API responses entirely. If received from a client, the field will continue to be ignored, just as it is today.

Modified API:

- `GET /zones/:zone_id/dns_records`
- `POST /zones/:zone_id/dns_records`
- `GET /zones/:zone_id/dns_records/:dns_record_id`
- `PATCH /zones/:zone_id/dns_records/:dns_record_id`
- `PUT /zones/:zone_id/dns_records/:dns_record_id`

## 2024-06-30

**Mobile redirect**

Deprecation date: June 30, 2024

This endpoint and its related APIs are deprecated in favor of [Single Redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/). Refer to [Perform mobile redirects](https://developers.cloudflare.com/rules/url-forwarding/examples/perform-mobile-redirects/) to migrate Mobile Redirect to Redirect Rules.

Deprecated API:

- `GET /zones/:zone_identifier/settings/mobile_redirect`
- `PATCH /zones/:zone_identifier/settings/mobile_redirect`

Replacement: [Single Redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/)

## 2024-06-14

**Server-side Excludes**

Deprecation date: June 14, 2024

The Server-side Excludes feature and its API endpoints are deprecated.

Deprecated APIs:

- `GET /zones/:zone_id/settings/server_side_exclude`
- `PATCH /zones/:zone_id/settings/server_side_exclude`

## 2024-05-31

**Name-Related Data Fields on SRV (DNS) Records**

Deprecation date: May 31, 2024

The name of an SRV record normally consists of three parts: the service (e.g., `_xmpp`), the protocol (e.g., `_tcp`), and the base name (`example.com`).

The complete name would then be, e.g., `_xmpp._tcp.example.com`.

When interacting with DNS records through the [API](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/create/), SRV records contain both a full `name` as well as a `data` map containing the individual components of the name:

```txt
{
  "name": "_xmpp._tcp.example.com",
  "data": {
    "service": "_xmpp",
    "proto": "_tcp",
    "name": "example.com",
    ...
  },
  ...
}
```

We are deprecating the `service`, `proto` and `name` fields *within* the `data` map in favor of the `name` field *outside* the data map, which is the same name field that's used by all other record types.

Before the end of life date, please ensure that:

- when reading SRV records, you use only the `name` outside of the data map and ignore `service`, `proto` and `name` within the data map if they exist; and
- when writing SRV records, you set the `name` outside of the data map and **do not set** `service`, `proto` or `name` within the data map.

After the end of life date, the API will stop producing the `service`, `proto` and `name` data fields, and if any of them are received from a client, an error will be returned.

This deprecation does not affect other SRV data fields not mentioned above (`priority`, `weight`, `port`, `target`) or data fields for any other record type other than SRV.

Modified API:

- `GET /zones/:zone_id/dns_records`
- `POST /zones/:zone_id/dns_records`
- `GET /zones/:zone_id/dns_records/:dns_record_id`
- `PATCH /zones/:zone_id/dns_records/:dns_record_id`
- `PUT /zones/:zone_id/dns_records/:dns_record_id`

## 2024-03-31

**Privacy Pass API Removal**

Deprecation date: March 31, 2024

In 2017, Cloudflare [announced support](https://blog.cloudflare.com/cloudflare-supports-privacy-pass/) for Privacy Pass, a recent protocol to let users prove their identity across multiple sites anonymously without enabling tracking. The initial use case was to provide untraceable tokens to sites to vouch for users who might otherwise have been presented with a CAPTCHA challenge. In the time since this release, Privacy Pass has evolved both at the [IETF](https://datatracker.ietf.org/wg/privacypass/documents/) and within Cloudflare. The version announced in 2017 is now considered legacy, and these legacy Privacy Pass tokens are no longer supported as an alternative to Cloudflare challenges. As has been discussed on our blog [The end road for CAPTCHA](https://blog.cloudflare.com/end-cloudflare-captcha/), Cloudflare uses a variety of signals to infer if incoming traffic is likely automated. The (legacy) Privacy Pass zone setting is no longer meaningful to Cloudflare customers as Cloudflare now operates [CAPTCHA free](https://blog.cloudflare.com/turnstile-ga/), and supports the latest [Privacy Pass draft](https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/).

In September 2023, support for legacy Privacy Pass tokens as an alternative to Cloudflare Managed Challenge was removed. By the end of March 2024, the current public-facing API will be removed as well.

Deprecated API:

- `GET zones/:zone_identifier/settings/privacy_pass`
- `POST zones/:zone_identifier/settings/privacy_pass`

## 2024-02-04

**Argo Tunnel**

Deprecation date: February 4, 2024

This endpoint and its related APIs are deprecated in favor of the Cloudflare Tunnels equivalent APIs.

Deprecated API:

- `GET accounts/:account_identifier/tunnels`
- `POST accounts/:account_identifier/tunnels`
- `GET accounts/:account_identifier/tunnels/:tunnel_id`
- `DELETE accounts/:account_identifier/tunnels/:tunnel_id`

Replacement: Cloudflare Tunnel API

## 2023-07-01

**ChaCha20 TLS Cipher Removal**

Deprecation date: July 1, 2023

Back in 2016, Cloudflare [introduced support](https://blog.cloudflare.com/it-takes-two-to-chacha-poly/) for `ChaCha20-Poly1305` cipher suites for TLS 1.2. At the time, we introduced two variants of these new suites, the "standard" suites as defined by the IETF RFC 7905, and "draft" suites that followed an earlier draft of said specification. The draft suites were added for compatibility with some older Android devices that at the time did not yet support the proper `ChaCha20-Poly1305` standard versions. This was in 2016, and in the meantime the standard `ChaCha20-Poly1305` cipher suites have gained much wider adoption, to the point were traffic using the old suites has dropped significantly. Due to the current low usage and the non-standard nature of these cipher suites, we are now deprecating their support on the Cloudflare network.

This should not affect customer zones in any way, as clients that might currently use these cipher suites will be able to fallback to different ones. In addition, unlike the standard variants, these legacy cipher suites are not exposed directly through our API (e.g. through the TLS cipher suites preferences endpoint), and their deprecation will not affect customer configurations in any way.

As of July 1st, 2023, the ChaCha20-Poly1305 ciphers have been deprecated and are deemed End of Life by Cloudflare. If you have clients that currently rely on these ciphers, it is strongly recommended to upgrade them to newer, more secure ciphers. Be aware that these deprecated ciphers will be completely removed in the first quarter of 2024, and requests using them will start to fail. Take proactive measures to ensure a smooth transition and maintain the security of your systems.

## 2023-07-01

**Transfer-Encoding and Content-Length headers**

Deprecation date: July 1, 2023

Previously, RFC 2616 allowed the use of `Transfer-Encoding` and `Content-Length` HTTP headers in the same request. RFC 7230 supersedes RFC 2616 and prohibits the use of `Transfer-Encoding` and `Content-Length` headers in the same request because they can cause HTTP request smuggling vulnerabilities.

Starting on July 1st, 2023, Cloudflare will decline requests with both `Transfer-Encoding` and `Content-Length` HTTP headers.

## 2023-06-06

**Account Billing Profile, User Billing Profile, and User Billing History**

Deprecation date: June 6, 2023

There is no API replacement for these endpoints. As an alternative, please log in to your Cloudflare account to view your:

- [Invoices & Billing Email](https://dash.cloudflare.com/?to=/:account/billing)
- [Billing subscriptions](https://dash.cloudflare.com/?to=/:account/billing/subscriptions)
- [Billing profile payment info](https://dash.cloudflare.com/?to=/:account/billing/payment-info)

Deprecated API:

- `GET accounts/{account_identifier}/billing/profile`
- `GET user/billing/profile`
- `GET user/billing/history`

## 2023-04-03

**Load Balancing - notification\_email**

Deprecation date: April 3, 2023

This field is deprecated and has been moved to [Cloudflare centralized notification service](https://developers.cloudflare.com/notifications/).

`notification_email` is the email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list.

## 2023-03-19

**Access Bookmark applications**

Deprecation date: March 19, 2023

This endpoint is deprecated in favor of using a specialized Access Application App Type API.

Deprecated API:

- `GET accounts/:identifier/access/bookmarks`
- `GET accounts/:identifier/access/bookmarks/:uuid`
- `POST accounts/:identifier/access/bookmarks/:uuid`
- `PUT accounts/:identifier/access/bookmarks/:uuid`
- `DELETE accounts/:identifier/access/bookmarks/:uuid`

Replacement: Access applications app type API

## 2022-10-11

**Page Shield**

Deprecation date: October 11, 2022

Replace `script_monitor` in Page Shield API routes with `page_shield`.

## 2022-07-01

**Cloudflare Images - Create authenticated direct upload URL v1**

Deprecation date: July 1, 2022

This endpoint is deprecated in favor of using v2, which allows you to control metadata, define an access policy, and get the image ID.

Deprecated API: `POST accounts/:account_identifier/images/v1/direct_upload`

Replacement: `POST accounts/:account_identifier/images/v2/direct_upload`

## 2021-03-01

**Zone Analytics API**

Deprecation date: March 1, 2021

This API is deprecated in favor of the [GraphQL Analytics API](https://developers.cloudflare.com/analytics/graphql-api/), which provides equivalent data and more features, including the ability to select only the metrics that you need. For more information, refer to the [Zone analytics to GraphQL analytics migration guide](https://developers.cloudflare.com/analytics/graphql-api/migration-guides/zone-analytics/).

Deprecated API:

- `GET zones/:zone_identifier/analytics/dashboard`
- `GET zones/:zone_identifier/analytics/colos`

Replacement: GraphQL Analytics API

## 2020-04-02

**Organizations**

Deprecation date: April 2, 2020

This endpoint and its related APIs are deprecated in favor of the `/accounts` equivalent API, which has a broader range of features and is backwards compatible with the `/organizations` API.

Deprecated API:

- `GET organizations/:identifier`
- `PATCH organizations/:identifier`
- `GET organizations/:organization_identifier/invites`
- `POST organizations/:organization_identifier/invites`
- `GET organizations/:organization_identifier/invites/:identifier`
- `PATCH organizations/:organization_identifier/invites/:identifier`
- `DELETE organizations/:organization_identifier/invites/:identifier`
- `GET organizations/:organization_identifier/members`
- `GET organizations/:organization_identifier/members/:identifier`
- `PATCH organizations/:organization_identifier/members/:identifier`
- `DELETE organizations/:organization_identifier/members/:identifier`
- `GET organizations/:organization_identifier/roles`
- `GET organizations/:organization_identifier/roles/:identifier`
- `GET organizations/:organization_identifier/audit_logs`
- `GET organizations/:organization_identifier/railguns`
- `POST organizations/:organization_identifier/railguns`
- `GET organizations/:organization_identifier/railguns/:identifier`
- `PATCH organizations/:organization_identifier/railguns/:identifier`
- `DELETE organizations/:organization_identifier/railguns/:identifier`
- `GET organizations/:organization_identifier/railguns/:identifier/zones`

Replacement: Accounts API

## Related resources

- [Available RSS feeds](https://developers.cloudflare.com/fundamentals/new-features/available-rss-feeds/) (for the [Cloudflare changelog](https://developers.cloudflare.com/changelog/))
- [Subscribe to Cloudflare Status](https://developers.cloudflare.com/support/cloudflare-status/)
- [Planned maintenance windows](https://developers.cloudflare.com/support/disruptive-maintenance/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"BlogPosting","@id":"https://developers.cloudflare.com/fundamentals/api/reference/deprecations/#page","headline":"API deprecations","description":"Track Cloudflare API deprecations, removal timelines, and replacement endpoints.","url":"https://developers.cloudflare.com/fundamentals/api/reference/deprecations/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Query Cloudflare analytics data using GraphQL.
title: GraphQL Analytics API
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/analytics/llms.txt  
> Use this file to discover all available pages before exploring further.

# GraphQL Analytics API

Last updated Apr 23, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/analytics/graphql-api/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

The GraphQL Analytics API provides data regarding HTTP requests passing through Cloudflare's network, as well as data from specific products, such as Firewall or Load Balancing. Network Analytics users also have access to packet-level data. Use the GraphQL Analytics API to select specific datasets and metrics of interest, filter and aggregate the data along various dimensions, and integrate the results with other applications.

The basis of the API is the [GraphQL framework ↗](https://graphql.org/), created and open-sourced by Facebook. There is an active developer community for GraphQL and powerful clients for running queries, which makes it easy to get started. GraphQL is especially useful for building visualizations and powers the analytics in the Cloudflare dashboard.

GraphQL models a business domain as a graph using a schema. In the schema, there are logical definitions for different types of nodes and their connections (edges). These nodes are the datasets you use for your analytics. You write queries in GraphQL much like in SQL: you specify the dataset (table), the metrics to retrieve (such as requests and bytes), and filter or group by dimensions (for example, a time period).

GraphQL differs from a traditional API: it has one single endpoint:

```txt
https://api.cloudflare.com/client/v4/graphql
```

You pass the query parameters as a JSON object in the payload of a `POST` request to this endpoint.

You can use `curl` to make requests to the GraphQL Analytics API. Alternatively, you can use a GraphQL client to construct queries and pass requests to the GraphQL Analytics API.

## Clients

We are using [GraphiQL ↗](https://github.com/skevy/graphiql-app) for our example GraphQL queries. There are many other popular open-source clients that you can find online, such as [Altair ↗](https://altairgraphql.dev) and [Insomnia ↗](https://insomnia.rest).

## Limitations

The purpose of the GraphQL API is to provide aggregated analytics about various Cloudflare products. These datasets should not be used as a measure for usage that Cloudflare uses for billing purposes. Billable traffic [excludes things like DDoS traffic ↗](https://blog.cloudflare.com/unmetered-mitigation), while GraphQL is a measure of overall consumption/usage, so it will include all measurable traffic.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/analytics/graphql-api/#page","headline":"GraphQL Analytics API","description":"Query Cloudflare analytics data using GraphQL.","url":"https://developers.cloudflare.com/analytics/graphql-api/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-23","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand Cloudflare API rate limits, rate-limiting headers, and how to handle throttled requests.
title: Rate limits
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Rate limits

Last updated Aug 25, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/reference/limits/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## API token limits

| Type | Limit |
| --- | --- |
| Client API per user/account token | 1200/5 minutes |
| Client API per IP | 200/second |
| GraphQL | Varies by query cost. Max 320/5 min |
| User API token quota | 50 |
| Account API token quota | 500 |

Note

The global rate limit for the Cloudflare API is 1,200 requests per five minute period per user, and applies cumulatively regardless of whether the request is made via the dashboard, API key, or API token.

If you exceed this limit, all API calls for the next five minutes will be blocked, receiving a `HTTP 429 - Too Many Requests` response.

Some specific API calls have their own limits and are documented separately, such as the following:

- [Cache Purge APIs](https://developers.cloudflare.com/cache/how-to/purge-cache/#availability-and-limits)
- [GraphQL APIs](https://developers.cloudflare.com/analytics/graphql-api/limits/)
- [Rulesets APIs](https://developers.cloudflare.com/ruleset-engine/rulesets-api/#limits)
- [Lists API](https://developers.cloudflare.com/waf/tools/lists/lists-api/#rate-limiting-for-lists-api-requests)
- [Gateway Lists API](https://developers.cloudflare.com/cloudflare-one/reusable-components/lists/#api-rate-limit)

Enterprise customers can also [contact Cloudflare Support](https://developers.cloudflare.com/support/contacting-cloudflare-support/) to raise the Client API per user, GraphQL, or API token limits to a higher value.

## Rate limiting headers

The following headers are returned when calling REST APIs:

- `Ratelimit`: List of service limit items, composed of the limit name, the remaining quota ( `r`) and the time next window resets ( `t`). For example: `"default";r=50;t=30`
- `Ratelimit-Policy`: List of quota policy items, composed of the policy name, the total quota ( `q`) and the time window the quota applies to ( `w`). For example: `"burst";q=100;w=60`
- `retry-after`: The number of seconds, rounded up, until more capacity is available. Note, this header is only returned when the request has exceeded the rate limit.

[Cloudflare's SDKs](https://developers.cloudflare.com/fundamentals/api/reference/sdks/) will also automatically work with the headers and back off in response to rate limits.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/reference/limits/#page","headline":"Rate limits","description":"Understand Cloudflare API rate limits, rate-limiting headers, and how to handle throttled requests.","url":"https://developers.cloudflare.com/fundamentals/api/reference/limits/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-25","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review available Cloudflare API token permissions for user, account, and zone resources.
title: API token permissions
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# API token permissions

Last updated Sep 16, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/reference/permissions/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Permissions are segmented into three categories based on resource:

- Zone permissions
- Account permissions
- User permissions

Each category contains permission groups related to those resources. DNS permissions belong to the Zone category, while Billing permissions belong to the Account category. Below is a list of the available token permissions.

To obtain an updated list of token permissions, including the permission ID and the scope of each permission, use the [List permission groups](https://developers.cloudflare.com/api/resources/user/subresources/tokens/subresources/permission_groups/methods/list/) endpoint.

## User permissions

The applicable scope of user permissions is `com.cloudflare.api.user`.

| Name | Description |
| --- | --- |
| API Tokens Read | Grants read access to user's [API tokens](https://developers.cloudflare.com/fundamentals/api/reference/permissions/). |
| API Tokens Edit | Grants write access to user's [API tokens](https://developers.cloudflare.com/fundamentals/api/reference/permissions/). |
| Memberships Read | Grants read access to a user's [account memberships](https://developers.cloudflare.com/fundamentals/manage-members/manage/). |
| Memberships Edit | Grants write access to a user's [account memberships](https://developers.cloudflare.com/fundamentals/manage-members/manage/). |
| User Details Read | Grants read access to user details. |
| User Details Edit | Grants write access to user details. |

| Name | Description |
| --- | --- |
| API Tokens Read | Grants read access to user's [API tokens](https://developers.cloudflare.com/fundamentals/api/reference/permissions/). |
| API Tokens Write | Grants write access to user's [API tokens](https://developers.cloudflare.com/fundamentals/api/reference/permissions/). |
| Memberships Read | Grants read access to a user's [account memberships](https://developers.cloudflare.com/fundamentals/manage-members/manage/). |
| Memberships Write | Grants write access to a user's [account memberships](https://developers.cloudflare.com/fundamentals/manage-members/manage/). |
| User Details Read | Grants read access to user details. |
| User Details Write | Grants write access to user details. |

## Account permissions

The applicable scope of account permissions is `com.cloudflare.api.account`.

Note

The `AI Gateway Read`, `Run`, and `Edit` permissions are account-scoped only — they cannot be restricted to a single gateway. For details, refer to [Authenticated Gateway](https://developers.cloudflare.com/ai-gateway/configuration/authentication/).

| Name | Description |
| --- | --- |
| Access: Apps and Policies Read | Grants read access to Cloudflare Access [applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/) and [policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/). |
| Access: Apps and Policies Revoke | Grants ability to revoke [Cloudflare Access application tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/access-settings/session-management/) |
| Access: Apps and Policies Edit | Grants write access to Cloudflare Access [applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/) and [policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/). |
| Access: Apps Read | Grants read access to [Cloudflare Access applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/). |
| Access: Apps Revoke | Grants ability to revoke [Cloudflare Access application tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/access-settings/session-management/). |
| Access: Apps Edit | Grants write access to [Cloudflare Access applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/). |
| Access: Audit Logs Read | Grants read access to [Cloudflare Access authentication logs](https://developers.cloudflare.com/cloudflare-one/insights/logs/dashboard-logs/access-authentication-logs/). |
| Access: Custom Pages Read | Grants read access to [Cloudflare Access custom block pages](https://developers.cloudflare.com/cloudflare-one/reusable-components/custom-pages/access-block-page/). |
| Access: Custom Pages Edit | Grants write access to [Cloudflare Access custom block pages](https://developers.cloudflare.com/cloudflare-one/reusable-components/custom-pages/access-block-page/). |
| Access: Device Posture Read | Grants read access to [Cloudflare Access device posture](https://developers.cloudflare.com/cloudflare-one/reusable-components/posture-checks/). |
| Access: Device Posture Edit | Grants write access to [Cloudflare Access device posture](https://developers.cloudflare.com/cloudflare-one/reusable-components/posture-checks/). |
| Access: Groups Read | Grants read access to [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Groups Edit | Grants write access to [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Identity Providers Read | Grants read access to [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/). |
| Access: Identity Providers Edit | Grants write access to [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/). |
| Access: Keys Read | Grants read access to [Cloudflare Access signing keys](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/). |
| Access: Keys Edit | Grants ability to rotate [Cloudflare Access signing keys](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/). |
| Access: Mutual TLS Certificates Read | Grants read access to [Cloudflare Access mTLS certificates](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/). |
| Access: Mutual TLS Certificates Edit | Grants write access to [Cloudflare Access mTLS certificates](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/). |
| Access: Organizations Read | Grants read access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/). |
| Access: Organizations Revoke | Grants ability to [revoke user sessions](https://developers.cloudflare.com/cloudflare-one/access-controls/access-settings/session-management/#revoke-user-sessions) in a Zero Trust organization. |
| Access: Organizations Edit | Grants write access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/). |
| Access: Organizations, Identity Providers, and Groups Read | Grants read access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/), [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/), and [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Organizations, Identity Providers, and Groups Revoke | Grants ability to [revoke users](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/seat-management/#revoke-a-user) from your Zero Trust organization. |
| Access: Organizations, Identity Providers, and Groups Edit | Grants write access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/), [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/), and [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Policies Read | Grants read access to [Cloudflare Access policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/). |
| Access: Policies Edit | Grants write access to [Cloudflare Access policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/). |
| Access: Policy Test Read | Grants read access to Cloudflare Access policy test [results](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/subresources/users/methods/list/) and [status](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/methods/get/). |
| Access: Policy Test Edit | Grants access to [test Cloudflare Access policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/#test-your-policies). |
| Access: Population Read | Grants read access to the [SCIM users and groups](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/scim/) synced from an identity provider to Cloudflare Access. |
| Access: Population Edit | Grants write access to the [SCIM users and groups](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/scim/) synced from an identity provider to Cloudflare Access. |
| Access: SCIM Logs Read | Grants read access to [Cloudflare Access SCIM provisioning logs](https://developers.cloudflare.com/cloudflare-one/insights/logs/dashboard-logs/scim-logs/). |
| Access: Service Tokens Read | Grants read access to [Cloudflare Access service tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/). |
| Access: Service Tokens Edit | Grants write access to [Cloudflare Access service tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/). |
| Access: SSH Auditing Read | Grants read access to [Cloudflare Access SSH CAs](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/). |
| Access: SSH Auditing Edit | Grants write access to [Cloudflare Access SSH CAs](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/). |
| Access: Tags Read | Grants read access to [Cloudflare Access tags](https://developers.cloudflare.com/cloudflare-one/reusable-components/tags/). |
| Access: Tags Edit | Grants write access to [Cloudflare Access tags](https://developers.cloudflare.com/cloudflare-one/reusable-components/tags/). |
| Access: Users Read | Grants read access to [users in a Zero Trust organization](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/). |
| Access: Users Edit | Grants access to update a user's name in a Zero Trust organization. |
| Account Analytics Read | Grants read access to [account analytics](https://developers.cloudflare.com/analytics/account-and-zone-analytics/account-analytics/). |
| Account Custom Pages Read | Grants read access to account-level [Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Account Custom Pages Edit | Grants write access to account-level [Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Account Filter Lists Read | Grants read access to Account Filter Lists. |
| Account Filter Lists Edit | Grants write access to Account Filter Lists. |
| Account Firewall Access Rules Read | Grants read access to account firewall access rules. |
| Account Firewall Access Rules Edit | Grants write access to account firewall access rules. |
| Account Rulesets Read | Grants read access to [Account Rulesets](https://developers.cloudflare.com/ruleset-engine/about/rulesets/). |
| Account Rulesets Edit | Grants write access to [Account Rulesets](https://developers.cloudflare.com/ruleset-engine/about/rulesets/). |
| Account Security Center Insights | Grants read access to [Security Center Insights](https://developers.cloudflare.com/security/security-insights/). |
| Account Security Center Insights Edit | Grants write access to [Security Center Insights](https://developers.cloudflare.com/security/security-insights/). |
| Account Settings Read | Grants read access to [Account resources, account membership, and account level features](https://developers.cloudflare.com/fundamentals/account/). |
| Account Settings Edit | Grants write access to [Account resources, account membership, and account level features](https://developers.cloudflare.com/fundamentals/account/). |
| Account: SSL and Certificates Read | Grants read access to [SSL and Certificates](https://developers.cloudflare.com/ssl/). |
| Account: SSL and Certificates Edit | Grants write access to [SSL and Certificates](https://developers.cloudflare.com/ssl/). |
| Account WAF Read | Grants read access to [Account WAF](https://developers.cloudflare.com/waf/). |
| Account WAF Edit | Grants write access to [Account WAF](https://developers.cloudflare.com/waf/). |
| Address Maps Edit | Grants write access to [Address Maps](https://developers.cloudflare.com/byoip/address-maps/) |
| Address Maps Read | Grants read access to [Address Maps](https://developers.cloudflare.com/byoip/address-maps/) |
| Address Maps Read | Grants read access to [Address Maps](https://developers.cloudflare.com/byoip/address-maps/) |
| AI Gateway Edit | Grants edit access to [AI Gateway](https://developers.cloudflare.com/ai-gateway/) |
| AI Gateway Read | Grants read access to [AI Gateway](https://developers.cloudflare.com/ai-gateway/) |
| AI Gateway Run | Grants run access to [Non-realtime WebSockets API](https://developers.cloudflare.com/ai-gateway/usage/websockets-api/non-realtime-api/) |
| Allow Request Tracer Read | Grants read access to Request Tracer. |
| API Gateway Read | Grants read access to [API Gateway (including API Shield)](https://developers.cloudflare.com/api-shield/) for all domains in an account. |
| API Gateway Edit | Grants write access to [API Gateway (including API Shield)](https://developers.cloudflare.com/api-shield/) for all domains in an account. |
| Billing Read | Grants read access to [billing profile, subscriptions, and access to fetch invoices](https://developers.cloudflare.com/billing/) and entitlements. |
| Billing Edit | Grants write access to [billing profile, subscriptions, and access to fetch invoices and entitlements](https://developers.cloudflare.com/billing/). |
| Bulk URL Redirects Read | Grants read access to [Bulk Redirects](https://developers.cloudflare.com/rules/url-forwarding/bulk-redirects/). |
| Bulk URL Redirects Edit | Grants write access to [Bulk Redirects](https://developers.cloudflare.com/rules/url-forwarding/bulk-redirects/). |
| China Network Steering Read | Grants read access to [China Network Steering](https://developers.cloudflare.com/china-network/). |
| China Network Steering Edit | Grants write access to [China Network Steering](https://developers.cloudflare.com/china-network/). |
| Cloudchamber Read | Grants read access to Cloudchamber deployments. |
| Cloudchamber Edit | Grants write access to Cloudchamber deployments. |
| Cloudflare Realtime Read | Grants read access to Cloudflare Realtime. |
| Cloudflare Realtime Edit | Grants write access to Cloudflare Realtime. |
| Cloudflare CASB Read | Grants read access to [Cloud Access Security Broker](https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/). |
| Cloudflare CASB Edit | Grants write access to [Cloud Access Security Broker](https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/). |
| Cloudflare DEX Read | Grants read access to [Digital Experience Monitoring](https://developers.cloudflare.com/cloudflare-one/insights/dex/). |
| Cloudflare DEX Edit | Grants write access to [Digital Experience Monitoring](https://developers.cloudflare.com/cloudflare-one/insights/dex/). |
| Cloudflare Images Read | Grants read access to [Cloudflare Images](https://developers.cloudflare.com/images/). |
| Cloudflare Images Edit | Grants write access to [Cloudflare Images](https://developers.cloudflare.com/images/). |
| Cloudflare One Connector: cloudflared Read | Grants read access to [`cloudflared` connectors](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) |
| Cloudflare One Connector: cloudflared Edit | Grants write access to [`cloudflared` connectors](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) |
| Cloudflare One Connector: WARP Read | Grants read access to [Cloudflare Mesh nodes](https://developers.cloudflare.com/mesh/) |
| Cloudflare One Connector: WARP Edit | Grants write access to [Cloudflare Mesh nodes](https://developers.cloudflare.com/mesh/) |
| Cloudflare One Connectors Read | Grants read access to Cloudflare One connectors |
| Cloudflare One Connectors Edit | Grants write access to Cloudflare One connectors |
| Cloudflare One Networks Read | Grants read access to Cloudflare One routes and virtual networks |
| Cloudflare One Networks Edit | Grants write access to Cloudflare One routes and virtual networks |
| Cloudflare Pages Read | Grants access to view [Cloudflare Pages](https://developers.cloudflare.com/pages/) projects. |
| Cloudflare Pages Edit | Grants access to create, edit and delete [Cloudflare Pages](https://developers.cloudflare.com/pages/) projects. |
| Cloudflare Tunnel Read | Grants access to view [Cloudflare Tunnels](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/). |
| Cloudflare Tunnel Edit | Grants access to create and delete [Cloudflare Tunnels](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/). |
| Cloudforce One Read | Grants read access to Cloudforce One. |
| Cloudforce One Edit | Grants write access to Cloudforce One. |
| Email Security Read | Grants read access to [Cloud Email Security](https://developers.cloudflare.com/email-security/). |
| Email Security Edit | Grants write access to [Email Security](https://developers.cloudflare.com/email-security/). |
| Constellation Read | Grants read access to [Constellation](https://developers.cloudflare.com/constellation/). |
| Constellation Edit | Grants write access to [Constellation](https://developers.cloudflare.com/constellation/). |
| Containers Read | Grants read access to [Containers](https://developers.cloudflare.com/containers/). |
| Containers Edit | Grants write access to [Containers](https://developers.cloudflare.com/containers/). |
| D1 Read | Grants read access to [D1](https://developers.cloudflare.com/d1/). |
| D1 Edit | Grants write access to [D1](https://developers.cloudflare.com/d1/). |
| DDoS Botnet Feed Read | Grants read access to Botnet Feed reports. |
| DDoS Botnet Feed Edit | Grants write access to Botnet Feed configuration. |
| DDoS Protection Read | Grants read access to [DDoS protection](https://developers.cloudflare.com/ddos-protection/). |
| DDoS Protection Edit | Grants write access to [DDoS protection](https://developers.cloudflare.com/ddos-protection/). |
| DNS Firewall Read | Grants read access to [DNS Firewall](https://developers.cloudflare.com/dns/dns-firewall/). |
| DNS Firewall Edit | Grants write access to [DNS Firewall](https://developers.cloudflare.com/dns/dns-firewall/). |
| Email Routing Addresses Read | Grants read access to [Email Routing Addresses](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Email Routing Addresses Edit | Grants write access to [Email Routing Addresses](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Hyperdrive Read | Grants read access to [Hyperdrive](https://developers.cloudflare.com/hyperdrive/). |
| Hyperdrive Edit | Grants write access to [Hyperdrive](https://developers.cloudflare.com/hyperdrive/). |
| Intel Read | Grants read access to [Intel](https://developers.cloudflare.com/security-center/intel-apis/). |
| Intel Edit | Grants write access to [Intel](https://developers.cloudflare.com/security-center/intel-apis/). |
| Integration Edit | Grants write access to integrations. |
| IOT Read | Grants read access to [IOT ↗](https://blog.cloudflare.com/rethinking-internet-of-things-security/). |
| IOT Edit | Grants write access to [IOT ↗](https://blog.cloudflare.com/rethinking-internet-of-things-security/). |
| IP Prefixes: Read | Grants access to read IP prefix settings. |
| IP Prefixes: Edit | Grants access to read/write IP prefix settings. |
| IP Prefixes: BGP On Demand Read | Grants access to read IP prefix BGP configuration. |
| IP Prefixes: BGP On Demand Edit | Grants access to read and change IP prefix BGP configuration. |
| L3/4 DDoS Managed Ruleset Read | Grants read access to [L3/4 DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/network/). |
| L3/4 DDoS Managed Ruleset Edit | Grants write access to [L3/4 DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/network/). |
| Load Balancing: Monitors and Pools Read | Grants read access to account level [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Load Balancing: Monitors and Pools Edit | Grants write access to account level [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Logs Read | Grants read access to logs using [Logpull or Instant Logs](https://developers.cloudflare.com/logs/). |
| Logs Edit | Grants read and write access to [Logpull, Logpush, and Instant Logs](https://developers.cloudflare.com/logs/). |
| Magic Firewall Read | Grants read access to [Cloudflare Network Firewall](https://developers.cloudflare.com/cloudflare-network-firewall/). |
| Magic Firewall Edit | Grants write access to [Cloudflare Network Firewall](https://developers.cloudflare.com/cloudflare-network-firewall/). |
| Magic Firewall Packet Captures Read | Grants read access to [Packet Captures](https://developers.cloudflare.com/cloudflare-network-firewall/packet-captures/collect-pcaps/). |
| Magic Firewall Packet Captures Edit | Grants write access to [Packet Captures](https://developers.cloudflare.com/cloudflare-network-firewall/packet-captures/collect-pcaps/). |
| Magic Network Monitoring Read | Grants read access to [Network Flow](https://developers.cloudflare.com/network-flow/). |
| Magic Network Monitoring Edit | Grants write access to [Network Flow](https://developers.cloudflare.com/network-flow/). |
| Magic Transit Read | Grants read access to manage a user's [Magic Transit prefixes](https://developers.cloudflare.com/magic-transit/how-to/advertise-prefixes/). |
| Magic Transit Edit | Grants write access to manage a user's [Magic Transit prefixes](https://developers.cloudflare.com/magic-transit/how-to/advertise-prefixes/). |
| Notifications Read | Grants read access to [Notifications](https://developers.cloudflare.com/notifications/). |
| Notifications Edit | Grants write access to [Notifications](https://developers.cloudflare.com/notifications/). |
| Client-side security Read | Grants read access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Client-side security Edit | Grants write access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Workers Pipelines Read | Grants read access to Cloudflare Pipelines. |
| Workers Pipelines Edit | Grants write access to Cloudflare Pipelines. |
| Queues Read | Grants read access to [Queues](https://developers.cloudflare.com/queues/). |
| Queues Edit | Grants write access to [Queues](https://developers.cloudflare.com/queues/). |
| Rule Policies Read | Grants read access to Rule Policies. |
| Rule Policies Edit | Grants write access to Rule Policies. |
| Stream Read | Grants read access to [Cloudflare Stream](https://developers.cloudflare.com/stream/). |
| Stream Edit | Grants write access to [Cloudflare Stream](https://developers.cloudflare.com/stream/). |
| Transform Rules Read | Grants read access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Transform Rules Edit | Grants write access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Turnstile Read | Grants read access to [Turnstile](https://developers.cloudflare.com/turnstile/). |
| Turnstile Edit | Grants write access to [Turnstile](https://developers.cloudflare.com/turnstile/). |
| URL Scanner Read | Grants read access to [URL Scanner](https://developers.cloudflare.com/radar/investigate/url-scanner/). |
| URL Scanner Edit | Grants write access to [URL Scanner](https://developers.cloudflare.com/radar/investigate/url-scanner/). |
| Vectorize Read | Grants read access to [Vectorize](https://developers.cloudflare.com/vectorize/). |
| Vectorize Edit | Grants write access to [Vectorize](https://developers.cloudflare.com/vectorize/). |
| Workers AI Read | Grants read access to [Workers AI](https://developers.cloudflare.com/workers-ai/). |
| Workers AI Edit | Grants write access to [Workers AI](https://developers.cloudflare.com/workers-ai/). |
| Workers CI Read | Grants read access to [Workers CI](https://developers.cloudflare.com/workers/). |
| Workers CI Edit | Grants write access to [Workers CI](https://developers.cloudflare.com/workers). |
| Workers KV Storage Read | Grants read access to [Cloudflare Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Workers KV Storage Edit | Grants write access to [Cloudflare Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Workers R2 Storage Read | Grants read access to [Cloudflare R2 Storage](https://developers.cloudflare.com/r2/). |
| Workers R2 Storage Edit | Grants write access to [Cloudflare R2 Storage](https://developers.cloudflare.com/r2/). |
| Workers Scripts Read | Grants read access to [Cloudflare Workers scripts](https://developers.cloudflare.com/workers/). |
| Workers Scripts Edit | Grants write access to [Cloudflare Workers scripts](https://developers.cloudflare.com/workers/). |
| Workers Tail Read | Grants [`wrangler tail`](https://developers.cloudflare.com/workers/wrangler/commands/general/#tail) read permissions. |
| Zero Trust Read | Grants read access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) resources. |
| Zero Trust Report | Grants reporting access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/). |
| Zero Trust Edit | Grants write access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) resources. |
| Zero Trust: PII Read | Grants read access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) PII. |
| Zero Trust: Seats Edit | Grants write access to the number of [Zero Trust seats](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/seat-management/) your organization can use (and be billed for). |

| Name | Description |
| --- | --- |
| Access: Apps and Policies Read | Grants read access to Cloudflare Access [applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/) and [policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/). |
| Access: Apps and Policies Revoke | Grants ability to revoke [Cloudflare Access application tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/access-settings/session-management/) |
| Access: Apps and Policies Write | Grants write access to Cloudflare Access [applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/) and [policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/). |
| Access: Apps Read | Grants read access to [Cloudflare Access applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/). |
| Access: Apps Revoke | Grants ability to revoke [Cloudflare Access application tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/access-settings/session-management/). |
| Access: Apps Write | Grants write access to [Cloudflare Access applications](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/). |
| Access: Audit Logs Read | Grants read access to [Cloudflare Access authentication logs](https://developers.cloudflare.com/cloudflare-one/insights/logs/dashboard-logs/access-authentication-logs/). |
| Access: Custom Pages Read | Grants read access to [Cloudflare Access custom block pages](https://developers.cloudflare.com/cloudflare-one/reusable-components/custom-pages/access-block-page/). |
| Access: Custom Pages Write | Grants write access to [Cloudflare Access custom block pages](https://developers.cloudflare.com/cloudflare-one/reusable-components/custom-pages/access-block-page/). |
| Access: Device Posture Read | Grants read access to [Cloudflare Access device posture](https://developers.cloudflare.com/cloudflare-one/reusable-components/posture-checks/). |
| Access: Device Posture Write | Grants write access to [Cloudflare Access device posture](https://developers.cloudflare.com/cloudflare-one/reusable-components/posture-checks/). |
| Access: Groups Read | Grants read access to [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Groups Write | Grants write access to [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Identity Providers Read | Grants read access to [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/). |
| Access: Identity Providers Write | Grants write access to [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/). |
| Access: Keys Read | Grants read access to [Cloudflare Access signing keys](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/). |
| Access: Keys Write | Grants ability to rotate [Cloudflare Access signing keys](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/). |
| Access: Mutual TLS Certificates Read | Grants read access to [Cloudflare Access mTLS certificates](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/). |
| Access: Mutual TLS Certificates Write | Grants write access to [Cloudflare Access mTLS certificates](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/). |
| Access: Organizations Read | Grants read access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/). |
| Access: Organizations Revoke | Grants ability to [revoke user sessions](https://developers.cloudflare.com/cloudflare-one/access-controls/access-settings/session-management/#revoke-user-sessions) in a Zero Trust organization. |
| Access: Organizations Write | Grants write access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/). |
| Access: Organizations, Identity Providers, and Groups Read | Grants read access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/), [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/), and [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Organizations, Identity Providers, and Groups Revoke | Grants ability to [revoke users](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/seat-management/#revoke-a-user) from your Zero Trust organization. |
| Access: Organizations, Identity Providers, and Groups Write | Grants write access to [Zero Trust Organization settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list/), [Cloudflare One identity providers](https://developers.cloudflare.com/cloudflare-one/integrations/identity-providers/), and [Cloudflare Access rule groups](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/groups/). |
| Access: Policies Read | Grants read access to [Cloudflare Access policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/). |
| Access: Policies Write | Grants write access to [Cloudflare Access policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/). |
| Access: Policy Test Read | Grants read access to Cloudflare Access policy test [results](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/subresources/users/methods/list/) and [status](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/methods/get/). |
| Access: Policy Test Write | Grants access to [test Cloudflare Access policies](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/#test-your-policies). |
| Access: Population Read | Grants read access to the [SCIM users and groups](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/scim/) synced from an identity provider to Cloudflare Access. |
| Access: Population Write | Grants write access to the [SCIM users and groups](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/scim/) synced from an identity provider to Cloudflare Access. |
| Access: SCIM Logs Read | Grants read access to [Cloudflare Access SCIM provisioning logs](https://developers.cloudflare.com/cloudflare-one/insights/logs/dashboard-logs/scim-logs/). |
| Access: Service Tokens Read | Grants read access to [Cloudflare Access service tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/). |
| Access: Service Tokens Write | Grants write access to [Cloudflare Access service tokens](https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/service-tokens/). |
| Access: SSH Auditing Read | Grants read access to [Cloudflare Access SSH CAs](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/). |
| Access: SSH Auditing Write | Grants write access to [Cloudflare Access SSH CAs](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/). |
| Access: Tags Read | Grants read access to [Cloudflare Access tags](https://developers.cloudflare.com/cloudflare-one/reusable-components/tags/). |
| Access: Tags Write | Grants write access to [Cloudflare Access tags](https://developers.cloudflare.com/cloudflare-one/reusable-components/tags/). |
| Access: Users Read | Grants read access to [users in a Zero Trust organization](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/). |
| Access: Users Write | Grants access to update a user's name in a Zero Trust organization. |
| Account Analytics Read | Grants read access to [account analytics](https://developers.cloudflare.com/analytics/account-and-zone-analytics/account-analytics/). |
| Account Custom Pages Read | Grants read access to account-level [Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Account Custom Pages Write | Grants write access to account-level [Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Account Rule Lists Read | Grants read access to Account Filter Lists. |
| Account Rule Lists Write | Grants write access to Account Filter Lists. |
| Account Firewall Access Rules Read | Grants read access to account firewall access rules. |
| Account Firewall Access Rules Write | Grants write access to account firewall access rules. |
| Account Rulesets Read | Grants read access to [Account Rulesets](https://developers.cloudflare.com/ruleset-engine/about/rulesets/). |
| Account Rulesets Write | Grants write access to [Account Rulesets](https://developers.cloudflare.com/ruleset-engine/about/rulesets/). |
| Account Security Center Insights | Grants read access to [Security Center Insights](https://developers.cloudflare.com/security/security-insights/). |
| Account Security Center Insights Write | Grants write access to [Security Center Insights](https://developers.cloudflare.com/security/security-insights/). |
| Account Settings Read | Grants read access to [Account resources, account membership, and account level features](https://developers.cloudflare.com/fundamentals/account/). |
| Account Settings Write | Grants write access to [Account resources, account membership, and account level features](https://developers.cloudflare.com/fundamentals/account/). |
| Account: SSL and Certificates Read | Grants read access to [SSL and Certificates](https://developers.cloudflare.com/ssl/). |
| Account: SSL and Certificates Write | Grants write access to [SSL and Certificates](https://developers.cloudflare.com/ssl/). |
| Account WAF Read | Grants read access to [Account WAF](https://developers.cloudflare.com/waf/). |
| Account WAF Write | Grants write access to [Account WAF](https://developers.cloudflare.com/waf/). |
| Address Maps Write | Grants write access to [Address Maps](https://developers.cloudflare.com/byoip/address-maps/) |
| Address Maps Read | Grants read access to [Address Maps](https://developers.cloudflare.com/byoip/address-maps/) |
| Address Maps Read | Grants read access to [Address Maps](https://developers.cloudflare.com/byoip/address-maps/) |
| AI Gateway Edit | Grants edit access to [AI Gateway](https://developers.cloudflare.com/ai-gateway/) |
| AI Gateway Read | Grants read access to [AI Gateway](https://developers.cloudflare.com/ai-gateway/) |
| AI Gateway Run | Grants run access to [Non-realtime WebSockets API](https://developers.cloudflare.com/ai-gateway/usage/websockets-api/non-realtime-api/) |
| Allow Request Tracer Read | Grants read access to Request Tracer. |
| Account API Gateway Read | Grants read access to [API Gateway (including API Shield)](https://developers.cloudflare.com/api-shield/) for all domains in an account. |
| Account API Gateway Write | Grants write access to [API Gateway (including API Shield)](https://developers.cloudflare.com/api-shield/) for all domains in an account. |
| Billing Read | Grants read access to [billing profile, subscriptions, and access to fetch invoices](https://developers.cloudflare.com/billing/) and entitlements. |
| Billing Write | Grants write access to [billing profile, subscriptions, and access to fetch invoices and entitlements](https://developers.cloudflare.com/billing/). |
| Mass URL Redirects Read | Grants read access to [Bulk Redirects](https://developers.cloudflare.com/rules/url-forwarding/bulk-redirects/). |
| Mass URL Redirects Write | Grants write access to [Bulk Redirects](https://developers.cloudflare.com/rules/url-forwarding/bulk-redirects/). |
| China Network Steering Read | Grants read access to [China Network Steering](https://developers.cloudflare.com/china-network/). |
| China Network Steering Write | Grants write access to [China Network Steering](https://developers.cloudflare.com/china-network/). |
| Cloudchamber Read | Grants read access to Cloudchamber deployments. |
| Cloudchamber Write | Grants write access to Cloudchamber deployments. |
| Realtime Read | Grants read access to Cloudflare Realtime. |
| Realtime Write | Grants write access to Cloudflare Realtime. |
| Cloudflare CASB Read | Grants read access to [Cloud Access Security Broker](https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/). |
| Cloudflare CASB Write | Grants write access to [Cloud Access Security Broker](https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/). |
| Cloudflare DEX Read | Grants read access to [Digital Experience Monitoring](https://developers.cloudflare.com/cloudflare-one/insights/dex/). |
| Cloudflare DEX Write | Grants write access to [Digital Experience Monitoring](https://developers.cloudflare.com/cloudflare-one/insights/dex/). |
| Images Read | Grants read access to [Cloudflare Images](https://developers.cloudflare.com/images/). |
| Images Write | Grants write access to [Cloudflare Images](https://developers.cloudflare.com/images/). |
| Cloudflare One Connector: cloudflared Read | Grants read access to [`cloudflared` connectors](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) |
| Cloudflare One Connector: cloudflared Write | Grants write access to [`cloudflared` connectors](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) |
| Cloudflare One Connector: WARP Read | Grants read access to [Cloudflare Mesh nodes](https://developers.cloudflare.com/mesh/) |
| Cloudflare One Connector: WARP Write | Grants write access to [Cloudflare Mesh nodes](https://developers.cloudflare.com/mesh/) |
| Cloudflare One Connectors Read | Grants read access to Cloudflare One connectors |
| Cloudflare One Connectors Write | Grants write access to Cloudflare One connectors |
| Cloudflare One Networks Read | Grants read access to Cloudflare One routes and virtual networks |
| Cloudflare One Networks Write | Grants write access to Cloudflare One routes and virtual networks |
| Pages Read | Grants access to view [Cloudflare Pages](https://developers.cloudflare.com/pages/) projects. |
| Pages Write | Grants access to create, edit and delete [Cloudflare Pages](https://developers.cloudflare.com/pages/) projects. |
| Cloudflare Tunnel Read | Grants access to view [Cloudflare Tunnels](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/). |
| Cloudflare Tunnel Write | Grants access to create and delete [Cloudflare Tunnels](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/). |
| Cloudforce One Read | Grants read access to Cloudforce One. |
| Cloudforce One Write | Grants write access to Cloudforce One. |
| Cloud Email Security: Read | Grants read access to [Cloud Email Security](https://developers.cloudflare.com/email-security/). |
| Cloud Email Security: Write | Grants write access to [Email Security](https://developers.cloudflare.com/email-security/). |
| Constellation Read | Grants read access to [Constellation](https://developers.cloudflare.com/constellation/). |
| Constellation Write | Grants write access to [Constellation](https://developers.cloudflare.com/constellation/). |
| Containers Read | Grants read access to [Containers](https://developers.cloudflare.com/containers/). |
| Containers Write | Grants write access to [Containers](https://developers.cloudflare.com/containers/). |
| D1 Read | Grants read access to [D1](https://developers.cloudflare.com/d1/). |
| D1 Write | Grants write access to [D1](https://developers.cloudflare.com/d1/). |
| DDoS Botnet Feed Read | Grants read access to Botnet Feed reports. |
| DDoS Botnet Feed Write | Grants write access to Botnet Feed configuration. |
| DDoS Protection Read | Grants read access to [DDoS protection](https://developers.cloudflare.com/ddos-protection/). |
| DDoS Protection Write | Grants write access to [DDoS protection](https://developers.cloudflare.com/ddos-protection/). |
| DNS Firewall Read | Grants read access to [DNS Firewall](https://developers.cloudflare.com/dns/dns-firewall/). |
| DNS Firewall Write | Grants write access to [DNS Firewall](https://developers.cloudflare.com/dns/dns-firewall/). |
| Email Routing Addresses Read | Grants read access to [Email Routing Addresses](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Email Routing Addresses Write | Grants write access to [Email Routing Addresses](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Hyperdrive Read | Grants read access to [Hyperdrive](https://developers.cloudflare.com/hyperdrive/). |
| Hyperdrive Write | Grants write access to [Hyperdrive](https://developers.cloudflare.com/hyperdrive/). |
| Intel Read | Grants read access to [Intel](https://developers.cloudflare.com/security-center/intel-apis/). |
| Intel Write | Grants write access to [Intel](https://developers.cloudflare.com/security-center/intel-apis/). |
| Integration Write | Grants write access to integrations. |
| IOT Read | Grants read access to [IOT ↗](https://blog.cloudflare.com/rethinking-internet-of-things-security/). |
| IOT Write | Grants write access to [IOT ↗](https://blog.cloudflare.com/rethinking-internet-of-things-security/). |
| IP Prefixes: Read | Grants access to read IP prefix settings. |
| IP Prefixes: Write | Grants access to read/write IP prefix settings. |
| IP Prefixes: BGP On Demand Read | Grants access to read IP prefix BGP configuration. |
| IP Prefixes: BGP On Demand Write | Grants access to read and change IP prefix BGP configuration. |
| L4 DDoS Managed Ruleset Read | Grants read access to [L3/4 DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/network/). |
| L4 DDoS Managed Ruleset Write | Grants write access to [L3/4 DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/network/). |
| Load Balancing: Monitors and Pools Read | Grants read access to account level [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Load Balancing: Monitors and Pools Write | Grants write access to account level [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Logs Read | Grants read access to logs using [Logpull or Instant Logs](https://developers.cloudflare.com/logs/). |
| Logs Write | Grants read and write access to [Logpull, Logpush, and Instant Logs](https://developers.cloudflare.com/logs/). |
| Magic Firewall Read | Grants read access to [Cloudflare Network Firewall](https://developers.cloudflare.com/cloudflare-network-firewall/). |
| Magic Firewall Write | Grants write access to [Cloudflare Network Firewall](https://developers.cloudflare.com/cloudflare-network-firewall/). |
| Magic Firewall Packet Captures - Read PCAPs API | Grants read access to [Packet Captures](https://developers.cloudflare.com/cloudflare-network-firewall/packet-captures/collect-pcaps/). |
| Magic Firewall Packet Captures - Write PCAPs API | Grants write access to [Packet Captures](https://developers.cloudflare.com/cloudflare-network-firewall/packet-captures/collect-pcaps/). |
| Magic Network Monitoring Read | Grants read access to [Network Flow](https://developers.cloudflare.com/network-flow/). |
| Magic Network Monitoring Write | Grants write access to [Network Flow](https://developers.cloudflare.com/network-flow/). |
| Magic Transit Read | Grants read access to manage a user's [Magic Transit prefixes](https://developers.cloudflare.com/magic-transit/how-to/advertise-prefixes/). |
| Magic Transit Write | Grants write access to manage a user's [Magic Transit prefixes](https://developers.cloudflare.com/magic-transit/how-to/advertise-prefixes/). |
| Notifications Read | Grants read access to [Notifications](https://developers.cloudflare.com/notifications/). |
| Notifications Write | Grants write access to [Notifications](https://developers.cloudflare.com/notifications/). |
| Page Shield Read | Grants read access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Page Shield Write | Grants write access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Pipelines Read | Grants read access to Cloudflare Pipelines. |
| Pipelines Write | Grants write access to Cloudflare Pipelines. |
| Queues Read | Grants read access to [Queues](https://developers.cloudflare.com/queues/). |
| Queues Write | Grants write access to [Queues](https://developers.cloudflare.com/queues/). |
| Rule Policies Read | Grants read access to Rule Policies. |
| Rule Policies Write | Grants write access to Rule Policies. |
| Stream Read | Grants read access to [Cloudflare Stream](https://developers.cloudflare.com/stream/). |
| Stream Write | Grants write access to [Cloudflare Stream](https://developers.cloudflare.com/stream/). |
| Transform Rules Read | Grants read access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Transform Rules Write | Grants write access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Turnstile Read | Grants read access to [Turnstile](https://developers.cloudflare.com/turnstile/). |
| Turnstile Write | Grants write access to [Turnstile](https://developers.cloudflare.com/turnstile/). |
| URL Scanner Read | Grants read access to [URL Scanner](https://developers.cloudflare.com/radar/investigate/url-scanner/). |
| URL Scanner Write | Grants write access to [URL Scanner](https://developers.cloudflare.com/radar/investigate/url-scanner/). |
| Vectorize Read | Grants read access to [Vectorize](https://developers.cloudflare.com/vectorize/). |
| Vectorize Write | Grants write access to [Vectorize](https://developers.cloudflare.com/vectorize/). |
| Workers AI Read | Grants read access to [Workers AI](https://developers.cloudflare.com/workers-ai/). |
| Workers AI Write | Grants write access to [Workers AI](https://developers.cloudflare.com/workers-ai/). |
| Workers CI Read | Grants read access to [Workers CI](https://developers.cloudflare.com/workers/). |
| Workers CI Write | Grants write access to [Workers CI](https://developers.cloudflare.com/workers). |
| Workers KV Storage Read | Grants read access to [Cloudflare Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Workers KV Storage Write | Grants write access to [Cloudflare Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Workers R2 Storage Read | Grants read access to [Cloudflare R2 Storage](https://developers.cloudflare.com/r2/). |
| Workers R2 Storage Write | Grants write access to [Cloudflare R2 Storage](https://developers.cloudflare.com/r2/). |
| Workers Scripts Read | Grants read access to [Cloudflare Workers scripts](https://developers.cloudflare.com/workers/). |
| Workers Scripts Write | Grants write access to [Cloudflare Workers scripts](https://developers.cloudflare.com/workers/). |
| Workers Tail Read | Grants [`wrangler tail`](https://developers.cloudflare.com/workers/wrangler/commands/general/#tail) read permissions. |
| Zero Trust Read | Grants read access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) resources. |
| Zero Trust Report | Grants reporting access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/). |
| Zero Trust Write | Grants write access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) resources. |
| Zero Trust: PII Read | Grants read access to [Cloudflare Zero Trust](https://developers.cloudflare.com/cloudflare-one/) PII. |
| Zero Trust: Seats Write | Grants write access to the number of [Zero Trust seats](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/seat-management/) your organization can use (and be billed for). |

## Zone permissions

The applicable scope of zone permissions is `com.cloudflare.api.account.zone`.

| Name | Description |
| --- | --- |
| Access: Apps and Policies Read | Grants read access to [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) zone resources. |
| Access: Apps and Policies Revoke | Grants ability to revoke all tokens to [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) zone resources. |
| Access: Apps and Policies Edit | Grants write access to [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) zone resources. |
| Analytics Read | Grants read access to [analytics](https://developers.cloudflare.com/analytics/account-and-zone-analytics/zone-analytics/). |
| API Gateway Read | Grants read access to [API Gateway](https://developers.cloudflare.com/api-shield/) zone resources. |
| API Gateway Edit | Grants write access to [API Gateway](https://developers.cloudflare.com/api-shield/) zone resources. |
| Apps Edit | Grants full access to Cloudflare Apps (deprecated, refer to [Workers](https://developers.cloudflare.com/workers/) instead). |
| Bot Management Read | Grants read access to [Bot Management](https://developers.cloudflare.com/bots/plans/bm-subscription/). |
| Bot Management Edit | Grants write access to [Bot Management](https://developers.cloudflare.com/bots/plans/bm-subscription/). |
| Bot Management Feedback Read | Grants read access to [Bot Management feedback](https://developers.cloudflare.com/bots/concepts/feedback-loop/). |
| Bot Management Feedback Edit | Grants write access to [Bot Management feedback](https://developers.cloudflare.com/bots/concepts/feedback-loop/). |
| Cache Purge | Grants access to [purge cache](https://developers.cloudflare.com/cache/how-to/purge-cache/). |
| Cache Rules Read | Grants read access to [Cache Rules](https://developers.cloudflare.com/cache/how-to/cache-rules/). |
| Cache Rules Edit | Grants write access to [Cache Rules](https://developers.cloudflare.com/cache/how-to/cache-rules/). |
| Cloud Connector Read | Grants read access to [Cloud Connector rules](https://developers.cloudflare.com/rules/cloud-connector/). |
| Cloud Connector Edit | Grants write access to [Cloud Connector rules](https://developers.cloudflare.com/rules/cloud-connector/). |
| Config Rules Read | Grants read access to [Configuration Rules](https://developers.cloudflare.com/rules/configuration-rules/). |
| Config Rules Edit | Grants write access to [Configuration Rules](https://developers.cloudflare.com/rules/configuration-rules/). |
| Custom Error Rules Read | Grants read access to [Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/). |
| Custom Error Rules Edit | Grants write access to [Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/). |
| Custom Pages Read | Grants read access to [Custom Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Custom Pages Edit | Grants write access to [Custom Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Dmarc Management Read | Grants read access to [DMARC Management](https://developers.cloudflare.com/dmarc-management/). |
| Dmarc Management Edit | Grants write access to [DMARC Management](https://developers.cloudflare.com/dmarc-management/). |
| DNS Read | Grants read access to [DNS](https://developers.cloudflare.com/dns/). |
| DNS Write | Grants write access to [DNS](https://developers.cloudflare.com/dns/). |
| Email Routing Rules Read | Grants read access to [Email Routing Rules](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Email Routing Rules Edit | Grants write access to [Email Routing Rules](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Firewall Services Read | Grants read access to Firewall resources. |
| Firewall Services Edit | Grants write access to Firewall resources. |
| Health Checks Read | Grants read access to [Health Checks](https://developers.cloudflare.com/health-checks/). |
| Health Checks Edit | Grants write access to [Health Checks](https://developers.cloudflare.com/health-checks/). |
| HTTP DDoS Managed Ruleset Read | Grants read access to [HTTP DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/http/). |
| HTTP DDoS Managed Ruleset Edit | Grants write access to [HTTP DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/http/). |
| Load Balancers Read | Grants read access to [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Load Balancers Edit | Grants write access to [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Logs Read | Grants read access to logs using [Logpull](https://developers.cloudflare.com/logs/). |
| Logs Edit | Grants write access to [Logpull and Logpush](https://developers.cloudflare.com/logs/). |
| Managed Headers Read | Grants read access to [Managed Headers](https://developers.cloudflare.com/rules/transform/managed-transforms/). |
| Managed Headers Edit | Grants write access to [Managed Headers](https://developers.cloudflare.com/rules/transform/managed-transforms/). |
| Origin Rules Read | Grants read access to [Origin Rules](https://developers.cloudflare.com/rules/origin-rules/). |
| Origin Rules Edit | Grants write access to [Origin Rules](https://developers.cloudflare.com/rules/origin-rules/). |
| Page Rules Read | Grants read access to [Page Rules](https://developers.cloudflare.com/rules/page-rules/). |
| Page Rules Edit | Grants write access to [Page Rules](https://developers.cloudflare.com/rules/page-rules/). |
| Client-side security Read | Grants read access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Client-side security Edit | Grants write access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Response Compression Read | Grants read access to [Response Compression](https://developers.cloudflare.com/rules/compression-rules/). |
| Response Compression Edit | Grants write access to [Response Compression](https://developers.cloudflare.com/rules/compression-rules/). |
| Sanitize Read | Grants read access to sanitization. |
| Sanitize Edit | Grants write access to sanitization. |
| Single Redirect Read | Grants read access to zone-level [Single Redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/). |
| Single Redirect Edit | Grants write access to zone-level [Single Redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/). |
| SSL and Certificates Read | Grants read access to [SSL configuration and certificate management](https://developers.cloudflare.com/ssl/). |
| SSL and Certificates Edit | Grants write access to [SSL configuration and certificate management](https://developers.cloudflare.com/ssl/). |
| Transform Rules Read | Grants read access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Transform Rules Edit | Grants write access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Waiting Room Read | Grants read access to [Waiting Room](https://developers.cloudflare.com/waiting-room/). |
| Waiting Room Edit | Grants write access to [Waiting Room](https://developers.cloudflare.com/waiting-room/). |
| Web3 Hostnames Read | Grants read access to [Web3 Hostnames](https://developers.cloudflare.com/web3/). |
| Web3 Hostnames Edit | Grants write access to [Web3 Hostnames](https://developers.cloudflare.com/web3/). |
| Workers Routes Read | Grants read access to [Cloudflare Workers](https://developers.cloudflare.com/workers/) and [Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Workers Routes Edit | Grants write access to [Cloudflare Workers](https://developers.cloudflare.com/workers/) and [Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Zaraz Read | Grants read access to [Zaraz](https://developers.cloudflare.com/zaraz/) zone level settings. |
| Zaraz Edit | Grants write access to [Zaraz](https://developers.cloudflare.com/zaraz/) zone level settings. |
| Zone Read | Grants read access to zone management. |
| Zone Edit | Grants write access to zone management. |
| Zone Security Center Insights | Grants read access to zone level [Security Center Insights](https://developers.cloudflare.com/security/security-insights/). |
| Zone Security Center Insights Edit | Grants write access to zone level [Security Center Zone Insights](https://developers.cloudflare.com/security/security-insights/). |
| Zone Settings Read | Grants read access to zone settings. |
| Zone Settings Edit | Grants write access to zone settings. |
| Zone Versioning Read | Grants read access to [Zone Versioning](https://developers.cloudflare.com/version-management/) at zone level. |
| Zone Versioning Edit | Grants write access to [Zone Versioning](https://developers.cloudflare.com/version-management/) at zone level. |
| Zone WAF Read | Grants read access to [Zone WAF](https://developers.cloudflare.com/waf/). |
| Zone WAF Edit | Grants write access to [Zone WAF](https://developers.cloudflare.com/waf/). |

| Name | Description |
| --- | --- |
| Access: Apps and Policies Read | Grants read access to [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) zone resources. |
| Access: Apps and Policies Revoke | Grants ability to revoke all tokens to [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) zone resources. |
| Access: Apps and Policies Write | Grants write access to [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/) zone resources. |
| Analytics Read | Grants read access to [analytics](https://developers.cloudflare.com/analytics/account-and-zone-analytics/zone-analytics/). |
| Domain API Gateway Read | Grants read access to [API Gateway](https://developers.cloudflare.com/api-shield/) zone resources. |
| Domain API Gateway Write | Grants write access to [API Gateway](https://developers.cloudflare.com/api-shield/) zone resources. |
| Apps Write | Grants full access to Cloudflare Apps (deprecated, refer to [Workers](https://developers.cloudflare.com/workers/) instead). |
| Bot Management Read | Grants read access to [Bot Management](https://developers.cloudflare.com/bots/plans/bm-subscription/). |
| Bot Management Write | Grants write access to [Bot Management](https://developers.cloudflare.com/bots/plans/bm-subscription/). |
| Bot Management Feedback Read | Grants read access to [Bot Management feedback](https://developers.cloudflare.com/bots/concepts/feedback-loop/). |
| Bot Management Feedback Write | Grants write access to [Bot Management feedback](https://developers.cloudflare.com/bots/concepts/feedback-loop/). |
| Cache Purge | Grants access to [purge cache](https://developers.cloudflare.com/cache/how-to/purge-cache/). |
| Cache Settings Read | Grants read access to [Cache Rules](https://developers.cloudflare.com/cache/how-to/cache-rules/). |
| Cache Settings Write | Grants write access to [Cache Rules](https://developers.cloudflare.com/cache/how-to/cache-rules/). |
| Cloud Connector Read | Grants read access to [Cloud Connector rules](https://developers.cloudflare.com/rules/cloud-connector/). |
| Cloud Connector Write | Grants write access to [Cloud Connector rules](https://developers.cloudflare.com/rules/cloud-connector/). |
| Config Settings Read | Grants read access to [Configuration Rules](https://developers.cloudflare.com/rules/configuration-rules/). |
| Config Settings Write | Grants write access to [Configuration Rules](https://developers.cloudflare.com/rules/configuration-rules/). |
| Custom Errors Read | Grants read access to [Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/). |
| Custom Errors Write | Grants write access to [Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/). |
| Custom Pages Read | Grants read access to [Custom Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Custom Pages Write | Grants write access to [Custom Error Pages](https://developers.cloudflare.com/rules/custom-errors/). |
| Email Security DMARC Reports Read | Grants read access to [DMARC Management](https://developers.cloudflare.com/dmarc-management/). |
| Email Security DMARC Reports Write | Grants write access to [DMARC Management](https://developers.cloudflare.com/dmarc-management/). |
| DNS Read | Grants read access to [DNS](https://developers.cloudflare.com/dns/). |
| DNS Write | Grants write access to [DNS](https://developers.cloudflare.com/dns/). |
| Email Routing Rules Read | Grants read access to [Email Routing Rules](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Email Routing Rules Write | Grants write access to [Email Routing Rules](https://developers.cloudflare.com/email-service/configuration/email-routing-addresses/). |
| Firewall Services Read | Grants read access to Firewall resources. |
| Firewall Services Write | Grants write access to Firewall resources. |
| Health Checks Read | Grants read access to [Health Checks](https://developers.cloudflare.com/health-checks/). |
| Health Checks Write | Grants write access to [Health Checks](https://developers.cloudflare.com/health-checks/). |
| HTTP DDoS Managed Ruleset Read | Grants read access to [HTTP DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/http/). |
| HTTP DDoS Managed Ruleset Write | Grants write access to [HTTP DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/managed-rulesets/http/). |
| Load Balancers Read | Grants read access to [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Load Balancers Write | Grants write access to [load balancer resources](https://developers.cloudflare.com/load-balancing/). |
| Logs Read | Grants read access to logs using [Logpull](https://developers.cloudflare.com/logs/). |
| Logs Write | Grants write access to [Logpull and Logpush](https://developers.cloudflare.com/logs/). |
| Managed headers Read | Grants read access to [Managed Headers](https://developers.cloudflare.com/rules/transform/managed-transforms/). |
| Managed headers Write | Grants write access to [Managed Headers](https://developers.cloudflare.com/rules/transform/managed-transforms/). |
| Origin Read | Grants read access to [Origin Rules](https://developers.cloudflare.com/rules/origin-rules/). |
| Origin Write | Grants write access to [Origin Rules](https://developers.cloudflare.com/rules/origin-rules/). |
| Page Rules Read | Grants read access to [Page Rules](https://developers.cloudflare.com/rules/page-rules/). |
| Page Rules Write | Grants write access to [Page Rules](https://developers.cloudflare.com/rules/page-rules/). |
| Domain Page Shield Read | Grants read access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Domain Page Shield Write | Grants write access to [client-side security](https://developers.cloudflare.com/client-side-security/) (previously known as Page Shield). |
| Response Compression Read | Grants read access to [Response Compression](https://developers.cloudflare.com/rules/compression-rules/). |
| Response Compression Write | Grants write access to [Response Compression](https://developers.cloudflare.com/rules/compression-rules/). |
| Sanitize Read | Grants read access to sanitization. |
| Sanitize Write | Grants write access to sanitization. |
| Dynamic URL Redirects Read | Grants read access to zone-level [Single Redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/). |
| Dynamic URL Redirects Write | Grants write access to zone-level [Single Redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/). |
| SSL and Certificates Read | Grants read access to [SSL configuration and certificate management](https://developers.cloudflare.com/ssl/). |
| SSL and Certificates Write | Grants write access to [SSL configuration and certificate management](https://developers.cloudflare.com/ssl/). |
| Zone Transform Rules Read | Grants read access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Zone Transform Rules Write | Grants write access to [Transform Rules](https://developers.cloudflare.com/rules/transform/). |
| Waiting Rooms Read | Grants read access to [Waiting Room](https://developers.cloudflare.com/waiting-room/). |
| Waiting Rooms Write | Grants write access to [Waiting Room](https://developers.cloudflare.com/waiting-room/). |
| Web3 Hostnames Read | Grants read access to [Web3 Hostnames](https://developers.cloudflare.com/web3/). |
| Web3 Hostnames Write | Grants write access to [Web3 Hostnames](https://developers.cloudflare.com/web3/). |
| Workers Routes Read | Grants read access to [Cloudflare Workers](https://developers.cloudflare.com/workers/) and [Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Workers Routes Write | Grants write access to [Cloudflare Workers](https://developers.cloudflare.com/workers/) and [Workers KV Storage](https://developers.cloudflare.com/kv/api/). |
| Zaraz Read | Grants read access to [Zaraz](https://developers.cloudflare.com/zaraz/) zone level settings. |
| Zaraz Write | Grants write access to [Zaraz](https://developers.cloudflare.com/zaraz/) zone level settings. |
| Zone Read | Grants read access to zone management. |
| Zone Write | Grants write access to zone management. |
| Zone Security Center Insights | Grants read access to zone level [Security Center Insights](https://developers.cloudflare.com/security/security-insights/). |
| Zone Security Center Insights Write | Grants write access to zone level [Security Center Zone Insights](https://developers.cloudflare.com/security/security-insights/). |
| Zone Settings Read | Grants read access to zone settings. |
| Zone Settings Write | Grants write access to zone settings. |
| Zone Versioning Read | Grants read access to [Zone Versioning](https://developers.cloudflare.com/version-management/) at zone level. |
| Zone Versioning Write | Grants write access to [Zone Versioning](https://developers.cloudflare.com/version-management/) at zone level. |
| Zone WAF Read | Grants read access to [Zone WAF](https://developers.cloudflare.com/waf/). |
| Zone WAF Write | Grants write access to [Zone WAF](https://developers.cloudflare.com/waf/). |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/reference/permissions/#page","headline":"API token permissions","description":"Review available Cloudflare API token permissions for user, account, and zone resources.","url":"https://developers.cloudflare.com/fundamentals/api/reference/permissions/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-16","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
title: API Reference
---

[Skip to content](#_top)

# API Reference

### Libraries

TypeScript

7.1.0

```
npm install cloudflare
```

[Read Docs](https://developers.cloudflare.com/api/typescript)

Python

5.7.0

```
pip install cloudflare
```

[Read Docs](https://developers.cloudflare.com/api/python)

Go

v7.10.0

```
go get -u github.com/cloudflare/cloudflare-go/v7@v7.10.0
```

[Read Docs](https://developers.cloudflare.com/api/go)

Terraform

5.25.0

```
terraform {
  required_providers {
    cloudflare = {
      source  = "cloudflare/cloudflare"
      version = "~> 5.0"
    }
  }
}
```

[Read Docs](https://developers.cloudflare.com/api/terraform)

### API Overview

#### Accounts

##### [List Accounts](https://developers.cloudflare.com/api/resources/accounts/methods/list)

GET/accounts

##### [Account Details](https://developers.cloudflare.com/api/resources/accounts/methods/get)

GET/accounts/{account\_id}

##### [Create an Account](https://developers.cloudflare.com/api/resources/accounts/methods/create)

POST/accounts

##### [Update Account](https://developers.cloudflare.com/api/resources/accounts/methods/update)

PUT/accounts/{account\_id}

##### [Delete a specific account](https://developers.cloudflare.com/api/resources/accounts/methods/delete)

DELETE/accounts/{account\_id}

#### AccountsAccount Organizations

##### [Move account](https://developers.cloudflare.com/api/resources/accounts/subresources/account_organizations/methods/create)

POST/accounts/{account\_id}/move

#### AccountsAccount Profile

##### [Get account profile](https://developers.cloudflare.com/api/resources/accounts/subresources/account_profile/methods/get)

GET/accounts/{account\_id}/profile

##### [Modify account profile](https://developers.cloudflare.com/api/resources/accounts/subresources/account_profile/methods/update)

PUT/accounts/{account\_id}/profile

#### AccountsMembers

##### [List Members](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/list)

GET/accounts/{account\_id}/members

##### [Member Details](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/get)

GET/accounts/{account\_id}/members/{member\_id}

##### [Add Member](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/create)

POST/accounts/{account\_id}/members

##### [Update Member](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/update)

PUT/accounts/{account\_id}/members/{member\_id}

##### [Remove Member](https://developers.cloudflare.com/api/resources/accounts/subresources/members/methods/delete)

DELETE/accounts/{account\_id}/members/{member\_id}

#### AccountsRoles

##### [List Roles](https://developers.cloudflare.com/api/resources/accounts/subresources/roles/methods/list)

Deprecated

GET/accounts/{account\_id}/roles

##### [Role Details](https://developers.cloudflare.com/api/resources/accounts/subresources/roles/methods/get)

Deprecated

GET/accounts/{account\_id}/roles/{role\_id}

#### AccountsSubscriptions

##### [List Subscriptions](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/subscriptions

##### [Get Subscription](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/methods/get_by_identifier)

GET/accounts/{account\_id}/subscriptions/{subscription\_identifier}

##### [Create Subscription](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/subscriptions

##### [Update Subscription](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/methods/update)

PUT/accounts/{account\_id}/subscriptions/{subscription\_identifier}

##### [Delete Subscription](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/methods/delete)

DELETE/accounts/{account\_id}/subscriptions/{subscription\_identifier}

##### [Cancel Delayed Downgrade](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/methods/cancel_downgrade)

POST/accounts/{account\_id}/subscriptions/cancel-downgrade

#### AccountsSubscriptionsCancel Reason

##### [Create Cancel Reason](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/subresources/cancel_reason/methods/create)

POST/accounts/{account\_id}/subscriptions/{subscription\_identifier}/cancel-reason

##### [Get Cancel Reason](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/subresources/cancel_reason/methods/get)

GET/accounts/{account\_id}/subscriptions/{subscription\_identifier}/cancel-reason

#### AccountsSubscriptionsActions

##### [Append Subscription Action](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/subresources/actions/methods/append)

POST/accounts/{account\_id}/subscriptions/{subscription\_identifier}/action/append

#### AccountsSubscriptionsBulk

##### [Create Subscriptions](https://developers.cloudflare.com/api/resources/accounts/subresources/subscriptions/subresources/bulk/methods/create)

POST/accounts/{account\_id}/bulk/subscriptions

#### AccountsTokens

##### [List Tokens](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/list)

GET/accounts/{account\_id}/tokens

##### [Token Details](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/get)

GET/accounts/{account\_id}/tokens/{token\_id}

##### [Create Token](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/create)

POST/accounts/{account\_id}/tokens

##### [Update Token](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/update)

PUT/accounts/{account\_id}/tokens/{token\_id}

##### [Delete Token](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/delete)

DELETE/accounts/{account\_id}/tokens/{token\_id}

##### [Verify Token](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/methods/verify)

GET/accounts/{account\_id}/tokens/verify

#### AccountsTokensPermission Groups

##### [List Permission Groups](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/subresources/permission_groups/methods/list)

GET/accounts/{account\_id}/tokens/permission\_groups

##### [List Permission Groups](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/subresources/permission_groups/methods/get)

GET/accounts/{account\_id}/tokens/permission\_groups

#### AccountsTokensValue

##### [Roll Token](https://developers.cloudflare.com/api/resources/accounts/subresources/tokens/subresources/value/methods/update)

PUT/accounts/{account\_id}/tokens/{token\_id}/value

#### AccountsLogs

#### AccountsLogsAudit

##### [Get account audit logs (Version 2)](https://developers.cloudflare.com/api/resources/accounts/subresources/logs/subresources/audit/methods/list)

GET/accounts/{account\_id}/logs/audit

##### [Get resource change history from an account audit log entry (Version 2)](https://developers.cloudflare.com/api/resources/accounts/subresources/logs/subresources/audit/methods/history)

GET/accounts/{account\_id}/logs/audit/{id}/history

##### [List account audit log product categories (Version 2)](https://developers.cloudflare.com/api/resources/accounts/subresources/logs/subresources/audit/methods/product_categories)

GET/accounts/{account\_id}/logs/audit/product\_categories

#### AccountsEntitlements

##### [Get Account Entitlements](https://developers.cloudflare.com/api/resources/accounts/subresources/entitlements/methods/list)

GET/accounts/{account\_id}/entitlements

#### AccountsSpeed Settings

#### AccountsSpeed SettingsTransformations

##### [List Image Resizing configurations for account](https://developers.cloudflare.com/api/resources/accounts/subresources/speed_settings/subresources/transformations/methods/get)

GET/accounts/{account\_id}/settings/transformations

#### AccountsPayment Methods

##### [List Payment Methods](https://developers.cloudflare.com/api/resources/accounts/subresources/payment_methods/methods/list)

GET/accounts/{account\_id}/payment-methods

##### [Create Payment Method](https://developers.cloudflare.com/api/resources/accounts/subresources/payment_methods/methods/create)

POST/accounts/{account\_id}/payment-methods

##### [Get Payment Method](https://developers.cloudflare.com/api/resources/accounts/subresources/payment_methods/methods/get)

GET/accounts/{account\_id}/payment-methods/{payment\_method\_id}

##### [Update Payment Method](https://developers.cloudflare.com/api/resources/accounts/subresources/payment_methods/methods/update)

PUT/accounts/{account\_id}/payment-methods/{payment\_method\_id}

##### [Delete Payment Method](https://developers.cloudflare.com/api/resources/accounts/subresources/payment_methods/methods/delete)

DELETE/accounts/{account\_id}/payment-methods/{payment\_method\_id}

##### [Set Default Payment Method](https://developers.cloudflare.com/api/resources/accounts/subresources/payment_methods/methods/set_as_default)

POST/accounts/{account\_id}/payment-methods/{payment\_method\_id}/set-as-default

#### AccountsPay Invoice

##### [Pay Invoice](https://developers.cloudflare.com/api/resources/accounts/subresources/pay_invoice/methods/create)

POST/accounts/{account\_id}/pay-invoice

#### AccountsPay Bad Debt

##### [Pay Bad Debt](https://developers.cloudflare.com/api/resources/accounts/subresources/pay_bad_debt/methods/create)

POST/accounts/{account\_id}/pay-bad-debt

#### AccountsReceipts

##### [Get Receipt PDF](https://developers.cloudflare.com/api/resources/accounts/subresources/receipts/methods/pdf)

GET/accounts/{account\_id}/receipts/{receipt\_id}/pdf

#### AccountsInvoices

##### [Toggle PDF Invoices](https://developers.cloudflare.com/api/resources/accounts/subresources/invoices/methods/edit)

PATCH/accounts/{account\_id}/invoices

#### AccountsClient Secret

##### [Create Setup Intent](https://developers.cloudflare.com/api/resources/accounts/subresources/client_secret/methods/create)

POST/accounts/{account\_id}/client-secret

#### Organizations

##### [List organizations the user has access to](https://developers.cloudflare.com/api/resources/organizations/methods/list)

GET/organizations

##### [Get organization](https://developers.cloudflare.com/api/resources/organizations/methods/get)

GET/organizations/{organization\_id}

##### [Create organization](https://developers.cloudflare.com/api/resources/organizations/methods/create)

POST/organizations

##### [Modify organization.](https://developers.cloudflare.com/api/resources/organizations/methods/update)

PUT/organizations/{organization\_id}

##### [Delete organization.](https://developers.cloudflare.com/api/resources/organizations/methods/delete)

DELETE/organizations/{organization\_id}

#### OrganizationsOrganization Accounts

##### [Get organization accounts](https://developers.cloudflare.com/api/resources/organizations/subresources/organization_accounts/methods/get)

GET/organizations/{organization\_id}/accounts

#### OrganizationsOrganization Profile

##### [Get organization profile](https://developers.cloudflare.com/api/resources/organizations/subresources/organization_profile/methods/get)

GET/organizations/{organization\_id}/profile

##### [Modify organization profile.](https://developers.cloudflare.com/api/resources/organizations/subresources/organization_profile/methods/update)

PUT/organizations/{organization\_id}/profile

#### OrganizationsMembers

##### [List organization members](https://developers.cloudflare.com/api/resources/organizations/subresources/members/methods/list)

GET/organizations/{organization\_id}/members

##### [Get organization member](https://developers.cloudflare.com/api/resources/organizations/subresources/members/methods/get)

GET/organizations/{organization\_id}/members/{member\_id}

##### [Create organization member](https://developers.cloudflare.com/api/resources/organizations/subresources/members/methods/create)

POST/organizations/{organization\_id}/members

##### [Delete organization member](https://developers.cloudflare.com/api/resources/organizations/subresources/members/methods/delete)

DELETE/organizations/{organization\_id}/members/{member\_id}

#### OrganizationsLogs

#### OrganizationsLogsAudit

##### [Get organization audit logs (Version 2)](https://developers.cloudflare.com/api/resources/organizations/subresources/logs/subresources/audit/methods/list)

GET/organizations/{organization\_id}/logs/audit

##### [Get resource change history from an organization audit log entry (Version 2)](https://developers.cloudflare.com/api/resources/organizations/subresources/logs/subresources/audit/methods/history)

GET/organizations/{organization\_id}/logs/audit/{id}/history

#### OrganizationsBilling

#### OrganizationsBillingUsage

##### [Get Organization Usage (Version 2, Alpha, Restricted)](https://developers.cloudflare.com/api/resources/organizations/subresources/billing/subresources/usage/methods/get)

GET/organizations/{organization\_id}/billable/usage

#### Tenants

##### [Get tenant](https://developers.cloudflare.com/api/resources/tenants/methods/get)

GET/tenants/{tenant\_id}

#### TenantsAccount Types

##### [Get tenant account types](https://developers.cloudflare.com/api/resources/tenants/subresources/account_types/methods/list)

GET/tenants/{tenant\_id}/account\_types

#### TenantsAccounts

##### [List tenant accounts](https://developers.cloudflare.com/api/resources/tenants/subresources/accounts/methods/list)

GET/tenants/{tenant\_id}/accounts

#### TenantsEntitlements

##### [List tenant entitlements](https://developers.cloudflare.com/api/resources/tenants/subresources/entitlements/methods/get)

GET/tenants/{tenant\_id}/entitlements

#### TenantsMemberships

##### [List tenant memberships](https://developers.cloudflare.com/api/resources/tenants/subresources/memberships/methods/list)

GET/tenants/{tenant\_id}/memberships

#### Origin CA Certificates

##### [List Certificates](https://developers.cloudflare.com/api/resources/origin_ca_certificates/methods/list)

GET/certificates

##### [Get Certificate](https://developers.cloudflare.com/api/resources/origin_ca_certificates/methods/get)

GET/certificates/{certificate\_id}

##### [Create Certificate](https://developers.cloudflare.com/api/resources/origin_ca_certificates/methods/create)

POST/certificates

##### [Revoke Certificate](https://developers.cloudflare.com/api/resources/origin_ca_certificates/methods/delete)

DELETE/certificates/{certificate\_id}

#### IPs

##### [Cloudflare/JD Cloud IP Details](https://developers.cloudflare.com/api/resources/ips/methods/list)

GET/ips

#### Memberships

##### [List Memberships](https://developers.cloudflare.com/api/resources/memberships/methods/list)

GET/memberships

##### [Membership Details](https://developers.cloudflare.com/api/resources/memberships/methods/get)

GET/memberships/{membership\_id}

##### [Update Membership](https://developers.cloudflare.com/api/resources/memberships/methods/update)

PUT/memberships/{membership\_id}

##### [Delete Membership](https://developers.cloudflare.com/api/resources/memberships/methods/delete)

DELETE/memberships/{membership\_id}

#### User

##### [User Details](https://developers.cloudflare.com/api/resources/user/methods/get)

GET/user

##### [Edit User](https://developers.cloudflare.com/api/resources/user/methods/edit)

PATCH/user

#### UserAudit Logs

##### [Get user audit logs](https://developers.cloudflare.com/api/resources/user/subresources/audit_logs/methods/list)

GET/user/audit\_logs

#### UserBilling

#### UserBillingHistory

##### [Billing History Details](https://developers.cloudflare.com/api/resources/user/subresources/billing/subresources/history/methods/list)

Deprecated

GET/user/billing/history

#### UserBillingProfile

##### [Billing Profile Details](https://developers.cloudflare.com/api/resources/user/subresources/billing/subresources/profile/methods/get)

Deprecated

GET/user/billing/profile

#### UserInvites

##### [List Invitations](https://developers.cloudflare.com/api/resources/user/subresources/invites/methods/list)

GET/user/invites

##### [Invitation Details](https://developers.cloudflare.com/api/resources/user/subresources/invites/methods/get)

GET/user/invites/{invite\_id}

##### [Respond to Invitation](https://developers.cloudflare.com/api/resources/user/subresources/invites/methods/edit)

PATCH/user/invites/{invite\_id}

#### UserOrganizations

##### [List Organizations](https://developers.cloudflare.com/api/resources/user/subresources/organizations/methods/list)

Deprecated

GET/user/organizations

##### [Organization Details](https://developers.cloudflare.com/api/resources/user/subresources/organizations/methods/get)

Deprecated

GET/user/organizations/{organization\_id}

##### [Leave Organization](https://developers.cloudflare.com/api/resources/user/subresources/organizations/methods/delete)

Deprecated

DELETE/user/organizations/{organization\_id}

#### UserSpectrum Analytics

#### UserSpectrum AnalyticsZones

#### UserSpectrum AnalyticsZonesReports

##### [Get zones bandwidth report](https://developers.cloudflare.com/api/resources/user/subresources/spectrum_analytics/subresources/zones/subresources/reports/methods/get)

GET/user/spectrum\_analytics/zones/report

#### UserSubscriptions

##### [Get User Subscriptions](https://developers.cloudflare.com/api/resources/user/subresources/subscriptions/methods/get)

GET/user/subscriptions

##### [Update User Subscription](https://developers.cloudflare.com/api/resources/user/subresources/subscriptions/methods/update)

PUT/user/subscriptions/{identifier}

##### [Delete User Subscription](https://developers.cloudflare.com/api/resources/user/subresources/subscriptions/methods/delete)

DELETE/user/subscriptions/{identifier}

#### UserTenants

##### [List user tenants](https://developers.cloudflare.com/api/resources/user/subresources/tenants/methods/list)

GET/user/tenants

#### UserTokens

##### [List Tokens](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/list)

GET/user/tokens

##### [Token Details](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/get)

GET/user/tokens/{token\_id}

##### [Create Token](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/create)

POST/user/tokens

##### [Update Token](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/update)

PUT/user/tokens/{token\_id}

##### [Delete Token](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/delete)

DELETE/user/tokens/{token\_id}

##### [Verify Token](https://developers.cloudflare.com/api/resources/user/subresources/tokens/methods/verify)

GET/user/tokens/verify

#### UserTokensPermission Groups

##### [List Token Permission Groups](https://developers.cloudflare.com/api/resources/user/subresources/tokens/subresources/permission_groups/methods/list)

GET/user/tokens/permission\_groups

#### UserTokensValue

##### [Roll Token](https://developers.cloudflare.com/api/resources/user/subresources/tokens/subresources/value/methods/update)

PUT/user/tokens/{token\_id}/value

#### Zones

##### [List Zones](https://developers.cloudflare.com/api/resources/zones/methods/list)

GET/zones

##### [Zone Details](https://developers.cloudflare.com/api/resources/zones/methods/get)

GET/zones/{zone\_id}

##### [Create Zone](https://developers.cloudflare.com/api/resources/zones/methods/create)

POST/zones

##### [Edit Zone](https://developers.cloudflare.com/api/resources/zones/methods/edit)

PATCH/zones/{zone\_id}

##### [Delete Zone](https://developers.cloudflare.com/api/resources/zones/methods/delete)

DELETE/zones/{zone\_id}

#### ZonesActivation Check

##### [Rerun the Activation Check](https://developers.cloudflare.com/api/resources/zones/subresources/activation_check/methods/trigger)

PUT/zones/{zone\_id}/activation\_check

#### ZonesObservability

#### ZonesObservabilityTracing

#### ZonesObservabilityTracingSettings

##### [View zone tracing settings](https://developers.cloudflare.com/api/resources/zones/subresources/observability/subresources/tracing/subresources/settings/methods/get)

GET/zones/{zone\_id}/observability/tracing/settings

##### [Update zone tracing settings](https://developers.cloudflare.com/api/resources/zones/subresources/observability/subresources/tracing/subresources/settings/methods/update)

PATCH/zones/{zone\_id}/observability/tracing/settings

##### [Reset zone tracing settings](https://developers.cloudflare.com/api/resources/zones/subresources/observability/subresources/tracing/subresources/settings/methods/delete)

DELETE/zones/{zone\_id}/observability/tracing/settings

#### ZonesObservabilityTracingRules

##### [View zone trace rules](https://developers.cloudflare.com/api/resources/zones/subresources/observability/subresources/tracing/subresources/rules/methods/get)

GET/zones/{zone\_id}/observability/tracing/rules

##### [Replace zone trace rules](https://developers.cloudflare.com/api/resources/zones/subresources/observability/subresources/tracing/subresources/rules/methods/update)

PUT/zones/{zone\_id}/observability/tracing/rules

##### [Delete zone trace rules](https://developers.cloudflare.com/api/resources/zones/subresources/observability/subresources/tracing/subresources/rules/methods/delete)

DELETE/zones/{zone\_id}/observability/tracing/rules

#### ZonesSettings

##### [Get all zone settings](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/list)

Deprecated

GET/zones/{zone\_id}/settings

##### [Get zone setting](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/get)

GET/zones/{zone\_id}/settings/{setting\_id}

##### [Edit zone setting](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/edit)

PATCH/zones/{zone\_id}/settings/{setting\_id}

##### [Edit multiple zone settings](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/bulk_edit)

Deprecated

PATCH/zones/{zone\_id}/settings

#### ZonesTransformations Allowed Origins

##### [Get Image Transformations Allowed Origins setting](https://developers.cloudflare.com/api/resources/zones/subresources/transformations_allowed_origins/methods/get)

GET/zones/{zone\_id}/settings/transformations\_allowed\_origins

##### [Change Image Transformations Allowed Origins setting](https://developers.cloudflare.com/api/resources/zones/subresources/transformations_allowed_origins/methods/edit)

PATCH/zones/{zone\_id}/settings/transformations\_allowed\_origins

#### ZonesTransformations C2pa

##### [Get Image Transformations C2PA setting](https://developers.cloudflare.com/api/resources/zones/subresources/transformations_c2pa/methods/get)

GET/zones/{zone\_id}/settings/transformations\_c2pa

##### [Change Image Transformations C2PA setting](https://developers.cloudflare.com/api/resources/zones/subresources/transformations_c2pa/methods/edit)

PATCH/zones/{zone\_id}/settings/transformations\_c2pa

#### ZonesNEL

##### [Get NEL setting](https://developers.cloudflare.com/api/resources/zones/subresources/nel/methods/get)

GET/zones/{zone\_id}/settings/nel

##### [Edit NEL setting](https://developers.cloudflare.com/api/resources/zones/subresources/nel/methods/edit)

PATCH/zones/{zone\_id}/settings/nel

#### ZonesEnvironments

##### [List zone environments](https://developers.cloudflare.com/api/resources/zones/subresources/environments/methods/list)

GET/zones/{zone\_id}/environments

##### [Create zone environments](https://developers.cloudflare.com/api/resources/zones/subresources/environments/methods/create)

POST/zones/{zone\_id}/environments

##### [Upsert zone environments](https://developers.cloudflare.com/api/resources/zones/subresources/environments/methods/update)

PUT/zones/{zone\_id}/environments

##### [Partially update zone environments](https://developers.cloudflare.com/api/resources/zones/subresources/environments/methods/edit)

PATCH/zones/{zone\_id}/environments

##### [Delete zone environment](https://developers.cloudflare.com/api/resources/zones/subresources/environments/methods/delete)

DELETE/zones/{zone\_id}/environments/{environment\_id}

##### [Roll back zone environment](https://developers.cloudflare.com/api/resources/zones/subresources/environments/methods/rollback)

POST/zones/{zone\_id}/environments/{environment\_id}/rollback

#### ZonesCustom Nameservers

##### [Get Account Custom Nameserver Related Zone Metadata](https://developers.cloudflare.com/api/resources/zones/subresources/custom_nameservers/methods/get)

Deprecated

GET/zones/{zone\_id}/custom\_ns

##### [Set Account Custom Nameserver Related Zone Metadata](https://developers.cloudflare.com/api/resources/zones/subresources/custom_nameservers/methods/update)

Deprecated

PUT/zones/{zone\_id}/custom\_ns

#### ZonesHolds

##### [Get Zone Hold](https://developers.cloudflare.com/api/resources/zones/subresources/holds/methods/get)

GET/zones/{zone\_id}/hold

##### [Create Zone Hold](https://developers.cloudflare.com/api/resources/zones/subresources/holds/methods/create)

POST/zones/{zone\_id}/hold

##### [Update Zone Hold](https://developers.cloudflare.com/api/resources/zones/subresources/holds/methods/edit)

PATCH/zones/{zone\_id}/hold

##### [Remove Zone Hold](https://developers.cloudflare.com/api/resources/zones/subresources/holds/methods/delete)

DELETE/zones/{zone\_id}/hold

#### ZonesSubscriptions

##### [Zone Subscription Details](https://developers.cloudflare.com/api/resources/zones/subresources/subscriptions/methods/get)

GET/zones/{zone\_id}/subscription

##### [Create Zone Subscription](https://developers.cloudflare.com/api/resources/zones/subresources/subscriptions/methods/create)

POST/zones/{zone\_id}/subscription

##### [Update Zone Subscription](https://developers.cloudflare.com/api/resources/zones/subresources/subscriptions/methods/update)

PUT/zones/{zone\_id}/subscription

#### ZonesPlans

##### [List Available Plans](https://developers.cloudflare.com/api/resources/zones/subresources/plans/methods/list)

GET/zones/{zone\_id}/available\_plans

##### [Available Plan Details](https://developers.cloudflare.com/api/resources/zones/subresources/plans/methods/get)

GET/zones/{zone\_id}/available\_plans/{plan\_identifier}

#### ZonesRate Plans

##### [List Available Rate Plans](https://developers.cloudflare.com/api/resources/zones/subresources/rate_plans/methods/get)

GET/zones/{zone\_id}/available\_rate\_plans

#### ZonesEntitlements

##### [Get Zone Entitlements](https://developers.cloudflare.com/api/resources/zones/subresources/entitlements/methods/list)

GET/zones/{zone\_id}/entitlements

#### ZonesCT

#### ZonesCTAlerting

##### [Get CT Alerting Subscription](https://developers.cloudflare.com/api/resources/zones/subresources/ct/subresources/alerting/methods/get)

GET/zones/{zone\_id}/ct/alerting

##### [Update CT Alerting Subscription](https://developers.cloudflare.com/api/resources/zones/subresources/ct/subresources/alerting/methods/edit)

PATCH/zones/{zone\_id}/ct/alerting

#### Load Balancers

##### [List account or zone Load Balancers](https://developers.cloudflare.com/api/resources/load_balancers/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/load\_balancers

##### [account or zone Load Balancer Details](https://developers.cloudflare.com/api/resources/load_balancers/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/load\_balancers/{load\_balancer\_id}

##### [Create account or zone Load Balancer](https://developers.cloudflare.com/api/resources/load_balancers/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/load\_balancers

##### [Update account or zone Load Balancer](https://developers.cloudflare.com/api/resources/load_balancers/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/load\_balancers/{load\_balancer\_id}

##### [Patch account or zone Load Balancer](https://developers.cloudflare.com/api/resources/load_balancers/methods/edit)

PATCH/{accounts\_or\_zones}/{account\_or\_zone\_id}/load\_balancers/{load\_balancer\_id}

##### [Delete account or zone Load Balancer](https://developers.cloudflare.com/api/resources/load_balancers/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/load\_balancers/{load\_balancer\_id}

#### Load BalancersMonitors

##### [List Monitors](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/methods/list)

GET/accounts/{account\_id}/load\_balancers/monitors

##### [Monitor Details](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/methods/get)

GET/accounts/{account\_id}/load\_balancers/monitors/{monitor\_id}

##### [Create Monitor](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/methods/create)

POST/accounts/{account\_id}/load\_balancers/monitors

##### [Update Monitor](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/methods/update)

PUT/accounts/{account\_id}/load\_balancers/monitors/{monitor\_id}

##### [Patch Monitor](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/methods/edit)

PATCH/accounts/{account\_id}/load\_balancers/monitors/{monitor\_id}

##### [Delete Monitor](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/methods/delete)

DELETE/accounts/{account\_id}/load\_balancers/monitors/{monitor\_id}

#### Load BalancersMonitorsPreviews

##### [Preview Monitor](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/subresources/previews/methods/create)

POST/accounts/{account\_id}/load\_balancers/monitors/{monitor\_id}/preview

#### Load BalancersMonitorsReferences

##### [List Monitor References](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitors/subresources/references/methods/get)

GET/accounts/{account\_id}/load\_balancers/monitors/{monitor\_id}/references

#### Load BalancersMonitor Groups

##### [List Monitor Groups](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/methods/list)

GET/accounts/{account\_id}/load\_balancers/monitor\_groups

##### [Monitor Group Details](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/methods/get)

GET/accounts/{account\_id}/load\_balancers/monitor\_groups/{monitor\_group\_id}

##### [Create Monitor Group](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/methods/create)

POST/accounts/{account\_id}/load\_balancers/monitor\_groups

##### [Update Monitor Group](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/methods/update)

PUT/accounts/{account\_id}/load\_balancers/monitor\_groups/{monitor\_group\_id}

##### [Patch Monitor Group](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/methods/edit)

PATCH/accounts/{account\_id}/load\_balancers/monitor\_groups/{monitor\_group\_id}

##### [Delete Monitor Group](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/methods/delete)

DELETE/accounts/{account\_id}/load\_balancers/monitor\_groups/{monitor\_group\_id}

#### Load BalancersMonitor GroupsReferences

##### [List Monitor Group References](https://developers.cloudflare.com/api/resources/load_balancers/subresources/monitor_groups/subresources/references/methods/get)

GET/accounts/{account\_id}/load\_balancers/monitor\_groups/{monitor\_group\_id}/references

#### Load BalancersPools

##### [List Pools](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/list)

GET/accounts/{account\_id}/load\_balancers/pools

##### [Pool Details](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/get)

GET/accounts/{account\_id}/load\_balancers/pools/{pool\_id}

##### [Create Pool](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/create)

POST/accounts/{account\_id}/load\_balancers/pools

##### [Update Pool](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/update)

PUT/accounts/{account\_id}/load\_balancers/pools/{pool\_id}

##### [Patch Pool](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/edit)

PATCH/accounts/{account\_id}/load\_balancers/pools/{pool\_id}

##### [Delete Pool](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/delete)

DELETE/accounts/{account\_id}/load\_balancers/pools/{pool\_id}

##### [Patch Pools](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/methods/bulk_edit)

PATCH/accounts/{account\_id}/load\_balancers/pools

#### Load BalancersPoolsHealth

##### [Pool Health Details](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/subresources/health/methods/get)

GET/accounts/{account\_id}/load\_balancers/pools/{pool\_id}/health

##### [Preview Pool](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/subresources/health/methods/create)

POST/accounts/{account\_id}/load\_balancers/pools/{pool\_id}/preview

#### Load BalancersPoolsReferences

##### [List Pool References](https://developers.cloudflare.com/api/resources/load_balancers/subresources/pools/subresources/references/methods/get)

GET/accounts/{account\_id}/load\_balancers/pools/{pool\_id}/references

#### Load BalancersPreviews

##### [Preview Result](https://developers.cloudflare.com/api/resources/load_balancers/subresources/previews/methods/get)

GET/accounts/{account\_id}/load\_balancers/preview/{preview\_id}

#### Load BalancersRegions

##### [List Regions](https://developers.cloudflare.com/api/resources/load_balancers/subresources/regions/methods/list)

GET/accounts/{account\_id}/load\_balancers/regions

##### [Get Region](https://developers.cloudflare.com/api/resources/load_balancers/subresources/regions/methods/get)

GET/accounts/{account\_id}/load\_balancers/regions/{region\_id}

#### Load BalancersSearches

##### [Search Resources](https://developers.cloudflare.com/api/resources/load_balancers/subresources/searches/methods/list)

GET/accounts/{account\_id}/load\_balancers/search

#### Cache

##### [Purge Cached Content](https://developers.cloudflare.com/api/resources/cache/methods/purge)

POST/zones/{zone\_id}/purge\_cache

##### [Purge Cached Content by Environment](https://developers.cloudflare.com/api/resources/cache/methods/purge_environment)

POST/zones/{zone\_id}/environments/{environment\_id}/purge\_cache

#### CacheCache Reserve

##### [Get Cache Reserve setting](https://developers.cloudflare.com/api/resources/cache/subresources/cache_reserve/methods/get)

GET/zones/{zone\_id}/cache/cache\_reserve

##### [Change Cache Reserve setting](https://developers.cloudflare.com/api/resources/cache/subresources/cache_reserve/methods/edit)

PATCH/zones/{zone\_id}/cache/cache\_reserve

##### [Get Cache Reserve Clear](https://developers.cloudflare.com/api/resources/cache/subresources/cache_reserve/methods/status)

GET/zones/{zone\_id}/cache/cache\_reserve\_clear

##### [Start Cache Reserve Clear](https://developers.cloudflare.com/api/resources/cache/subresources/cache_reserve/methods/clear)

POST/zones/{zone\_id}/cache/cache\_reserve\_clear

#### CacheSmart Tiered Cache

##### [Get Smart Tiered Cache setting](https://developers.cloudflare.com/api/resources/cache/subresources/smart_tiered_cache/methods/get)

GET/zones/{zone\_id}/cache/tiered\_cache\_smart\_topology\_enable

##### [Create Smart Tiered Cache setting](https://developers.cloudflare.com/api/resources/cache/subresources/smart_tiered_cache/methods/create)

POST/zones/{zone\_id}/cache/tiered\_cache\_smart\_topology\_enable

##### [Patch Smart Tiered Cache setting](https://developers.cloudflare.com/api/resources/cache/subresources/smart_tiered_cache/methods/edit)

PATCH/zones/{zone\_id}/cache/tiered\_cache\_smart\_topology\_enable

##### [Delete Smart Tiered Cache setting](https://developers.cloudflare.com/api/resources/cache/subresources/smart_tiered_cache/methods/delete)

DELETE/zones/{zone\_id}/cache/tiered\_cache\_smart\_topology\_enable

#### CacheVariants

##### [Get variants setting](https://developers.cloudflare.com/api/resources/cache/subresources/variants/methods/get)

GET/zones/{zone\_id}/cache/variants

##### [Change variants setting](https://developers.cloudflare.com/api/resources/cache/subresources/variants/methods/edit)

PATCH/zones/{zone\_id}/cache/variants

##### [Delete variants setting](https://developers.cloudflare.com/api/resources/cache/subresources/variants/methods/delete)

DELETE/zones/{zone\_id}/cache/variants

#### CacheRegional Tiered Cache

##### [Get Regional Tiered Cache setting](https://developers.cloudflare.com/api/resources/cache/subresources/regional_tiered_cache/methods/get)

GET/zones/{zone\_id}/cache/regional\_tiered\_cache

##### [Change Regional Tiered Cache setting](https://developers.cloudflare.com/api/resources/cache/subresources/regional_tiered_cache/methods/edit)

PATCH/zones/{zone\_id}/cache/regional\_tiered\_cache

#### CacheOrigin Cloud Regions

##### [List origin cloud region mappings](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/list)

GET/zones/{zone\_id}/origin/cloud\_regions

##### [Get an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/get)

GET/zones/{zone\_id}/origin/cloud\_regions/{origin\_ip}

##### [Create or replace an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/update)

PUT/zones/{zone\_id}/origin/cloud\_regions/{origin\_ip}

##### [Delete an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/delete)

DELETE/zones/{zone\_id}/origin/cloud\_regions/{origin\_ip}

##### [Batch create or replace origin cloud region mappings](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/bulk_update)

PUT/zones/{zone\_id}/origin/cloud\_regions/batch

##### [Batch delete origin cloud region mappings](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/bulk_delete)

DELETE/zones/{zone\_id}/origin/cloud\_regions/batch

##### [List supported cloud vendors and regions](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/supported_regions)

GET/zones/{zone\_id}/origin/cloud\_regions/supported\_regions

##### [List origin cloud region mappings](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/list_v1)

Deprecated

GET/zones/{zone\_id}/cache/origin\_cloud\_regions

##### [Create an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/create_v1)

Deprecated

POST/zones/{zone\_id}/cache/origin\_cloud\_regions

##### [Create or update an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/edit_v1)

Deprecated

PATCH/zones/{zone\_id}/cache/origin\_cloud\_regions

##### [Get an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/get_v1)

Deprecated

GET/zones/{zone\_id}/cache/origin\_cloud\_regions/{origin\_ip}

##### [Delete an origin cloud region mapping](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/delete_v1)

Deprecated

DELETE/zones/{zone\_id}/cache/origin\_cloud\_regions/{origin\_ip}

##### [Batch create or update origin cloud region mappings](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/bulk_edit_v1)

Deprecated

PATCH/zones/{zone\_id}/cache/origin\_cloud\_regions/batch

##### [Batch delete origin cloud region mappings](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/bulk_delete_v1)

Deprecated

DELETE/zones/{zone\_id}/cache/origin\_cloud\_regions/batch

##### [List supported cloud vendors and regions](https://developers.cloudflare.com/api/resources/cache/subresources/origin_cloud_regions/methods/supported_regions_v1)

Deprecated

GET/zones/{zone\_id}/cache/origin\_cloud\_regions/supported\_regions

#### SSL

#### SSLAnalyze

##### [Analyze Certificate](https://developers.cloudflare.com/api/resources/ssl/subresources/analyze/methods/create)

POST/zones/{zone\_id}/ssl/analyze

#### SSLCertificate Packs

##### [List Certificate Packs](https://developers.cloudflare.com/api/resources/ssl/subresources/certificate_packs/methods/list)

GET/zones/{zone\_id}/ssl/certificate\_packs

##### [Get Certificate Pack](https://developers.cloudflare.com/api/resources/ssl/subresources/certificate_packs/methods/get)

GET/zones/{zone\_id}/ssl/certificate\_packs/{certificate\_pack\_id}

##### [Order Advanced Certificate Manager Certificate Pack](https://developers.cloudflare.com/api/resources/ssl/subresources/certificate_packs/methods/create)

POST/zones/{zone\_id}/ssl/certificate\_packs/order

##### [Restart Validation or Update Advanced Certificate Manager Certificate Pack](https://developers.cloudflare.com/api/resources/ssl/subresources/certificate_packs/methods/edit)

PATCH/zones/{zone\_id}/ssl/certificate\_packs/{certificate\_pack\_id}

##### [Delete Advanced Certificate Manager Certificate Pack](https://developers.cloudflare.com/api/resources/ssl/subresources/certificate_packs/methods/delete)

DELETE/zones/{zone\_id}/ssl/certificate\_packs/{certificate\_pack\_id}

#### SSLCertificate PacksQuota

##### [Get Certificate Pack Quotas](https://developers.cloudflare.com/api/resources/ssl/subresources/certificate_packs/subresources/quota/methods/get)

GET/zones/{zone\_id}/ssl/certificate\_packs/quota

#### SSLRecommendations

##### [SSL/TLS Recommendation](https://developers.cloudflare.com/api/resources/ssl/subresources/recommendations/methods/get)

Deprecated

GET/zones/{zone\_id}/ssl/recommendation

#### SSLAutomatic Upgrader

##### [Get Automatic SSL/TLS enrollment status for the given zone](https://developers.cloudflare.com/api/resources/ssl/subresources/automatic_upgrader/methods/get)

GET/zones/{zone\_id}/settings/ssl\_automatic\_mode

##### [Patch Automatic SSL/TLS Enrollment status for given zone](https://developers.cloudflare.com/api/resources/ssl/subresources/automatic_upgrader/methods/patch)

PATCH/zones/{zone\_id}/settings/ssl\_automatic\_mode

#### SSLAuto Origin TLS Kex

##### [Get Auto-Origin TLS KEX enrollment status for the given zone](https://developers.cloudflare.com/api/resources/ssl/subresources/auto_origin_tls_kex/methods/get)

GET/zones/{zone\_id}/settings/auto\_origin\_tls\_kex

##### [Patch Auto-Origin TLS KEX enrollment status for the given zone](https://developers.cloudflare.com/api/resources/ssl/subresources/auto_origin_tls_kex/methods/edit)

PATCH/zones/{zone\_id}/settings/auto\_origin\_tls\_kex

#### SSLUniversal

#### SSLUniversalSettings

##### [Universal SSL Settings Details](https://developers.cloudflare.com/api/resources/ssl/subresources/universal/subresources/settings/methods/get)

GET/zones/{zone\_id}/ssl/universal/settings

##### [Edit Universal SSL Settings](https://developers.cloudflare.com/api/resources/ssl/subresources/universal/subresources/settings/methods/edit)

PATCH/zones/{zone\_id}/ssl/universal/settings

#### SSLVerification

##### [SSL Verification Details](https://developers.cloudflare.com/api/resources/ssl/subresources/verification/methods/get)

GET/zones/{zone\_id}/ssl/verification

##### [Edit SSL Certificate Pack Validation Method](https://developers.cloudflare.com/api/resources/ssl/subresources/verification/methods/edit)

PATCH/zones/{zone\_id}/ssl/verification/{certificate\_pack\_id}

#### ACM

#### ACMTotal TLS

##### [Total TLS Settings Details](https://developers.cloudflare.com/api/resources/acm/subresources/total_tls/methods/get)

GET/zones/{zone\_id}/acm/total\_tls

##### [Enable or Disable Total TLS](https://developers.cloudflare.com/api/resources/acm/subresources/total_tls/methods/update)

POST/zones/{zone\_id}/acm/total\_tls

##### [Enable or Disable Total TLS](https://developers.cloudflare.com/api/resources/acm/subresources/total_tls/methods/edit)

POST/zones/{zone\_id}/acm/total\_tls

#### ACMCustom Trust Store

##### [List Custom Origin Trust Store Details](https://developers.cloudflare.com/api/resources/acm/subresources/custom_trust_store/methods/list)

GET/zones/{zone\_id}/acm/custom\_trust\_store

##### [Upload Custom Origin Trust Store](https://developers.cloudflare.com/api/resources/acm/subresources/custom_trust_store/methods/create)

POST/zones/{zone\_id}/acm/custom\_trust\_store

##### [Custom Origin Trust Store Details](https://developers.cloudflare.com/api/resources/acm/subresources/custom_trust_store/methods/get)

GET/zones/{zone\_id}/acm/custom\_trust\_store/{custom\_origin\_trust\_store\_id}

##### [Delete Custom Origin Trust Store](https://developers.cloudflare.com/api/resources/acm/subresources/custom_trust_store/methods/delete)

DELETE/zones/{zone\_id}/acm/custom\_trust\_store/{custom\_origin\_trust\_store\_id}

#### Analytics Query

##### [Query analytics summary](https://developers.cloudflare.com/api/resources/analytics_query/methods/summary)

POST/accounts/{account\_id}/analytics/query/{dataset}/summary

##### [Query analytics timeseries](https://developers.cloudflare.com/api/resources/analytics_query/methods/timeseries)

POST/accounts/{account\_id}/analytics/query/{dataset}/timeseries

##### [Query analytics top-N](https://developers.cloudflare.com/api/resources/analytics_query/methods/top_n)

POST/accounts/{account\_id}/analytics/query/{dataset}/top-n

#### Analytics QueryData Security

#### Analytics QueryData SecurityContent Findings

##### [Top integrations by content findings](https://developers.cloudflare.com/api/resources/analytics_query/subresources/data_security/subresources/content_findings/methods/top_n)

POST/accounts/{account\_id}/analytics/query/data-security/content-findings/top-n

#### Analytics QueryData SecurityFindings

##### [Data security findings summary](https://developers.cloudflare.com/api/resources/analytics_query/subresources/data_security/subresources/findings/methods/summary)

POST/accounts/{account\_id}/analytics/query/data-security/findings/summary

##### [Data security findings timeseries](https://developers.cloudflare.com/api/resources/analytics_query/subresources/data_security/subresources/findings/methods/timeseries)

POST/accounts/{account\_id}/analytics/query/data-security/findings/timeseries

#### Argo

#### ArgoSmart Routing

##### [Get Argo Smart Routing setting](https://developers.cloudflare.com/api/resources/argo/subresources/smart_routing/methods/get)

GET/zones/{zone\_id}/argo/smart\_routing

##### [Patch Argo Smart Routing setting](https://developers.cloudflare.com/api/resources/argo/subresources/smart_routing/methods/edit)

PATCH/zones/{zone\_id}/argo/smart\_routing

#### ArgoTiered Caching

##### [Get Tiered Caching setting](https://developers.cloudflare.com/api/resources/argo/subresources/tiered_caching/methods/get)

GET/zones/{zone\_id}/argo/tiered\_caching

##### [Patch Tiered Caching setting](https://developers.cloudflare.com/api/resources/argo/subresources/tiered_caching/methods/edit)

PATCH/zones/{zone\_id}/argo/tiered\_caching

#### Certificate Authorities

#### Certificate AuthoritiesHostname Associations

##### [List Hostname Associations](https://developers.cloudflare.com/api/resources/certificate_authorities/subresources/hostname_associations/methods/get)

GET/zones/{zone\_id}/certificate\_authorities/hostname\_associations

##### [Replace Hostname Associations](https://developers.cloudflare.com/api/resources/certificate_authorities/subresources/hostname_associations/methods/update)

PUT/zones/{zone\_id}/certificate\_authorities/hostname\_associations

#### Client Certificates

##### [List Client Certificates](https://developers.cloudflare.com/api/resources/client_certificates/methods/list)

GET/zones/{zone\_id}/client\_certificates

##### [Client Certificate Details](https://developers.cloudflare.com/api/resources/client_certificates/methods/get)

GET/zones/{zone\_id}/client\_certificates/{client\_certificate\_id}

##### [Create Client Certificate](https://developers.cloudflare.com/api/resources/client_certificates/methods/create)

POST/zones/{zone\_id}/client\_certificates

##### [Reactivate Client Certificate](https://developers.cloudflare.com/api/resources/client_certificates/methods/edit)

PATCH/zones/{zone\_id}/client\_certificates/{client\_certificate\_id}

##### [Revoke Client Certificate](https://developers.cloudflare.com/api/resources/client_certificates/methods/delete)

DELETE/zones/{zone\_id}/client\_certificates/{client\_certificate\_id}

#### Custom Certificates

##### [List SSL Configurations](https://developers.cloudflare.com/api/resources/custom_certificates/methods/list)

GET/zones/{zone\_id}/custom\_certificates

##### [SSL Configuration Details](https://developers.cloudflare.com/api/resources/custom_certificates/methods/get)

GET/zones/{zone\_id}/custom\_certificates/{custom\_certificate\_id}

##### [Create SSL Configuration](https://developers.cloudflare.com/api/resources/custom_certificates/methods/create)

POST/zones/{zone\_id}/custom\_certificates

##### [Edit SSL Configuration](https://developers.cloudflare.com/api/resources/custom_certificates/methods/edit)

PATCH/zones/{zone\_id}/custom\_certificates/{custom\_certificate\_id}

##### [Delete SSL Configuration](https://developers.cloudflare.com/api/resources/custom_certificates/methods/delete)

DELETE/zones/{zone\_id}/custom\_certificates/{custom\_certificate\_id}

#### Custom CertificatesPrioritize

##### [Re-prioritize SSL Certificates](https://developers.cloudflare.com/api/resources/custom_certificates/subresources/prioritize/methods/update)

PUT/zones/{zone\_id}/custom\_certificates/prioritize

#### Custom Csrs

##### [List Custom CSRs](https://developers.cloudflare.com/api/resources/custom_csrs/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_csrs

##### [Create Custom CSR](https://developers.cloudflare.com/api/resources/custom_csrs/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_csrs

##### [Custom CSR Details](https://developers.cloudflare.com/api/resources/custom_csrs/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_csrs/{custom\_csr\_id}

##### [Delete Custom CSR](https://developers.cloudflare.com/api/resources/custom_csrs/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_csrs/{custom\_csr\_id}

#### Custom Hostnames

##### [List Custom Hostnames](https://developers.cloudflare.com/api/resources/custom_hostnames/methods/list)

GET/zones/{zone\_id}/custom\_hostnames

##### [Custom Hostname Details](https://developers.cloudflare.com/api/resources/custom_hostnames/methods/get)

GET/zones/{zone\_id}/custom\_hostnames/{custom\_hostname\_id}

##### [Create Custom Hostname](https://developers.cloudflare.com/api/resources/custom_hostnames/methods/create)

POST/zones/{zone\_id}/custom\_hostnames

##### [Edit Custom Hostname](https://developers.cloudflare.com/api/resources/custom_hostnames/methods/edit)

PATCH/zones/{zone\_id}/custom\_hostnames/{custom\_hostname\_id}

##### [Delete Custom Hostname (and any issued SSL certificates)](https://developers.cloudflare.com/api/resources/custom_hostnames/methods/delete)

DELETE/zones/{zone\_id}/custom\_hostnames/{custom\_hostname\_id}

#### Custom HostnamesFallback Origin

##### [Get Fallback Origin for Custom Hostnames](https://developers.cloudflare.com/api/resources/custom_hostnames/subresources/fallback_origin/methods/get)

GET/zones/{zone\_id}/custom\_hostnames/fallback\_origin

##### [Update Fallback Origin for Custom Hostnames](https://developers.cloudflare.com/api/resources/custom_hostnames/subresources/fallback_origin/methods/update)

PUT/zones/{zone\_id}/custom\_hostnames/fallback\_origin

##### [Delete Fallback Origin for Custom Hostnames](https://developers.cloudflare.com/api/resources/custom_hostnames/subresources/fallback_origin/methods/delete)

DELETE/zones/{zone\_id}/custom\_hostnames/fallback\_origin

#### Custom HostnamesCertificate Pack

#### Custom HostnamesCertificate PackCertificates

##### [Replace Custom Certificate and Custom Key In Custom Hostname](https://developers.cloudflare.com/api/resources/custom_hostnames/subresources/certificate_pack/subresources/certificates/methods/update)

PUT/zones/{zone\_id}/custom\_hostnames/{custom\_hostname\_id}/certificate\_pack/{certificate\_pack\_id}/certificates/{certificate\_id}

##### [Delete Single Certificate And Key For Custom Hostname](https://developers.cloudflare.com/api/resources/custom_hostnames/subresources/certificate_pack/subresources/certificates/methods/delete)

DELETE/zones/{zone\_id}/custom\_hostnames/{custom\_hostname\_id}/certificate\_pack/{certificate\_pack\_id}/certificates/{certificate\_id}

#### Custom HostnamesQuota

##### [Get Custom Hostname Quota](https://developers.cloudflare.com/api/resources/custom_hostnames/subresources/quota/methods/get)

GET/zones/{zone\_id}/custom\_hostnames/quota

#### Account Custom Nameservers

##### [List Account Custom Nameservers](https://developers.cloudflare.com/api/resources/custom_nameservers/methods/get)

GET/accounts/{account\_id}/custom\_ns

##### [Add Account Custom Nameserver](https://developers.cloudflare.com/api/resources/custom_nameservers/methods/create)

POST/accounts/{account\_id}/custom\_ns

##### [Delete Account Custom Nameserver](https://developers.cloudflare.com/api/resources/custom_nameservers/methods/delete)

DELETE/accounts/{account\_id}/custom\_ns/{custom\_ns\_id}

#### Tenant Custom Nameservers

##### [List Tenant Custom Nameservers](https://developers.cloudflare.com/api/resources/tenant_custom_nameservers/methods/get)

GET/tenants/{tenant\_tag}/custom\_ns

##### [Add Tenant Custom Nameserver](https://developers.cloudflare.com/api/resources/tenant_custom_nameservers/methods/create)

POST/tenants/{tenant\_tag}/custom\_ns

##### [Delete Tenant Custom Nameserver](https://developers.cloudflare.com/api/resources/tenant_custom_nameservers/methods/delete)

DELETE/tenants/{tenant\_tag}/custom\_ns/{custom\_ns\_id}

#### DNS Firewall

##### [List DNS Firewall Clusters](https://developers.cloudflare.com/api/resources/dns_firewall/methods/list)

GET/accounts/{account\_id}/dns\_firewall

##### [DNS Firewall Cluster Details](https://developers.cloudflare.com/api/resources/dns_firewall/methods/get)

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}

##### [Create DNS Firewall Cluster](https://developers.cloudflare.com/api/resources/dns_firewall/methods/create)

POST/accounts/{account\_id}/dns\_firewall

##### [Update DNS Firewall Cluster](https://developers.cloudflare.com/api/resources/dns_firewall/methods/edit)

PATCH/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}

##### [Delete DNS Firewall Cluster](https://developers.cloudflare.com/api/resources/dns_firewall/methods/delete)

DELETE/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}

#### DNS FirewallAnalytics

#### DNS FirewallAnalyticsReports

##### [Table](https://developers.cloudflare.com/api/resources/dns_firewall/subresources/analytics/subresources/reports/methods/get)

Deprecated

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/dns\_analytics/report

#### DNS FirewallAnalyticsReportsBytimes

##### [By Time](https://developers.cloudflare.com/api/resources/dns_firewall/subresources/analytics/subresources/reports/subresources/bytimes/methods/get)

Deprecated

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/dns\_analytics/report/bytime

#### DNS FirewallReverse DNS

##### [Show DNS Firewall Cluster Reverse DNS](https://developers.cloudflare.com/api/resources/dns_firewall/subresources/reverse_dns/methods/get)

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/reverse\_dns

##### [Update DNS Firewall Cluster Reverse DNS](https://developers.cloudflare.com/api/resources/dns_firewall/subresources/reverse_dns/methods/edit)

PATCH/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/reverse\_dns

#### DNS

#### DNSDNSSEC

##### [DNSSEC Details](https://developers.cloudflare.com/api/resources/dns/subresources/dnssec/methods/get)

GET/zones/{zone\_id}/dnssec

##### [Edit DNSSEC Status](https://developers.cloudflare.com/api/resources/dns/subresources/dnssec/methods/edit)

PATCH/zones/{zone\_id}/dnssec

##### [Delete DNSSEC records](https://developers.cloudflare.com/api/resources/dns/subresources/dnssec/methods/delete)

DELETE/zones/{zone\_id}/dnssec

#### DNSDNSSECZsk

##### [List DNSSEC ZSKs](https://developers.cloudflare.com/api/resources/dns/subresources/dnssec/subresources/zsk/methods/list)

GET/zones/{zone\_id}/dnssec/zsk

#### DNSRecords

##### [List DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/list)

GET/zones/{zone\_id}/dns\_records

##### [DNS Record Details](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/get)

GET/zones/{zone\_id}/dns\_records/{dns\_record\_id}

##### [Create DNS Record](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/create)

POST/zones/{zone\_id}/dns\_records

##### [Overwrite DNS Record](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/update)

PUT/zones/{zone\_id}/dns\_records/{dns\_record\_id}

##### [Update DNS Record](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/edit)

PATCH/zones/{zone\_id}/dns\_records/{dns\_record\_id}

##### [Delete DNS Record](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/delete)

DELETE/zones/{zone\_id}/dns\_records/{dns\_record\_id}

##### [Export DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/export)

GET/zones/{zone\_id}/dns\_records/export

##### [Import DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/import)

POST/zones/{zone\_id}/dns\_records/import

##### [Scan DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/scan)

Deprecated

POST/zones/{zone\_id}/dns\_records/scan

##### [Trigger DNS Record Scan](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/scan_trigger)

POST/zones/{zone\_id}/dns\_records/scan/trigger

##### [Review Scanned DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/scan_review)

POST/zones/{zone\_id}/dns\_records/scan/review

##### [List Scanned DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/scan_list)

GET/zones/{zone\_id}/dns\_records/scan/review

##### [Batch DNS Records](https://developers.cloudflare.com/api/resources/dns/subresources/records/methods/batch)

POST/zones/{zone\_id}/dns\_records/batch

#### DNSUsage

#### DNSUsageZone

##### [Get DNS Record Usage](https://developers.cloudflare.com/api/resources/dns/subresources/usage/subresources/zone/methods/get)

GET/zones/{zone\_id}/dns\_records/usage

#### DNSUsageAccount

##### [Get DNS Record Usage for Account](https://developers.cloudflare.com/api/resources/dns/subresources/usage/subresources/account/methods/get)

GET/accounts/{account\_id}/dns\_records/usage

#### DNSSettings

#### DNSSettingsZone

##### [Show DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/methods/get)

GET/zones/{zone\_id}/dns\_settings

##### [Update DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/zone/methods/edit)

PATCH/zones/{zone\_id}/dns\_settings

#### DNSSettingsAccount

##### [Show DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/methods/get)

GET/accounts/{account\_id}/dns\_settings

##### [Update DNS Settings](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/methods/edit)

PATCH/accounts/{account\_id}/dns\_settings

#### DNSSettingsAccountViews

##### [List Internal DNS Views](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/subresources/views/methods/list)

GET/accounts/{account\_id}/dns\_settings/views

##### [DNS Internal View Details](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/subresources/views/methods/get)

GET/accounts/{account\_id}/dns\_settings/views/{view\_id}

##### [Create Internal DNS View](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/subresources/views/methods/create)

POST/accounts/{account\_id}/dns\_settings/views

##### [Update Internal DNS View](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/subresources/views/methods/edit)

PATCH/accounts/{account\_id}/dns\_settings/views/{view\_id}

##### [Delete Internal DNS View](https://developers.cloudflare.com/api/resources/dns/subresources/settings/subresources/account/subresources/views/methods/delete)

DELETE/accounts/{account\_id}/dns\_settings/views/{view\_id}

#### DNSAnalytics

#### DNSAnalyticsReports

##### [Table](https://developers.cloudflare.com/api/resources/dns/subresources/analytics/subresources/reports/methods/get)

Deprecated

GET/zones/{zone\_id}/dns\_analytics/report

#### DNSAnalyticsReportsBytimes

##### [By Time](https://developers.cloudflare.com/api/resources/dns/subresources/analytics/subresources/reports/subresources/bytimes/methods/get)

Deprecated

GET/zones/{zone\_id}/dns\_analytics/report/bytime

#### DNSZone Transfers

#### DNSZone TransfersForce AXFR

##### [Force AXFR](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/force_axfr/methods/create)

POST/zones/{zone\_id}/secondary\_dns/force\_axfr

#### DNSZone TransfersIncoming

##### [Secondary Zone Configuration Details](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/incoming/methods/get)

GET/zones/{zone\_id}/secondary\_dns/incoming

##### [Create Secondary Zone Configuration](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/incoming/methods/create)

POST/zones/{zone\_id}/secondary\_dns/incoming

##### [Update Secondary Zone Configuration](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/incoming/methods/update)

PUT/zones/{zone\_id}/secondary\_dns/incoming

##### [Delete Secondary Zone Configuration](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/incoming/methods/delete)

DELETE/zones/{zone\_id}/secondary\_dns/incoming

#### DNSZone TransfersOutgoing

##### [Primary Zone Configuration Details](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/get)

GET/zones/{zone\_id}/secondary\_dns/outgoing

##### [Create Primary Zone Configuration](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/create)

POST/zones/{zone\_id}/secondary\_dns/outgoing

##### [Update Primary Zone Configuration](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/update)

PUT/zones/{zone\_id}/secondary\_dns/outgoing

##### [Delete Primary Zone Configuration](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/delete)

DELETE/zones/{zone\_id}/secondary\_dns/outgoing

##### [Disable Outgoing Zone Transfers](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/disable)

POST/zones/{zone\_id}/secondary\_dns/outgoing/disable

##### [Enable Outgoing Zone Transfers](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/enable)

POST/zones/{zone\_id}/secondary\_dns/outgoing/enable

##### [Force DNS NOTIFY](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/methods/force_notify)

POST/zones/{zone\_id}/secondary\_dns/outgoing/force\_notify

#### DNSZone TransfersOutgoingStatus

##### [Get Outgoing Zone Transfer Status](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/outgoing/subresources/status/methods/get)

GET/zones/{zone\_id}/secondary\_dns/outgoing/status

#### DNSZone TransfersACLs

##### [List ACLs](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/acls/methods/list)

GET/accounts/{account\_id}/secondary\_dns/acls

##### [ACL Details](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/acls/methods/get)

GET/accounts/{account\_id}/secondary\_dns/acls/{acl\_id}

##### [Create ACL](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/acls/methods/create)

POST/accounts/{account\_id}/secondary\_dns/acls

##### [Update ACL](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/acls/methods/update)

PUT/accounts/{account\_id}/secondary\_dns/acls/{acl\_id}

##### [Delete ACL](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/acls/methods/delete)

DELETE/accounts/{account\_id}/secondary\_dns/acls/{acl\_id}

#### DNSZone TransfersPeers

##### [List Peers](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/peers/methods/list)

GET/accounts/{account\_id}/secondary\_dns/peers

##### [Peer Details](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/peers/methods/get)

GET/accounts/{account\_id}/secondary\_dns/peers/{peer\_id}

##### [Create Peer](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/peers/methods/create)

POST/accounts/{account\_id}/secondary\_dns/peers

##### [Update Peer](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/peers/methods/update)

PUT/accounts/{account\_id}/secondary\_dns/peers/{peer\_id}

##### [Delete Peer](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/peers/methods/delete)

DELETE/accounts/{account\_id}/secondary\_dns/peers/{peer\_id}

#### DNSZone TransfersTSIGs

##### [List TSIGs](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/tsigs/methods/list)

GET/accounts/{account\_id}/secondary\_dns/tsigs

##### [TSIG Details](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/tsigs/methods/get)

GET/accounts/{account\_id}/secondary\_dns/tsigs/{tsig\_id}

##### [Create TSIG](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/tsigs/methods/create)

POST/accounts/{account\_id}/secondary\_dns/tsigs

##### [Update TSIG](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/tsigs/methods/update)

PUT/accounts/{account\_id}/secondary\_dns/tsigs/{tsig\_id}

##### [Delete TSIG](https://developers.cloudflare.com/api/resources/dns/subresources/zone_transfers/subresources/tsigs/methods/delete)

DELETE/accounts/{account\_id}/secondary\_dns/tsigs/{tsig\_id}

#### Email Security

#### Email SecurityInvestigate

##### [Search email messages](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/methods/list)

GET/accounts/{account\_id}/email-security/investigate

##### [Get message details](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/methods/get)

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}

#### Email SecurityInvestigateDetections

##### [Get message detection details](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/detections/methods/get)

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/detections

#### Email SecurityInvestigatePreview

##### [Get email preview](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/preview/methods/get)

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/preview

##### [Preview for non-detection messages](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/preview/methods/create)

POST/accounts/{account\_id}/email-security/investigate/preview

#### Email SecurityInvestigateRaw

##### [Get raw email content](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/raw/methods/get)

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/raw

#### Email SecurityInvestigateTrace

##### [Get email trace](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/trace/methods/get)

GET/accounts/{account\_id}/email-security/investigate/{investigate\_id}/trace

#### Email SecurityInvestigateMove

##### [Move a message](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/move/methods/create)

POST/accounts/{account\_id}/email-security/investigate/{investigate\_id}/move

##### [Move multiple messages](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/move/methods/bulk)

POST/accounts/{account\_id}/email-security/investigate/move

#### Email SecurityInvestigateReclassify

##### [Change email classification](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/reclassify/methods/create)

POST/accounts/{account\_id}/email-security/investigate/{investigate\_id}/reclassify

#### Email SecurityInvestigateRelease

##### [Release messages from quarantine](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/release/methods/bulk)

POST/accounts/{account\_id}/email-security/investigate/release

#### Email SecurityInvestigateBulk

##### [List bulk action jobs](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/bulk/methods/list)

GET/accounts/{account\_id}/email-security/investigate/bulk

##### [Create a bulk action job](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/bulk/methods/create)

POST/accounts/{account\_id}/email-security/investigate/bulk

##### [Get bulk action job details](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/bulk/methods/get)

GET/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}

##### [Delete a bulk action job](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/bulk/methods/delete)

DELETE/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}

#### Email SecurityInvestigateBulkCancel

##### [Cancel a bulk action job](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/bulk/subresources/cancel/methods/create)

POST/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}/cancel

#### Email SecurityInvestigateBulkMessages

##### [List messages for a bulk action job](https://developers.cloudflare.com/api/resources/email_security/subresources/investigate/subresources/bulk/subresources/messages/methods/list)

GET/accounts/{account\_id}/email-security/investigate/bulk/{job\_id}/messages

#### Email SecurityPhishguard

#### Email SecurityPhishguardReports

##### [Get PhishGuard reports](https://developers.cloudflare.com/api/resources/email_security/subresources/phishguard/subresources/reports/methods/list)

GET/accounts/{account\_id}/email-security/phishguard/reports

#### Email SecuritySettings

#### Email SecuritySettingsAllow Policies

##### [List email allow policies](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/allow_policies/methods/list)

GET/accounts/{account\_id}/email-security/settings/allow\_policies

##### [Get an email allow policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/allow_policies/methods/get)

GET/accounts/{account\_id}/email-security/settings/allow\_policies/{policy\_id}

##### [Create email allow policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/allow_policies/methods/create)

POST/accounts/{account\_id}/email-security/settings/allow\_policies

##### [Update an email allow policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/allow_policies/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/allow\_policies/{policy\_id}

##### [Delete an email allow policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/allow_policies/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/allow\_policies/{policy\_id}

##### [Batch allow policies operations](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/allow_policies/methods/batch)

POST/accounts/{account\_id}/email-security/settings/allow\_policies/batch

#### Email SecuritySettingsBlock Senders

##### [List blocked email senders](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/block_senders/methods/list)

GET/accounts/{account\_id}/email-security/settings/block\_senders

##### [Get a blocked email sender](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/block_senders/methods/get)

GET/accounts/{account\_id}/email-security/settings/block\_senders/{pattern\_id}

##### [Create blocked email sender](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/block_senders/methods/create)

POST/accounts/{account\_id}/email-security/settings/block\_senders

##### [Update a blocked email sender](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/block_senders/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/block\_senders/{pattern\_id}

##### [Delete a blocked email sender](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/block_senders/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/block\_senders/{pattern\_id}

##### [Batch blocked senders operations](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/block_senders/methods/batch)

POST/accounts/{account\_id}/email-security/settings/block\_senders/batch

#### Email SecuritySettingsContent Policies

##### [List content policies](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/content_policies/methods/list)

GET/accounts/{account\_id}/email-security/settings/content\_policies

##### [Get a content policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/content_policies/methods/get)

GET/accounts/{account\_id}/email-security/settings/content\_policies/{policy\_id}

##### [Create a content policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/content_policies/methods/create)

POST/accounts/{account\_id}/email-security/settings/content\_policies

##### [Update a content policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/content_policies/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/content\_policies/{policy\_id}

##### [Delete a content policy](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/content_policies/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/content\_policies/{policy\_id}

##### [Batch content policy operations](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/content_policies/methods/batch)

POST/accounts/{account\_id}/email-security/settings/content\_policies/batch

#### Email SecuritySettingsDomains

##### [List protected email domains](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/list)

GET/accounts/{account\_id}/email-security/settings/domains

##### [Get an email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/get)

GET/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Replace an email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/update)

PUT/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Update an email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Add a new email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/create)

POST/accounts/{account\_id}/email-security/settings/domains

##### [Unprotect an email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/domains/{domain\_id}

##### [Batch domain operations](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/batch)

POST/accounts/{account\_id}/email-security/settings/domains/batch

##### [Unprotect multiple email domains](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/domains/methods/bulk_delete)

Deprecated

DELETE/accounts/{account\_id}/email-security/settings/domains

#### Email SecuritySettingsImpersonation Registry

##### [List entries in impersonation registry](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/list)

GET/accounts/{account\_id}/email-security/settings/impersonation\_registry

##### [Get an impersonation registry entry](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/get)

GET/accounts/{account\_id}/email-security/settings/impersonation\_registry/{impersonation\_registry\_id}

##### [Create impersonation registry entry](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/create)

POST/accounts/{account\_id}/email-security/settings/impersonation\_registry

##### [Update an impersonation registry entry](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/impersonation\_registry/{impersonation\_registry\_id}

##### [Delete an impersonation registry entry](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/impersonation_registry/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/impersonation\_registry/{impersonation\_registry\_id}

#### Email SecuritySettingsSending Domain Restrictions

##### [List sending domain restrictions](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/list)

GET/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions

##### [Get a sending domain restriction](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/get)

GET/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions/{sending\_domain\_restriction\_id}

##### [Create a sending domain restriction](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/create)

POST/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions

##### [Update a sending domain restriction](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions/{sending\_domain\_restriction\_id}

##### [Delete a sending domain restriction](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/sending_domain_restrictions/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/sending\_domain\_restrictions/{sending\_domain\_restriction\_id}

#### Email SecuritySettingsTrusted Domains

##### [List trusted email domains](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/trusted_domains/methods/list)

GET/accounts/{account\_id}/email-security/settings/trusted\_domains

##### [Get a trusted email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/trusted_domains/methods/get)

GET/accounts/{account\_id}/email-security/settings/trusted\_domains/{trusted\_domain\_id}

##### [Create trusted email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/trusted_domains/methods/create)

POST/accounts/{account\_id}/email-security/settings/trusted\_domains

##### [Update a trusted email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/trusted_domains/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/trusted\_domains/{trusted\_domain\_id}

##### [Delete a trusted email domain](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/trusted_domains/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/trusted\_domains/{trusted\_domain\_id}

##### [Batch trusted domains operations](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/trusted_domains/methods/batch)

POST/accounts/{account\_id}/email-security/settings/trusted\_domains/batch

#### Email SecuritySettingsURL Ignore Patterns

##### [List URL ignore patterns](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/list)

GET/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns

##### [Get a URL ignore pattern](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/get)

GET/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns/{pattern\_id}

##### [Create a URL ignore pattern](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/create)

POST/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns

##### [Update a URL ignore pattern](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/edit)

PATCH/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns/{pattern\_id}

##### [Delete a URL ignore pattern](https://developers.cloudflare.com/api/resources/email_security/subresources/settings/subresources/url_ignore_patterns/methods/delete)

DELETE/accounts/{account\_id}/email-security/settings/url\_ignore\_patterns/{pattern\_id}

#### Email SecuritySubmissions

##### [Get reclassify submissions](https://developers.cloudflare.com/api/resources/email_security/subresources/submissions/methods/list)

GET/accounts/{account\_id}/email-security/submissions

#### Email Auth

#### Email AuthDMARC Reports

##### [Get DMARC Report Status](https://developers.cloudflare.com/api/resources/email_auth/subresources/dmarc_reports/methods/get)

GET/zones/{zone\_id}/email/auth/dmarc-reports

##### [Configure DMARC Reports](https://developers.cloudflare.com/api/resources/email_auth/subresources/dmarc_reports/methods/edit)

PATCH/zones/{zone\_id}/email/auth/dmarc-reports

#### Email AuthSPF

#### Email AuthSPFInspect

##### [Inspect SPF Record](https://developers.cloudflare.com/api/resources/email_auth/subresources/spf/subresources/inspect/methods/get)

GET/zones/{zone\_id}/email/auth/spf/inspect

#### Email Routing

##### [Get Email Routing settings](https://developers.cloudflare.com/api/resources/email_routing/methods/get)

GET/zones/{zone\_id}/email/routing

##### [Update Email Routing settings](https://developers.cloudflare.com/api/resources/email_routing/methods/edit)

PATCH/zones/{zone\_id}/email/routing

##### [Update Email Routing settings](https://developers.cloudflare.com/api/resources/email_routing/methods/update)

PUT/zones/{zone\_id}/email/routing

##### [Disable Email Routing](https://developers.cloudflare.com/api/resources/email_routing/methods/disable)

Deprecated

POST/zones/{zone\_id}/email/routing/disable

##### [Enable Email Routing](https://developers.cloudflare.com/api/resources/email_routing/methods/enable)

Deprecated

POST/zones/{zone\_id}/email/routing/enable

##### [Unlock Email Routing](https://developers.cloudflare.com/api/resources/email_routing/methods/unlock)

Deprecated

POST/zones/{zone\_id}/email/routing/unlock

#### Email RoutingDNS

##### [Email Routing - DNS settings](https://developers.cloudflare.com/api/resources/email_routing/subresources/dns/methods/get)

GET/zones/{zone\_id}/email/routing/dns

##### [Enable Email Routing](https://developers.cloudflare.com/api/resources/email_routing/subresources/dns/methods/create)

POST/zones/{zone\_id}/email/routing/dns

##### [Unlock Email Routing](https://developers.cloudflare.com/api/resources/email_routing/subresources/dns/methods/edit)

PATCH/zones/{zone\_id}/email/routing/dns

##### [Disable Email Routing](https://developers.cloudflare.com/api/resources/email_routing/subresources/dns/methods/delete)

DELETE/zones/{zone\_id}/email/routing/dns

#### Email RoutingRules

##### [List account or zone routing rules](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/email/routing/rules

##### [Get routing rule](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/methods/get)

GET/zones/{zone\_id}/email/routing/rules/{rule\_identifier}

##### [Create routing rule](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/methods/create)

POST/zones/{zone\_id}/email/routing/rules

##### [Update routing rule](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/methods/update)

PUT/zones/{zone\_id}/email/routing/rules/{rule\_identifier}

##### [Delete routing rule](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/methods/delete)

DELETE/zones/{zone\_id}/email/routing/rules/{rule\_identifier}

#### Email RoutingRulesCatch Alls

##### [Get catch-all rule](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/subresources/catch_alls/methods/get)

GET/zones/{zone\_id}/email/routing/rules/catch\_all

##### [Update catch-all rule](https://developers.cloudflare.com/api/resources/email_routing/subresources/rules/subresources/catch_alls/methods/update)

PUT/zones/{zone\_id}/email/routing/rules/catch\_all

#### Email RoutingAccount Rules

##### [List account or zone routing rules](https://developers.cloudflare.com/api/resources/email_routing/subresources/account_rules/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/email/routing/rules

#### Email RoutingAddresses

##### [List destination addresses](https://developers.cloudflare.com/api/resources/email_routing/subresources/addresses/methods/list)

GET/accounts/{account\_id}/email/routing/addresses

##### [Get a destination address](https://developers.cloudflare.com/api/resources/email_routing/subresources/addresses/methods/get)

GET/accounts/{account\_id}/email/routing/addresses/{destination\_address\_identifier}

##### [Create a destination address](https://developers.cloudflare.com/api/resources/email_routing/subresources/addresses/methods/create)

POST/accounts/{account\_id}/email/routing/addresses

##### [Update destination address](https://developers.cloudflare.com/api/resources/email_routing/subresources/addresses/methods/edit)

PATCH/accounts/{account\_id}/email/routing/addresses/{destination\_address\_identifier}

##### [Delete destination address](https://developers.cloudflare.com/api/resources/email_routing/subresources/addresses/methods/delete)

DELETE/accounts/{account\_id}/email/routing/addresses/{destination\_address\_identifier}

#### Email Sending

##### [Send an email](https://developers.cloudflare.com/api/resources/email_sending/methods/send)

POST/accounts/{account\_id}/email/sending/send

##### [Send a raw MIME email](https://developers.cloudflare.com/api/resources/email_sending/methods/send_raw)

POST/accounts/{account\_id}/email/sending/send\_raw

#### Email SendingSuppressions

##### [List account Email Sending suppressions](https://developers.cloudflare.com/api/resources/email_sending/subresources/suppressions/methods/list)

GET/accounts/{account\_id}/email/sending/suppressions

##### [Get account Email Sending suppression](https://developers.cloudflare.com/api/resources/email_sending/subresources/suppressions/methods/get)

GET/accounts/{account\_id}/email/sending/suppressions/{suppression\_id}

##### [Create account Email Sending suppression](https://developers.cloudflare.com/api/resources/email_sending/subresources/suppressions/methods/create)

POST/accounts/{account\_id}/email/sending/suppressions

##### [Update account Email Sending suppression](https://developers.cloudflare.com/api/resources/email_sending/subresources/suppressions/methods/edit)

PATCH/accounts/{account\_id}/email/sending/suppressions/{suppression\_id}

##### [Delete account Email Sending suppression](https://developers.cloudflare.com/api/resources/email_sending/subresources/suppressions/methods/delete)

DELETE/accounts/{account\_id}/email/sending/suppressions/{suppression\_id}

##### [Bulk import account Email Sending suppressions](https://developers.cloudflare.com/api/resources/email_sending/subresources/suppressions/methods/import)

POST/accounts/{account\_id}/email/sending/suppressions/bulk

#### Email SendingSubdomains

##### [List sending subdomains](https://developers.cloudflare.com/api/resources/email_sending/subresources/subdomains/methods/list)

GET/zones/{zone\_id}/email/sending/subdomains

##### [Get a sending subdomain](https://developers.cloudflare.com/api/resources/email_sending/subresources/subdomains/methods/get)

GET/zones/{zone\_id}/email/sending/subdomains/{subdomain\_id}

##### [Create a sending subdomain](https://developers.cloudflare.com/api/resources/email_sending/subresources/subdomains/methods/create)

POST/zones/{zone\_id}/email/sending/subdomains

##### [Update a sending subdomain](https://developers.cloudflare.com/api/resources/email_sending/subresources/subdomains/methods/edit)

PATCH/zones/{zone\_id}/email/sending/subdomains/{subdomain\_id}

##### [Delete a sending subdomain](https://developers.cloudflare.com/api/resources/email_sending/subresources/subdomains/methods/delete)

DELETE/zones/{zone\_id}/email/sending/subdomains/{subdomain\_id}

#### Email SendingSubdomainsDNS

##### [Get sending subdomain DNS records](https://developers.cloudflare.com/api/resources/email_sending/subresources/subdomains/subresources/dns/methods/get)

GET/zones/{zone\_id}/email/sending/subdomains/{subdomain\_id}/dns

#### Filters

##### [List filters](https://developers.cloudflare.com/api/resources/filters/methods/list)

Deprecated

GET/zones/{zone\_id}/filters

##### [Get a filter](https://developers.cloudflare.com/api/resources/filters/methods/get)

Deprecated

GET/zones/{zone\_id}/filters/{filter\_id}

##### [Create filters](https://developers.cloudflare.com/api/resources/filters/methods/create)

Deprecated

POST/zones/{zone\_id}/filters

##### [Update a filter](https://developers.cloudflare.com/api/resources/filters/methods/update)

Deprecated

PUT/zones/{zone\_id}/filters/{filter\_id}

##### [Delete a filter](https://developers.cloudflare.com/api/resources/filters/methods/delete)

Deprecated

DELETE/zones/{zone\_id}/filters/{filter\_id}

##### [Update filters](https://developers.cloudflare.com/api/resources/filters/methods/bulk_update)

Deprecated

PUT/zones/{zone\_id}/filters

##### [Delete filters](https://developers.cloudflare.com/api/resources/filters/methods/bulk_delete)

Deprecated

DELETE/zones/{zone\_id}/filters

#### Firewall

#### FirewallLockdowns

##### [List Zone Lockdown rules](https://developers.cloudflare.com/api/resources/firewall/subresources/lockdowns/methods/list)

GET/zones/{zone\_id}/firewall/lockdowns

##### [Get a Zone Lockdown rule](https://developers.cloudflare.com/api/resources/firewall/subresources/lockdowns/methods/get)

GET/zones/{zone\_id}/firewall/lockdowns/{lock\_downs\_id}

##### [Create a Zone Lockdown rule](https://developers.cloudflare.com/api/resources/firewall/subresources/lockdowns/methods/create)

POST/zones/{zone\_id}/firewall/lockdowns

##### [Update a Zone Lockdown rule](https://developers.cloudflare.com/api/resources/firewall/subresources/lockdowns/methods/update)

PUT/zones/{zone\_id}/firewall/lockdowns/{lock\_downs\_id}

##### [Delete a Zone Lockdown rule](https://developers.cloudflare.com/api/resources/firewall/subresources/lockdowns/methods/delete)

DELETE/zones/{zone\_id}/firewall/lockdowns/{lock\_downs\_id}

#### FirewallRules

##### [List firewall rules](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/list)

Deprecated

GET/zones/{zone\_id}/firewall/rules

##### [Get a firewall rule](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/get)

Deprecated

GET/zones/{zone\_id}/firewall/rules/{rule\_id}

##### [Create firewall rules](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/create)

Deprecated

POST/zones/{zone\_id}/firewall/rules

##### [Update a firewall rule](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/update)

Deprecated

PUT/zones/{zone\_id}/firewall/rules/{rule\_id}

##### [Update priority of a firewall rule](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/edit)

Deprecated

PATCH/zones/{zone\_id}/firewall/rules/{rule\_id}

##### [Delete a firewall rule](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/delete)

Deprecated

DELETE/zones/{zone\_id}/firewall/rules/{rule\_id}

##### [Update firewall rules](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/bulk_update)

Deprecated

PUT/zones/{zone\_id}/firewall/rules

##### [Update priority of firewall rules](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/bulk_edit)

Deprecated

PATCH/zones/{zone\_id}/firewall/rules

##### [Delete firewall rules](https://developers.cloudflare.com/api/resources/firewall/subresources/rules/methods/bulk_delete)

Deprecated

DELETE/zones/{zone\_id}/firewall/rules

#### FirewallAccess Rules

##### [List IP Access rules](https://developers.cloudflare.com/api/resources/firewall/subresources/access_rules/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/firewall/access\_rules/rules

##### [Get an IP Access rule](https://developers.cloudflare.com/api/resources/firewall/subresources/access_rules/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/firewall/access\_rules/rules/{rule\_id}

##### [Create an IP Access rule](https://developers.cloudflare.com/api/resources/firewall/subresources/access_rules/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/firewall/access\_rules/rules

##### [Update an IP Access rule](https://developers.cloudflare.com/api/resources/firewall/subresources/access_rules/methods/edit)

PATCH/{accounts\_or\_zones}/{account\_or\_zone\_id}/firewall/access\_rules/rules/{rule\_id}

##### [Delete an IP Access rule](https://developers.cloudflare.com/api/resources/firewall/subresources/access_rules/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/firewall/access\_rules/rules/{rule\_id}

#### FirewallUA Rules

##### [List User Agent Blocking rules](https://developers.cloudflare.com/api/resources/firewall/subresources/ua_rules/methods/list)

GET/zones/{zone\_id}/firewall/ua\_rules

##### [Get a User Agent Blocking rule](https://developers.cloudflare.com/api/resources/firewall/subresources/ua_rules/methods/get)

GET/zones/{zone\_id}/firewall/ua\_rules/{ua\_rule\_id}

##### [Create a User Agent Blocking rule](https://developers.cloudflare.com/api/resources/firewall/subresources/ua_rules/methods/create)

POST/zones/{zone\_id}/firewall/ua\_rules

##### [Update a User Agent Blocking rule](https://developers.cloudflare.com/api/resources/firewall/subresources/ua_rules/methods/update)

PUT/zones/{zone\_id}/firewall/ua\_rules/{ua\_rule\_id}

##### [Delete a User Agent Blocking rule](https://developers.cloudflare.com/api/resources/firewall/subresources/ua_rules/methods/delete)

DELETE/zones/{zone\_id}/firewall/ua\_rules/{ua\_rule\_id}

#### FirewallWAF

#### FirewallWAFOverrides

##### [List WAF overrides](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/overrides/methods/list)

Deprecated

GET/zones/{zone\_id}/firewall/waf/overrides

##### [Get a WAF override](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/overrides/methods/get)

Deprecated

GET/zones/{zone\_id}/firewall/waf/overrides/{overrides\_id}

##### [Create a WAF override](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/overrides/methods/create)

Deprecated

POST/zones/{zone\_id}/firewall/waf/overrides

##### [Update WAF override](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/overrides/methods/update)

Deprecated

PUT/zones/{zone\_id}/firewall/waf/overrides/{overrides\_id}

##### [Delete a WAF override](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/overrides/methods/delete)

Deprecated

DELETE/zones/{zone\_id}/firewall/waf/overrides/{overrides\_id}

#### FirewallWAFPackages

##### [List WAF packages](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/methods/list)

Deprecated

GET/zones/{zone\_id}/firewall/waf/packages

##### [Get a WAF package](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/methods/get)

Deprecated

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}

#### FirewallWAFPackagesGroups

##### [List WAF rule groups](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/subresources/groups/methods/list)

Deprecated

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/groups

##### [Get a WAF rule group](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/subresources/groups/methods/get)

Deprecated

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/groups/{group\_id}

##### [Update a WAF rule group](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/subresources/groups/methods/edit)

Deprecated

PATCH/zones/{zone\_id}/firewall/waf/packages/{package\_id}/groups/{group\_id}

#### FirewallWAFPackagesRules

##### [List WAF rules](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/subresources/rules/methods/list)

Deprecated

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/rules

##### [Get a WAF rule](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/subresources/rules/methods/get)

Deprecated

GET/zones/{zone\_id}/firewall/waf/packages/{package\_id}/rules/{rule\_id}

##### [Update a WAF rule](https://developers.cloudflare.com/api/resources/firewall/subresources/waf/subresources/packages/subresources/rules/methods/edit)

Deprecated

PATCH/zones/{zone\_id}/firewall/waf/packages/{package\_id}/rules/{rule\_id}

#### Healthchecks

##### [List Health Checks](https://developers.cloudflare.com/api/resources/healthchecks/methods/list)

GET/zones/{zone\_id}/healthchecks

##### [Health Check Details](https://developers.cloudflare.com/api/resources/healthchecks/methods/get)

GET/zones/{zone\_id}/healthchecks/{healthcheck\_id}

##### [Create Health Check](https://developers.cloudflare.com/api/resources/healthchecks/methods/create)

POST/zones/{zone\_id}/healthchecks

##### [Update Health Check](https://developers.cloudflare.com/api/resources/healthchecks/methods/update)

PUT/zones/{zone\_id}/healthchecks/{healthcheck\_id}

##### [Patch Health Check](https://developers.cloudflare.com/api/resources/healthchecks/methods/edit)

PATCH/zones/{zone\_id}/healthchecks/{healthcheck\_id}

##### [Delete Health Check](https://developers.cloudflare.com/api/resources/healthchecks/methods/delete)

DELETE/zones/{zone\_id}/healthchecks/{healthcheck\_id}

#### HealthchecksPreviews

##### [Health Check Preview Details](https://developers.cloudflare.com/api/resources/healthchecks/subresources/previews/methods/get)

GET/zones/{zone\_id}/healthchecks/preview/{healthcheck\_id}

##### [Create Preview Health Check](https://developers.cloudflare.com/api/resources/healthchecks/subresources/previews/methods/create)

POST/zones/{zone\_id}/healthchecks/preview

##### [Delete Preview Health Check](https://developers.cloudflare.com/api/resources/healthchecks/subresources/previews/methods/delete)

DELETE/zones/{zone\_id}/healthchecks/preview/{healthcheck\_id}

#### Keyless Certificates

##### [List Keyless SSL Configurations](https://developers.cloudflare.com/api/resources/keyless_certificates/methods/list)

GET/zones/{zone\_id}/keyless\_certificates

##### [Get Keyless SSL Configuration](https://developers.cloudflare.com/api/resources/keyless_certificates/methods/get)

GET/zones/{zone\_id}/keyless\_certificates/{keyless\_certificate\_id}

##### [Create Keyless SSL Configuration](https://developers.cloudflare.com/api/resources/keyless_certificates/methods/create)

POST/zones/{zone\_id}/keyless\_certificates

##### [Edit Keyless SSL Configuration](https://developers.cloudflare.com/api/resources/keyless_certificates/methods/edit)

PATCH/zones/{zone\_id}/keyless\_certificates/{keyless\_certificate\_id}

##### [Delete Keyless SSL Configuration](https://developers.cloudflare.com/api/resources/keyless_certificates/methods/delete)

DELETE/zones/{zone\_id}/keyless\_certificates/{keyless\_certificate\_id}

#### Logpush

#### LogpushDatasets

#### LogpushDatasetsFields

##### [List fields](https://developers.cloudflare.com/api/resources/logpush/subresources/datasets/subresources/fields/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/datasets/{dataset\_id}/fields

#### LogpushDatasetsJobs

##### [List Logpush jobs for a dataset](https://developers.cloudflare.com/api/resources/logpush/subresources/datasets/subresources/jobs/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/datasets/{dataset\_id}/jobs

#### LogpushEdge

##### [List Instant Logs jobs](https://developers.cloudflare.com/api/resources/logpush/subresources/edge/methods/get)

GET/zones/{zone\_id}/logpush/edge/jobs

##### [Create Instant Logs job](https://developers.cloudflare.com/api/resources/logpush/subresources/edge/methods/create)

POST/zones/{zone\_id}/logpush/edge/jobs

#### LogpushJobs

##### [List Logpush jobs](https://developers.cloudflare.com/api/resources/logpush/subresources/jobs/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/jobs

##### [Get Logpush job details](https://developers.cloudflare.com/api/resources/logpush/subresources/jobs/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/jobs/{job\_id}

##### [Create Logpush job](https://developers.cloudflare.com/api/resources/logpush/subresources/jobs/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/jobs

##### [Update Logpush job](https://developers.cloudflare.com/api/resources/logpush/subresources/jobs/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/jobs/{job\_id}

##### [Delete Logpush job](https://developers.cloudflare.com/api/resources/logpush/subresources/jobs/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/jobs/{job\_id}

#### LogpushOwnership

##### [Get ownership challenge](https://developers.cloudflare.com/api/resources/logpush/subresources/ownership/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/ownership

##### [Validate ownership challenge](https://developers.cloudflare.com/api/resources/logpush/subresources/ownership/methods/validate)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/ownership/validate

#### LogpushTransformers

##### [List transformers](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/methods/list)

GET/accounts/{account\_id}/logpush/transformers

##### [Get transformer](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/methods/get)

GET/accounts/{account\_id}/logpush/transformers/{transformer\_id}

##### [Create transformer](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/methods/create)

POST/accounts/{account\_id}/logpush/transformers

##### [Update transformer](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/methods/update)

PUT/accounts/{account\_id}/logpush/transformers/{transformer\_id}

##### [Delete transformer](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/methods/delete)

DELETE/accounts/{account\_id}/logpush/transformers/{transformer\_id}

##### [Preview transformer](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/methods/preview)

POST/accounts/{account\_id}/logpush/transformers/preview

#### LogpushTransformersContent

##### [Get transformer content](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/subresources/content/methods/get)

GET/accounts/{account\_id}/logpush/transformers/{transformer\_id}/content

#### LogpushTransformersVersions

##### [List transformer versions](https://developers.cloudflare.com/api/resources/logpush/subresources/transformers/subresources/versions/methods/list)

GET/accounts/{account\_id}/logpush/transformers/{transformer\_id}/versions

#### LogpushValidate

##### [Validate destination](https://developers.cloudflare.com/api/resources/logpush/subresources/validate/methods/destination)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/validate/destination

##### [Check destination exists](https://developers.cloudflare.com/api/resources/logpush/subresources/validate/methods/destination_exists)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/validate/destination/exists

##### [Validate origin](https://developers.cloudflare.com/api/resources/logpush/subresources/validate/methods/origin)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logpush/validate/origin

#### Logs

#### LogsLog Explorer

#### LogsLog ExplorerQuery

##### [Run a log query](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/query/methods/sql)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/query/sql

#### LogsLog ExplorerDatasets

##### [List account or zone datasets](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/datasets/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/datasets

##### [Get an account or zone dataset](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/datasets/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/datasets/{dataset\_id}

##### [Create an account or zone dataset](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/datasets/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/datasets

##### [Update an account or zone dataset](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/datasets/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/datasets/{dataset\_id}

##### [Delete an account or zone dataset](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/datasets/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/datasets/{dataset\_id}

#### LogsLog ExplorerDatasetsAvailable

##### [List available account or zone datasets](https://developers.cloudflare.com/api/resources/logs/subresources/log_explorer/subresources/datasets/subresources/available/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/logs/explorer/datasets/available

#### LogsControl

#### LogsControlRetention

##### [Get log retention flag](https://developers.cloudflare.com/api/resources/logs/subresources/control/subresources/retention/methods/get)

GET/zones/{zone\_id}/logs/control/retention/flag

##### [Update log retention flag](https://developers.cloudflare.com/api/resources/logs/subresources/control/subresources/retention/methods/create)

POST/zones/{zone\_id}/logs/control/retention/flag

#### LogsControlCmb

#### LogsControlCmbConfig

##### [Get CMB config](https://developers.cloudflare.com/api/resources/logs/subresources/control/subresources/cmb/subresources/config/methods/get)

GET/accounts/{account\_id}/logs/control/cmb/config

##### [Update CMB config](https://developers.cloudflare.com/api/resources/logs/subresources/control/subresources/cmb/subresources/config/methods/create)

POST/accounts/{account\_id}/logs/control/cmb/config

##### [Delete CMB config](https://developers.cloudflare.com/api/resources/logs/subresources/control/subresources/cmb/subresources/config/methods/delete)

DELETE/accounts/{account\_id}/logs/control/cmb/config

#### LogsRayID

##### [Get logs RayIDs](https://developers.cloudflare.com/api/resources/logs/subresources/rayid/methods/get)

GET/zones/{zone\_id}/logs/rayids/{ray\_id}

#### LogsReceived

##### [Get logs received](https://developers.cloudflare.com/api/resources/logs/subresources/received/methods/get)

GET/zones/{zone\_id}/logs/received

#### LogsReceivedFields

##### [List fields](https://developers.cloudflare.com/api/resources/logs/subresources/received/subresources/fields/methods/get)

GET/zones/{zone\_id}/logs/received/fields

#### Origin TLS Client Auth

##### [List Certificates](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/methods/list)

Deprecated

GET/zones/{zone\_id}/origin\_tls\_client\_auth

##### [Get Certificate Details](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/methods/get)

Deprecated

GET/zones/{zone\_id}/origin\_tls\_client\_auth/{certificate\_id}

##### [Upload Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/methods/create)

Deprecated

POST/zones/{zone\_id}/origin\_tls\_client\_auth

##### [Delete Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/methods/delete)

Deprecated

DELETE/zones/{zone\_id}/origin\_tls\_client\_auth/{certificate\_id}

#### Origin TLS Client AuthZone Certificates

##### [List Certificates](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/zone_certificates/methods/list)

GET/zones/{zone\_id}/origin\_tls\_client\_auth

##### [Get Certificate Details](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/zone_certificates/methods/get)

GET/zones/{zone\_id}/origin\_tls\_client\_auth/{certificate\_id}

##### [Upload Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/zone_certificates/methods/create)

POST/zones/{zone\_id}/origin\_tls\_client\_auth

##### [Delete Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/zone_certificates/methods/delete)

DELETE/zones/{zone\_id}/origin\_tls\_client\_auth/{certificate\_id}

#### Origin TLS Client AuthHostnames

##### [Get the Hostname Status for Client Authentication](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/hostnames/methods/get)

GET/zones/{zone\_id}/origin\_tls\_client\_auth/hostnames/{hostname}

##### [Enable or Disable a Hostname for Client Authentication](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/hostnames/methods/update)

PUT/zones/{zone\_id}/origin\_tls\_client\_auth/hostnames

#### Origin TLS Client AuthHostname Certificates

##### [List Certificates](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/hostname_certificates/methods/list)

GET/zones/{zone\_id}/origin\_tls\_client\_auth/hostnames/certificates

##### [Get the Hostname Client Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/hostname_certificates/methods/get)

GET/zones/{zone\_id}/origin\_tls\_client\_auth/hostnames/certificates/{certificate\_id}

##### [Upload a Hostname Client Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/hostname_certificates/methods/create)

POST/zones/{zone\_id}/origin\_tls\_client\_auth/hostnames/certificates

##### [Delete Hostname Client Certificate](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/hostname_certificates/methods/delete)

DELETE/zones/{zone\_id}/origin\_tls\_client\_auth/hostnames/certificates/{certificate\_id}

#### Origin TLS Client AuthSettings

##### [Get Enablement Setting for Zone](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/settings/methods/get)

GET/zones/{zone\_id}/origin\_tls\_client\_auth/settings

##### [Set Enablement for Zone](https://developers.cloudflare.com/api/resources/origin_tls_client_auth/subresources/settings/methods/update)

PUT/zones/{zone\_id}/origin\_tls\_client\_auth/settings

#### Page Rules

##### [List Page Rules](https://developers.cloudflare.com/api/resources/page_rules/methods/list)

GET/zones/{zone\_id}/pagerules

##### [Get a Page Rule](https://developers.cloudflare.com/api/resources/page_rules/methods/get)

GET/zones/{zone\_id}/pagerules/{pagerule\_id}

##### [Create a Page Rule](https://developers.cloudflare.com/api/resources/page_rules/methods/create)

POST/zones/{zone\_id}/pagerules

##### [Update a Page Rule](https://developers.cloudflare.com/api/resources/page_rules/methods/update)

PUT/zones/{zone\_id}/pagerules/{pagerule\_id}

##### [Edit a Page Rule](https://developers.cloudflare.com/api/resources/page_rules/methods/edit)

PATCH/zones/{zone\_id}/pagerules/{pagerule\_id}

##### [Delete a Page Rule](https://developers.cloudflare.com/api/resources/page_rules/methods/delete)

DELETE/zones/{zone\_id}/pagerules/{pagerule\_id}

#### Rate Limits

##### [List rate limits](https://developers.cloudflare.com/api/resources/rate_limits/methods/list)

Deprecated

GET/zones/{zone\_id}/rate\_limits

##### [Get a rate limit](https://developers.cloudflare.com/api/resources/rate_limits/methods/get)

Deprecated

GET/zones/{zone\_id}/rate\_limits/{rate\_limit\_id}

##### [Create a rate limit](https://developers.cloudflare.com/api/resources/rate_limits/methods/create)

Deprecated

POST/zones/{zone\_id}/rate\_limits

##### [Update a rate limit](https://developers.cloudflare.com/api/resources/rate_limits/methods/edit)

Deprecated

PUT/zones/{zone\_id}/rate\_limits/{rate\_limit\_id}

##### [Delete a rate limit](https://developers.cloudflare.com/api/resources/rate_limits/methods/delete)

Deprecated

DELETE/zones/{zone\_id}/rate\_limits/{rate\_limit\_id}

#### Smart Shield

##### [Get Smart Shield Settings](https://developers.cloudflare.com/api/resources/smart_shield/methods/get)

GET/zones/{zone\_id}/smart\_shield

##### [Patch Smart Shield Settings](https://developers.cloudflare.com/api/resources/smart_shield/methods/update)

PATCH/zones/{zone\_id}/smart\_shield

#### Smart ShieldHealth Checks

##### [List Health Checks](https://developers.cloudflare.com/api/resources/smart_shield/subresources/health_checks/methods/list)

GET/zones/{zone\_id}/smart\_shield/healthchecks

##### [Health Check Details](https://developers.cloudflare.com/api/resources/smart_shield/subresources/health_checks/methods/get)

GET/zones/{zone\_id}/smart\_shield/healthchecks/{healthcheck\_id}

##### [Create Health Check](https://developers.cloudflare.com/api/resources/smart_shield/subresources/health_checks/methods/create)

POST/zones/{zone\_id}/smart\_shield/healthchecks

##### [Update Health Check](https://developers.cloudflare.com/api/resources/smart_shield/subresources/health_checks/methods/update)

PUT/zones/{zone\_id}/smart\_shield/healthchecks/{healthcheck\_id}

##### [Patch Health Check](https://developers.cloudflare.com/api/resources/smart_shield/subresources/health_checks/methods/edit)

PATCH/zones/{zone\_id}/smart\_shield/healthchecks/{healthcheck\_id}

##### [Delete Health Check](https://developers.cloudflare.com/api/resources/smart_shield/subresources/health_checks/methods/delete)

DELETE/zones/{zone\_id}/smart\_shield/healthchecks/{healthcheck\_id}

#### Smart ShieldCache Reserve Clear

##### [Get Cache Reserve Clear](https://developers.cloudflare.com/api/resources/smart_shield/subresources/cache_reserve_clear/methods/status)

GET/zones/{zone\_id}/smart\_shield/cache\_reserve\_clear

##### [Start Cache Reserve Clear](https://developers.cloudflare.com/api/resources/smart_shield/subresources/cache_reserve_clear/methods/clear)

POST/zones/{zone\_id}/smart\_shield/cache\_reserve\_clear

#### Waiting Rooms

##### [List waiting rooms for account or zone](https://developers.cloudflare.com/api/resources/waiting_rooms/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/waiting\_rooms

##### [Waiting room details](https://developers.cloudflare.com/api/resources/waiting_rooms/methods/get)

GET/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}

##### [Create waiting room](https://developers.cloudflare.com/api/resources/waiting_rooms/methods/create)

POST/zones/{zone\_id}/waiting\_rooms

##### [Update waiting room](https://developers.cloudflare.com/api/resources/waiting_rooms/methods/update)

PUT/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}

##### [Patch waiting room](https://developers.cloudflare.com/api/resources/waiting_rooms/methods/edit)

PATCH/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}

##### [Delete waiting room](https://developers.cloudflare.com/api/resources/waiting_rooms/methods/delete)

DELETE/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}

#### Waiting RoomsPage

##### [Create a custom waiting room page preview](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/page/methods/preview)

POST/zones/{zone\_id}/waiting\_rooms/preview

#### Waiting RoomsEvents

##### [List events](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/methods/list)

GET/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events

##### [Event details](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/methods/get)

GET/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events/{event\_id}

##### [Create event](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/methods/create)

POST/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events

##### [Update event](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/methods/update)

PUT/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events/{event\_id}

##### [Patch event](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/methods/edit)

PATCH/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events/{event\_id}

##### [Delete event](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/methods/delete)

DELETE/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events/{event\_id}

#### Waiting RoomsEventsDetails

##### [Preview active event details](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/events/subresources/details/methods/get)

GET/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/events/{event\_id}/details

#### Waiting RoomsRules

##### [List Waiting Room Rules](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/rules/methods/get)

GET/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/rules

##### [Create Waiting Room Rule](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/rules/methods/create)

POST/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/rules

##### [Replace Waiting Room Rules](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/rules/methods/update)

PUT/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/rules

##### [Patch Waiting Room Rule](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/rules/methods/edit)

PATCH/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/rules/{rule\_id}

##### [Delete Waiting Room Rule](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/rules/methods/delete)

DELETE/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/rules/{rule\_id}

#### Waiting RoomsStatuses

##### [Get waiting room status](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/statuses/methods/get)

GET/zones/{zone\_id}/waiting\_rooms/{waiting\_room\_id}/status

#### Waiting RoomsSettings

##### [Get zone-level Waiting Room settings](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/settings/methods/get)

GET/zones/{zone\_id}/waiting\_rooms/settings

##### [Update zone-level Waiting Room settings](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/settings/methods/update)

PUT/zones/{zone\_id}/waiting\_rooms/settings

##### [Patch zone-level Waiting Room settings](https://developers.cloudflare.com/api/resources/waiting_rooms/subresources/settings/methods/edit)

PATCH/zones/{zone\_id}/waiting\_rooms/settings

#### Web3

#### Web3Hostnames

##### [List Web3 Hostnames](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/methods/list)

GET/zones/{zone\_id}/web3/hostnames

##### [Web3 Hostname Details](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/methods/get)

GET/zones/{zone\_id}/web3/hostnames/{identifier}

##### [Create Web3 Hostname](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/methods/create)

POST/zones/{zone\_id}/web3/hostnames

##### [Edit Web3 Hostname](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/methods/edit)

PATCH/zones/{zone\_id}/web3/hostnames/{identifier}

##### [Delete Web3 Hostname](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/methods/delete)

DELETE/zones/{zone\_id}/web3/hostnames/{identifier}

#### Web3HostnamesIPFS Universal Paths

#### Web3HostnamesIPFS Universal PathsContent Lists

##### [IPFS Universal Path Gateway Content List Details](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/methods/get)

GET/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list

##### [Update IPFS Universal Path Gateway Content List](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/methods/update)

PUT/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list

#### Web3HostnamesIPFS Universal PathsContent ListsEntries

##### [List IPFS Universal Path Gateway Content List Entries](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/subresources/entries/methods/list)

GET/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list/entries

##### [IPFS Universal Path Gateway Content List Entry Details](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/subresources/entries/methods/get)

GET/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list/entries/{content\_list\_entry\_identifier}

##### [Create IPFS Universal Path Gateway Content List Entry](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/subresources/entries/methods/create)

POST/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list/entries

##### [Edit IPFS Universal Path Gateway Content List Entry](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/subresources/entries/methods/update)

PUT/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list/entries/{content\_list\_entry\_identifier}

##### [Delete IPFS Universal Path Gateway Content List Entry](https://developers.cloudflare.com/api/resources/web3/subresources/hostnames/subresources/ipfs_universal_paths/subresources/content_lists/subresources/entries/methods/delete)

DELETE/zones/{zone\_id}/web3/hostnames/{identifier}/ipfs\_universal\_path/content\_list/entries/{content\_list\_entry\_identifier}

#### Workers

#### WorkersBeta

#### WorkersBetaWorkers

##### [List Workers](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/list)

GET/accounts/{account\_id}/workers/workers

##### [Get Worker](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/get)

GET/accounts/{account\_id}/workers/workers/{worker\_id}

##### [Create Worker](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/create)

POST/accounts/{account\_id}/workers/workers

##### [Update Worker](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/update)

PUT/accounts/{account\_id}/workers/workers/{worker\_id}

##### [Edit Worker](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/edit)

PATCH/accounts/{account\_id}/workers/workers/{worker\_id}

##### [Delete Worker](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/delete)

DELETE/accounts/{account\_id}/workers/workers/{worker\_id}

#### WorkersBetaWorkersVersions

##### [List Worker Versions](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/subresources/versions/methods/list)

GET/accounts/{account\_id}/workers/workers/{worker\_id}/versions

##### [Get Worker Version](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/subresources/versions/methods/get)

GET/accounts/{account\_id}/workers/workers/{worker\_id}/versions/{version\_id}

##### [Create Worker Version](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/subresources/versions/methods/create)

POST/accounts/{account\_id}/workers/workers/{worker\_id}/versions

##### [Delete Worker Version](https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/subresources/versions/methods/delete)

DELETE/accounts/{account\_id}/workers/workers/{worker\_id}/versions/{version\_id}

#### WorkersRoutes

##### [List Worker Routes](https://developers.cloudflare.com/api/resources/workers/subresources/routes/methods/list)

GET/zones/{zone\_id}/workers/routes

##### [Get Worker Route](https://developers.cloudflare.com/api/resources/workers/subresources/routes/methods/get)

GET/zones/{zone\_id}/workers/routes/{route\_id}

##### [Create Worker Route](https://developers.cloudflare.com/api/resources/workers/subresources/routes/methods/create)

POST/zones/{zone\_id}/workers/routes

##### [Replace Worker Route](https://developers.cloudflare.com/api/resources/workers/subresources/routes/methods/update)

PUT/zones/{zone\_id}/workers/routes/{route\_id}

##### [Delete Worker Route](https://developers.cloudflare.com/api/resources/workers/subresources/routes/methods/delete)

DELETE/zones/{zone\_id}/workers/routes/{route\_id}

#### WorkersAssets

#### WorkersAssetsUpload

##### [Upload Worker Assets](https://developers.cloudflare.com/api/resources/workers/subresources/assets/subresources/upload/methods/create)

POST/accounts/{account\_id}/workers/assets/upload

#### WorkersScripts

##### [List Worker Scripts](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/methods/list)

GET/accounts/{account\_id}/workers/scripts

##### [Search Worker Scripts](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/methods/search)

GET/accounts/{account\_id}/workers/scripts-search

##### [Download Worker Script](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}

##### [Upload Worker Module](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/methods/update)

PUT/accounts/{account\_id}/workers/scripts/{script\_name}

##### [Delete Worker](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/methods/delete)

DELETE/accounts/{account\_id}/workers/scripts/{script\_name}

#### WorkersScriptsAssets

#### WorkersScriptsAssetsUpload

##### [Create Worker Assets Upload Session](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/assets/subresources/upload/methods/create)

POST/accounts/{account\_id}/workers/scripts/{script\_name}/assets-upload-session

#### WorkersScriptsSubdomain

##### [Get Worker Script Subdomain](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/subdomain/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/subdomain

##### [Update Worker Script Subdomain](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/subdomain/methods/create)

POST/accounts/{account\_id}/workers/scripts/{script\_name}/subdomain

##### [Delete Worker Script Subdomain](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/subdomain/methods/delete)

DELETE/accounts/{account\_id}/workers/scripts/{script\_name}/subdomain

#### WorkersScriptsSchedules

##### [Get Worker Script Schedules (Cron Triggers)](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/schedules/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/schedules

##### [Update Worker Script Schedules (Cron Triggers)](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/schedules/methods/update)

PUT/accounts/{account\_id}/workers/scripts/{script\_name}/schedules

#### WorkersScriptsTail

##### [List Worker Tails](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/tail/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/tails

##### [Start Worker Tail](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/tail/methods/create)

POST/accounts/{account\_id}/workers/scripts/{script\_name}/tails

##### [Delete Worker Tail](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/tail/methods/delete)

DELETE/accounts/{account\_id}/workers/scripts/{script\_name}/tails/{id}

#### WorkersScriptsContent

##### [Get Worker Script Content](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/content/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/content/v2

##### [Replace Worker Script Content](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/content/methods/update)

PUT/accounts/{account\_id}/workers/scripts/{script\_name}/content

#### WorkersScriptsSettings

##### [Get Worker Script Settings](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/settings/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/script-settings

##### [Patch Worker Script Settings](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/settings/methods/edit)

PATCH/accounts/{account\_id}/workers/scripts/{script\_name}/script-settings

#### WorkersScriptsDeployments

##### [List Worker Deployments](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/deployments/methods/list)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/deployments

##### [Create Worker Deployment](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/deployments/methods/create)

POST/accounts/{account\_id}/workers/scripts/{script\_name}/deployments

##### [Get Worker Deployment](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/deployments/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/deployments/{deployment\_id}

##### [Delete Worker Deployment](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/deployments/methods/delete)

DELETE/accounts/{account\_id}/workers/scripts/{script\_name}/deployments/{deployment\_id}

#### WorkersScriptsVersions

##### [List Versions](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/versions/methods/list)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/versions

##### [Get Worker Script Version](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/versions/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/versions/{version\_id}

##### [Upload Version](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/versions/methods/create)

POST/accounts/{account\_id}/workers/scripts/{script\_name}/versions

#### WorkersScriptsSecrets

##### [List secrets bound to a Worker script](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/secrets/methods/list)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/secrets

##### [Get a secret binding](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/secrets/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/secrets/{secret\_name}

##### [Add a secret to a Worker script](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/secrets/methods/update)

PUT/accounts/{account\_id}/workers/scripts/{script\_name}/secrets

##### [Delete Worker script secret](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/secrets/methods/delete)

DELETE/accounts/{account\_id}/workers/scripts/{script\_name}/secrets/{secret\_name}

##### [Patch multiple Worker script secrets](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/secrets/methods/bulk_update)

PATCH/accounts/{account\_id}/workers/scripts/{script\_name}/secrets-bulk

#### WorkersScriptsScript And Version Settings

##### [Get Worker Script and Version Settings](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/script_and_version_settings/methods/get)

GET/accounts/{account\_id}/workers/scripts/{script\_name}/settings

##### [Patch Worker Script and Version Settings](https://developers.cloudflare.com/api/resources/workers/subresources/scripts/subresources/script_and_version_settings/methods/edit)

PATCH/accounts/{account\_id}/workers/scripts/{script\_name}/settings

#### WorkersAccount Settings

##### [Fetch Workers Account Settings](https://developers.cloudflare.com/api/resources/workers/subresources/account_settings/methods/get)

GET/accounts/{account\_id}/workers/account-settings

##### [Configure Workers Account Settings](https://developers.cloudflare.com/api/resources/workers/subresources/account_settings/methods/update)

PUT/accounts/{account\_id}/workers/account-settings

#### WorkersDomains

##### [List Worker Domains](https://developers.cloudflare.com/api/resources/workers/subresources/domains/methods/list)

GET/accounts/{account\_id}/workers/domains

##### [Get Worker Domain](https://developers.cloudflare.com/api/resources/workers/subresources/domains/methods/get)

GET/accounts/{account\_id}/workers/domains/{domain\_id}

##### [Attach Worker Domain](https://developers.cloudflare.com/api/resources/workers/subresources/domains/methods/update)

PUT/accounts/{account\_id}/workers/domains

##### [Detach Worker Domain](https://developers.cloudflare.com/api/resources/workers/subresources/domains/methods/delete)

DELETE/accounts/{account\_id}/workers/domains/{domain\_id}

#### WorkersSubdomains

##### [Get a Workers Subdomain](https://developers.cloudflare.com/api/resources/workers/subresources/subdomains/methods/get)

GET/accounts/{account\_id}/workers/subdomain

##### [Create a Workers Subdomain](https://developers.cloudflare.com/api/resources/workers/subresources/subdomains/methods/update)

PUT/accounts/{account\_id}/workers/subdomain

##### [Delete Workers Subdomain](https://developers.cloudflare.com/api/resources/workers/subresources/subdomains/methods/delete)

DELETE/accounts/{account\_id}/workers/subdomain

#### WorkersObservability

#### WorkersObservabilityTelemetry

##### [List keys](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/telemetry/methods/keys)

POST/accounts/{account\_id}/workers/observability/telemetry/keys

##### [Run a query](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/telemetry/methods/query)

POST/accounts/{account\_id}/workers/observability/telemetry/query

##### [List values](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/telemetry/methods/values)

POST/accounts/{account\_id}/workers/observability/telemetry/values

##### [Prepare live tail](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/telemetry/methods/live_tail)

POST/accounts/{account\_id}/workers/observability/telemetry/live-tail

##### [Live tail heartbeat](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/telemetry/methods/live_tail_heartbeat)

POST/accounts/{account\_id}/workers/observability/telemetry/live-tail/heartbeat

#### WorkersObservabilityDestinations

##### [Get Destinations](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/destinations/methods/list)

GET/accounts/{account\_id}/workers/observability/destinations

##### [Create Destination](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/destinations/methods/create)

POST/accounts/{account\_id}/workers/observability/destinations

##### [Update Destination](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/destinations/methods/update)

PATCH/accounts/{account\_id}/workers/observability/destinations/{slug}

##### [Delete Destination](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/destinations/methods/delete)

DELETE/accounts/{account\_id}/workers/observability/destinations/{slug}

#### WorkersObservabilityQueries

##### [Save query](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/queries/methods/create)

POST/accounts/{account\_id}/workers/observability/queries

##### [List queries](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/queries/methods/list)

GET/accounts/{account\_id}/workers/observability/queries

#### WorkersObservabilityShared Queries

##### [Create a sharable link to a query result](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/shared_queries/methods/create)

POST/accounts/{account\_id}/workers/observability/shared/query

##### [View a query that has been shared](https://developers.cloudflare.com/api/resources/workers/subresources/observability/subresources/shared_queries/methods/get)

GET/accounts/{account\_id}/workers/observability/shared/query/{id}

#### KV

#### KVNamespaces

##### [List Namespaces](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/list)

GET/accounts/{account\_id}/storage/kv/namespaces

##### [Get a Namespace](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/get)

GET/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}

##### [Create a Namespace](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/create)

POST/accounts/{account\_id}/storage/kv/namespaces

##### [Rename a Namespace](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/update)

PUT/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}

##### [Remove a Namespace](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/delete)

DELETE/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}

##### [Write multiple key-value pairs](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/bulk_update)

PUT/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/bulk

##### [Delete multiple key-value pairs](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/bulk_delete)

POST/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/bulk/delete

##### [Get multiple key-value pairs](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/methods/bulk_get)

POST/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/bulk/get

#### KVNamespacesKeys

##### [List a Namespace's Keys](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/keys/methods/list)

GET/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/keys

##### [Write multiple key-value pairs](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/keys/methods/bulk_update)

Deprecated

PUT/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/bulk

##### [Delete multiple key-value pairs](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/keys/methods/bulk_delete)

Deprecated

POST/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/bulk/delete

##### [Get multiple key-value pairs](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/keys/methods/bulk_get)

Deprecated

POST/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/bulk/get

#### KVNamespacesMetadata

##### [Read the metadata for a key](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/metadata/methods/get)

GET/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/metadata/{key\_name}

#### KVNamespacesValues

##### [Read key-value pair](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/values/methods/get)

GET/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/values/{key\_name}

##### [Write key-value pair with optional metadata](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/values/methods/update)

PUT/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/values/{key\_name}

##### [Delete key-value pair](https://developers.cloudflare.com/api/resources/kv/subresources/namespaces/subresources/values/methods/delete)

DELETE/accounts/{account\_id}/storage/kv/namespaces/{namespace\_id}/values/{key\_name}

#### Durable Objects

#### Durable ObjectsNamespaces

##### [List Durable Object Namespaces](https://developers.cloudflare.com/api/resources/durable_objects/subresources/namespaces/methods/list)

GET/accounts/{account\_id}/workers/durable\_objects/namespaces

#### Durable ObjectsNamespacesObjects

##### [List Objects in a Durable Object namespace](https://developers.cloudflare.com/api/resources/durable_objects/subresources/namespaces/subresources/objects/methods/list)

GET/accounts/{account\_id}/workers/durable\_objects/namespaces/{id}/objects

#### Queues

##### [List Queues](https://developers.cloudflare.com/api/resources/queues/methods/list)

GET/accounts/{account\_id}/queues

##### [Get Queue](https://developers.cloudflare.com/api/resources/queues/methods/get)

GET/accounts/{account\_id}/queues/{queue\_id}

##### [Get Queue Metrics](https://developers.cloudflare.com/api/resources/queues/methods/get_metrics)

GET/accounts/{account\_id}/queues/{queue\_id}/metrics

##### [Create Queue](https://developers.cloudflare.com/api/resources/queues/methods/create)

POST/accounts/{account\_id}/queues

##### [Update Queue](https://developers.cloudflare.com/api/resources/queues/methods/update)

PUT/accounts/{account\_id}/queues/{queue\_id}

##### [Update Queue](https://developers.cloudflare.com/api/resources/queues/methods/edit)

PATCH/accounts/{account\_id}/queues/{queue\_id}

##### [Delete Queue](https://developers.cloudflare.com/api/resources/queues/methods/delete)

DELETE/accounts/{account\_id}/queues/{queue\_id}

#### QueuesMessages

##### [Push Message](https://developers.cloudflare.com/api/resources/queues/subresources/messages/methods/push)

POST/accounts/{account\_id}/queues/{queue\_id}/messages

##### [Acknowledge + Retry Queue Messages](https://developers.cloudflare.com/api/resources/queues/subresources/messages/methods/ack)

POST/accounts/{account\_id}/queues/{queue\_id}/messages/ack

##### [Pull Queue Messages](https://developers.cloudflare.com/api/resources/queues/subresources/messages/methods/pull)

POST/accounts/{account\_id}/queues/{queue\_id}/messages/pull

##### [Push Message Batch](https://developers.cloudflare.com/api/resources/queues/subresources/messages/methods/bulk_push)

POST/accounts/{account\_id}/queues/{queue\_id}/messages/batch

##### [Peek Queue Messages](https://developers.cloudflare.com/api/resources/queues/subresources/messages/methods/peek)

POST/accounts/{account\_id}/queues/{queue\_id}/messages/peek

##### [Purge Peeked Queue Messages](https://developers.cloudflare.com/api/resources/queues/subresources/messages/methods/purge)

POST/accounts/{account\_id}/queues/{queue\_id}/messages/purge

#### QueuesPurge

##### [Get Queue Purge Status](https://developers.cloudflare.com/api/resources/queues/subresources/purge/methods/status)

GET/accounts/{account\_id}/queues/{queue\_id}/purge

##### [Purge Queue](https://developers.cloudflare.com/api/resources/queues/subresources/purge/methods/start)

POST/accounts/{account\_id}/queues/{queue\_id}/purge

#### QueuesConsumers

##### [List Queue Consumers](https://developers.cloudflare.com/api/resources/queues/subresources/consumers/methods/list)

GET/accounts/{account\_id}/queues/{queue\_id}/consumers

##### [Get Queue Consumer](https://developers.cloudflare.com/api/resources/queues/subresources/consumers/methods/get)

GET/accounts/{account\_id}/queues/{queue\_id}/consumers/{consumer\_id}

##### [Create a Queue Consumer](https://developers.cloudflare.com/api/resources/queues/subresources/consumers/methods/create)

POST/accounts/{account\_id}/queues/{queue\_id}/consumers

##### [Update Queue Consumer](https://developers.cloudflare.com/api/resources/queues/subresources/consumers/methods/update)

PUT/accounts/{account\_id}/queues/{queue\_id}/consumers/{consumer\_id}

##### [Delete Queue Consumer](https://developers.cloudflare.com/api/resources/queues/subresources/consumers/methods/delete)

DELETE/accounts/{account\_id}/queues/{queue\_id}/consumers/{consumer\_id}

#### QueuesSubscriptions

##### [List Event Subscriptions](https://developers.cloudflare.com/api/resources/queues/subresources/subscriptions/methods/list)

GET/accounts/{account\_id}/event\_subscriptions/subscriptions

##### [Get Event Subscription](https://developers.cloudflare.com/api/resources/queues/subresources/subscriptions/methods/get)

GET/accounts/{account\_id}/event\_subscriptions/subscriptions/{subscription\_id}

##### [Create Event Subscription](https://developers.cloudflare.com/api/resources/queues/subresources/subscriptions/methods/create)

POST/accounts/{account\_id}/event\_subscriptions/subscriptions

##### [Update Event Subscription](https://developers.cloudflare.com/api/resources/queues/subresources/subscriptions/methods/update)

PATCH/accounts/{account\_id}/event\_subscriptions/subscriptions/{subscription\_id}

##### [Delete Event Subscription](https://developers.cloudflare.com/api/resources/queues/subresources/subscriptions/methods/delete)

DELETE/accounts/{account\_id}/event\_subscriptions/subscriptions/{subscription\_id}

#### API Gateway

#### API GatewayConfigurations

##### [Get session identifier settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/configurations/methods/get)

GET/zones/{zone\_id}/api\_gateway/configuration

##### [Update session identifier settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/configurations/methods/update)

PUT/zones/{zone\_id}/api\_gateway/configuration

#### API GatewayDiscovery

##### [Export discovered API operations as OpenAPI schemas](https://developers.cloudflare.com/api/resources/api_gateway/subresources/discovery/methods/get)

GET/zones/{zone\_id}/api\_gateway/discovery

#### API GatewayDiscoveryOperations

##### [List discovered web and API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/discovery/subresources/operations/methods/list)

GET/zones/{zone\_id}/api\_gateway/discovery/operations

##### [Edit discovered web and API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/discovery/subresources/operations/methods/bulk_edit)

PATCH/zones/{zone\_id}/api\_gateway/discovery/operations

#### API GatewayLabels

##### [List operation labels](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/methods/list)

GET/zones/{zone\_id}/api\_gateway/labels

#### API GatewayLabelsUser

##### [Create user-defined operation labels](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/methods/bulk_create)

POST/zones/{zone\_id}/api\_gateway/labels/user

##### [Delete user-defined operation labels](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/methods/bulk_delete)

DELETE/zones/{zone\_id}/api\_gateway/labels/user

##### [Get a user-defined operation label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/methods/get)

GET/zones/{zone\_id}/api\_gateway/labels/user/{name}

##### [Update a user-defined operation label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/methods/update)

PUT/zones/{zone\_id}/api\_gateway/labels/user/{name}

##### [Edit a user-defined operation label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/methods/edit)

PATCH/zones/{zone\_id}/api\_gateway/labels/user/{name}

##### [Delete a user-defined operation label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/methods/delete)

DELETE/zones/{zone\_id}/api\_gateway/labels/user/{name}

#### API GatewayLabelsUserResources

#### API GatewayLabelsUserResourcesOperation

##### [Replace operations attached to a user-defined label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/user/subresources/resources/subresources/operation/methods/update)

PUT/zones/{zone\_id}/api\_gateway/labels/user/{name}/resources/operation

#### API GatewayLabelsManaged

##### [Get a managed operation label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/managed/methods/get)

GET/zones/{zone\_id}/api\_gateway/labels/managed/{name}

#### API GatewayLabelsManagedResources

#### API GatewayLabelsManagedResourcesOperation

##### [Replace operations attached to a managed label](https://developers.cloudflare.com/api/resources/api_gateway/subresources/labels/subresources/managed/subresources/resources/subresources/operation/methods/update)

PUT/zones/{zone\_id}/api\_gateway/labels/managed/{name}/resources/operation

#### API GatewayOperations

##### [List web and API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/methods/list)

GET/zones/{zone\_id}/api\_gateway/operations

##### [Get a web or API operation](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/methods/get)

GET/zones/{zone\_id}/api\_gateway/operations/{operation\_id}

##### [Create a web or API operation](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/methods/create)

POST/zones/{zone\_id}/api\_gateway/operations/item

##### [Delete a web or API operation](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/methods/delete)

DELETE/zones/{zone\_id}/api\_gateway/operations/{operation\_id}

##### [Create web or API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/methods/bulk_create)

POST/zones/{zone\_id}/api\_gateway/operations

##### [Delete web or API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/methods/bulk_delete)

DELETE/zones/{zone\_id}/api\_gateway/operations

#### API GatewayOperationsLabels

##### [Replace labels on a web or API operation](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/labels/methods/update)

PUT/zones/{zone\_id}/api\_gateway/operations/{operation\_id}/labels

##### [Attach labels to a web or API operation](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/labels/methods/create)

POST/zones/{zone\_id}/api\_gateway/operations/{operation\_id}/labels

##### [Remove labels from a web or API operation](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/labels/methods/delete)

DELETE/zones/{zone\_id}/api\_gateway/operations/{operation\_id}/labels

##### [Replace labels on web or API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/labels/methods/bulk_update)

PUT/zones/{zone\_id}/api\_gateway/operations/labels

##### [Attach labels to web or API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/labels/methods/bulk_create)

POST/zones/{zone\_id}/api\_gateway/operations/labels

##### [Remove labels from web or API operations](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/labels/methods/bulk_delete)

DELETE/zones/{zone\_id}/api\_gateway/operations/labels

#### API GatewayOperationsSchema Validation

##### [Retrieve operation-level schema validation settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/schema_validation/methods/get)

Deprecated

GET/zones/{zone\_id}/api\_gateway/operations/{operation\_id}/schema\_validation

##### [Update operation-level schema validation settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/schema_validation/methods/update)

Deprecated

PUT/zones/{zone\_id}/api\_gateway/operations/{operation\_id}/schema\_validation

##### [Update multiple operation-level schema validation settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/operations/subresources/schema_validation/methods/edit)

Deprecated

PATCH/zones/{zone\_id}/api\_gateway/operations/schema\_validation

#### API GatewaySchemas

##### [Export web and API operations as OpenAPI schemas](https://developers.cloudflare.com/api/resources/api_gateway/subresources/schemas/methods/list)

GET/zones/{zone\_id}/api\_gateway/schemas

#### API GatewaySettings

#### API GatewaySettingsSchema Validation

##### [Retrieve zone level schema validation settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/settings/subresources/schema_validation/methods/get)

Deprecated

GET/zones/{zone\_id}/api\_gateway/settings/schema\_validation

##### [Update zone level schema validation settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/settings/subresources/schema_validation/methods/update)

Deprecated

PUT/zones/{zone\_id}/api\_gateway/settings/schema\_validation

##### [Update zone level schema validation settings](https://developers.cloudflare.com/api/resources/api_gateway/subresources/settings/subresources/schema_validation/methods/edit)

Deprecated

PATCH/zones/{zone\_id}/api\_gateway/settings/schema\_validation

#### API GatewayUser Schemas

##### [Retrieve information about all schemas on a zone](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/methods/list)

Deprecated

GET/zones/{zone\_id}/api\_gateway/user\_schemas

##### [Retrieve information about a specific schema on a zone](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/methods/get)

Deprecated

GET/zones/{zone\_id}/api\_gateway/user\_schemas/{schema\_id}

##### [Upload a legacy schema](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/methods/create)

Deprecated

POST/zones/{zone\_id}/api\_gateway/user\_schemas

##### [Enable validation for a schema](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/methods/edit)

Deprecated

PATCH/zones/{zone\_id}/api\_gateway/user\_schemas/{schema\_id}

##### [Delete a schema](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/methods/delete)

Deprecated

DELETE/zones/{zone\_id}/api\_gateway/user\_schemas/{schema\_id}

#### API GatewayUser SchemasOperations

##### [Retrieve all operations from a schema](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/subresources/operations/methods/list)

Deprecated

GET/zones/{zone\_id}/api\_gateway/user\_schemas/{schema\_id}/operations

#### API GatewayUser SchemasHosts

##### [Retrieve schema hosts in a zone](https://developers.cloudflare.com/api/resources/api_gateway/subresources/user_schemas/subresources/hosts/methods/list)

Deprecated

GET/zones/{zone\_id}/api\_gateway/user\_schemas/hosts

#### API GatewayExpression Template

#### API GatewayExpression TemplateFallthrough

##### [Generate a fallthrough WAF expression template](https://developers.cloudflare.com/api/resources/api_gateway/subresources/expression_template/subresources/fallthrough/methods/create)

Deprecated

POST/zones/{zone\_id}/api\_gateway/expression-template/fallthrough

#### Managed Transforms

##### [List Managed Transforms](https://developers.cloudflare.com/api/resources/managed_transforms/methods/list)

GET/zones/{zone\_id}/managed\_headers

##### [Update Managed Transforms](https://developers.cloudflare.com/api/resources/managed_transforms/methods/edit)

PATCH/zones/{zone\_id}/managed\_headers

##### [Delete Managed Transforms](https://developers.cloudflare.com/api/resources/managed_transforms/methods/delete)

DELETE/zones/{zone\_id}/managed\_headers

#### Page Shield

##### [Get client-side security settings](https://developers.cloudflare.com/api/resources/page_shield/methods/get)

GET/zones/{zone\_id}/page\_shield

##### [Update client-side security settings](https://developers.cloudflare.com/api/resources/page_shield/methods/update)

PUT/zones/{zone\_id}/page\_shield

#### Page ShieldPolicies

##### [List content security rules](https://developers.cloudflare.com/api/resources/page_shield/subresources/policies/methods/list)

GET/zones/{zone\_id}/page\_shield/policies

##### [Get a content security rule](https://developers.cloudflare.com/api/resources/page_shield/subresources/policies/methods/get)

GET/zones/{zone\_id}/page\_shield/policies/{policy\_id}

##### [Create a content security rule](https://developers.cloudflare.com/api/resources/page_shield/subresources/policies/methods/create)

POST/zones/{zone\_id}/page\_shield/policies

##### [Update a content security rule](https://developers.cloudflare.com/api/resources/page_shield/subresources/policies/methods/update)

PUT/zones/{zone\_id}/page\_shield/policies/{policy\_id}

##### [Delete a content security rule](https://developers.cloudflare.com/api/resources/page_shield/subresources/policies/methods/delete)

DELETE/zones/{zone\_id}/page\_shield/policies/{policy\_id}

#### Page ShieldConnections

##### [List detected connections](https://developers.cloudflare.com/api/resources/page_shield/subresources/connections/methods/list)

GET/zones/{zone\_id}/page\_shield/connections

##### [Get a detected connection](https://developers.cloudflare.com/api/resources/page_shield/subresources/connections/methods/get)

GET/zones/{zone\_id}/page\_shield/connections/{connection\_id}

#### Page ShieldScripts

##### [List detected scripts](https://developers.cloudflare.com/api/resources/page_shield/subresources/scripts/methods/list)

GET/zones/{zone\_id}/page\_shield/scripts

##### [Get a detected script](https://developers.cloudflare.com/api/resources/page_shield/subresources/scripts/methods/get)

GET/zones/{zone\_id}/page\_shield/scripts/{script\_id}

#### Page ShieldCookies

##### [List detected cookies](https://developers.cloudflare.com/api/resources/page_shield/subresources/cookies/methods/list)

GET/zones/{zone\_id}/page\_shield/cookies

##### [Get a detected cookie](https://developers.cloudflare.com/api/resources/page_shield/subresources/cookies/methods/get)

GET/zones/{zone\_id}/page\_shield/cookies/{cookie\_id}

#### Rulesets

##### [List account or zone rulesets](https://developers.cloudflare.com/api/resources/rulesets/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets

##### [Get an account or zone ruleset](https://developers.cloudflare.com/api/resources/rulesets/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}

##### [Create an account or zone ruleset](https://developers.cloudflare.com/api/resources/rulesets/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets

##### [Update an account or zone ruleset](https://developers.cloudflare.com/api/resources/rulesets/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}

##### [Delete an account or zone ruleset](https://developers.cloudflare.com/api/resources/rulesets/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}

#### RulesetsPhases

##### [Get an account or zone entry point ruleset](https://developers.cloudflare.com/api/resources/rulesets/subresources/phases/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/phases/{ruleset\_phase}/entrypoint

##### [Update an account or zone entry point ruleset](https://developers.cloudflare.com/api/resources/rulesets/subresources/phases/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/phases/{ruleset\_phase}/entrypoint

#### RulesetsPhasesVersions

##### [List an account or zone entry point ruleset's versions](https://developers.cloudflare.com/api/resources/rulesets/subresources/phases/subresources/versions/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/phases/{ruleset\_phase}/entrypoint/versions

##### [Get an account or zone entry point ruleset version](https://developers.cloudflare.com/api/resources/rulesets/subresources/phases/subresources/versions/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/phases/{ruleset\_phase}/entrypoint/versions/{ruleset\_version}

#### RulesetsRules

##### [Create an account or zone ruleset rule](https://developers.cloudflare.com/api/resources/rulesets/subresources/rules/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}/rules

##### [Update an account or zone ruleset rule](https://developers.cloudflare.com/api/resources/rulesets/subresources/rules/methods/edit)

PATCH/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}/rules/{rule\_id}

##### [Delete an account or zone ruleset rule](https://developers.cloudflare.com/api/resources/rulesets/subresources/rules/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}/rules/{rule\_id}

#### RulesetsVersions

##### [List an account or zone ruleset's versions](https://developers.cloudflare.com/api/resources/rulesets/subresources/versions/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}/versions

##### [Get an account or zone ruleset version](https://developers.cloudflare.com/api/resources/rulesets/subresources/versions/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}/versions/{ruleset\_version}

##### [Delete an account or zone ruleset version](https://developers.cloudflare.com/api/resources/rulesets/subresources/versions/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/rulesets/{ruleset\_id}/versions/{ruleset\_version}

#### URL Normalization

##### [Get URL Normalization settings](https://developers.cloudflare.com/api/resources/url_normalization/methods/get)

GET/zones/{zone\_id}/url\_normalization

##### [Update URL Normalization settings](https://developers.cloudflare.com/api/resources/url_normalization/methods/update)

PUT/zones/{zone\_id}/url\_normalization

##### [Delete URL Normalization settings](https://developers.cloudflare.com/api/resources/url_normalization/methods/delete)

DELETE/zones/{zone\_id}/url\_normalization

#### Spectrum

#### SpectrumAnalytics

#### SpectrumAnalyticsAggregates

#### SpectrumAnalyticsAggregatesCurrents

##### [Get current aggregated analytics](https://developers.cloudflare.com/api/resources/spectrum/subresources/analytics/subresources/aggregates/subresources/currents/methods/get)

GET/zones/{zone\_id}/spectrum/analytics/aggregate/current

#### SpectrumAnalyticsEvents

#### SpectrumAnalyticsEventsBytimes

##### [Get analytics by time](https://developers.cloudflare.com/api/resources/spectrum/subresources/analytics/subresources/events/subresources/bytimes/methods/get)

GET/zones/{zone\_id}/spectrum/analytics/events/bytime

#### SpectrumAnalyticsEventsSummaries

##### [Get analytics summary](https://developers.cloudflare.com/api/resources/spectrum/subresources/analytics/subresources/events/subresources/summaries/methods/get)

GET/zones/{zone\_id}/spectrum/analytics/events/summary

#### SpectrumApps

##### [List Spectrum applications](https://developers.cloudflare.com/api/resources/spectrum/subresources/apps/methods/list)

GET/zones/{zone\_id}/spectrum/apps

##### [Get Spectrum application configuration](https://developers.cloudflare.com/api/resources/spectrum/subresources/apps/methods/get)

GET/zones/{zone\_id}/spectrum/apps/{app\_id}

##### [Create Spectrum application using a name for the origin](https://developers.cloudflare.com/api/resources/spectrum/subresources/apps/methods/create)

POST/zones/{zone\_id}/spectrum/apps

##### [Update Spectrum application configuration using a name for the origin](https://developers.cloudflare.com/api/resources/spectrum/subresources/apps/methods/update)

PUT/zones/{zone\_id}/spectrum/apps/{app\_id}

##### [Delete Spectrum application](https://developers.cloudflare.com/api/resources/spectrum/subresources/apps/methods/delete)

DELETE/zones/{zone\_id}/spectrum/apps/{app\_id}

#### SpectrumProtocols

##### [List Spectrum application protocols](https://developers.cloudflare.com/api/resources/spectrum/subresources/protocols/methods/list)

GET/zones/{zone\_id}/spectrum/protocols

#### Addressing

#### AddressingRegional Hostnames

##### [List Regional Hostnames](https://developers.cloudflare.com/api/resources/addressing/subresources/regional_hostnames/methods/list)

GET/zones/{zone\_id}/addressing/regional\_hostnames

##### [Fetch Regional Hostname](https://developers.cloudflare.com/api/resources/addressing/subresources/regional_hostnames/methods/get)

GET/zones/{zone\_id}/addressing/regional\_hostnames/{hostname}

##### [Create Regional Hostname](https://developers.cloudflare.com/api/resources/addressing/subresources/regional_hostnames/methods/create)

POST/zones/{zone\_id}/addressing/regional\_hostnames

##### [Update Regional Hostname](https://developers.cloudflare.com/api/resources/addressing/subresources/regional_hostnames/methods/edit)

PATCH/zones/{zone\_id}/addressing/regional\_hostnames/{hostname}

##### [Delete Regional Hostname](https://developers.cloudflare.com/api/resources/addressing/subresources/regional_hostnames/methods/delete)

DELETE/zones/{zone\_id}/addressing/regional\_hostnames/{hostname}

#### AddressingRegional HostnamesRegions

##### [List Regions](https://developers.cloudflare.com/api/resources/addressing/subresources/regional_hostnames/subresources/regions/methods/list)

GET/accounts/{account\_id}/addressing/regional\_hostnames/regions

#### AddressingServices

##### [List Services](https://developers.cloudflare.com/api/resources/addressing/subresources/services/methods/list)

GET/accounts/{account\_id}/addressing/services

#### AddressingAddress Maps

##### [List Address Maps](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/methods/list)

GET/accounts/{account\_id}/addressing/address\_maps

##### [Address Map Details](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/methods/get)

GET/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}

##### [Create Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/methods/create)

POST/accounts/{account\_id}/addressing/address\_maps

##### [Update Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/methods/edit)

PATCH/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}

##### [Delete Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/methods/delete)

DELETE/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}

#### AddressingAddress MapsAccounts

##### [Add an account membership to an Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/subresources/accounts/methods/update)

PUT/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}/accounts/{member\_account\_id}

##### [Remove an account membership from an Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/subresources/accounts/methods/delete)

DELETE/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}/accounts/{member\_account\_id}

#### AddressingAddress MapsIPs

##### [Add an IP to an Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/subresources/ips/methods/update)

PUT/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}/ips/{ip\_address}

##### [Remove an IP from an Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/subresources/ips/methods/delete)

DELETE/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}/ips/{ip\_address}

#### AddressingAddress MapsZones

##### [Add a zone membership to an Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/subresources/zones/methods/update)

PUT/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}/zones/{zone\_id}

##### [Remove a zone membership from an Address Map](https://developers.cloudflare.com/api/resources/addressing/subresources/address_maps/subresources/zones/methods/delete)

DELETE/accounts/{account\_id}/addressing/address\_maps/{address\_map\_id}/zones/{zone\_id}

#### AddressingLOA Documents

##### [Download LOA Document](https://developers.cloudflare.com/api/resources/addressing/subresources/loa_documents/methods/get)

GET/accounts/{account\_id}/addressing/loa\_documents/{loa\_document\_id}/download

##### [Upload LOA Document](https://developers.cloudflare.com/api/resources/addressing/subresources/loa_documents/methods/create)

POST/accounts/{account\_id}/addressing/loa\_documents

#### AddressingPrefixes

##### [List Prefixes](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/methods/list)

GET/accounts/{account\_id}/addressing/prefixes

##### [Prefix Details](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/methods/get)

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}

##### [Add Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/methods/create)

POST/accounts/{account\_id}/addressing/prefixes

##### [Update Prefix Description](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/methods/edit)

PATCH/accounts/{account\_id}/addressing/prefixes/{prefix\_id}

##### [Delete Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/methods/delete)

DELETE/accounts/{account\_id}/addressing/prefixes/{prefix\_id}

##### [Validate Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/methods/validate)

POST/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/validate

#### AddressingPrefixesService Bindings

##### [List Service Bindings](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/service_bindings/methods/list)

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bindings

##### [Get Service Binding](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/service_bindings/methods/get)

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bindings/{binding\_id}

##### [Create Service Binding](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/service_bindings/methods/create)

POST/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bindings

##### [Delete Service Binding](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/service_bindings/methods/delete)

DELETE/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bindings/{binding\_id}

#### AddressingPrefixesBGP Prefixes

##### [List BGP Prefixes](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/methods/list)

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/prefixes

##### [Fetch BGP Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/methods/get)

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/prefixes/{bgp\_prefix\_id}

##### [Create BGP Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/methods/create)

POST/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/prefixes

##### [Update BGP Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/methods/edit)

PATCH/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/prefixes/{bgp\_prefix\_id}

##### [Delete BGP Prefix](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/methods/delete)

DELETE/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/prefixes/{bgp\_prefix\_id}

#### AddressingPrefixesAdvertisement Status

##### [Get Advertisement Status](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/advertisement_status/methods/get)

Deprecated

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/status

##### [Update Prefix Dynamic Advertisement Status](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/advertisement_status/methods/edit)

Deprecated

PATCH/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/bgp/status

#### AddressingPrefixesDelegations

##### [List Prefix Delegations](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/delegations/methods/list)

GET/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/delegations

##### [Create Prefix Delegation](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/delegations/methods/create)

POST/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/delegations

##### [Delete Prefix Delegation](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/delegations/methods/delete)

DELETE/accounts/{account\_id}/addressing/prefixes/{prefix\_id}/delegations/{delegation\_id}

#### Data Localization Suite

#### Data Localization SuiteRegions

##### [List DLS regions for an account](https://developers.cloudflare.com/api/resources/dls/subresources/regions/methods/list)

GET/accounts/{account\_id}/dls/regions

##### [Get a DLS region](https://developers.cloudflare.com/api/resources/dls/subresources/regions/methods/get)

GET/accounts/{account\_id}/dls/regions/{region\_id}

#### Data Localization SuiteRegional Services

#### Data Localization SuiteRegional ServicesPrefix Bindings

##### [List DLS prefix bindings for an account](https://developers.cloudflare.com/api/resources/dls/subresources/regional_services/subresources/prefix_bindings/methods/list)

GET/accounts/{account\_id}/dls/regional\_services/prefix\_bindings

##### [Get a DLS prefix binding](https://developers.cloudflare.com/api/resources/dls/subresources/regional_services/subresources/prefix_bindings/methods/get)

GET/accounts/{account\_id}/dls/regional\_services/prefix\_bindings/{binding\_id}

##### [Create a DLS prefix binding](https://developers.cloudflare.com/api/resources/dls/subresources/regional_services/subresources/prefix_bindings/methods/create)

POST/accounts/{account\_id}/dls/regional\_services/prefix\_bindings

##### [Update a DLS prefix binding](https://developers.cloudflare.com/api/resources/dls/subresources/regional_services/subresources/prefix_bindings/methods/edit)

PATCH/accounts/{account\_id}/dls/regional\_services/prefix\_bindings/{binding\_id}

##### [Delete a DLS prefix binding](https://developers.cloudflare.com/api/resources/dls/subresources/regional_services/subresources/prefix_bindings/methods/delete)

DELETE/accounts/{account\_id}/dls/regional\_services/prefix\_bindings/{binding\_id}

#### Audit Logs

##### [Get account audit logs](https://developers.cloudflare.com/api/resources/audit_logs/methods/list)

GET/accounts/{account\_id}/audit\_logs

#### Billing

##### [Validate Billing Address](https://developers.cloudflare.com/api/resources/billing/methods/address_validation)

POST/billing/address-validation

#### BillingProfiles

##### [Get Billing Profile](https://developers.cloudflare.com/api/resources/billing/subresources/profiles/methods/get)

GET/accounts/{account\_id}/billing/profile

##### [Create Billing Profile](https://developers.cloudflare.com/api/resources/billing/subresources/profiles/methods/create)

POST/accounts/{account\_id}/billing/profile

##### [Update Billing Profile](https://developers.cloudflare.com/api/resources/billing/subresources/profiles/methods/update)

PUT/accounts/{account\_id}/billing/profile

##### [Delete Billing Profile](https://developers.cloudflare.com/api/resources/billing/subresources/profiles/methods/delete)

DELETE/accounts/{account\_id}/billing/profile

##### [Update Billing Email](https://developers.cloudflare.com/api/resources/billing/subresources/profiles/methods/update_billing_email)

PATCH/accounts/{account\_id}/billing/profile

#### BillingProfilesPayment Method

##### [Create Payment Intent for Billing Profile](https://developers.cloudflare.com/api/resources/billing/subresources/profiles/subresources/payment_method/methods/create)

POST/accounts/{account\_id}/billing/profile/payment-method

#### BillingUsage

##### [Get Account Billable Usage Info (Version 1, Alpha)](https://developers.cloudflare.com/api/resources/billing/subresources/usage/methods/paygo_info)

Deprecated

GET/accounts/{account\_id}/billable-usage/info

##### [Get Account Billable Usage (Version 1, Alpha)](https://developers.cloudflare.com/api/resources/billing/subresources/usage/methods/paygo)

Deprecated

GET/accounts/{account\_id}/billable-usage

##### [Get Account Usage (Version 2, Alpha, Restricted)](https://developers.cloudflare.com/api/resources/billing/subresources/usage/methods/get)

Deprecated

GET/accounts/{account\_id}/billable/usage

##### [Get Account Billable Usage Info (Version 1, Alpha)](https://developers.cloudflare.com/api/resources/billing/subresources/usage/methods/get_account_usage_info_v1)

GET/accounts/{account\_id}/billable-usage/info

##### [Get Account Billable Usage (Version 1, Alpha)](https://developers.cloudflare.com/api/resources/billing/subresources/usage/methods/get_account_usage_v1)

GET/accounts/{account\_id}/billable-usage

##### [Get Account Usage (Version 2, Alpha, Restricted)](https://developers.cloudflare.com/api/resources/billing/subresources/usage/methods/get_account_usage_v2)

GET/accounts/{account\_id}/billable/usage

#### BillingCredits

##### [Get Account Credits](https://developers.cloudflare.com/api/resources/billing/subresources/credits/methods/get)

GET/accounts/{account\_id}/billing/credits

#### BillingHistory

##### [Get Account Billing History](https://developers.cloudflare.com/api/resources/billing/subresources/history/methods/list)

GET/accounts/{account\_id}/billing/history

#### BillingBad Debt

##### [Get Account Bad Debt](https://developers.cloudflare.com/api/resources/billing/subresources/bad_debt/methods/get)

GET/accounts/{account\_id}/billing/bad-debt

#### BillingUnpaid Invoice

##### [Get Unpaid Invoices](https://developers.cloudflare.com/api/resources/billing/subresources/unpaid_invoice/methods/get)

GET/accounts/{account\_id}/billing/unpaid-invoice

#### BillingRate Plans

##### [Get Rate Plan by Public Key](https://developers.cloudflare.com/api/resources/billing/subresources/rate_plans/methods/get)

GET/billing/rate\_plans/{public\_key}

#### Brand Protection

##### [Create new URL submissions](https://developers.cloudflare.com/api/resources/brand_protection/methods/submit)

POST/accounts/{account\_id}/brand-protection/submit

##### [Read submitted URLs by ID](https://developers.cloudflare.com/api/resources/brand_protection/methods/url_info)

GET/accounts/{account\_id}/brand-protection/url-info

#### Brand ProtectionQueries

##### [Create new saved string queries](https://developers.cloudflare.com/api/resources/brand_protection/subresources/queries/methods/create)

POST/accounts/{account\_id}/brand-protection/queries

##### [Delete saved string queries by ID](https://developers.cloudflare.com/api/resources/brand_protection/subresources/queries/methods/delete)

DELETE/accounts/{account\_id}/brand-protection/queries

##### [Create new saved string queries in bulk](https://developers.cloudflare.com/api/resources/brand_protection/subresources/queries/methods/bulk)

POST/accounts/{account\_id}/brand-protection/queries/bulk

#### Brand ProtectionMatches

##### [Read matches for string queries by ID](https://developers.cloudflare.com/api/resources/brand_protection/subresources/matches/methods/get)

GET/accounts/{account\_id}/brand-protection/matches

##### [Download matches for string queries by ID](https://developers.cloudflare.com/api/resources/brand_protection/subresources/matches/methods/download)

GET/accounts/{account\_id}/brand-protection/matches/download

#### Brand ProtectionLogos

##### [Create new saved logo queries from image files](https://developers.cloudflare.com/api/resources/brand_protection/subresources/logos/methods/create)

POST/accounts/{account\_id}/brand-protection/logos

##### [Delete saved logo queries by ID](https://developers.cloudflare.com/api/resources/brand_protection/subresources/logos/methods/delete)

DELETE/accounts/{account\_id}/brand-protection/logos/{logo\_id}

#### Brand ProtectionLogo Matches

##### [Read matches for logo queries by ID](https://developers.cloudflare.com/api/resources/brand_protection/subresources/logo_matches/methods/get)

GET/accounts/{account\_id}/brand-protection/logo-matches

##### [Download matches for logo queries by ID](https://developers.cloudflare.com/api/resources/brand_protection/subresources/logo_matches/methods/download)

GET/accounts/{account\_id}/brand-protection/logo-matches/download

#### Brand ProtectionV2

#### Brand ProtectionV2Queries

##### [Get queries](https://developers.cloudflare.com/api/resources/brand_protection/subresources/v2/subresources/queries/methods/get)

GET/accounts/{account\_id}/cloudforce-one/v2/brand-protection/domain/queries

#### Brand ProtectionV2Matches

##### [List saved query matches](https://developers.cloudflare.com/api/resources/brand_protection/subresources/v2/subresources/matches/methods/get)

GET/accounts/{account\_id}/cloudforce-one/v2/brand-protection/domain/matches

#### Brand ProtectionV2Logos

##### [Insert logo query](https://developers.cloudflare.com/api/resources/brand_protection/subresources/v2/subresources/logos/methods/create)

POST/accounts/{account\_id}/cloudforce-one/v2/brand-protection/logo/queries

##### [Delete logo query](https://developers.cloudflare.com/api/resources/brand_protection/subresources/v2/subresources/logos/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/v2/brand-protection/logo/queries/{query\_id}

##### [Get logo queries](https://developers.cloudflare.com/api/resources/brand_protection/subresources/v2/subresources/logos/methods/get)

GET/accounts/{account\_id}/cloudforce-one/v2/brand-protection/logo/queries

#### Brand ProtectionV2Logo Matches

##### [List logo matches](https://developers.cloudflare.com/api/resources/brand_protection/subresources/v2/subresources/logo_matches/methods/get)

GET/accounts/{account\_id}/cloudforce-one/v2/brand-protection/logo/matches

#### Diagnostics

#### DiagnosticsTraceroutes

##### [Traceroute](https://developers.cloudflare.com/api/resources/diagnostics/subresources/traceroutes/methods/create)

POST/accounts/{account\_id}/diagnostics/traceroute

#### DiagnosticsEndpoint Healthchecks

##### [List Endpoint Health Checks](https://developers.cloudflare.com/api/resources/diagnostics/subresources/endpoint-healthchecks/methods/list)

GET/accounts/{account\_id}/diagnostics/endpoint-healthchecks

##### [Endpoint Health Check](https://developers.cloudflare.com/api/resources/diagnostics/subresources/endpoint-healthchecks/methods/create)

POST/accounts/{account\_id}/diagnostics/endpoint-healthchecks

##### [Get Endpoint Health Check](https://developers.cloudflare.com/api/resources/diagnostics/subresources/endpoint-healthchecks/methods/get)

GET/accounts/{account\_id}/diagnostics/endpoint-healthchecks/{id}

##### [Delete Endpoint Health Check](https://developers.cloudflare.com/api/resources/diagnostics/subresources/endpoint-healthchecks/methods/delete)

DELETE/accounts/{account\_id}/diagnostics/endpoint-healthchecks/{id}

##### [Update Endpoint Health Check](https://developers.cloudflare.com/api/resources/diagnostics/subresources/endpoint-healthchecks/methods/update)

PUT/accounts/{account\_id}/diagnostics/endpoint-healthchecks/{id}

#### Images

#### ImagesV1

##### [List images](https://developers.cloudflare.com/api/resources/images/subresources/v1/methods/list)

Deprecated

GET/accounts/{account\_id}/images/v1

##### [Image details](https://developers.cloudflare.com/api/resources/images/subresources/v1/methods/get)

GET/accounts/{account\_id}/images/v1/{image\_id}

##### [Upload an image](https://developers.cloudflare.com/api/resources/images/subresources/v1/methods/create)

POST/accounts/{account\_id}/images/v1

##### [Update image](https://developers.cloudflare.com/api/resources/images/subresources/v1/methods/edit)

PATCH/accounts/{account\_id}/images/v1/{image\_id}

##### [Delete image](https://developers.cloudflare.com/api/resources/images/subresources/v1/methods/delete)

DELETE/accounts/{account\_id}/images/v1/{image\_id}

#### ImagesV1Keys

##### [List Signing Keys](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/keys/methods/list)

GET/accounts/{account\_id}/images/v1/keys

##### [Create a new Signing Key](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/keys/methods/update)

PUT/accounts/{account\_id}/images/v1/keys/{signing\_key\_name}

##### [Delete Signing Key](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/keys/methods/delete)

DELETE/accounts/{account\_id}/images/v1/keys/{signing\_key\_name}

#### ImagesV1Stats

##### [Images usage statistics](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/stats/methods/get)

GET/accounts/{account\_id}/images/v1/stats

#### ImagesV1Variants

##### [List variants](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/variants/methods/list)

GET/accounts/{account\_id}/images/v1/variants

##### [Variant details](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/variants/methods/get)

GET/accounts/{account\_id}/images/v1/variants/{variant\_id}

##### [Create a variant](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/variants/methods/create)

POST/accounts/{account\_id}/images/v1/variants

##### [Update a variant](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/variants/methods/edit)

PATCH/accounts/{account\_id}/images/v1/variants/{variant\_id}

##### [Delete a variant](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/variants/methods/delete)

DELETE/accounts/{account\_id}/images/v1/variants/{variant\_id}

#### ImagesV1Blobs

##### [Download image](https://developers.cloudflare.com/api/resources/images/subresources/v1/subresources/blobs/methods/get)

GET/accounts/{account\_id}/images/v1/{image\_id}/blob

#### ImagesV2

##### [List images V2](https://developers.cloudflare.com/api/resources/images/subresources/v2/methods/list)

GET/accounts/{account\_id}/images/v2

#### ImagesV2Direct Uploads

##### [Create authenticated direct upload URL V2](https://developers.cloudflare.com/api/resources/images/subresources/v2/subresources/direct_uploads/methods/create)

POST/accounts/{account\_id}/images/v2/direct\_upload

#### Intel

#### IntelASN

##### [Get ASN Overview.](https://developers.cloudflare.com/api/resources/intel/subresources/asn/methods/get)

GET/accounts/{account\_id}/intel/asn/{asn}

#### IntelASNSubnets

##### [Get ASN Subnets](https://developers.cloudflare.com/api/resources/intel/subresources/asn/subresources/subnets/methods/get)

GET/accounts/{account\_id}/intel/asn/{asn}/subnets

#### IntelDNS

##### [Get Passive DNS by IP](https://developers.cloudflare.com/api/resources/intel/subresources/dns/methods/list)

GET/accounts/{account\_id}/intel/dns

#### IntelDomains

##### [Get Domain Details](https://developers.cloudflare.com/api/resources/intel/subresources/domains/methods/get)

GET/accounts/{account\_id}/intel/domain

#### IntelDomainsBulks

##### [Get Multiple Domain Details](https://developers.cloudflare.com/api/resources/intel/subresources/domains/subresources/bulks/methods/get)

GET/accounts/{account\_id}/intel/domain/bulk

#### IntelDomain History

##### [Get Domain History](https://developers.cloudflare.com/api/resources/intel/subresources/domain_history/methods/get)

GET/accounts/{account\_id}/intel/domain-history

#### IntelIPs

##### [Get IP Overview](https://developers.cloudflare.com/api/resources/intel/subresources/ips/methods/get)

GET/accounts/{account\_id}/intel/ip

#### IntelIP Lists

#### IntelMiscategorizations

##### [Create Miscategorization](https://developers.cloudflare.com/api/resources/intel/subresources/miscategorizations/methods/create)

POST/accounts/{account\_id}/intel/miscategorization

#### IntelWhois

##### [Get WHOIS Record](https://developers.cloudflare.com/api/resources/intel/subresources/whois/methods/get)

GET/accounts/{account\_id}/intel/whois

#### IntelURLs

##### [Get URL Intelligence](https://developers.cloudflare.com/api/resources/intel/subresources/urls/methods/get)

GET/accounts/{account\_id}/intel/url

#### IntelIndicator Feeds

##### [Get indicator feeds owned by this account](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/methods/list)

GET/accounts/{account\_id}/intel/indicator-feeds

##### [Get indicator feed metadata](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/methods/get)

GET/accounts/{account\_id}/intel/indicator-feeds/{feed\_id}

##### [Create new indicator feed](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/methods/create)

POST/accounts/{account\_id}/intel/indicator-feeds

##### [Update indicator feed metadata](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/methods/update)

PUT/accounts/{account\_id}/intel/indicator-feeds/{feed\_id}

##### [Get indicator feed data](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/methods/data)

GET/accounts/{account\_id}/intel/indicator-feeds/{feed\_id}/data

#### IntelIndicator FeedsSnapshots

##### [Update indicator feed data](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/subresources/snapshots/methods/update)

PUT/accounts/{account\_id}/intel/indicator-feeds/{feed\_id}/snapshot

#### IntelIndicator FeedsPermissions

##### [List indicator feed permissions](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/subresources/permissions/methods/list)

GET/accounts/{account\_id}/intel/indicator-feeds/permissions/view

##### [Grant permission to indicator feed](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/subresources/permissions/methods/create)

PUT/accounts/{account\_id}/intel/indicator-feeds/permissions/add

##### [Revoke permission to indicator feed](https://developers.cloudflare.com/api/resources/intel/subresources/indicator_feeds/subresources/permissions/methods/delete)

PUT/accounts/{account\_id}/intel/indicator-feeds/permissions/remove

#### IntelIndicator FeedsDownloads

#### IntelSinkholes

##### [List sinkholes owned by this account](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/methods/list)

GET/accounts/{account\_id}/intel/sinkholes

##### [Get a sinkhole](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/methods/get)

GET/accounts/{account\_id}/intel/sinkholes/{sinkhole\_id}

##### [Create a new sinkhole for your account](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/methods/create)

POST/accounts/{account\_id}/intel/sinkholes

##### [Update a sinkhole](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/methods/update)

PUT/accounts/{account\_id}/intel/sinkholes/{sinkhole\_id}

##### [Delete a sinkhole](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/methods/delete)

DELETE/accounts/{account\_id}/intel/sinkholes/{sinkhole\_id}

#### IntelSinkholesIngresses

##### [Create an ingress rule](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/subresources/ingresses/methods/create)

POST/zones/{zone\_id}/intel/sinkholes/{sinkhole\_id}/ingresses

##### [Get an ingress rule](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/subresources/ingresses/methods/get)

GET/zones/{zone\_id}/intel/sinkholes/{sinkhole\_id}/ingresses/{ingress\_id}

##### [Update an ingress rule](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/subresources/ingresses/methods/update)

PUT/zones/{zone\_id}/intel/sinkholes/{sinkhole\_id}/ingresses/{ingress\_id}

##### [Delete an ingress rule](https://developers.cloudflare.com/api/resources/intel/subresources/sinkholes/subresources/ingresses/methods/delete)

DELETE/zones/{zone\_id}/intel/sinkholes/{sinkhole\_id}/ingresses/{ingress\_id}

#### IntelAttack Surface Report

#### IntelAttack Surface ReportIssue Types

##### [Retrieves Security Center Issues Types](https://developers.cloudflare.com/api/resources/intel/subresources/attack_surface_report/subresources/issue_types/methods/get)

GET/accounts/{account\_id}/intel/attack-surface-report/issue-types

#### IntelAttack Surface ReportIssues

##### [Retrieves Security Center Issues](https://developers.cloudflare.com/api/resources/intel/subresources/attack_surface_report/subresources/issues/methods/list)

Deprecated

GET/accounts/{account\_id}/intel/attack-surface-report/issues

##### [Retrieves Security Center Issue Counts by Class](https://developers.cloudflare.com/api/resources/intel/subresources/attack_surface_report/subresources/issues/methods/class)

Deprecated

GET/accounts/{account\_id}/intel/attack-surface-report/issues/class

##### [Retrieves Security Center Issue Counts by Severity](https://developers.cloudflare.com/api/resources/intel/subresources/attack_surface_report/subresources/issues/methods/severity)

Deprecated

GET/accounts/{account\_id}/intel/attack-surface-report/issues/severity

##### [Retrieves Security Center Issue Counts by Type](https://developers.cloudflare.com/api/resources/intel/subresources/attack_surface_report/subresources/issues/methods/type)

Deprecated

GET/accounts/{account\_id}/intel/attack-surface-report/issues/type

#### Magic Transit

#### Magic TransitApps

##### [List Apps](https://developers.cloudflare.com/api/resources/magic_transit/subresources/apps/methods/list)

GET/accounts/{account\_id}/magic/apps

##### [Create a new App](https://developers.cloudflare.com/api/resources/magic_transit/subresources/apps/methods/create)

POST/accounts/{account\_id}/magic/apps

##### [Update an App](https://developers.cloudflare.com/api/resources/magic_transit/subresources/apps/methods/update)

PUT/accounts/{account\_id}/magic/apps/{account\_app\_id}

##### [Update an App](https://developers.cloudflare.com/api/resources/magic_transit/subresources/apps/methods/edit)

PATCH/accounts/{account\_id}/magic/apps/{account\_app\_id}

##### [Delete Account App](https://developers.cloudflare.com/api/resources/magic_transit/subresources/apps/methods/delete)

DELETE/accounts/{account\_id}/magic/apps/{account\_app\_id}

#### Magic TransitCf Interconnects

##### [List interconnects](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf_interconnects/methods/list)

GET/accounts/{account\_id}/magic/cf\_interconnects

##### [List interconnect Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf_interconnects/methods/get)

GET/accounts/{account\_id}/magic/cf\_interconnects/{cf\_interconnect\_id}

##### [Update interconnect](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf_interconnects/methods/update)

PUT/accounts/{account\_id}/magic/cf\_interconnects/{cf\_interconnect\_id}

##### [Update multiple interconnects](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf_interconnects/methods/bulk_update)

PUT/accounts/{account\_id}/magic/cf\_interconnects

#### Magic TransitGRE Tunnels

##### [List GRE tunnels](https://developers.cloudflare.com/api/resources/magic_transit/subresources/gre_tunnels/methods/list)

GET/accounts/{account\_id}/magic/gre\_tunnels

##### [List GRE Tunnel Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/gre_tunnels/methods/get)

GET/accounts/{account\_id}/magic/gre\_tunnels/{gre\_tunnel\_id}

##### [Create a GRE tunnel](https://developers.cloudflare.com/api/resources/magic_transit/subresources/gre_tunnels/methods/create)

POST/accounts/{account\_id}/magic/gre\_tunnels

##### [Update GRE Tunnel](https://developers.cloudflare.com/api/resources/magic_transit/subresources/gre_tunnels/methods/update)

PUT/accounts/{account\_id}/magic/gre\_tunnels/{gre\_tunnel\_id}

##### [Delete GRE Tunnel](https://developers.cloudflare.com/api/resources/magic_transit/subresources/gre_tunnels/methods/delete)

DELETE/accounts/{account\_id}/magic/gre\_tunnels/{gre\_tunnel\_id}

##### [Update multiple GRE tunnels](https://developers.cloudflare.com/api/resources/magic_transit/subresources/gre_tunnels/methods/bulk_update)

PUT/accounts/{account\_id}/magic/gre\_tunnels

#### Magic TransitIPSEC Tunnels

##### [List IPsec tunnels](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/list)

GET/accounts/{account\_id}/magic/ipsec\_tunnels

##### [List IPsec tunnel details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/get)

GET/accounts/{account\_id}/magic/ipsec\_tunnels/{ipsec\_tunnel\_id}

##### [Create an IPsec tunnel](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/create)

POST/accounts/{account\_id}/magic/ipsec\_tunnels

##### [Update IPsec Tunnel](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/update)

PUT/accounts/{account\_id}/magic/ipsec\_tunnels/{ipsec\_tunnel\_id}

##### [Delete IPsec Tunnel](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/delete)

DELETE/accounts/{account\_id}/magic/ipsec\_tunnels/{ipsec\_tunnel\_id}

##### [Update multiple IPsec tunnels](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/bulk_update)

PUT/accounts/{account\_id}/magic/ipsec\_tunnels

##### [Generate Pre-Shared Key (PSK) for IPsec tunnels](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/psk_generate)

POST/accounts/{account\_id}/magic/ipsec\_tunnels/{ipsec\_tunnel\_id}/psk\_generate

##### [Set Pre-Shared Keys (PSK) for IPsec tunnels](https://developers.cloudflare.com/api/resources/magic_transit/subresources/ipsec_tunnels/methods/psk_set)

POST/accounts/{account\_id}/magic/ipsec\_tunnels/psk

#### Magic TransitRoutes

##### [List Routes](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/list)

GET/accounts/{account\_id}/magic/routes

##### [Route Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/get)

GET/accounts/{account\_id}/magic/routes/{route\_id}

##### [Create a Route](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/create)

POST/accounts/{account\_id}/magic/routes

##### [Update Route](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/update)

PUT/accounts/{account\_id}/magic/routes/{route\_id}

##### [Delete Route](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/delete)

DELETE/accounts/{account\_id}/magic/routes/{route\_id}

##### [Update Many Routes](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/bulk_update)

PUT/accounts/{account\_id}/magic/routes

##### [Delete Many Routes](https://developers.cloudflare.com/api/resources/magic_transit/subresources/routes/methods/empty)

DELETE/accounts/{account\_id}/magic/routes

#### Magic TransitBGP Filter Profiles

##### [List BGP Filter Profiles](https://developers.cloudflare.com/api/resources/magic_transit/subresources/bgp_filter_profiles/methods/list)

GET/accounts/{account\_id}/magic/bgp/filter\_profiles

##### [Get BGP Filter Profile](https://developers.cloudflare.com/api/resources/magic_transit/subresources/bgp_filter_profiles/methods/get)

GET/accounts/{account\_id}/magic/bgp/filter\_profiles/{profile\_id}

##### [Create BGP Filter Profile](https://developers.cloudflare.com/api/resources/magic_transit/subresources/bgp_filter_profiles/methods/create)

POST/accounts/{account\_id}/magic/bgp/filter\_profiles

##### [Update BGP Filter Profile](https://developers.cloudflare.com/api/resources/magic_transit/subresources/bgp_filter_profiles/methods/update)

PUT/accounts/{account\_id}/magic/bgp/filter\_profiles/{profile\_id}

##### [Delete BGP Filter Profile](https://developers.cloudflare.com/api/resources/magic_transit/subresources/bgp_filter_profiles/methods/delete)

DELETE/accounts/{account\_id}/magic/bgp/filter\_profiles/{profile\_id}

#### Magic TransitSites

##### [List Sites](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/methods/list)

GET/accounts/{account\_id}/magic/sites

##### [Site Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/methods/get)

GET/accounts/{account\_id}/magic/sites/{site\_id}

##### [Create a new Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/methods/create)

POST/accounts/{account\_id}/magic/sites

##### [Update Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/methods/update)

PUT/accounts/{account\_id}/magic/sites/{site\_id}

##### [Patch Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/methods/edit)

PATCH/accounts/{account\_id}/magic/sites/{site\_id}

##### [Delete Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/methods/delete)

DELETE/accounts/{account\_id}/magic/sites/{site\_id}

#### Magic TransitSitesApp Configuration

##### [List App Configs](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/app_configuration/methods/list)

GET/accounts/{account\_id}/magic/sites/{site\_id}/app\_configs

##### [Create a new App Config](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/app_configuration/methods/create)

POST/accounts/{account\_id}/magic/sites/{site\_id}/app\_configs

##### [Update an App Config](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/app_configuration/methods/update)

PUT/accounts/{account\_id}/magic/sites/{site\_id}/app\_configs/{app\_config\_id}

##### [Update an App Config](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/app_configuration/methods/edit)

PATCH/accounts/{account\_id}/magic/sites/{site\_id}/app\_configs/{app\_config\_id}

##### [Delete App Config](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/app_configuration/methods/delete)

DELETE/accounts/{account\_id}/magic/sites/{site\_id}/app\_configs/{app\_config\_id}

#### Magic TransitSitesACLs

##### [List Site ACLs](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/acls/methods/list)

GET/accounts/{account\_id}/magic/sites/{site\_id}/acls

##### [Site ACL Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/acls/methods/get)

GET/accounts/{account\_id}/magic/sites/{site\_id}/acls/{acl\_id}

##### [Create a new Site ACL](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/acls/methods/create)

POST/accounts/{account\_id}/magic/sites/{site\_id}/acls

##### [Update Site ACL](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/acls/methods/update)

PUT/accounts/{account\_id}/magic/sites/{site\_id}/acls/{acl\_id}

##### [Patch Site ACL](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/acls/methods/edit)

PATCH/accounts/{account\_id}/magic/sites/{site\_id}/acls/{acl\_id}

##### [Delete Site ACL](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/acls/methods/delete)

DELETE/accounts/{account\_id}/magic/sites/{site\_id}/acls/{acl\_id}

#### Magic TransitSitesLANs

##### [List Site LANs](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/lans/methods/list)

GET/accounts/{account\_id}/magic/sites/{site\_id}/lans

##### [Site LAN Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/lans/methods/get)

GET/accounts/{account\_id}/magic/sites/{site\_id}/lans/{lan\_id}

##### [Create a new Site LAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/lans/methods/create)

POST/accounts/{account\_id}/magic/sites/{site\_id}/lans

##### [Update Site LAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/lans/methods/update)

PUT/accounts/{account\_id}/magic/sites/{site\_id}/lans/{lan\_id}

##### [Patch Site LAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/lans/methods/edit)

PATCH/accounts/{account\_id}/magic/sites/{site\_id}/lans/{lan\_id}

##### [Delete Site LAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/lans/methods/delete)

DELETE/accounts/{account\_id}/magic/sites/{site\_id}/lans/{lan\_id}

#### Magic TransitSitesWANs

##### [List Site WANs](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/wans/methods/list)

GET/accounts/{account\_id}/magic/sites/{site\_id}/wans

##### [Site WAN Details](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/wans/methods/get)

GET/accounts/{account\_id}/magic/sites/{site\_id}/wans/{wan\_id}

##### [Create a new Site WAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/wans/methods/create)

POST/accounts/{account\_id}/magic/sites/{site\_id}/wans

##### [Update Site WAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/wans/methods/update)

PUT/accounts/{account\_id}/magic/sites/{site\_id}/wans/{wan\_id}

##### [Patch Site WAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/wans/methods/edit)

PATCH/accounts/{account\_id}/magic/sites/{site\_id}/wans/{wan\_id}

##### [Delete Site WAN](https://developers.cloudflare.com/api/resources/magic_transit/subresources/sites/subresources/wans/methods/delete)

DELETE/accounts/{account\_id}/magic/sites/{site\_id}/wans/{wan\_id}

#### Magic TransitConnectors

##### [List Connectors](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/methods/list)

GET/accounts/{account\_id}/magic/connectors

##### [Get Connector](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/methods/get)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}

##### [Create Connector](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/methods/create)

POST/accounts/{account\_id}/magic/connectors

##### [Update Connector](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/methods/update)

PUT/accounts/{account\_id}/magic/connectors/{connector\_id}

##### [Edit Connector](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/methods/edit)

PATCH/accounts/{account\_id}/magic/connectors/{connector\_id}

##### [Delete Connector](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/methods/delete)

DELETE/accounts/{account\_id}/magic/connectors/{connector\_id}

#### Magic TransitConnectorsInterrupts

##### [List Interrupts](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/interrupts/methods/list)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/interrupts

##### [Create Interrupt](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/interrupts/methods/create)

POST/accounts/{account\_id}/magic/connectors/{connector\_id}/interrupts

#### Magic TransitConnectorsEvents

##### [List Events](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/events/methods/list)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/telemetry/events

##### [Get Event](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/events/methods/get)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/telemetry/events/{event\_t}.{event\_n}

#### Magic TransitConnectorsEventsLatest

##### [Get latest Events](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/events/subresources/latest/methods/list)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/telemetry/events/latest

#### Magic TransitConnectorsSnapshots

##### [List Snapshots](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/snapshots/methods/list)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/telemetry/snapshots

##### [Get Snapshot](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/snapshots/methods/get)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/telemetry/snapshots/{snapshot\_t}

#### Magic TransitConnectorsSnapshotsLatest

##### [Get latest Snapshots](https://developers.cloudflare.com/api/resources/magic_transit/subresources/connectors/subresources/snapshots/subresources/latest/methods/list)

GET/accounts/{account\_id}/magic/connectors/{connector\_id}/telemetry/snapshots/latest

#### Magic TransitCf1 Sites

##### [List CF1 Sites](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/methods/list)

GET/accounts/{account\_id}/magic/cf1\_sites

##### [Get CF1 Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/methods/get)

GET/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}

##### [Create CF1 Sites](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/methods/create)

POST/accounts/{account\_id}/magic/cf1\_sites

##### [Update CF1 Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/methods/update)

PATCH/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}

##### [Delete CF1 Site](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/methods/delete)

DELETE/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}

#### Magic TransitCf1 SitesRamps

##### [List CF1 Site Ramps](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/subresources/ramps/methods/list)

GET/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}/ramps

##### [Get CF1 Site Ramp](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/subresources/ramps/methods/get)

GET/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}/ramps/{ramp\_id}

##### [Create CF1 Site Ramps](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/subresources/ramps/methods/create)

POST/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}/ramps

##### [Delete CF1 Site Ramp](https://developers.cloudflare.com/api/resources/magic_transit/subresources/cf1_sites/subresources/ramps/methods/delete)

DELETE/accounts/{account\_id}/magic/cf1\_sites/{cf1\_site\_id}/ramps/{ramp\_id}

#### Magic TransitPCAPs

##### [List packet capture requests](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/methods/list)

GET/accounts/{account\_id}/pcaps

##### [Get PCAP request](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/methods/get)

GET/accounts/{account\_id}/pcaps/{pcap\_id}

##### [Create PCAP request](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/methods/create)

POST/accounts/{account\_id}/pcaps

##### [Stop full PCAP](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/methods/stop)

PUT/accounts/{account\_id}/pcaps/{pcap\_id}/stop

#### Magic TransitPCAPsOwnership

##### [List PCAPs Bucket Ownership](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/get)

GET/accounts/{account\_id}/pcaps/ownership

##### [Add buckets for full packet captures](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/create)

POST/accounts/{account\_id}/pcaps/ownership

##### [Delete buckets for full packet captures](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/delete)

DELETE/accounts/{account\_id}/pcaps/ownership/{ownership\_id}

##### [Validate buckets for full packet captures](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/validate)

POST/accounts/{account\_id}/pcaps/ownership/validate

#### Magic TransitPCAPsDownload

##### [Download Simple PCAP](https://developers.cloudflare.com/api/resources/magic_transit/subresources/pcaps/subresources/download/methods/get)

GET/accounts/{account\_id}/pcaps/{pcap\_id}/download

#### DDoS Protection

#### DDoS ProtectionAdvanced TCP Protection

#### DDoS ProtectionAdvanced TCP ProtectionAllowlist

##### [List all allowlist prefixes.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/allowlist/methods/list)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/allowlist

##### [Create allowlist prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/allowlist/methods/create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/allowlist

##### [Delete all allowlist prefixes.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/allowlist/methods/bulk_delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/allowlist

#### DDoS ProtectionAdvanced TCP ProtectionAllowlistItems

##### [Get allowlist prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/allowlist/subresources/items/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/allowlist/{prefix\_id}

##### [Update allowlist prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/allowlist/subresources/items/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/allowlist/{prefix\_id}

##### [Delete allowlist prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/allowlist/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/allowlist/{prefix\_id}

#### DDoS ProtectionAdvanced TCP ProtectionPrefixes

##### [List all prefixes.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/methods/list)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes

##### [Create prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/methods/create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes

##### [Delete all prefixes.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/methods/bulk_delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes

##### [Create multiple prefixes.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/methods/bulk_create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes/bulk

#### DDoS ProtectionAdvanced TCP ProtectionPrefixesItems

##### [Get prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/subresources/items/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes/{prefix\_id}

##### [Update prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/subresources/items/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes/{prefix\_id}

##### [Delete prefix.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/prefixes/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/prefixes/{prefix\_id}

#### DDoS ProtectionAdvanced TCP ProtectionSYN Protection

#### DDoS ProtectionAdvanced TCP ProtectionSYN ProtectionFilters

##### [List all SYN Protection filters.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/filters/methods/list)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/filters

##### [Create a SYN Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/filters/methods/create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/filters

##### [Delete all SYN Protection filters.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/filters/methods/bulk_delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/filters

#### DDoS ProtectionAdvanced TCP ProtectionSYN ProtectionFiltersItems

##### [Get SYN Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/filters/subresources/items/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/filters/{filter\_id}

##### [Update SYN Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/filters/subresources/items/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/filters/{filter\_id}

##### [Delete SYN Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/filters/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/filters/{filter\_id}

#### DDoS ProtectionAdvanced TCP ProtectionSYN ProtectionRules

##### [List all SYN Protection rules.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/rules/methods/list)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/rules

##### [Create SYN Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/rules/methods/create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/rules

##### [Delete all SYN Protection rules.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/rules/methods/bulk_delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/rules

#### DDoS ProtectionAdvanced TCP ProtectionSYN ProtectionRulesItems

##### [Get SYN Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/rules/subresources/items/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/rules/{rule\_id}

##### [Update SYN Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/rules/subresources/items/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/rules/{rule\_id}

##### [Delete SYN Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/syn_protection/subresources/rules/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/syn\_protection/rules/{rule\_id}

#### DDoS ProtectionAdvanced TCP ProtectionTCP Flow Protection

#### DDoS ProtectionAdvanced TCP ProtectionTCP Flow ProtectionFilters

##### [List all TCP Flow Protection filters.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/filters/methods/list)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/filters

##### [Create a TCP Flow Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/filters/methods/create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/filters

##### [Delete all TCP Flow Protection filters.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/filters/methods/bulk_delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/filters

#### DDoS ProtectionAdvanced TCP ProtectionTCP Flow ProtectionFiltersItems

##### [Get TCP Flow Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/filters/subresources/items/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/filters/{filter\_id}

##### [Update TCP Flow Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/filters/subresources/items/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/filters/{filter\_id}

##### [Delete TCP Flow Protection filter.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/filters/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/filters/{filter\_id}

#### DDoS ProtectionAdvanced TCP ProtectionTCP Flow ProtectionRules

##### [List all TCP Flow Protection rules.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/rules/methods/list)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/rules

##### [Create TCP Flow Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/rules/methods/create)

POST/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/rules

##### [Delete all TCP Flow Protection rules.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/rules/methods/bulk_delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/rules

#### DDoS ProtectionAdvanced TCP ProtectionTCP Flow ProtectionRulesItems

##### [Get TCP Flow Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/rules/subresources/items/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/rules/{rule\_id}

##### [Update TCP Flow Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/rules/subresources/items/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/rules/{rule\_id}

##### [Delete TCP Flow Protection rule.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/tcp_flow_protection/subresources/rules/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_flow\_protection/rules/{rule\_id}

#### DDoS ProtectionAdvanced TCP ProtectionStatus

##### [Get protection status.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/status/methods/get)

GET/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_protection\_status

##### [Update protection status.](https://developers.cloudflare.com/api/resources/ddos_protection/subresources/advanced_tcp_protection/subresources/status/methods/edit)

PATCH/accounts/{account\_id}/magic/advanced\_tcp\_protection/configs/tcp\_protection\_status

#### Magic Network Monitoring

#### Magic Network MonitoringVPC Flows

#### Magic Network MonitoringVPC FlowsTokens

##### [Generate authentication token for VPC flow logs export.](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/vpc_flows/subresources/tokens/methods/create)

POST/accounts/{account\_id}/mnm/vpc-flows/token

#### Magic Network MonitoringConfigs

##### [List account configuration](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/configs/methods/get)

GET/accounts/{account\_id}/mnm/config

##### [Create account configuration](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/configs/methods/create)

POST/accounts/{account\_id}/mnm/config

##### [Update an entire account configuration](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/configs/methods/update)

PUT/accounts/{account\_id}/mnm/config

##### [Update account configuration fields](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/configs/methods/edit)

PATCH/accounts/{account\_id}/mnm/config

##### [Delete account configuration](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/configs/methods/delete)

DELETE/accounts/{account\_id}/mnm/config

#### Magic Network MonitoringConfigsFull

##### [List rules and account configuration](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/configs/subresources/full/methods/get)

GET/accounts/{account\_id}/mnm/config/full

#### Magic Network MonitoringRules

##### [List rules](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/methods/list)

GET/accounts/{account\_id}/mnm/rules

##### [Get rule](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/methods/get)

GET/accounts/{account\_id}/mnm/rules/{rule\_id}

##### [Create rules](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/methods/create)

POST/accounts/{account\_id}/mnm/rules

##### [Update rules](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/methods/update)

PUT/accounts/{account\_id}/mnm/rules

##### [Update rule](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/methods/edit)

PATCH/accounts/{account\_id}/mnm/rules/{rule\_id}

##### [Delete rule](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/methods/delete)

DELETE/accounts/{account\_id}/mnm/rules/{rule\_id}

#### Magic Network MonitoringRulesAdvertisements

##### [Update advertisement for rule](https://developers.cloudflare.com/api/resources/magic_network_monitoring/subresources/rules/subresources/advertisements/methods/edit)

PATCH/accounts/{account\_id}/mnm/rules/{rule\_id}/advertisement

#### Magic Cloud Networking

#### Magic Cloud NetworkingCatalog Syncs

##### [List Catalog Syncs](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/list)

GET/accounts/{account\_id}/magic/cloud/catalog-syncs

##### [Read Catalog Sync](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/get)

GET/accounts/{account\_id}/magic/cloud/catalog-syncs/{sync\_id}

##### [Create Catalog Sync](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/create)

POST/accounts/{account\_id}/magic/cloud/catalog-syncs

##### [Update Catalog Sync](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/update)

PUT/accounts/{account\_id}/magic/cloud/catalog-syncs/{sync\_id}

##### [Patch Catalog Sync](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/edit)

PATCH/accounts/{account\_id}/magic/cloud/catalog-syncs/{sync\_id}

##### [Delete Catalog Sync](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/delete)

DELETE/accounts/{account\_id}/magic/cloud/catalog-syncs/{sync\_id}

##### [Run Catalog Sync](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/methods/refresh)

POST/accounts/{account\_id}/magic/cloud/catalog-syncs/{sync\_id}/refresh

#### Magic Cloud NetworkingCatalog SyncsPrebuilt Policies

##### [List Prebuilt Policies](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/catalog_syncs/subresources/prebuilt_policies/methods/list)

GET/accounts/{account\_id}/magic/cloud/catalog-syncs/prebuilt-policies

#### Magic Cloud NetworkingOn Ramps

##### [List On-ramps](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/list)

GET/accounts/{account\_id}/magic/cloud/onramps

##### [Read On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/get)

GET/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}

##### [Create On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/create)

POST/accounts/{account\_id}/magic/cloud/onramps

##### [Update On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/update)

PUT/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}

##### [Patch On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/edit)

PATCH/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}

##### [Delete On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/delete)

DELETE/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}

##### [Apply On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/apply)

POST/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}/apply

##### [Export as Terraform](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/export)

POST/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}/export

##### [Plan On-ramp](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/methods/plan)

POST/accounts/{account\_id}/magic/cloud/onramps/{onramp\_id}/plan

#### Magic Cloud NetworkingOn RampsAddress Spaces

##### [Read Magic WAN Address Space](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/subresources/address_spaces/methods/list)

GET/accounts/{account\_id}/magic/cloud/onramps/magic\_wan\_address\_space

##### [Update Magic WAN Address Space](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/subresources/address_spaces/methods/update)

PUT/accounts/{account\_id}/magic/cloud/onramps/magic\_wan\_address\_space

##### [Patch Magic WAN Address Space](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/on_ramps/subresources/address_spaces/methods/edit)

PATCH/accounts/{account\_id}/magic/cloud/onramps/magic\_wan\_address\_space

#### Magic Cloud NetworkingCloud Integrations

##### [List Cloud Integrations](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/list)

GET/accounts/{account\_id}/magic/cloud/providers

##### [Read Cloud Integration](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/get)

GET/accounts/{account\_id}/magic/cloud/providers/{provider\_id}

##### [Create Cloud Integration](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/create)

POST/accounts/{account\_id}/magic/cloud/providers

##### [Update Cloud Integration](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/update)

PUT/accounts/{account\_id}/magic/cloud/providers/{provider\_id}

##### [Patch Cloud Integration](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/edit)

PATCH/accounts/{account\_id}/magic/cloud/providers/{provider\_id}

##### [Delete Cloud Integration](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/delete)

DELETE/accounts/{account\_id}/magic/cloud/providers/{provider\_id}

##### [Run Discovery for All Integrations](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/discover_all)

POST/accounts/{account\_id}/magic/cloud/providers/discover

##### [Run Discovery](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/discover)

POST/accounts/{account\_id}/magic/cloud/providers/{provider\_id}/discover

##### [Get Cloud Integration Setup Config](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/cloud_integrations/methods/initial_setup)

GET/accounts/{account\_id}/magic/cloud/providers/{provider\_id}/initial\_setup

#### Magic Cloud NetworkingResources

##### [List Resources](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/resources/methods/list)

GET/accounts/{account\_id}/magic/cloud/resources

##### [Read Resource](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/resources/methods/get)

GET/accounts/{account\_id}/magic/cloud/resources/{resource\_id}

##### [Export Resources](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/resources/methods/export)

GET/accounts/{account\_id}/magic/cloud/resources/export

##### [Preview Rego Query](https://developers.cloudflare.com/api/resources/magic_cloud_networking/subresources/resources/methods/policy_preview)

POST/accounts/{account\_id}/magic/cloud/resources/policy-preview

#### Network Interconnects

#### Network InterconnectsCNIs

##### [List existing CNI objects](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/cnis/methods/list)

GET/accounts/{account\_id}/cni/cnis

##### [Get information about a CNI object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/cnis/methods/get)

GET/accounts/{account\_id}/cni/cnis/{cni}

##### [Create a new CNI object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/cnis/methods/create)

POST/accounts/{account\_id}/cni/cnis

##### [Modify stored information about a CNI object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/cnis/methods/update)

PUT/accounts/{account\_id}/cni/cnis/{cni}

##### [Delete a specified CNI object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/cnis/methods/delete)

DELETE/accounts/{account\_id}/cni/cnis/{cni}

#### Network InterconnectsInterconnects

##### [List existing interconnects](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/interconnects/methods/list)

GET/accounts/{account\_id}/cni/interconnects

##### [Get information about an interconnect object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/interconnects/methods/get)

GET/accounts/{account\_id}/cni/interconnects/{icon}

##### [Create a new interconnect](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/interconnects/methods/create)

POST/accounts/{account\_id}/cni/interconnects

##### [Delete an interconnect object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/interconnects/methods/delete)

DELETE/accounts/{account\_id}/cni/interconnects/{icon}

##### [Generate the Letter of Authorization (LOA) for a given interconnect](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/interconnects/methods/loa)

GET/accounts/{account\_id}/cni/interconnects/{icon}/loa

##### [Get the current status of an interconnect object](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/interconnects/methods/status)

GET/accounts/{account\_id}/cni/interconnects/{icon}/status

#### Network InterconnectsSettings

##### [Get the current settings for the active account](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/settings/methods/get)

GET/accounts/{account\_id}/cni/settings

##### [Update the current settings for the active account](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/settings/methods/update)

PUT/accounts/{account\_id}/cni/settings

#### Network InterconnectsSlots

##### [Retrieve a list of all slots matching the specified parameters](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/slots/methods/list)

GET/accounts/{account\_id}/cni/slots

##### [Get information about the specified slot](https://developers.cloudflare.com/api/resources/network_interconnects/subresources/slots/methods/get)

GET/accounts/{account\_id}/cni/slots/{slot}

#### MTLS Certificates

##### [List mTLS certificates](https://developers.cloudflare.com/api/resources/mtls_certificates/methods/list)

GET/accounts/{account\_id}/mtls\_certificates

##### [Get mTLS certificate](https://developers.cloudflare.com/api/resources/mtls_certificates/methods/get)

GET/accounts/{account\_id}/mtls\_certificates/{mtls\_certificate\_id}

##### [Upload mTLS certificate](https://developers.cloudflare.com/api/resources/mtls_certificates/methods/create)

POST/accounts/{account\_id}/mtls\_certificates

##### [Delete mTLS certificate](https://developers.cloudflare.com/api/resources/mtls_certificates/methods/delete)

DELETE/accounts/{account\_id}/mtls\_certificates/{mtls\_certificate\_id}

#### MTLS CertificatesAssociations

##### [List mTLS certificate associations](https://developers.cloudflare.com/api/resources/mtls_certificates/subresources/associations/methods/get)

GET/accounts/{account\_id}/mtls\_certificates/{mtls\_certificate\_id}/associations

#### Pages

#### PagesProjects

##### [Get projects](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/list)

GET/accounts/{account\_id}/pages/projects

##### [Get project](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/get)

GET/accounts/{account\_id}/pages/projects/{project\_name}

##### [Get upload token](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/get_upload_token)

GET/accounts/{account\_id}/pages/projects/{project\_name}/upload-token

##### [Create project](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/create)

POST/accounts/{account\_id}/pages/projects

##### [Update project](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/edit)

PATCH/accounts/{account\_id}/pages/projects/{project\_name}

##### [Delete project](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/delete)

DELETE/accounts/{account\_id}/pages/projects/{project\_name}

##### [Purge build cache](https://developers.cloudflare.com/api/resources/pages/subresources/projects/methods/purge_build_cache)

POST/accounts/{account\_id}/pages/projects/{project\_name}/purge\_build\_cache

#### PagesProjectsDeployments

##### [Get deployments](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/methods/list)

GET/accounts/{account\_id}/pages/projects/{project\_name}/deployments

##### [Get deployment info](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/methods/get)

GET/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}

##### [Create deployment](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/methods/create)

POST/accounts/{account\_id}/pages/projects/{project\_name}/deployments

##### [Delete deployment](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/methods/delete)

DELETE/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}

##### [Retry deployment](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/methods/retry)

POST/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}/retry

##### [Rollback deployment](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/methods/rollback)

POST/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}/rollback

#### PagesProjectsDeploymentsHistory

#### PagesProjectsDeploymentsHistoryLogs

##### [Get deployment logs](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/subresources/history/subresources/logs/methods/get)

GET/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}/history/logs

#### PagesProjectsDeploymentsTails

##### [Create deployment tail](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/subresources/tails/methods/create)

POST/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}/tails

##### [Delete deployment tail](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/deployments/subresources/tails/methods/delete)

DELETE/accounts/{account\_id}/pages/projects/{project\_name}/deployments/{deployment\_id}/tails/{tail\_id}

#### PagesProjectsDomains

##### [Get domains](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/domains/methods/list)

GET/accounts/{account\_id}/pages/projects/{project\_name}/domains

##### [Get domain](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/domains/methods/get)

GET/accounts/{account\_id}/pages/projects/{project\_name}/domains/{domain\_name}

##### [Add domain](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/domains/methods/create)

POST/accounts/{account\_id}/pages/projects/{project\_name}/domains

##### [Patch domain](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/domains/methods/edit)

PATCH/accounts/{account\_id}/pages/projects/{project\_name}/domains/{domain\_name}

##### [Delete domain](https://developers.cloudflare.com/api/resources/pages/subresources/projects/subresources/domains/methods/delete)

DELETE/accounts/{account\_id}/pages/projects/{project\_name}/domains/{domain\_name}

#### PagesAssets

##### [Upsert asset hashes](https://developers.cloudflare.com/api/resources/pages/subresources/assets/methods/upsert_hashes)

POST/pages/assets/upsert-hashes

##### [Check missing assets](https://developers.cloudflare.com/api/resources/pages/subresources/assets/methods/check_missing)

POST/pages/assets/check-missing

##### [Upload asset](https://developers.cloudflare.com/api/resources/pages/subresources/assets/methods/upload)

POST/pages/assets/upload

#### Registrar

Registrar API for searching, checking, registering, and managing domains through Cloudflare Registrar.

## Prerequisites

Before using this API, ensure:

1. **Cloudflare account** — the caller must have a valid Cloudflare account.
2. **Billing profile** — the account must have a billing profile with a valid, current default payment method (credit card or other accepted method). This cannot be set up via API — the account owner must configure billing at `https://dash.cloudflare.com/{account_id}/billing/payment-info` before calling `POST /registrations`.
3. **API authentication** — use an API token or API key with the appropriate Registrar permissions for the operations you are calling.

## Terminology: domain extension

Throughout this API, “extension” refers to the domain extension part of a fully qualified domain name — the portion after the registrable label. For example, in `example.co.uk`, the extension is `co.uk` (not just `uk`). This covers both top-level domains like `com` and multi-level extensions like `co.uk`. This is distinct from other uses of the word “extension” (e.g., EPP extensions).

## Supported extensions

This API supports programmatic registration for all extensions supported by the dashboard experience, with the following exceptions:

`giving`, `mom`, `inc`, `lol`, `sh`, `link`, `cc`, `new`

Cloudflare Registrar supports 400+ extensions in the dashboard. Extensions listed above can be registered at `https://dash.cloudflare.com/{account_id}/domains/registrations`.

## Typical workflow

1. **Search** — call `GET /domain-search?q={keyword}` to discover available domains.
2. **Check** — call `POST /domain-check` with candidate domains to verify real-time availability and pricing.
3. **Review the response** — if `registrable: false`, inspect `reason` to understand whether the domain is unavailable, the extension is not supported by this API, the extension is not supported by Cloudflare Registrar at all, or the extension’s registry has frozen new registrations.
4. **Handle premium domains** — if `tier: premium`, premium registration is not currently supported by this API. Surface the premium pricing to the user, but do not proceed to `POST /registrations` for that domain.
5. **Observe the registration schema** — call `GET /extensions/:extension_name` to discover the required values for registering this extension.
6. **Register** — call `POST /registrations` with the chosen domain name for supported non-premium registrations.
7. **Confirm completion** — if the response is `201 Created`, registration completed within the default timeout and no polling is needed.
8. **Poll when needed** — if the response is `202 Accepted`, poll `links.self` from the workflow response.
9. **Stop for user action** — if `state: action_required`, stop polling and surface `context.action` to the user. The workflow will not resolve on its own.
10. **Continue when blocked** — if `state: blocked`, continue polling and inform the user that a third party, such as the extension registry or losing registrar, is delaying progress.
11. **Review failures before retrying** — if `state: failed`, review `error.code` and `error.message`, then decide whether user action or a new Check call is needed.

**All successful domain registrations are non-refundable.** Once the registration workflow completes with `state: succeeded`, the charge cannot be reversed. Confirm pricing and domain choice with the user before calling `POST /registrations`.

## Default behavior for mutating operations

By default, mutating operations such as create and update hold the connection for a bounded, server-defined amount of time while the operation completes. In most cases, the response contains a completed workflow status and no polling is required.

- **Completed within the synchronous wait window:** Returns `201` (create) or `200` (update) with a `workflow_status` where `state: succeeded` and `completed: true`.
- **Still processing after the synchronous wait window:** Returns `202 Accepted` with a `workflow_status` where `completed: false`. Use the `links.self` URL to poll for completion.

## Non-blocking mode

To receive an immediate `202 Accepted` response without waiting, send the `Prefer: respond-async` request header (RFC 7240). The server will acknowledge it with a `Preference-Applied: respond-async` response header.

## Polling

When the response is `202`, poll the workflow status endpoint indicated by `links.self` in the response body until the workflow reaches a terminal state or requires user action.

##### [Search for available domains](https://developers.cloudflare.com/api/resources/registrar/methods/search)

GET/accounts/{account\_id}/registrar/domain-search

##### [Check domain availability](https://developers.cloudflare.com/api/resources/registrar/methods/check)

POST/accounts/{account\_id}/registrar/domain-check

#### RegistrarDomains

##### [List domains](https://developers.cloudflare.com/api/resources/registrar/subresources/domains/methods/list)

Deprecated

GET/accounts/{account\_id}/registrar/domains

##### [Get domain](https://developers.cloudflare.com/api/resources/registrar/subresources/domains/methods/get)

Deprecated

GET/accounts/{account\_id}/registrar/domains/{domain\_name}

##### [Update domain](https://developers.cloudflare.com/api/resources/registrar/subresources/domains/methods/update)

Deprecated

PUT/accounts/{account\_id}/registrar/domains/{domain\_name}

#### RegistrarRegistrations

##### [Create Registration](https://developers.cloudflare.com/api/resources/registrar/subresources/registrations/methods/create)

POST/accounts/{account\_id}/registrar/registrations

##### [List Registrations](https://developers.cloudflare.com/api/resources/registrar/subresources/registrations/methods/list)

GET/accounts/{account\_id}/registrar/registrations

##### [Get Registration](https://developers.cloudflare.com/api/resources/registrar/subresources/registrations/methods/get)

GET/accounts/{account\_id}/registrar/registrations/{domain\_name}

##### [Update Registration](https://developers.cloudflare.com/api/resources/registrar/subresources/registrations/methods/edit)

PATCH/accounts/{account\_id}/registrar/registrations/{domain\_name}

#### RegistrarRegistration Status

##### [Get Registration Status](https://developers.cloudflare.com/api/resources/registrar/subresources/registration_status/methods/get)

GET/accounts/{account\_id}/registrar/registrations/{domain\_name}/registration-status

#### RegistrarUpdate Status

##### [Get Update Status](https://developers.cloudflare.com/api/resources/registrar/subresources/update_status/methods/get)

GET/accounts/{account\_id}/registrar/registrations/{domain\_name}/update-status

#### RegistrarExtensions

##### [List extensions](https://developers.cloudflare.com/api/resources/registrar/subresources/extensions/methods/list)

GET/accounts/{account\_id}/registrar/extensions

##### [Get extension](https://developers.cloudflare.com/api/resources/registrar/subresources/extensions/methods/get)

GET/accounts/{account\_id}/registrar/extensions/{extension}

#### Registrar Sandbox

Use the Registrar Sandbox API to test domain search, availability checks, registration, and domain management flows without buying real domains.

**This API is a test environment for the production Registrar API.**

## Prerequisites

Before using this API, make sure you have:

1. **Cloudflare account** — the caller must have a valid Cloudflare account.
2. **API authentication** — create an API token with Registrar Sandbox permissions.

## How the Sandbox API differs from the production Registrar API

Because the Sandbox API is intended for testing, it behaves differently from the production Registrar API in a few important ways:

1. **No billing** — you will not be charged real money for purchasing a domain.
2. **No real domains** — purchased domains are test records and will not be reachable on the Internet.
3. **No DNS zones** — purchasing a domain does not create a zone resource.
4. **No Registration Express Mode** — you must provide full contact data.

Sandbox purchases are still persisted. If you purchase a domain in the sandbox, that domain will not be available for others to purchase in the sandbox.

## Terminology: domain extension

Throughout this API, “extension” refers to the domain extension part of a fully qualified domain name — the portion after the registrable label. For example, in `example.co.uk`, the extension is `co.uk` (not just `uk`). This covers both top-level domains like `com` and multi-level extensions like `co.uk`. This is distinct from other uses of the word “extension” (e.g., EPP extensions).

## Supported extensions

The Sandbox API currently supports programmatic registration for these extensions:

`com`, `net`

The production Registrar API supports 40+ extensions.

Cloudflare Registrar supports 400+ extensions in the dashboard. Extensions not listed above can be registered at `https://dash.cloudflare.com/{account_id}/domains/registrations`.

## Typical workflow

1. **Search** — call `GET /domain-search?q={keyword}` to discover available domains.
2. **Check** — call `POST /domain-check` with candidate domains to verify real-time availability and pricing.
3. **Review the response** — if `registrable: false`, inspect `reason` to understand whether the domain is unavailable, the extension is not supported by this API, the extension is not supported by Cloudflare Registrar at all, or the extension’s registry has frozen new registrations.
4. **Handle premium domains** — if `tier: premium`, premium registration is not currently supported by this API. The Sandbox API currently supports only `com` and `net`, which do not have premium registrations, but clients should still handle this response for consistency with the production Registrar API. Surface the premium pricing to the user, but do not proceed to `POST /registrations` for that domain.
5. **Observe the registration schema** — call `GET /extensions/:extension_name` to discover the required values for registering this extension.
6. **Register** — call `POST /registrations` with the chosen domain name for supported non-premium registrations.
7. **Confirm completion** — if the response is `201 Created`, registration completed within the default timeout and no polling is needed.
8. **Poll when needed** — if the response is `202 Accepted`, poll `links.self` from the workflow response.
9. **Stop for user action** — if `state: action_required`, stop polling and surface `context.action` to the user. The workflow will not resolve on its own.
10. **Continue when blocked** — if `state: blocked`, continue polling and inform the user that a third party, such as the extension registry or losing registrar, is delaying progress.
11. **Review failures before retrying** — if `state: failed`, review `error.code` and `error.message`, then decide whether user action or a new Check call is needed.

## Default behavior for mutating operations

By default, mutating operations such as create and update hold the connection for a bounded, server-defined amount of time while the operation completes. In most cases, the response contains a completed workflow status and no polling is required.

- **Completed within the synchronous wait window:** Returns `201` (create) or `200` (update) with a `workflow_status` where `state: succeeded` and `completed: true`.
- **Still processing after the synchronous wait window:** Returns `202 Accepted` with a `workflow_status` where `completed: false`. Use the `links.self` URL to poll for completion.

## Non-blocking mode

To receive an immediate `202 Accepted` response without waiting, send the `Prefer: respond-async` request header (RFC 7240). The server will acknowledge it with a `Preference-Applied: respond-async` response header.

## Polling

When the response is `202`, poll the workflow status endpoint indicated by `links.self` in the response body until the workflow reaches a terminal state or requires user action.

##### [Search for available domains](https://developers.cloudflare.com/api/resources/registrar_sandbox/methods/search)

GET/accounts/{account\_id}/registrar-sandbox/domain-search

##### [Check domain availability](https://developers.cloudflare.com/api/resources/registrar_sandbox/methods/check)

POST/accounts/{account\_id}/registrar-sandbox/domain-check

#### Registrar SandboxRegistrations

##### [Create Registration](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/registrations/methods/create)

POST/accounts/{account\_id}/registrar-sandbox/registrations

##### [List Registrations](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/registrations/methods/list)

GET/accounts/{account\_id}/registrar-sandbox/registrations

##### [Get Registration](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/registrations/methods/get)

GET/accounts/{account\_id}/registrar-sandbox/registrations/{domain\_name}

##### [Update Registration](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/registrations/methods/edit)

PATCH/accounts/{account\_id}/registrar-sandbox/registrations/{domain\_name}

#### Registrar SandboxRegistration Status

##### [Get Registration Status](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/registration_status/methods/get)

GET/accounts/{account\_id}/registrar-sandbox/registrations/{domain\_name}/registration-status

#### Registrar SandboxUpdate Status

##### [Get Update Status](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/update_status/methods/get)

GET/accounts/{account\_id}/registrar-sandbox/registrations/{domain\_name}/update-status

#### Registrar SandboxExtensions

##### [List extensions](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/extensions/methods/list)

GET/accounts/{account\_id}/registrar-sandbox/extensions

##### [Get extension](https://developers.cloudflare.com/api/resources/registrar_sandbox/subresources/extensions/methods/get)

GET/accounts/{account\_id}/registrar-sandbox/extensions/{extension}

#### Rules Trace

#### Rules TraceTraces

##### [Request Trace](https://developers.cloudflare.com/api/resources/request_tracers/subresources/traces/methods/create)

POST/accounts/{account\_id}/request-tracer/trace

#### Rules Lists

#### Rules ListsLists

##### [Get lists](https://developers.cloudflare.com/api/resources/rules/subresources/lists/methods/list)

GET/accounts/{account\_id}/rules/lists

##### [Get a list](https://developers.cloudflare.com/api/resources/rules/subresources/lists/methods/get)

GET/accounts/{account\_id}/rules/lists/{list\_id}

##### [Create a list](https://developers.cloudflare.com/api/resources/rules/subresources/lists/methods/create)

POST/accounts/{account\_id}/rules/lists

##### [Update a list](https://developers.cloudflare.com/api/resources/rules/subresources/lists/methods/update)

PUT/accounts/{account\_id}/rules/lists/{list\_id}

##### [Delete a list](https://developers.cloudflare.com/api/resources/rules/subresources/lists/methods/delete)

DELETE/accounts/{account\_id}/rules/lists/{list\_id}

#### Rules ListsListsBulk Operations

##### [Get bulk operation status](https://developers.cloudflare.com/api/resources/rules/subresources/lists/subresources/bulk_operations/methods/get)

GET/accounts/{account\_id}/rules/lists/bulk\_operations/{operation\_id}

#### Rules ListsListsItems

##### [Get list items](https://developers.cloudflare.com/api/resources/rules/subresources/lists/subresources/items/methods/list)

GET/accounts/{account\_id}/rules/lists/{list\_id}/items

##### [Get a list item](https://developers.cloudflare.com/api/resources/rules/subresources/lists/subresources/items/methods/get)

GET/accounts/{account\_id}/rules/lists/{list\_id}/items/{item\_id}

##### [Create list items](https://developers.cloudflare.com/api/resources/rules/subresources/lists/subresources/items/methods/create)

POST/accounts/{account\_id}/rules/lists/{list\_id}/items

##### [Update all list items](https://developers.cloudflare.com/api/resources/rules/subresources/lists/subresources/items/methods/update)

PUT/accounts/{account\_id}/rules/lists/{list\_id}/items

##### [Delete list items](https://developers.cloudflare.com/api/resources/rules/subresources/lists/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/rules/lists/{list\_id}/items

#### Stream

##### [List videos](https://developers.cloudflare.com/api/resources/stream/methods/list)

GET/accounts/{account\_id}/stream

##### [Retrieve video details](https://developers.cloudflare.com/api/resources/stream/methods/get)

GET/accounts/{account\_id}/stream/{identifier}

##### [Initiate video uploads using TUS](https://developers.cloudflare.com/api/resources/stream/methods/create)

POST/accounts/{account\_id}/stream

##### [Edit video details](https://developers.cloudflare.com/api/resources/stream/methods/edit)

POST/accounts/{account\_id}/stream/{identifier}

##### [Delete video](https://developers.cloudflare.com/api/resources/stream/methods/delete)

DELETE/accounts/{account\_id}/stream/{identifier}

#### StreamAudio Tracks

##### [List additional audio tracks on a video](https://developers.cloudflare.com/api/resources/stream/subresources/audio_tracks/methods/get)

GET/accounts/{account\_id}/stream/{identifier}/audio

##### [Edit additional audio tracks on a video](https://developers.cloudflare.com/api/resources/stream/subresources/audio_tracks/methods/edit)

PATCH/accounts/{account\_id}/stream/{identifier}/audio/{audio\_identifier}

##### [Delete additional audio tracks on a video](https://developers.cloudflare.com/api/resources/stream/subresources/audio_tracks/methods/delete)

DELETE/accounts/{account\_id}/stream/{identifier}/audio/{audio\_identifier}

##### [Add audio tracks to a video](https://developers.cloudflare.com/api/resources/stream/subresources/audio_tracks/methods/copy)

POST/accounts/{account\_id}/stream/{identifier}/audio/copy

#### StreamVideos

##### [Storage use](https://developers.cloudflare.com/api/resources/stream/subresources/videos/methods/storage_usage)

GET/accounts/{account\_id}/stream/storage-usage

#### StreamClip

##### [Clip videos given a start and end time](https://developers.cloudflare.com/api/resources/stream/subresources/clip/methods/create)

POST/accounts/{account\_id}/stream/clip

#### StreamCopy

##### [Upload videos from a URL](https://developers.cloudflare.com/api/resources/stream/subresources/copy/methods/create)

POST/accounts/{account\_id}/stream/copy

#### StreamDirect Upload

##### [Upload videos via direct upload URLs](https://developers.cloudflare.com/api/resources/stream/subresources/direct_upload/methods/create)

POST/accounts/{account\_id}/stream/direct\_upload

#### StreamKeys

##### [List signing keys](https://developers.cloudflare.com/api/resources/stream/subresources/keys/methods/get)

GET/accounts/{account\_id}/stream/keys

##### [Create signing keys](https://developers.cloudflare.com/api/resources/stream/subresources/keys/methods/create)

POST/accounts/{account\_id}/stream/keys

##### [Delete signing keys](https://developers.cloudflare.com/api/resources/stream/subresources/keys/methods/delete)

DELETE/accounts/{account\_id}/stream/keys/{identifier}

#### StreamLive Inputs

##### [List live inputs](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/methods/list)

GET/accounts/{account\_id}/stream/live\_inputs

##### [Retrieve a live input](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/methods/get)

GET/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}

##### [Create a live input](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/methods/create)

POST/accounts/{account\_id}/stream/live\_inputs

##### [Update a live input](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/methods/update)

PUT/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}

##### [Delete a live input](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/methods/delete)

DELETE/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}

#### StreamLive InputsOutputs

##### [List all outputs associated with a specified live input](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/subresources/outputs/methods/list)

GET/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}/outputs

##### [Create a new output, connected to a live input](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/subresources/outputs/methods/create)

POST/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}/outputs

##### [Update an output](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/subresources/outputs/methods/update)

PUT/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}/outputs/{output\_identifier}

##### [Delete an output](https://developers.cloudflare.com/api/resources/stream/subresources/live_inputs/subresources/outputs/methods/delete)

DELETE/accounts/{account\_id}/stream/live\_inputs/{live\_input\_identifier}/outputs/{output\_identifier}

#### StreamWatermarks

##### [List watermark profiles](https://developers.cloudflare.com/api/resources/stream/subresources/watermarks/methods/list)

GET/accounts/{account\_id}/stream/watermarks

##### [Watermark profile details](https://developers.cloudflare.com/api/resources/stream/subresources/watermarks/methods/get)

GET/accounts/{account\_id}/stream/watermarks/{identifier}

##### [Create watermark profiles via basic upload](https://developers.cloudflare.com/api/resources/stream/subresources/watermarks/methods/create)

POST/accounts/{account\_id}/stream/watermarks

##### [Delete watermark profiles](https://developers.cloudflare.com/api/resources/stream/subresources/watermarks/methods/delete)

DELETE/accounts/{account\_id}/stream/watermarks/{identifier}

#### StreamWebhooks

##### [View webhook](https://developers.cloudflare.com/api/resources/stream/subresources/webhooks/methods/get)

GET/accounts/{account\_id}/stream/webhook

##### [Create VOD webhooks](https://developers.cloudflare.com/api/resources/stream/subresources/webhooks/methods/update)

PUT/accounts/{account\_id}/stream/webhook

##### [Delete webhooks](https://developers.cloudflare.com/api/resources/stream/subresources/webhooks/methods/delete)

DELETE/accounts/{account\_id}/stream/webhook

#### StreamCaptions

##### [List captions or subtitles](https://developers.cloudflare.com/api/resources/stream/subresources/captions/methods/get)

GET/accounts/{account\_id}/stream/{identifier}/captions

#### StreamCaptionsLanguage

##### [List captions or subtitles for a provided language](https://developers.cloudflare.com/api/resources/stream/subresources/captions/subresources/language/methods/get)

GET/accounts/{account\_id}/stream/{identifier}/captions/{language}

##### [Generate captions or subtitles for a provided language via AI](https://developers.cloudflare.com/api/resources/stream/subresources/captions/subresources/language/methods/create)

POST/accounts/{account\_id}/stream/{identifier}/captions/{language}/generate

##### [Upload captions or subtitles](https://developers.cloudflare.com/api/resources/stream/subresources/captions/subresources/language/methods/update)

PUT/accounts/{account\_id}/stream/{identifier}/captions/{language}

##### [Delete captions or subtitles](https://developers.cloudflare.com/api/resources/stream/subresources/captions/subresources/language/methods/delete)

DELETE/accounts/{account\_id}/stream/{identifier}/captions/{language}

#### StreamCaptionsLanguageVtt

##### [Return WebVTT captions for a provided language](https://developers.cloudflare.com/api/resources/stream/subresources/captions/subresources/language/subresources/vtt/methods/get)

GET/accounts/{account\_id}/stream/{identifier}/captions/{language}/vtt

#### StreamDownloads

##### [List downloads](https://developers.cloudflare.com/api/resources/stream/subresources/downloads/methods/get)

GET/accounts/{account\_id}/stream/{identifier}/downloads

##### [Create downloads](https://developers.cloudflare.com/api/resources/stream/subresources/downloads/methods/create)

POST/accounts/{account\_id}/stream/{identifier}/downloads

##### [Delete downloads](https://developers.cloudflare.com/api/resources/stream/subresources/downloads/methods/delete)

DELETE/accounts/{account\_id}/stream/{identifier}/downloads

#### StreamEmbed

##### [Deprecated: Retrieve legacy embed code HTML](https://developers.cloudflare.com/api/resources/stream/subresources/embed/methods/get)

GET/accounts/{account\_id}/stream/{identifier}/embed

#### StreamToken

##### [Create signed URL tokens for videos](https://developers.cloudflare.com/api/resources/stream/subresources/token/methods/create)

POST/accounts/{account\_id}/stream/{identifier}/token

#### Alerting

#### AlertingAvailable Alerts

##### [Get Alert Types](https://developers.cloudflare.com/api/resources/alerting/subresources/available_alerts/methods/list)

GET/accounts/{account\_id}/alerting/v3/available\_alerts

#### AlertingDestinations

#### AlertingDestinationsEligible

##### [Get delivery mechanism eligibility](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/eligible/methods/get)

GET/accounts/{account\_id}/alerting/v3/destinations/eligible

#### AlertingDestinationsPagerduty

##### [List PagerDuty services](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/pagerduty/methods/get)

GET/accounts/{account\_id}/alerting/v3/destinations/pagerduty

##### [Create PagerDuty integration token](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/pagerduty/methods/create)

POST/accounts/{account\_id}/alerting/v3/destinations/pagerduty/connect

##### [Delete PagerDuty Services](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/pagerduty/methods/delete)

DELETE/accounts/{account\_id}/alerting/v3/destinations/pagerduty

##### [Connect PagerDuty](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/pagerduty/methods/link)

GET/accounts/{account\_id}/alerting/v3/destinations/pagerduty/connect/{token\_id}

#### AlertingDestinationsWebhooks

##### [List webhooks](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/webhooks/methods/list)

GET/accounts/{account\_id}/alerting/v3/destinations/webhooks

##### [Get a webhook](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/webhooks/methods/get)

GET/accounts/{account\_id}/alerting/v3/destinations/webhooks/{webhook\_id}

##### [Create a webhook](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/webhooks/methods/create)

POST/accounts/{account\_id}/alerting/v3/destinations/webhooks

##### [Update a webhook](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/webhooks/methods/update)

PUT/accounts/{account\_id}/alerting/v3/destinations/webhooks/{webhook\_id}

##### [Delete a webhook](https://developers.cloudflare.com/api/resources/alerting/subresources/destinations/subresources/webhooks/methods/delete)

DELETE/accounts/{account\_id}/alerting/v3/destinations/webhooks/{webhook\_id}

#### AlertingHistory

##### [List History](https://developers.cloudflare.com/api/resources/alerting/subresources/history/methods/list)

GET/accounts/{account\_id}/alerting/v3/history

#### AlertingPolicies

##### [List Notification policies](https://developers.cloudflare.com/api/resources/alerting/subresources/policies/methods/list)

GET/accounts/{account\_id}/alerting/v3/policies

##### [Get a Notification policy](https://developers.cloudflare.com/api/resources/alerting/subresources/policies/methods/get)

GET/accounts/{account\_id}/alerting/v3/policies/{policy\_id}

##### [Create a Notification policy](https://developers.cloudflare.com/api/resources/alerting/subresources/policies/methods/create)

POST/accounts/{account\_id}/alerting/v3/policies

##### [Update a Notification policy](https://developers.cloudflare.com/api/resources/alerting/subresources/policies/methods/update)

PUT/accounts/{account\_id}/alerting/v3/policies/{policy\_id}

##### [Delete a Notification policy](https://developers.cloudflare.com/api/resources/alerting/subresources/policies/methods/delete)

DELETE/accounts/{account\_id}/alerting/v3/policies/{policy\_id}

#### AlertingSilences

##### [List Silences](https://developers.cloudflare.com/api/resources/alerting/subresources/silences/methods/list)

GET/accounts/{account\_id}/alerting/v3/silences

##### [Get Silence](https://developers.cloudflare.com/api/resources/alerting/subresources/silences/methods/get)

GET/accounts/{account\_id}/alerting/v3/silences/{silence\_id}

##### [Create Silences](https://developers.cloudflare.com/api/resources/alerting/subresources/silences/methods/create)

POST/accounts/{account\_id}/alerting/v3/silences

##### [Update Silences](https://developers.cloudflare.com/api/resources/alerting/subresources/silences/methods/update)

PUT/accounts/{account\_id}/alerting/v3/silences

##### [Delete Silence](https://developers.cloudflare.com/api/resources/alerting/subresources/silences/methods/delete)

DELETE/accounts/{account\_id}/alerting/v3/silences/{silence\_id}

#### D1

#### D1Database

##### [List D1 Databases](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/list)

GET/accounts/{account\_id}/d1/database

##### [Get D1 Database](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/get)

GET/accounts/{account\_id}/d1/database/{database\_id}

##### [Create D1 Database](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/create)

POST/accounts/{account\_id}/d1/database

##### [Update D1 Database](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/update)

PUT/accounts/{account\_id}/d1/database/{database\_id}

##### [Update D1 Database partially](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/edit)

PATCH/accounts/{account\_id}/d1/database/{database\_id}

##### [Delete D1 Database](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/delete)

DELETE/accounts/{account\_id}/d1/database/{database\_id}

##### [Query D1 Database](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/query)

POST/accounts/{account\_id}/d1/database/{database\_id}/query

##### [Raw D1 Database query](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/raw)

POST/accounts/{account\_id}/d1/database/{database\_id}/raw

##### [Export D1 Database as SQL](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/export)

POST/accounts/{account\_id}/d1/database/{database\_id}/export

##### [Import SQL into your D1 Database](https://developers.cloudflare.com/api/resources/d1/subresources/database/methods/import)

POST/accounts/{account\_id}/d1/database/{database\_id}/import

#### D1DatabaseTime Travel

##### [Get D1 database bookmark](https://developers.cloudflare.com/api/resources/d1/subresources/database/subresources/time_travel/methods/get_bookmark)

GET/accounts/{account\_id}/d1/database/{database\_id}/time\_travel/bookmark

##### [Restore D1 Database to a bookmark or point in time](https://developers.cloudflare.com/api/resources/d1/subresources/database/subresources/time_travel/methods/restore)

POST/accounts/{account\_id}/d1/database/{database\_id}/time\_travel/restore

#### R2

#### R2Buckets

##### [List Buckets](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/methods/list)

GET/accounts/{account\_id}/r2/buckets

##### [Get Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}

##### [Create Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/methods/create)

POST/accounts/{account\_id}/r2/buckets

##### [Patch Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/methods/edit)

PATCH/accounts/{account\_id}/r2/buckets/{bucket\_name}

##### [Delete Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/methods/delete)

DELETE/accounts/{account\_id}/r2/buckets/{bucket\_name}

#### R2BucketsLifecycle

##### [Get Object Lifecycle Rules](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/lifecycle/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/lifecycle

##### [Put Object Lifecycle Rules](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/lifecycle/methods/update)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/lifecycle

#### R2BucketsCORS

##### [Get Bucket CORS Policy](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/cors/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/cors

##### [Put Bucket CORS Policy](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/cors/methods/update)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/cors

##### [Delete Bucket CORS Policy](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/cors/methods/delete)

DELETE/accounts/{account\_id}/r2/buckets/{bucket\_name}/cors

#### R2BucketsDomains

#### R2BucketsDomainsCustom

##### [List Custom Domains of Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/custom/methods/list)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/custom

##### [Get Custom Domain Settings](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/custom/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/custom/{domain}

##### [Attach Custom Domain To Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/custom/methods/create)

POST/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/custom

##### [Configure Custom Domain Settings](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/custom/methods/update)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/custom/{domain}

##### [Remove Custom Domain From Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/custom/methods/delete)

DELETE/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/custom/{domain}

#### R2BucketsDomainsManaged

##### [Get r2.dev Domain of Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/managed/methods/list)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/managed

##### [Update r2.dev Domain of Bucket](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/domains/subresources/managed/methods/update)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/domains/managed

#### R2BucketsEvent Notifications

##### [List Event Notification Rules](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/event_notifications/methods/list)

GET/accounts/{account\_id}/event\_notifications/r2/{bucket\_name}/configuration

##### [Get Event Notification Rule](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/event_notifications/methods/get)

GET/accounts/{account\_id}/event\_notifications/r2/{bucket\_name}/configuration/queues/{queue\_id}

##### [Create Event Notification Rule](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/event_notifications/methods/update)

PUT/accounts/{account\_id}/event\_notifications/r2/{bucket\_name}/configuration/queues/{queue\_id}

##### [Delete Event Notification Rules](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/event_notifications/methods/delete)

DELETE/accounts/{account\_id}/event\_notifications/r2/{bucket\_name}/configuration/queues/{queue\_id}

#### R2BucketsLocks

##### [Get Bucket Lock Rules](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/locks/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/lock

##### [Put Bucket Lock Rules](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/locks/methods/update)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/lock

#### R2BucketsMetrics

##### [Get Account-Level Metrics](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/metrics/methods/list)

GET/accounts/{account\_id}/r2/metrics

#### R2BucketsSippy

##### [Get Sippy Configuration](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/sippy/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/sippy

##### [Enable Sippy](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/sippy/methods/update)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/sippy

##### [Disable Sippy](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/sippy/methods/delete)

DELETE/accounts/{account\_id}/r2/buckets/{bucket\_name}/sippy

#### R2BucketsObjects

##### [List Objects](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/objects/methods/list)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/objects

##### [Get Object](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/objects/methods/get)

GET/accounts/{account\_id}/r2/buckets/{bucket\_name}/objects/{object\_key}

##### [Upload Object](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/objects/methods/upload)

PUT/accounts/{account\_id}/r2/buckets/{bucket\_name}/objects/{object\_key}

##### [Delete Object](https://developers.cloudflare.com/api/resources/r2/subresources/buckets/subresources/objects/methods/delete)

DELETE/accounts/{account\_id}/r2/buckets/{bucket\_name}/objects/{object\_key}

#### R2Temporary Credentials

##### [Create Temporary Access Credentials](https://developers.cloudflare.com/api/resources/r2/subresources/temporary_credentials/methods/create)

POST/accounts/{account\_id}/r2/temp-access-credentials

#### R2Super Slurper

#### R2Super SlurperJobs

##### [List jobs](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/list)

GET/accounts/{account\_id}/slurper/jobs

##### [Get job details](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/get)

GET/accounts/{account\_id}/slurper/jobs/{job\_id}

##### [Create a job](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/create)

POST/accounts/{account\_id}/slurper/jobs

##### [Abort all jobs](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/abort_all)

PUT/accounts/{account\_id}/slurper/jobs/abortAll

##### [Abort a job](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/abort)

PUT/accounts/{account\_id}/slurper/jobs/{job\_id}/abort

##### [Pause a job](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/pause)

PUT/accounts/{account\_id}/slurper/jobs/{job\_id}/pause

##### [Get job progress](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/progress)

GET/accounts/{account\_id}/slurper/jobs/{job\_id}/progress

##### [Resume a job](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/methods/resume)

PUT/accounts/{account\_id}/slurper/jobs/{job\_id}/resume

#### R2Super SlurperJobsLogs

##### [Get job logs](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/jobs/subresources/logs/methods/list)

GET/accounts/{account\_id}/slurper/jobs/{job\_id}/logs

#### R2Super SlurperConnectivity Precheck

##### [Check source connectivity](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/connectivity_precheck/methods/source)

PUT/accounts/{account\_id}/slurper/source/connectivity-precheck

##### [Check target connectivity](https://developers.cloudflare.com/api/resources/r2/subresources/super_slurper/subresources/connectivity_precheck/methods/target)

PUT/accounts/{account\_id}/slurper/target/connectivity-precheck

#### R2 Data Catalog

##### [List R2 catalogs](https://developers.cloudflare.com/api/resources/r2_data_catalog/methods/list)

GET/accounts/{account\_id}/r2-catalog

##### [Get R2 catalog details](https://developers.cloudflare.com/api/resources/r2_data_catalog/methods/get)

GET/accounts/{account\_id}/r2-catalog/{bucket\_name}

##### [Enable R2 bucket as a catalog](https://developers.cloudflare.com/api/resources/r2_data_catalog/methods/enable)

POST/accounts/{account\_id}/r2-catalog/{bucket\_name}/enable

##### [Disable R2 catalog](https://developers.cloudflare.com/api/resources/r2_data_catalog/methods/disable)

POST/accounts/{account\_id}/r2-catalog/{bucket\_name}/disable

##### [Delete R2 catalog metadata](https://developers.cloudflare.com/api/resources/r2_data_catalog/methods/delete)

POST/accounts/{account\_id}/r2-catalog/{bucket\_name}/delete

#### R2 Data CatalogMaintenance Configs

##### [Get catalog maintenance configuration](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/maintenance_configs/methods/get)

GET/accounts/{account\_id}/r2-catalog/{bucket\_name}/maintenance-configs

##### [Update catalog maintenance configuration](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/maintenance_configs/methods/update)

POST/accounts/{account\_id}/r2-catalog/{bucket\_name}/maintenance-configs

#### R2 Data CatalogCredentials

##### [Store catalog credentials](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/credentials/methods/create)

POST/accounts/{account\_id}/r2-catalog/{bucket\_name}/credential

#### R2 Data CatalogNamespaces

##### [List namespaces in catalog](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/namespaces/methods/list)

GET/accounts/{account\_id}/r2-catalog/{bucket\_name}/namespaces

#### R2 Data CatalogNamespacesTables

##### [List tables in namespace](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/namespaces/subresources/tables/methods/list)

GET/accounts/{account\_id}/r2-catalog/{bucket\_name}/namespaces/{namespace}/tables

#### R2 Data CatalogNamespacesTablesMaintenance Configs

##### [Get table maintenance configuration](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/namespaces/subresources/tables/subresources/maintenance_configs/methods/get)

GET/accounts/{account\_id}/r2-catalog/{bucket\_name}/namespaces/{namespace}/tables/{table\_name}/maintenance-configs

##### [Update table maintenance configuration](https://developers.cloudflare.com/api/resources/r2_data_catalog/subresources/namespaces/subresources/tables/subresources/maintenance_configs/methods/update)

POST/accounts/{account\_id}/r2-catalog/{bucket\_name}/namespaces/{namespace}/tables/{table\_name}/maintenance-configs

#### Workers For Platforms

#### Workers For PlatformsDispatch

#### Workers For PlatformsDispatchNamespaces

##### [List Workers for Platforms Dispatch Namespaces](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/methods/list)

GET/accounts/{account\_id}/workers/dispatch/namespaces

##### [Get Workers for Platforms Dispatch Namespace](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/methods/get)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}

##### [Create Workers for Platforms Dispatch Namespace](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/methods/create)

POST/accounts/{account\_id}/workers/dispatch/namespaces

##### [Delete Workers for Platforms Dispatch Namespace](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/methods/delete)

DELETE/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}

#### Workers For PlatformsDispatchNamespacesScripts

##### [Get Workers for Platforms Script details](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/methods/get)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}

##### [Upload Workers for Platforms Script Module](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/methods/update)

PUT/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}

##### [Delete Workers for Platforms Script](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/methods/delete)

DELETE/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}

#### Workers For PlatformsDispatchNamespacesScriptsAsset Upload

##### [Create Workers for Platforms Assets Upload Session](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/asset_upload/methods/create)

POST/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/assets-upload-session

#### Workers For PlatformsDispatchNamespacesScriptsContent

##### [Get Workers for Platforms Script Content](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/content/methods/get)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/content

##### [Replace Workers for Platforms Script Content](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/content/methods/update)

PUT/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/content

#### Workers For PlatformsDispatchNamespacesScriptsSettings

##### [Get Workers for Platforms Script Settings](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/settings/methods/get)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/settings

##### [Patch Workers for Platforms Script Settings](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/settings/methods/edit)

PATCH/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/settings

#### Workers For PlatformsDispatchNamespacesScriptsBindings

##### [Get Workers for Platforms Script Bindings](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/bindings/methods/get)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/bindings

#### Workers For PlatformsDispatchNamespacesScriptsSecrets

##### [List Workers for Platforms Script Secrets](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/secrets/methods/list)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/secrets

##### [Get Workers for Platforms Script Secret](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/secrets/methods/get)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/secrets/{secret\_name}

##### [Add a secret to a Workers for Platforms script](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/secrets/methods/update)

PUT/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/secrets

##### [Delete Workers for Platforms script secret](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/secrets/methods/delete)

DELETE/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/secrets/{secret\_name}

##### [Patch multiple Workers for Platforms script secrets](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/secrets/methods/bulk_update)

PATCH/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/secrets-bulk

#### Workers For PlatformsDispatchNamespacesScriptsTags

##### [List Workers for Platforms Script Tags](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/tags/methods/list)

GET/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/tags

##### [Replace Workers for Platforms Script Tags](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/tags/methods/update)

PUT/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/tags

##### [Delete Workers for Platforms Script Tag](https://developers.cloudflare.com/api/resources/workers_for_platforms/subresources/dispatch/subresources/namespaces/subresources/scripts/subresources/tags/methods/delete)

DELETE/accounts/{account\_id}/workers/dispatch/namespaces/{dispatch\_namespace}/scripts/{script\_name}/tags/{tag}

#### Zero Trust

#### Zero TrustDevices

##### [List devices (deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/methods/list)

Deprecated

GET/accounts/{account\_id}/devices

##### [Get device (deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/methods/get)

Deprecated

GET/accounts/{account\_id}/devices/{device\_id}

#### Zero TrustDevicesDevices

##### [List devices](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/devices/methods/list)

GET/accounts/{account\_id}/devices/physical-devices

##### [Get device](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/devices/methods/get)

GET/accounts/{account\_id}/devices/physical-devices/{device\_id}

##### [Delete device](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/devices/methods/delete)

DELETE/accounts/{account\_id}/devices/physical-devices/{device\_id}

##### [Revoke device registrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/devices/methods/revoke)

Deprecated

POST/accounts/{account\_id}/devices/physical-devices/{device\_id}/revoke

#### Zero TrustDevicesResilience

#### Zero TrustDevicesResilienceGlobal WARP Override

##### [Get Global Disconnect](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/resilience/subresources/global_warp_override/methods/get)

GET/accounts/{account\_id}/devices/resilience/disconnect

##### [Set Global Disconnect](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/resilience/subresources/global_warp_override/methods/create)

POST/accounts/{account\_id}/devices/resilience/disconnect

#### Zero TrustDevicesRegistrations

##### [List registrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/registrations/methods/list)

GET/accounts/{account\_id}/devices/registrations

##### [Get registration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/registrations/methods/get)

GET/accounts/{account\_id}/devices/registrations/{registration\_id}

##### [Delete registration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/registrations/methods/delete)

DELETE/accounts/{account\_id}/devices/registrations/{registration\_id}

##### [Delete registrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/registrations/methods/bulk_delete)

DELETE/accounts/{account\_id}/devices/registrations

##### [Revoke registrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/registrations/methods/revoke)

Deprecated

POST/accounts/{account\_id}/devices/registrations/revoke

##### [Unrevoke registrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/registrations/methods/unrevoke)

Deprecated

POST/accounts/{account\_id}/devices/registrations/unrevoke

#### Zero TrustDevicesDEX Tests

##### [List Device DEX tests](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/list)

GET/accounts/{account\_id}/dex/devices/dex\_tests

##### [Get Device DEX test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/get)

GET/accounts/{account\_id}/dex/devices/dex\_tests/{dex\_test\_id}

##### [Create Device DEX test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/create)

POST/accounts/{account\_id}/dex/devices/dex\_tests

##### [Update Device DEX test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/update)

PUT/accounts/{account\_id}/dex/devices/dex\_tests/{dex\_test\_id}

##### [Delete Device DEX test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/dex_tests/methods/delete)

DELETE/accounts/{account\_id}/dex/devices/dex\_tests/{dex\_test\_id}

#### Zero TrustDevicesIP Profiles

##### [List IP profiles](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/list)

GET/accounts/{account\_id}/devices/ip-profiles

##### [Get IP profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/get)

GET/accounts/{account\_id}/devices/ip-profiles/{profile\_id}

##### [Create IP profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/create)

POST/accounts/{account\_id}/devices/ip-profiles

##### [Update IP profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/update)

PATCH/accounts/{account\_id}/devices/ip-profiles/{profile\_id}

##### [Delete IP profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/ip_profiles/methods/delete)

DELETE/accounts/{account\_id}/devices/ip-profiles/{profile\_id}

#### Zero TrustDevicesDeployment Groups

##### [List deployment groups](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/list)

GET/accounts/{account\_id}/devices/deployment-groups

##### [Get deployment group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/get)

GET/accounts/{account\_id}/devices/deployment-groups/{group\_id}

##### [Create deployment group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/create)

POST/accounts/{account\_id}/devices/deployment-groups

##### [Update deployment group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/edit)

PATCH/accounts/{account\_id}/devices/deployment-groups/{group\_id}

##### [Delete deployment group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/deployment_groups/methods/delete)

DELETE/accounts/{account\_id}/devices/deployment-groups/{group\_id}

#### Zero TrustDevicesNetworks

##### [List your device managed networks](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/networks/methods/list)

GET/accounts/{account\_id}/devices/networks

##### [Get device managed network details](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/networks/methods/get)

GET/accounts/{account\_id}/devices/networks/{network\_id}

##### [Create a device managed network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/networks/methods/create)

POST/accounts/{account\_id}/devices/networks

##### [Update a device managed network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/networks/methods/update)

PUT/accounts/{account\_id}/devices/networks/{network\_id}

##### [Delete a device managed network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/networks/methods/delete)

DELETE/accounts/{account\_id}/devices/networks/{network\_id}

#### Zero TrustDevicesFleet Status

##### [Get the latest status of a device.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/fleet_status/methods/get)

GET/accounts/{account\_id}/dex/devices/{device\_id}/fleet-status/live

#### Zero TrustDevicesPolicies

#### Zero TrustDevicesPoliciesDefault

##### [Get the default device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/methods/get)

GET/accounts/{account\_id}/devices/policy

##### [Update the default device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/methods/edit)

PATCH/accounts/{account\_id}/devices/policy

#### Zero TrustDevicesPoliciesDefaultExcludes

##### [Get the Split Tunnel exclude list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/excludes/methods/get)

GET/accounts/{account\_id}/devices/policy/exclude

##### [Set the Split Tunnel exclude list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/excludes/methods/update)

PUT/accounts/{account\_id}/devices/policy/exclude

#### Zero TrustDevicesPoliciesDefaultIncludes

##### [Get the Split Tunnel include list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/includes/methods/get)

GET/accounts/{account\_id}/devices/policy/include

##### [Set the Split Tunnel include list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/includes/methods/update)

PUT/accounts/{account\_id}/devices/policy/include

#### Zero TrustDevicesPoliciesDefaultFallback Domains

##### [Get your Local Domain Fallback list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/fallback_domains/methods/get)

GET/accounts/{account\_id}/devices/policy/fallback\_domains

##### [Set your Local Domain Fallback list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/fallback_domains/methods/update)

PUT/accounts/{account\_id}/devices/policy/fallback\_domains

#### Zero TrustDevicesPoliciesDefaultCertificates

##### [Get device certificate provisioning status](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/certificates/methods/get)

GET/zones/{zone\_id}/devices/policy/certificates

##### [Update device certificate provisioning status](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/default/subresources/certificates/methods/edit)

PATCH/zones/{zone\_id}/devices/policy/certificates

#### Zero TrustDevicesPoliciesCustom

##### [List device settings profiles](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/list)

GET/accounts/{account\_id}/devices/policies

##### [Get device settings profile by ID](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/get)

GET/accounts/{account\_id}/devices/policy/{policy\_id}

##### [Create a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/create)

POST/accounts/{account\_id}/devices/policy

##### [Update a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/edit)

PATCH/accounts/{account\_id}/devices/policy/{policy\_id}

##### [Delete a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/methods/delete)

DELETE/accounts/{account\_id}/devices/policy/{policy\_id}

#### Zero TrustDevicesPoliciesCustomExcludes

##### [Get the Split Tunnel exclude list for a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/excludes/methods/get)

GET/accounts/{account\_id}/devices/policy/{policy\_id}/exclude

##### [Set the Split Tunnel exclude list for a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/excludes/methods/update)

PUT/accounts/{account\_id}/devices/policy/{policy\_id}/exclude

#### Zero TrustDevicesPoliciesCustomIncludes

##### [Get the Split Tunnel include list for a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/includes/methods/get)

GET/accounts/{account\_id}/devices/policy/{policy\_id}/include

##### [Set the Split Tunnel include list for a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/includes/methods/update)

PUT/accounts/{account\_id}/devices/policy/{policy\_id}/include

#### Zero TrustDevicesPoliciesCustomFallback Domains

##### [Get the Local Domain Fallback list for a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/fallback_domains/methods/get)

GET/accounts/{account\_id}/devices/policy/{policy\_id}/fallback\_domains

##### [Set the Local Domain Fallback list for a device settings profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/policies/subresources/custom/subresources/fallback_domains/methods/update)

PUT/accounts/{account\_id}/devices/policy/{policy\_id}/fallback\_domains

#### Zero TrustDevicesPosture

##### [List posture rules](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/methods/list)

GET/accounts/{account\_id}/devices/posture

##### [Get posture rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/methods/get)

GET/accounts/{account\_id}/devices/posture/{rule\_id}

##### [Create posture rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/methods/create)

POST/accounts/{account\_id}/devices/posture

##### [Update posture rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/methods/update)

PUT/accounts/{account\_id}/devices/posture/{rule\_id}

##### [Delete posture rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/methods/delete)

DELETE/accounts/{account\_id}/devices/posture/{rule\_id}

#### Zero TrustDevicesPostureIntegrations

##### [List posture integrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/list)

GET/accounts/{account\_id}/devices/posture/integration

##### [Get posture integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/get)

GET/accounts/{account\_id}/devices/posture/integration/{integration\_id}

##### [Create posture integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/create)

POST/accounts/{account\_id}/devices/posture/integration

##### [Update posture integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/edit)

PATCH/accounts/{account\_id}/devices/posture/integration/{integration\_id}

##### [Delete posture integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/posture/subresources/integrations/methods/delete)

DELETE/accounts/{account\_id}/devices/posture/integration/{integration\_id}

#### Zero TrustDevicesRevoke

##### [Revoke devices (deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/revoke/methods/create)

Deprecated

POST/accounts/{account\_id}/devices/revoke

#### Zero TrustDevicesSettings

##### [Get device settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/settings/methods/get)

GET/accounts/{account\_id}/devices/settings

##### [Update device settings (deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/settings/methods/update)

Deprecated

PUT/accounts/{account\_id}/devices/settings

##### [Update device settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/settings/methods/edit)

PATCH/accounts/{account\_id}/devices/settings

##### [Reset device settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/settings/methods/delete)

DELETE/accounts/{account\_id}/devices/settings

#### Zero TrustDevicesUnrevoke

##### [Unrevoke devices (deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/unrevoke/methods/create)

Deprecated

POST/accounts/{account\_id}/devices/unrevoke

#### Zero TrustDevicesOverride Codes

##### [Get override codes (deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/override_codes/methods/list)

Deprecated

GET/accounts/{account\_id}/devices/{device\_id}/override\_codes

##### [Get override codes](https://developers.cloudflare.com/api/resources/zero_trust/subresources/devices/subresources/override_codes/methods/get)

GET/accounts/{account\_id}/devices/registrations/{registration\_id}/override\_codes

#### Zero TrustIdentity Providers

##### [List Access identity providers](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers

##### [Get an Access identity provider](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers/{identity\_provider\_id}

##### [Add an Access identity provider](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers

##### [Update an Access identity provider](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers/{identity\_provider\_id}

##### [Delete an Access identity provider](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/identity\_providers/{identity\_provider\_id}

#### Zero TrustIdentity ProvidersSCIM

#### Zero TrustIdentity ProvidersSCIMGroups

##### [List SCIM Group resources](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/subresources/scim/subresources/groups/methods/list)

GET/accounts/{account\_id}/access/identity\_providers/{identity\_provider\_id}/scim/groups

#### Zero TrustIdentity ProvidersSCIMUsers

##### [List SCIM User resources](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/subresources/scim/subresources/users/methods/list)

GET/accounts/{account\_id}/access/identity\_providers/{identity\_provider\_id}/scim/users

#### Zero TrustIdentity ProvidersSAML Certificate

##### [Create SAML encryption certificate for Identity Provider](https://developers.cloudflare.com/api/resources/zero_trust/subresources/identity_providers/subresources/saml_certificate/methods/create)

POST/accounts/{account\_id}/access/identity\_providers/{identity\_provider\_id}/saml\_certificate

#### Zero TrustOrganizations

##### [Get your Zero Trust organization](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Create your Zero Trust organization](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Update your Zero Trust organization](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations

##### [Revoke all Access tokens for a user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/methods/revoke_users)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/organizations/revoke\_user

#### Zero TrustOrganizationsDOH

##### [Get your Zero Trust organization DoH settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/subresources/doh/methods/get)

GET/accounts/{account\_id}/access/organizations/doh

##### [Update your Zero Trust organization DoH settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/organizations/subresources/doh/methods/update)

PUT/accounts/{account\_id}/access/organizations/doh

#### Zero TrustSeats

##### [Update a user seat](https://developers.cloudflare.com/api/resources/zero_trust/subresources/seats/methods/edit)

PATCH/accounts/{account\_id}/access/seats

#### Zero TrustAccess

#### Zero TrustAccessAI Controls

#### Zero TrustAccessAI ControlsMcp

#### Zero TrustAccessAI ControlsMcpPortals

##### [List MCP Portals](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/list)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Create a new MCP Portal](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/create)

POST/accounts/{account\_id}/access/ai-controls/mcp/portals

##### [Read details of an MCP Portal](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/read)

GET/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Update an MCP Portal](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/update)

PUT/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

##### [Delete an MCP Portal](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/portals/methods/delete)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/portals/{id}

#### Zero TrustAccessAI ControlsMcpServers

##### [List MCP Servers](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/list)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Create a new MCP Server](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/create)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers

##### [Read the details of an MCP Server](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/read)

GET/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Update an MCP Server](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/update)

PUT/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Delete an MCP Server](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/delete)

DELETE/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}

##### [Sync MCP Server Capabilities](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/ai_controls/subresources/mcp/subresources/servers/methods/sync)

POST/accounts/{account\_id}/access/ai-controls/mcp/servers/{id}/sync

#### Zero TrustAccessGateway CA

##### [List SSH Certificate Authorities (CA)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/list)

GET/accounts/{account\_id}/access/gateway\_ca

##### [Add a new SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/create)

POST/accounts/{account\_id}/access/gateway\_ca

##### [Delete an SSH Certificate Authority (CA)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/gateway_ca/methods/delete)

DELETE/accounts/{account\_id}/access/gateway\_ca/{certificate\_id}

#### Zero TrustAccessIdP Federation Grants

##### [List IdP federation grants](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/list)

GET/accounts/{account\_id}/access/idp\_federation\_grants

##### [Create an IdP federation grant](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/create)

POST/accounts/{account\_id}/access/idp\_federation\_grants

##### [Get an IdP federation grant](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/get)

GET/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

##### [Delete an IdP federation grant](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/idp_federation_grants/methods/delete)

DELETE/accounts/{account\_id}/access/idp\_federation\_grants/{grant\_id}

#### Zero TrustAccessSAML Certificates

##### [List SAML certificate sets](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/list)

GET/accounts/{account\_id}/access/saml\_certificates

##### [Get SAML certificate set](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}

##### [Rotate SAML certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/rotate)

POST/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/rotate

##### [Download current certificate in PEM format](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/saml_certificates/methods/get_pem)

GET/accounts/{account\_id}/access/saml\_certificates/{saml\_cert\_set\_id}/pem

#### Zero TrustAccessInfrastructure

#### Zero TrustAccessInfrastructureTargets

##### [List all targets](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/list)

GET/accounts/{account\_id}/infrastructure/targets

##### [Get target](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/get)

GET/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new target](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/create)

POST/accounts/{account\_id}/infrastructure/targets

##### [Update target](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/update)

PUT/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Delete target](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/delete)

DELETE/accounts/{account\_id}/infrastructure/targets/{target\_id}

##### [Create new targets](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_update)

PUT/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets (Deprecated)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete)

Deprecated

DELETE/accounts/{account\_id}/infrastructure/targets/batch

##### [Delete targets](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/infrastructure/subresources/targets/methods/bulk_delete_v2)

POST/accounts/{account\_id}/infrastructure/targets/batch\_delete

#### Zero TrustAccessApplications

##### [List Access applications](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Get an Access application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Add an Access application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps

##### [Update an Access application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Delete an Access application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}

##### [Revoke application tokens](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/methods/revoke_tokens)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/revoke\_tokens

#### Zero TrustAccessApplicationsCAs

##### [List short-lived certificate CAs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/ca

##### [Get a short-lived certificate CA](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### [Create a short-lived certificate CA](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

##### [Delete a short-lived certificate CA](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/cas/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/ca

#### Zero TrustAccessApplicationsUser Policy Checks

##### [Test Access policies](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/user_policy_checks/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/user\_policy\_checks

#### Zero TrustAccessApplicationsPolicies

##### [List Access application policies](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies

##### [Get an Access application policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### [Create an Access application policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies

##### [Update an Access application policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

##### [Delete an Access application policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policies/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/policies/{policy\_id}

#### Zero TrustAccessApplicationsPolicy Tests

##### [Get the current status of a given Access policy test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/methods/get)

GET/accounts/{account\_id}/access/policy-tests/{policy\_test\_id}

##### [Start Access policy test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/methods/create)

POST/accounts/{account\_id}/access/policy-tests

#### Zero TrustAccessApplicationsPolicy TestsUsers

##### [Get an Access policy test users page](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/policy_tests/subresources/users/methods/list)

GET/accounts/{account\_id}/access/policy-tests/{policy\_test\_id}/users

#### Zero TrustAccessApplicationsSettings

##### [Update Access application settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/settings/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/settings

##### [Update Access application settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/applications/subresources/settings/methods/edit)

PATCH/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/apps/{app\_id}/settings

#### Zero TrustAccessCertificates

##### [List mTLS certificates](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates

##### [Get an mTLS certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/{certificate\_id}

##### [Add an mTLS certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates

##### [Update an mTLS certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/{certificate\_id}

##### [Delete an mTLS certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/{certificate\_id}

#### Zero TrustAccessCertificatesSettings

##### [List all mTLS hostname settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/subresources/settings/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/settings

##### [Update an mTLS certificate's hostname settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/certificates/subresources/settings/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/certificates/settings

#### Zero TrustAccessGroups

##### [List Access groups](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/groups/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups

##### [Get an Access group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/groups/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups/{group\_id}

##### [Create an Access group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/groups/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups

##### [Update an Access group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/groups/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups/{group\_id}

##### [Delete an Access group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/groups/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/groups/{group\_id}

#### Zero TrustAccessService Tokens

##### [List service tokens](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens

##### [Get a service token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens/{service\_token\_id}

##### [Create a service token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens

##### [Update a service token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens/{service\_token\_id}

##### [Delete a service token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/access/service\_tokens/{service\_token\_id}

##### [Refresh a service token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/refresh)

POST/accounts/{account\_id}/access/service\_tokens/{service\_token\_id}/refresh

##### [Rotate a service token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/service_tokens/methods/rotate)

POST/accounts/{account\_id}/access/service\_tokens/{service\_token\_id}/rotate

#### Zero TrustAccessBookmarks

##### [List Bookmark applications](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/bookmarks/methods/list)

Deprecated

GET/accounts/{account\_id}/access/bookmarks

##### [Get a Bookmark application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/bookmarks/methods/get)

Deprecated

GET/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### [Create a Bookmark application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/bookmarks/methods/create)

Deprecated

POST/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### [Update a Bookmark application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/bookmarks/methods/update)

Deprecated

PUT/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

##### [Delete a Bookmark application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/bookmarks/methods/delete)

Deprecated

DELETE/accounts/{account\_id}/access/bookmarks/{bookmark\_id}

#### Zero TrustAccessKeys

##### [Get the Access key configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/keys/methods/get)

GET/accounts/{account\_id}/access/keys

##### [Update the Access key configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/keys/methods/update)

PUT/accounts/{account\_id}/access/keys

##### [Rotate Access keys](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/keys/methods/rotate)

POST/accounts/{account\_id}/access/keys/rotate

#### Zero TrustAccessLogs

#### Zero TrustAccessLogsAccess Requests

##### [Get Access authentication logs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/logs/subresources/access_requests/methods/list)

GET/accounts/{account\_id}/access/logs/access\_requests

#### Zero TrustAccessLogsSCIM

#### Zero TrustAccessLogsSCIMUpdates

##### [List Access SCIM update logs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/logs/subresources/scim/subresources/updates/methods/list)

GET/accounts/{account\_id}/access/logs/scim/updates

#### Zero TrustAccessUsers

##### [Get users](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/methods/list)

GET/accounts/{account\_id}/access/users

##### [Get a user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/methods/get)

GET/accounts/{account\_id}/access/users/{user\_id}

##### [Create a user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/methods/create)

POST/accounts/{account\_id}/access/users

##### [Update a user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/methods/update)

PUT/accounts/{account\_id}/access/users/{user\_id}

##### [Delete a user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/methods/delete)

DELETE/accounts/{account\_id}/access/users/{user\_id}

#### Zero TrustAccessUsersActive Sessions

##### [Get active sessions](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/subresources/active_sessions/methods/list)

GET/accounts/{account\_id}/access/users/{user\_id}/active\_sessions

##### [Get single active session](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/subresources/active_sessions/methods/get)

GET/accounts/{account\_id}/access/users/{user\_id}/active\_sessions/{nonce}

#### Zero TrustAccessUsersLast Seen Identity

##### [Get last seen identity](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/subresources/last_seen_identity/methods/get)

GET/accounts/{account\_id}/access/users/{user\_id}/last\_seen\_identity

#### Zero TrustAccessUsersFailed Logins

##### [Get failed logins](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/users/subresources/failed_logins/methods/list)

GET/accounts/{account\_id}/access/users/{user\_id}/failed\_logins

#### Zero TrustAccessCustom Pages

##### [List custom pages](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/custom_pages/methods/list)

GET/accounts/{account\_id}/access/custom\_pages

##### [Get a custom page](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/custom_pages/methods/get)

GET/accounts/{account\_id}/access/custom\_pages/{custom\_page\_id}

##### [Create a custom page](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/custom_pages/methods/create)

POST/accounts/{account\_id}/access/custom\_pages

##### [Update a custom page](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/custom_pages/methods/update)

PUT/accounts/{account\_id}/access/custom\_pages/{custom\_page\_id}

##### [Delete a custom page](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/custom_pages/methods/delete)

DELETE/accounts/{account\_id}/access/custom\_pages/{custom\_page\_id}

#### Zero TrustAccessTags

##### [List tags](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/tags/methods/list)

GET/accounts/{account\_id}/access/tags

##### [Get a tag](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/tags/methods/get)

GET/accounts/{account\_id}/access/tags/{tag\_name}

##### [Create a tag](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/tags/methods/create)

POST/accounts/{account\_id}/access/tags

##### [Update a tag](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/tags/methods/update)

PUT/accounts/{account\_id}/access/tags/{tag\_name}

##### [Delete a tag](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/tags/methods/delete)

DELETE/accounts/{account\_id}/access/tags/{tag\_name}

#### Zero TrustAccessPolicies

##### [List Access reusable policies](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/policies/methods/list)

GET/accounts/{account\_id}/access/policies

##### [Get an Access reusable policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/policies/methods/get)

GET/accounts/{account\_id}/access/policies/{policy\_id}

##### [Create an Access reusable policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/policies/methods/create)

POST/accounts/{account\_id}/access/policies

##### [Update an Access reusable policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/policies/methods/update)

PUT/accounts/{account\_id}/access/policies/{policy\_id}

##### [Delete an Access reusable policy](https://developers.cloudflare.com/api/resources/zero_trust/subresources/access/subresources/policies/methods/delete)

DELETE/accounts/{account\_id}/access/policies/{policy\_id}

#### Zero TrustCasb

#### Zero TrustCasbApplications

##### [List applications](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/applications/methods/list)

GET/accounts/{account\_id}/one/applications

##### [Get application details](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/applications/methods/get)

GET/accounts/{account\_id}/one/applications/{application\_id}

#### Zero TrustCasbApplicationsAuth Methods

##### [Get auth methods](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/applications/subresources/auth_methods/methods/list)

GET/accounts/{account\_id}/one/applications/{application\_id}/auth-methods

#### Zero TrustCasbIntegrations

##### [List integrations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/list)

GET/accounts/{account\_id}/one/integrations

##### [Get integration details](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/get)

GET/accounts/{account\_id}/one/integrations/{id}

##### [Create integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/create)

POST/accounts/{account\_id}/one/integrations

##### [Update integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/update)

PATCH/accounts/{account\_id}/one/integrations/{id}

##### [Delete integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/delete)

DELETE/accounts/{account\_id}/one/integrations/{id}

##### [Pause integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/pause)

POST/accounts/{account\_id}/one/integrations/{id}/pause

##### [Resume integration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/integrations/methods/resume)

POST/accounts/{account\_id}/one/integrations/{id}/resume

#### Zero TrustCasbPosture

#### Zero TrustCasbPostureFindings

##### [List posture findings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/list)

GET/accounts/{account\_id}/data-security/posture/findings

##### [Get a finding type](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/get)

GET/accounts/{account\_id}/data-security/posture/findings/{finding\_id}

##### [Create new findings export request](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/export)

POST/accounts/{account\_id}/data-security/posture/findings/export

##### [Mark a finding as ignored](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/ignore)

POST/accounts/{account\_id}/data-security/posture/findings/ignore

##### [Remove ignore marker from a finding](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/unignore)

POST/accounts/{account\_id}/data-security/posture/findings/unignore

##### [Update the severity for a finding](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/tune_severity)

POST/accounts/{account\_id}/data-security/posture/findings/{finding\_id}/tune\_finding\_severity

##### [Reset severity for a finding back to the default](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/methods/reset_severity)

POST/accounts/{account\_id}/data-security/posture/findings/{finding\_id}/reset\_finding\_severity

#### Zero TrustCasbPostureFindingsInstances

##### [List instances of a finding](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/subresources/instances/methods/list)

GET/accounts/{account\_id}/data-security/posture/findings/{finding\_id}/instances

##### [Get a finding instance using an instance ID](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/subresources/instances/methods/get)

GET/accounts/{account\_id}/data-security/posture/findings/{finding\_id}/instances/{instance\_id}

##### [Create a finding instances export](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/subresources/instances/methods/export)

POST/accounts/{account\_id}/data-security/posture/findings/{storage\_namespace\_id}/instances/export

##### [Archive a finding](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/subresources/instances/methods/archive)

POST/accounts/{account\_id}/data-security/posture/findings/{finding\_id}/instances/archive

##### [Remove the archive marking from a finding instance](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/findings/subresources/instances/methods/unarchive)

POST/accounts/{account\_id}/data-security/posture/findings/{finding\_id}/instances/unarchive

#### Zero TrustCasbPostureExports

##### [List all export jobs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/exports/methods/list)

GET/accounts/{account\_id}/data-security/posture/exports

##### [Get a single export job](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/exports/methods/get)

GET/accounts/{account\_id}/data-security/posture/exports/{id}

#### Zero TrustCasbPostureFinding Types

##### [List all finding types](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/finding_types/methods/list)

GET/accounts/{account\_id}/data-security/posture/finding\_types

##### [Get finding by ID](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/finding_types/methods/get)

GET/accounts/{account\_id}/data-security/posture/finding\_types/{finding\_type\_id}

#### Zero TrustCasbPostureFinding TypesRemediation Types

##### [List remediation types for a finding type](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/finding_types/subresources/remediation_types/methods/list)

GET/accounts/{account\_id}/data-security/posture/finding\_types/{finding\_type\_id}/remediation\_types

#### Zero TrustCasbPostureContent

##### [List DLP content findings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/content/methods/list)

GET/accounts/{account\_id}/data-security/posture/content

##### [Create a content export](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/content/methods/export)

POST/accounts/{account\_id}/data-security/posture/content/export

#### Zero TrustCasbPostureRemediations

#### Zero TrustCasbPostureRemediationsJobs

##### [List remediation jobs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/remediations/subresources/jobs/methods/list)

GET/accounts/{account\_id}/data-security/posture/remediations/jobs

##### [Creates remediation jobs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/remediations/subresources/jobs/methods/create)

POST/accounts/{account\_id}/data-security/posture/remediations/jobs

##### [Create a remediation jobs export](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/remediations/subresources/jobs/methods/export)

POST/accounts/{account\_id}/data-security/posture/remediations/jobs/export

#### Zero TrustCasbPosturePolicies

##### [List policy configurations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/policies/methods/list)

GET/accounts/{account\_id}/data-security/posture/policies

##### [Create a new policy configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/policies/methods/create)

POST/accounts/{account\_id}/data-security/posture/policies

##### [Get a policy configuration by ID](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/policies/methods/get)

GET/accounts/{account\_id}/data-security/posture/policies/{policy\_id}

##### [Update a policy configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/policies/methods/update)

PUT/accounts/{account\_id}/data-security/posture/policies/{policy\_id}

##### [Delete a policy configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/policies/methods/delete)

DELETE/accounts/{account\_id}/data-security/posture/policies/{policy\_id}

#### Zero TrustCasbPostureWebhooks

##### [List webhook configurations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/list)

GET/accounts/{account\_id}/data-security/posture/webhooks

##### [Create a new webhook configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/create)

POST/accounts/{account\_id}/data-security/posture/webhooks

##### [Get webhook configuration by ID](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/get)

GET/accounts/{account\_id}/data-security/posture/webhooks/{webhook\_id}

##### [Update an existing webhook configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/update)

PUT/accounts/{account\_id}/data-security/posture/webhooks/{webhook\_id}

##### [Delete a webhook configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/delete)

DELETE/accounts/{account\_id}/data-security/posture/webhooks/{webhook\_id}

##### [Test a webhook configuration before creating it](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/evaluate)

POST/accounts/{account\_id}/data-security/posture/webhooks/evaluate

##### [Test an existing webhook configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/methods/evaluate_existing)

POST/accounts/{account\_id}/data-security/posture/webhooks/{webhook\_id}/evaluate

#### Zero TrustCasbPostureWebhooksJobs

##### [Create webhook jobs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/casb/subresources/posture/subresources/webhooks/subresources/jobs/methods/create)

POST/accounts/{account\_id}/data-security/posture/webhooks/jobs

#### Zero TrustDEX

#### Zero TrustDEXWARP Change Events

##### [List WARP change events.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/warp_change_events/methods/get)

GET/accounts/{account\_id}/dex/warp-change-events

#### Zero TrustDEXCommands

##### [List account commands](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/commands/methods/list)

GET/accounts/{account\_id}/dex/commands

##### [Create account commands](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/commands/methods/create)

POST/accounts/{account\_id}/dex/commands

#### Zero TrustDEXCommandsDevices

##### [List devices eligible for remote captures](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/commands/subresources/devices/methods/list)

GET/accounts/{account\_id}/dex/commands/devices

#### Zero TrustDEXCommandsDownloads

##### [Download command output file](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/commands/subresources/downloads/methods/get)

GET/accounts/{account\_id}/dex/commands/{command\_id}/downloads/{filename}

#### Zero TrustDEXCommandsQuota

##### [Returns account commands usage, quota, and reset time](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/commands/subresources/quota/methods/get)

GET/accounts/{account\_id}/dex/commands/quota

#### Zero TrustDEXColos

##### [List Cloudflare colos](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/colos/methods/list)

GET/accounts/{account\_id}/dex/colos

#### Zero TrustDEXFleet Status

##### [Get live aggregate device details by dimension](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/fleet_status/methods/live)

GET/accounts/{account\_id}/dex/fleet-status/live

##### [Get over time aggregate details for devices by dimension](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/fleet_status/methods/over_time)

GET/accounts/{account\_id}/dex/fleet-status/over-time

#### Zero TrustDEXFleet StatusDevices

##### [List details of devices using WARP.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/fleet_status/subresources/devices/methods/list)

GET/accounts/{account\_id}/dex/fleet-status/devices

#### Zero TrustDEXHTTP Tests

##### [Get details and aggregate metrics for an http test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/http_tests/methods/get)

GET/accounts/{account\_id}/dex/http-tests/{test\_id}

#### Zero TrustDEXHTTP TestsPercentiles

##### [Get percentiles for an http test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/http_tests/subresources/percentiles/methods/get)

GET/accounts/{account\_id}/dex/http-tests/{test\_id}/percentiles

#### Zero TrustDEXTests

##### [List DEX test analytics](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/tests/methods/list)

GET/accounts/{account\_id}/dex/tests/overview

#### Zero TrustDEXTestsUnique Devices

##### [Get count of devices targeted](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/tests/subresources/unique_devices/methods/list)

GET/accounts/{account\_id}/dex/tests/unique-devices

#### Zero TrustDEXTraceroute Test Results

#### Zero TrustDEXTraceroute Test ResultsNetwork Path

##### [Get details for a specific traceroute test run](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/traceroute_test_results/subresources/network_path/methods/get)

GET/accounts/{account\_id}/dex/traceroute-test-results/{test\_result\_id}/network-path

#### Zero TrustDEXTraceroute Tests

##### [Get details and aggregate metrics for a traceroute test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/traceroute_tests/methods/get)

GET/accounts/{account\_id}/dex/traceroute-tests/{test\_id}

##### [Get percentiles for a traceroute test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/traceroute_tests/methods/percentiles)

GET/accounts/{account\_id}/dex/traceroute-tests/{test\_id}/percentiles

##### [Get network path breakdown for a traceroute test](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/traceroute_tests/methods/network_path)

GET/accounts/{account\_id}/dex/traceroute-tests/{test\_id}/network-path

#### Zero TrustDEXRules

##### [Get DEX Rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/rules/methods/get)

GET/accounts/{account\_id}/dex/rules/{rule\_id}

##### [Delete a DEX Rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/rules/methods/delete)

DELETE/accounts/{account\_id}/dex/rules/{rule\_id}

##### [Update a DEX Rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/rules/methods/update)

PATCH/accounts/{account\_id}/dex/rules/{rule\_id}

##### [Create a DEX Rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/rules/methods/create)

POST/accounts/{account\_id}/dex/rules

##### [List DEX Rules](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/rules/methods/list)

GET/accounts/{account\_id}/dex/rules

#### Zero TrustDEXDevices

#### Zero TrustDEXDevicesISPs

##### [List device ISPs](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dex/subresources/devices/subresources/isps/methods/list)

GET/accounts/{account\_id}/dex/devices/{device\_id}/isps

#### Zero TrustTunnels

##### [List All Tunnels](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/methods/list)

GET/accounts/{account\_id}/tunnels

#### Zero TrustTunnelsCloudflared

##### [List Cloudflare Tunnels](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/list)

GET/accounts/{account\_id}/cfd\_tunnel

##### [Get a Cloudflare Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/get)

GET/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}

##### [Create a Cloudflare Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/create)

POST/accounts/{account\_id}/cfd\_tunnel

##### [Update a Cloudflare Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/edit)

PATCH/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}

##### [Delete a Cloudflare Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/delete)

DELETE/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}

#### Zero TrustTunnelsCloudflaredConfigurations

##### [Get Tunnel configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/configurations/methods/get)

GET/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/configurations

##### [Update Tunnel configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/configurations/methods/update)

PUT/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/configurations

#### Zero TrustTunnelsCloudflaredConnections

##### [List Cloudflare Tunnel connections](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/connections/methods/get)

GET/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/connections

##### [Clean up Cloudflare Tunnel connections](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/connections/methods/delete)

DELETE/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/connections

#### Zero TrustTunnelsCloudflaredToken

##### [Get a Cloudflare Tunnel token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/token/methods/get)

GET/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/token

#### Zero TrustTunnelsCloudflaredConnectors

##### [Get Cloudflare Tunnel connector](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/connectors/methods/get)

GET/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/connectors/{connector\_id}

#### Zero TrustTunnelsCloudflaredManagement

##### [Get a Cloudflare Tunnel management token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/management/methods/create)

POST/accounts/{account\_id}/cfd\_tunnel/{tunnel\_id}/management

#### Zero TrustTunnelsWARP Connector

##### [List Warp Connector Tunnels](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/list)

GET/accounts/{account\_id}/warp\_connector

##### [Get a Warp Connector Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/get)

GET/accounts/{account\_id}/warp\_connector/{tunnel\_id}

##### [Create a Warp Connector Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/create)

POST/accounts/{account\_id}/warp\_connector

##### [Update a Warp Connector Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/edit)

PATCH/accounts/{account\_id}/warp\_connector/{tunnel\_id}

##### [Delete a Warp Connector Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/delete)

DELETE/accounts/{account\_id}/warp\_connector/{tunnel\_id}

#### Zero TrustTunnelsWARP ConnectorToken

##### [Get a Warp Connector Tunnel token](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/token/methods/get)

GET/accounts/{account\_id}/warp\_connector/{tunnel\_id}/token

#### Zero TrustTunnelsWARP ConnectorConnections

##### [List WARP Connector Tunnel connections](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/connections/methods/get)

GET/accounts/{account\_id}/warp\_connector/{tunnel\_id}/connections

#### Zero TrustTunnelsWARP ConnectorConnectors

##### [Get WARP Connector Tunnel connector](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/connectors/methods/get)

GET/accounts/{account\_id}/warp\_connector/{tunnel\_id}/connectors/{connector\_id}

#### Zero TrustTunnelsWARP ConnectorFailover

##### [Trigger a manual failover for a WARP Connector Tunnel](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/failover/methods/update)

PUT/accounts/{account\_id}/warp\_connector/{tunnel\_id}/failover

#### Zero TrustTunnelsWARP ConnectorConfigurations

##### [Get WARP Connector HA configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/configurations/methods/get)

GET/accounts/{account\_id}/warp\_connector/{tunnel\_id}/configurations

##### [Update WARP Connector HA configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/configurations/methods/update)

PUT/accounts/{account\_id}/warp\_connector/{tunnel\_id}/configurations

#### Zero TrustConnectivity Settings

##### [Get Zero Trust Connectivity Settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/connectivity_settings/methods/get)

GET/accounts/{account\_id}/zerotrust/connectivity\_settings

##### [Updates the Zero Trust Connectivity Settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/connectivity_settings/methods/edit)

PATCH/accounts/{account\_id}/zerotrust/connectivity\_settings

#### Zero TrustDLP

#### Zero TrustDLPCustom Prompt Topics

##### [List custom prompt topics](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/custom_prompt_topics/methods/list)

GET/accounts/{account\_id}/dlp/custom\_prompt\_topics

##### [Get custom prompt topic](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/custom_prompt_topics/methods/get)

GET/accounts/{account\_id}/dlp/custom\_prompt\_topics/{entry\_id}

##### [Create custom prompt topic](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/custom_prompt_topics/methods/create)

POST/accounts/{account\_id}/dlp/custom\_prompt\_topics

##### [Update custom prompt topic](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/custom_prompt_topics/methods/update)

PUT/accounts/{account\_id}/dlp/custom\_prompt\_topics/{entry\_id}

##### [Delete custom prompt topic](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/custom_prompt_topics/methods/delete)

DELETE/accounts/{account\_id}/dlp/custom\_prompt\_topics/{entry\_id}

#### Zero TrustDLPDatasets

##### [Fetch all datasets](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/methods/list)

GET/accounts/{account\_id}/dlp/datasets

##### [Fetch a specific dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/methods/get)

GET/accounts/{account\_id}/dlp/datasets/{dataset\_id}

##### [Create a new dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/methods/create)

POST/accounts/{account\_id}/dlp/datasets

##### [Update details about a dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/methods/update)

PUT/accounts/{account\_id}/dlp/datasets/{dataset\_id}

##### [Delete a dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/methods/delete)

DELETE/accounts/{account\_id}/dlp/datasets/{dataset\_id}

#### Zero TrustDLPDatasetsUpload

##### [Prepare to upload a new version of a dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/subresources/upload/methods/create)

POST/accounts/{account\_id}/dlp/datasets/{dataset\_id}/upload

##### [Upload a new version of a dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/subresources/upload/methods/edit)

POST/accounts/{account\_id}/dlp/datasets/{dataset\_id}/upload/{version}

#### Zero TrustDLPDatasetsVersions

##### [Sets the column information for a multi-column upload](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/subresources/versions/methods/create)

POST/accounts/{account\_id}/dlp/datasets/{dataset\_id}/versions/{version}

#### Zero TrustDLPDatasetsVersionsEntries

##### [Upload a new version of a multi-column dataset](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/datasets/subresources/versions/subresources/entries/methods/create)

POST/accounts/{account\_id}/dlp/datasets/{dataset\_id}/versions/{version}/entries/{entry\_id}

#### Zero TrustDLPPatterns

##### [Validate a DLP regex pattern](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/patterns/methods/validate)

POST/accounts/{account\_id}/dlp/patterns/validate

#### Zero TrustDLPPayload Logs

##### [Get payload log settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/payload_logs/methods/get)

GET/accounts/{account\_id}/dlp/payload\_log

##### [Set payload log settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/payload_logs/methods/update)

PUT/accounts/{account\_id}/dlp/payload\_log

#### Zero TrustDLPSettings

##### [Get DLP account-level settings.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/settings/methods/get)

GET/accounts/{account\_id}/dlp/settings

##### [Update DLP account-level settings (full replacement).](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/settings/methods/update)

PUT/accounts/{account\_id}/dlp/settings

##### [Partially update DLP account-level settings.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/settings/methods/edit)

PATCH/accounts/{account\_id}/dlp/settings

##### [Delete (reset) DLP account-level settings to initial values.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/settings/methods/delete)

DELETE/accounts/{account\_id}/dlp/settings

#### Zero TrustDLPEmail

#### Zero TrustDLPEmailAccount Mapping

##### [Get mapping](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/account_mapping/methods/get)

GET/accounts/{account\_id}/dlp/email/account\_mapping

##### [Create mapping](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/account_mapping/methods/create)

POST/accounts/{account\_id}/dlp/email/account\_mapping

#### Zero TrustDLPEmailRules

##### [List all email scanner rules](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/rules/methods/list)

GET/accounts/{account\_id}/dlp/email/rules

##### [Get an email scanner rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/rules/methods/get)

GET/accounts/{account\_id}/dlp/email/rules/{rule\_id}

##### [Create email scanner rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/rules/methods/create)

POST/accounts/{account\_id}/dlp/email/rules

##### [Update email scanner rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/rules/methods/update)

PUT/accounts/{account\_id}/dlp/email/rules/{rule\_id}

##### [Delete email scanner rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/rules/methods/delete)

DELETE/accounts/{account\_id}/dlp/email/rules/{rule\_id}

##### [Update email scanner rule priorities](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/email/subresources/rules/methods/bulk_edit)

PATCH/accounts/{account\_id}/dlp/email/rules

#### Zero TrustDLPProfiles

##### [List all profiles](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/methods/list)

GET/accounts/{account\_id}/dlp/profiles

##### [Get DLP Profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/methods/get)

GET/accounts/{account\_id}/dlp/profiles/{profile\_id}

#### Zero TrustDLPProfilesCustom

##### [Get custom profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/custom/methods/get)

GET/accounts/{account\_id}/dlp/profiles/custom/{profile\_id}

##### [Create custom profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/custom/methods/create)

POST/accounts/{account\_id}/dlp/profiles/custom

##### [Update custom profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/custom/methods/update)

PUT/accounts/{account\_id}/dlp/profiles/custom/{profile\_id}

##### [Delete custom profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/custom/methods/delete)

DELETE/accounts/{account\_id}/dlp/profiles/custom/{profile\_id}

#### Zero TrustDLPProfilesPredefined

##### [Get predefined profile config](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/predefined/methods/get)

GET/accounts/{account\_id}/dlp/profiles/predefined/{profile\_id}/config

##### [Update predefined profile config](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/predefined/methods/update)

PUT/accounts/{account\_id}/dlp/profiles/predefined/{profile\_id}/config

##### [Delete predefined profile](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/profiles/subresources/predefined/methods/delete)

DELETE/accounts/{account\_id}/dlp/profiles/predefined/{profile\_id}

#### Zero TrustDLPLimits

##### [Fetch limits associated with DLP for account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/limits/methods/list)

GET/accounts/{account\_id}/dlp/limits

#### Zero TrustDLPEntries

##### [List all entries](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/methods/list)

GET/accounts/{account\_id}/dlp/entries

##### [Get DLP Entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/methods/get)

GET/accounts/{account\_id}/dlp/entries/{entry\_id}

##### [Create custom entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/methods/create)

POST/accounts/{account\_id}/dlp/entries

##### [Update entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/methods/update)

PUT/accounts/{account\_id}/dlp/entries/{entry\_id}

##### [Delete custom entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/methods/delete)

DELETE/accounts/{account\_id}/dlp/entries/{entry\_id}

#### Zero TrustDLPEntriesCustom

##### [Create custom entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/custom/methods/create)

POST/accounts/{account\_id}/dlp/entries

##### [Update custom entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/custom/methods/update)

PUT/accounts/{account\_id}/dlp/entries/custom/{entry\_id}

##### [Delete custom entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/custom/methods/delete)

DELETE/accounts/{account\_id}/dlp/entries/{entry\_id}

##### [Get DLP Entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/custom/methods/get)

GET/accounts/{account\_id}/dlp/entries/{entry\_id}

##### [List all entries](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/custom/methods/list)

GET/accounts/{account\_id}/dlp/entries

#### Zero TrustDLPEntriesPredefined

##### [Create predefined entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/predefined/methods/create)

POST/accounts/{account\_id}/dlp/entries/predefined

##### [Update predefined entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/predefined/methods/update)

PUT/accounts/{account\_id}/dlp/entries/predefined/{entry\_id}

##### [Delete predefined entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/predefined/methods/delete)

DELETE/accounts/{account\_id}/dlp/entries/predefined/{entry\_id}

##### [Get DLP Entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/predefined/methods/get)

GET/accounts/{account\_id}/dlp/entries/{entry\_id}

##### [List all entries](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/predefined/methods/list)

GET/accounts/{account\_id}/dlp/entries

#### Zero TrustDLPEntriesIntegration

##### [Create integration entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/integration/methods/create)

POST/accounts/{account\_id}/dlp/entries/integration

##### [Update integration entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/integration/methods/update)

PUT/accounts/{account\_id}/dlp/entries/integration/{entry\_id}

##### [Delete integration entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/integration/methods/delete)

DELETE/accounts/{account\_id}/dlp/entries/integration/{entry\_id}

##### [Get DLP Entry](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/integration/methods/get)

GET/accounts/{account\_id}/dlp/entries/{entry\_id}

##### [List all entries](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/entries/subresources/integration/methods/list)

GET/accounts/{account\_id}/dlp/entries

#### Zero TrustDLPSensitivity Groups

##### [Retrieve all sensitivity groups in an account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/methods/list)

GET/accounts/{account\_id}/dlp/sensitivity\_groups

##### [Retrieve a specific sensitivity group.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/methods/get)

GET/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}

##### [Creates a new sensitivity group.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/methods/create)

POST/accounts/{account\_id}/dlp/sensitivity\_groups

##### [Update the attributes of a single sensitivity group.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/methods/update)

PUT/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}

##### [Delete a single sensitivity group.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/methods/delete)

DELETE/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}

#### Zero TrustDLPSensitivity GroupsLevels

##### [Retrieve all sensitivity levels in a sensitivity group](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/methods/list)

GET/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/levels

##### [Retrieve a specific sensitivity level.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/methods/get)

GET/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/levels/{sensitivity\_level\_id}

##### [Creates a new sensitivity level.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/methods/create)

POST/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/levels

##### [Update the attributes of a single sensitivity level.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/methods/update)

PUT/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/levels/{sensitivity\_level\_id}

##### [Delete a single sensitivity level.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/methods/delete)

DELETE/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/levels/{sensitivity\_level\_id}

#### Zero TrustDLPSensitivity GroupsLevelsOrder

##### [Retrieve the ordered list of level IDs for a sensitivity group.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/subresources/order/methods/get)

GET/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/level\_order

##### [Set the ordering of levels within a sensitivity group.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/sensitivity_groups/subresources/levels/subresources/order/methods/update)

PUT/accounts/{account\_id}/dlp/sensitivity\_groups/{sensitivity\_group\_id}/level\_order

#### Zero TrustDLPData Tag Categories

##### [Retrieve all data tag categories in an account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/methods/list)

GET/accounts/{account\_id}/dlp/data\_tag\_categories

##### [Retrieve a specific data tag category.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/methods/get)

GET/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}

##### [Creates a new data tag category.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/methods/create)

POST/accounts/{account\_id}/dlp/data\_tag\_categories

##### [Update the attributes of a single data tag category.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/methods/update)

PUT/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}

##### [Delete a single data tag category.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/methods/delete)

DELETE/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}

#### Zero TrustDLPData Tag CategoriesData Tags

##### [Retrieve all data tags in a data tag category](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/subresources/data_tags/methods/list)

GET/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}/data\_tags

##### [Retrieve a specific data tag.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/subresources/data_tags/methods/get)

GET/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}/data\_tags/{tag\_id}

##### [Creates a new data tag.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/subresources/data_tags/methods/create)

POST/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}/data\_tags

##### [Update the attributes of a single data tag.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/subresources/data_tags/methods/update)

PUT/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}/data\_tags/{tag\_id}

##### [Delete a single data tag.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_tag_categories/subresources/data_tags/methods/delete)

DELETE/accounts/{account\_id}/dlp/data\_tag\_categories/{category\_id}/data\_tags/{tag\_id}

#### Zero TrustDLPData Classes

##### [Retrieve all data classes in an account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_classes/methods/list)

GET/accounts/{account\_id}/dlp/data\_classes

##### [Retrieve a specific data class](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_classes/methods/get)

GET/accounts/{account\_id}/dlp/data\_classes/{data\_class\_id}

##### [Creates a new data class](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_classes/methods/create)

POST/accounts/{account\_id}/dlp/data\_classes

##### [Update the attributes of a single data class](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_classes/methods/update)

PUT/accounts/{account\_id}/dlp/data\_classes/{data\_class\_id}

##### [Delete a single data class](https://developers.cloudflare.com/api/resources/zero_trust/subresources/dlp/subresources/data_classes/methods/delete)

DELETE/accounts/{account\_id}/dlp/data\_classes/{data\_class\_id}

#### Zero TrustGateway

##### [Get Zero Trust account information](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/methods/list)

GET/accounts/{account\_id}/gateway

##### [Create Zero Trust account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/methods/create)

POST/accounts/{account\_id}/gateway

#### Zero TrustGatewayAudit SSH Settings

##### [Get Zero Trust SSH settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/audit_ssh_settings/methods/get)

GET/accounts/{account\_id}/gateway/audit\_ssh\_settings

##### [Update Zero Trust SSH settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/audit_ssh_settings/methods/update)

PUT/accounts/{account\_id}/gateway/audit\_ssh\_settings

##### [Rotate Zero Trust SSH account seed](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/audit_ssh_settings/methods/rotate_seed)

POST/accounts/{account\_id}/gateway/audit\_ssh\_settings/rotate\_seed

#### Zero TrustGatewayCategories

##### [List categories](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/categories/methods/list)

GET/accounts/{account\_id}/gateway/categories

#### Zero TrustGatewayApp Types

##### [List application and application type mappings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/app_types/methods/list)

GET/accounts/{account\_id}/gateway/app\_types

#### Zero TrustGatewayConfigurations

##### [Get Zero Trust account configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/configurations/methods/get)

GET/accounts/{account\_id}/gateway/configuration

##### [Update Zero Trust account configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/configurations/methods/update)

PUT/accounts/{account\_id}/gateway/configuration

##### [Patch Zero Trust account configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/configurations/methods/edit)

PATCH/accounts/{account\_id}/gateway/configuration

#### Zero TrustGatewayConfigurationsCustom Certificate

##### [Get Zero Trust certificate configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/configurations/subresources/custom_certificate/methods/get)

Deprecated

GET/accounts/{account\_id}/gateway/configuration/custom\_certificate

#### Zero TrustGatewayLists

##### [List Zero Trust lists](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/methods/list)

GET/accounts/{account\_id}/gateway/lists

##### [Get Zero Trust list details](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/methods/get)

GET/accounts/{account\_id}/gateway/lists/{list\_id}

##### [Create Zero Trust list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/methods/create)

POST/accounts/{account\_id}/gateway/lists

##### [Update Zero Trust list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/methods/update)

PUT/accounts/{account\_id}/gateway/lists/{list\_id}

##### [Patch Zero Trust list.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/methods/edit)

PATCH/accounts/{account\_id}/gateway/lists/{list\_id}

##### [Delete Zero Trust list](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/methods/delete)

DELETE/accounts/{account\_id}/gateway/lists/{list\_id}

#### Zero TrustGatewayListsItems

##### [Get Zero Trust list items](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/lists/subresources/items/methods/list)

GET/accounts/{account\_id}/gateway/lists/{list\_id}/items

#### Zero TrustGatewayLocations

##### [List Zero Trust Gateway locations](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/locations/methods/list)

GET/accounts/{account\_id}/gateway/locations

##### [Get Zero Trust Gateway location details](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/locations/methods/get)

GET/accounts/{account\_id}/gateway/locations/{location\_id}

##### [Create a Zero Trust Gateway location](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/locations/methods/create)

POST/accounts/{account\_id}/gateway/locations

##### [Update a Zero Trust Gateway location](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/locations/methods/update)

PUT/accounts/{account\_id}/gateway/locations/{location\_id}

##### [Delete a Zero Trust Gateway location](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/locations/methods/delete)

DELETE/accounts/{account\_id}/gateway/locations/{location\_id}

#### Zero TrustGatewayLogging

##### [Get logging settings for the Zero Trust account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/logging/methods/get)

GET/accounts/{account\_id}/gateway/logging

##### [Update Zero Trust account logging settings](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/logging/methods/update)

PUT/accounts/{account\_id}/gateway/logging

#### Zero TrustGatewayProxy Endpoints

##### [List proxy endpoints](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/list)

GET/accounts/{account\_id}/gateway/proxy\_endpoints

##### [Get a proxy endpoint](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/get)

GET/accounts/{account\_id}/gateway/proxy\_endpoints/{proxy\_endpoint\_id}

##### [Create a proxy endpoint](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/create)

POST/accounts/{account\_id}/gateway/proxy\_endpoints

##### [Update a proxy endpoint](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/edit)

PATCH/accounts/{account\_id}/gateway/proxy\_endpoints/{proxy\_endpoint\_id}

##### [Delete a proxy endpoint](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/proxy_endpoints/methods/delete)

DELETE/accounts/{account\_id}/gateway/proxy\_endpoints/{proxy\_endpoint\_id}

#### Zero TrustGatewayRules

##### [List Zero Trust Gateway rules](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/list)

GET/accounts/{account\_id}/gateway/rules

##### [Get Zero Trust Gateway rule details.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/get)

GET/accounts/{account\_id}/gateway/rules/{rule\_id}

##### [Create a Zero Trust Gateway rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/create)

POST/accounts/{account\_id}/gateway/rules

##### [Update a Zero Trust Gateway rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/update)

PUT/accounts/{account\_id}/gateway/rules/{rule\_id}

##### [Delete a Zero Trust Gateway rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/delete)

DELETE/accounts/{account\_id}/gateway/rules/{rule\_id}

##### [List Zero Trust Gateway rules inherited from the parent account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/list_tenant)

GET/accounts/{account\_id}/gateway/rules/tenant

##### [Reset the expiration of a Zero Trust Gateway Rule](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/reset_expiration)

POST/accounts/{account\_id}/gateway/rules/{rule\_id}/reset\_expiration

#### Zero TrustGatewayCertificates

##### [List Zero Trust certificates](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/certificates/methods/list)

GET/accounts/{account\_id}/gateway/certificates

##### [Get Zero Trust certificate details](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/certificates/methods/get)

GET/accounts/{account\_id}/gateway/certificates/{certificate\_id}

##### [Create Zero Trust certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/certificates/methods/create)

POST/accounts/{account\_id}/gateway/certificates

##### [Delete Zero Trust certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/certificates/methods/delete)

DELETE/accounts/{account\_id}/gateway/certificates/{certificate\_id}

##### [Activate a Zero Trust certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/certificates/methods/activate)

POST/accounts/{account\_id}/gateway/certificates/{certificate\_id}/activate

##### [Deactivate a Zero Trust certificate](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/certificates/methods/deactivate)

POST/accounts/{account\_id}/gateway/certificates/{certificate\_id}/deactivate

#### Zero TrustGatewayPacfiles

##### [List PAC files](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/list)

GET/accounts/{account\_id}/gateway/pacfiles

##### [Get a PAC file](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/get)

GET/accounts/{account\_id}/gateway/pacfiles/{pacfile\_id}

##### [Create a PAC file](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/create)

POST/accounts/{account\_id}/gateway/pacfiles

##### [Update a Zero Trust Gateway PAC file](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/update)

PUT/accounts/{account\_id}/gateway/pacfiles/{pacfile\_id}

##### [Delete a PAC file](https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/pacfiles/methods/delete)

DELETE/accounts/{account\_id}/gateway/pacfiles/{pacfile\_id}

#### Zero TrustNetworks

#### Zero TrustNetworksRoutes

##### [List tunnel routes](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/list)

GET/accounts/{account\_id}/teamnet/routes

##### [Get tunnel route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/get)

GET/accounts/{account\_id}/teamnet/routes/{route\_id}

##### [Create a tunnel route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/create)

POST/accounts/{account\_id}/teamnet/routes

##### [Update a tunnel route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/edit)

PATCH/accounts/{account\_id}/teamnet/routes/{route\_id}

##### [Delete a tunnel route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/delete)

DELETE/accounts/{account\_id}/teamnet/routes/{route\_id}

#### Zero TrustNetworksRoutesIPs

##### [Get tunnel route by IP](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/ips/methods/get)

GET/accounts/{account\_id}/teamnet/routes/ip/{ip}

#### Zero TrustNetworksRoutesNetworks

##### [Create a tunnel route (CIDR Endpoint)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/networks/methods/create)

Deprecated

POST/accounts/{account\_id}/teamnet/routes/network/{ip\_network\_encoded}

##### [Update a tunnel route (CIDR Endpoint)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/networks/methods/edit)

Deprecated

PATCH/accounts/{account\_id}/teamnet/routes/network/{ip\_network\_encoded}

##### [Delete a tunnel route (CIDR Endpoint)](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/networks/methods/delete)

Deprecated

DELETE/accounts/{account\_id}/teamnet/routes/network/{ip\_network\_encoded}

#### Zero TrustNetworksVirtual Networks

##### [List virtual networks](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/virtual_networks/methods/list)

GET/accounts/{account\_id}/teamnet/virtual\_networks

##### [Get a virtual network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/virtual_networks/methods/get)

GET/accounts/{account\_id}/teamnet/virtual\_networks/{virtual\_network\_id}

##### [Create a virtual network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/virtual_networks/methods/create)

POST/accounts/{account\_id}/teamnet/virtual\_networks

##### [Update a virtual network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/virtual_networks/methods/edit)

PATCH/accounts/{account\_id}/teamnet/virtual\_networks/{virtual\_network\_id}

##### [Delete a virtual network](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/virtual_networks/methods/delete)

DELETE/accounts/{account\_id}/teamnet/virtual\_networks/{virtual\_network\_id}

#### Zero TrustNetworksSubnets

##### [List Subnets](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/methods/list)

GET/accounts/{account\_id}/zerotrust/subnets

#### Zero TrustNetworksSubnetsWARP

##### [Create WARP IP subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/warp/methods/create)

POST/accounts/{account\_id}/zerotrust/subnets/warp

##### [Get WARP IP subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/warp/methods/get)

GET/accounts/{account\_id}/zerotrust/subnets/warp/{subnet\_id}

##### [Update WARP IP subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/warp/methods/edit)

PATCH/accounts/{account\_id}/zerotrust/subnets/warp/{subnet\_id}

##### [Delete WARP IP subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/warp/methods/delete)

DELETE/accounts/{account\_id}/zerotrust/subnets/warp/{subnet\_id}

#### Zero TrustNetworksSubnetsCloudflare Source

##### [Update Cloudflare Source Subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/cloudflare_source/methods/update)

PATCH/accounts/{account\_id}/zerotrust/subnets/cloudflare\_source/{address\_family}

#### Zero TrustNetworksSubnetsInitial Resolved IP

##### [Get Initial Resolved IP Subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/initial_resolved_ip/methods/get)

GET/accounts/{account\_id}/zerotrust/subnets/initial\_resolved\_ip/{address\_family}

##### [Update Initial Resolved IP Subnet](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/subnets/subresources/initial_resolved_ip/methods/update)

PUT/accounts/{account\_id}/zerotrust/subnets/initial\_resolved\_ip/{address\_family}

#### Zero TrustNetworksHostname Routes

##### [List hostname routes](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/hostname_routes/methods/list)

GET/accounts/{account\_id}/zerotrust/routes/hostname

##### [Get hostname route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/hostname_routes/methods/get)

GET/accounts/{account\_id}/zerotrust/routes/hostname/{hostname\_route\_id}

##### [Create hostname route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/hostname_routes/methods/create)

POST/accounts/{account\_id}/zerotrust/routes/hostname

##### [Update hostname route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/hostname_routes/methods/edit)

PATCH/accounts/{account\_id}/zerotrust/routes/hostname/{hostname\_route\_id}

##### [Delete hostname route](https://developers.cloudflare.com/api/resources/zero_trust/subresources/networks/subresources/hostname_routes/methods/delete)

DELETE/accounts/{account\_id}/zerotrust/routes/hostname/{hostname\_route\_id}

#### Zero TrustRisk Scoring

##### [Get risk event/score information for a specific user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/methods/get)

GET/accounts/{account\_id}/zt\_risk\_scoring/{user\_id}

##### [Clear the risk score for a particular user](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/methods/reset)

POST/accounts/{account\_id}/zt\_risk\_scoring/{user\_id}/reset

#### Zero TrustRisk ScoringBehaviours

##### [Get all behaviors and associated configuration](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/behaviours/methods/get)

GET/accounts/{account\_id}/zt\_risk\_scoring/behaviors

##### [Update configuration for risk behaviors](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/behaviours/methods/update)

PUT/accounts/{account\_id}/zt\_risk\_scoring/behaviors

#### Zero TrustRisk ScoringSummary

##### [Get risk score info for all users in the account](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/summary/methods/get)

GET/accounts/{account\_id}/zt\_risk\_scoring/summary

#### Zero TrustRisk ScoringIntegrations

##### [List all risk score integrations for the account.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/integrations/methods/list)

GET/accounts/{account\_id}/zt\_risk\_scoring/integrations

##### [Get risk score integration by id.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/integrations/methods/get)

GET/accounts/{account\_id}/zt\_risk\_scoring/integrations/{integration\_id}

##### [Create new risk score integration.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/integrations/methods/create)

POST/accounts/{account\_id}/zt\_risk\_scoring/integrations

##### [Update a risk score integration.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/integrations/methods/update)

PUT/accounts/{account\_id}/zt\_risk\_scoring/integrations/{integration\_id}

##### [Delete a risk score integration.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/integrations/methods/delete)

DELETE/accounts/{account\_id}/zt\_risk\_scoring/integrations/{integration\_id}

#### Zero TrustRisk ScoringIntegrationsReferences

##### [Get risk score integration by reference id.](https://developers.cloudflare.com/api/resources/zero_trust/subresources/risk_scoring/subresources/integrations/subresources/references/methods/get)

GET/accounts/{account\_id}/zt\_risk\_scoring/integrations/reference\_id/{reference\_id}

#### Zero TrustResource Library

#### Zero TrustResource LibraryApplications

##### [List applications](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/applications/methods/list)

GET/accounts/{account\_id}/resource-library/applications

##### [Get application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/applications/methods/get)

GET/accounts/{account\_id}/resource-library/applications/{id}

##### [Create application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/applications/methods/create)

POST/accounts/{account\_id}/resource-library/applications

##### [Update application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/applications/methods/update)

PATCH/accounts/{account\_id}/resource-library/applications/{id}

##### [Delete application](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/applications/methods/delete)

DELETE/accounts/{account\_id}/resource-library/applications/{id}

#### Zero TrustResource LibraryCategories

##### [List application categories](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/categories/methods/list)

GET/accounts/{account\_id}/resource-library/categories

##### [Get application category](https://developers.cloudflare.com/api/resources/zero_trust/subresources/resource_library/subresources/categories/methods/get)

GET/accounts/{account\_id}/resource-library/categories/{id}

#### Turnstile

#### TurnstileWidgets

##### [List Turnstile Widgets](https://developers.cloudflare.com/api/resources/turnstile/subresources/widgets/methods/list)

GET/accounts/{account\_id}/challenges/widgets

##### [Turnstile Widget Details](https://developers.cloudflare.com/api/resources/turnstile/subresources/widgets/methods/get)

GET/accounts/{account\_id}/challenges/widgets/{sitekey}

##### [Create a Turnstile Widget](https://developers.cloudflare.com/api/resources/turnstile/subresources/widgets/methods/create)

POST/accounts/{account\_id}/challenges/widgets

##### [Update a Turnstile Widget](https://developers.cloudflare.com/api/resources/turnstile/subresources/widgets/methods/update)

PUT/accounts/{account\_id}/challenges/widgets/{sitekey}

##### [Delete a Turnstile Widget](https://developers.cloudflare.com/api/resources/turnstile/subresources/widgets/methods/delete)

DELETE/accounts/{account\_id}/challenges/widgets/{sitekey}

##### [Rotate Secret for a Turnstile Widget](https://developers.cloudflare.com/api/resources/turnstile/subresources/widgets/methods/rotate_secret)

POST/accounts/{account\_id}/challenges/widgets/{sitekey}/rotate\_secret

#### Connectivity

#### ConnectivityDirectory

#### ConnectivityDirectoryServices

##### [List Workers VPC connectivity services](https://developers.cloudflare.com/api/resources/connectivity/subresources/directory/subresources/services/methods/list)

GET/accounts/{account\_id}/connectivity/directory/services

##### [Create Workers VPC connectivity service](https://developers.cloudflare.com/api/resources/connectivity/subresources/directory/subresources/services/methods/create)

POST/accounts/{account\_id}/connectivity/directory/services

##### [Get Workers VPC connectivity service](https://developers.cloudflare.com/api/resources/connectivity/subresources/directory/subresources/services/methods/get)

GET/accounts/{account\_id}/connectivity/directory/services/{service\_id}

##### [Update Workers VPC connectivity service](https://developers.cloudflare.com/api/resources/connectivity/subresources/directory/subresources/services/methods/update)

PUT/accounts/{account\_id}/connectivity/directory/services/{service\_id}

##### [Delete Workers VPC connectivity service](https://developers.cloudflare.com/api/resources/connectivity/subresources/directory/subresources/services/methods/delete)

DELETE/accounts/{account\_id}/connectivity/directory/services/{service\_id}

#### Hyperdrive

#### HyperdriveConfigs

##### [List Hyperdrives](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/list)

GET/accounts/{account\_id}/hyperdrive/configs

##### [Get Hyperdrive](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/get)

GET/accounts/{account\_id}/hyperdrive/configs/{hyperdrive\_id}

##### [Create Hyperdrive](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/create)

POST/accounts/{account\_id}/hyperdrive/configs

##### [Replace Hyperdrive](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/update)

PUT/accounts/{account\_id}/hyperdrive/configs/{hyperdrive\_id}

##### [Update Hyperdrive](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/edit)

PATCH/accounts/{account\_id}/hyperdrive/configs/{hyperdrive\_id}

##### [Restart Hyperdrive](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/restart)

POST/accounts/{account\_id}/hyperdrive/configs/{hyperdrive\_id}/restart

##### [Delete Hyperdrive](https://developers.cloudflare.com/api/resources/hyperdrive/subresources/configs/methods/delete)

DELETE/accounts/{account\_id}/hyperdrive/configs/{hyperdrive\_id}

#### RUM

#### RUMSite Info

##### [List Web Analytics sites](https://developers.cloudflare.com/api/resources/rum/subresources/site_info/methods/list)

GET/accounts/{account\_id}/rum/site\_info/list

##### [Get a Web Analytics site](https://developers.cloudflare.com/api/resources/rum/subresources/site_info/methods/get)

GET/accounts/{account\_id}/rum/site\_info/{site\_id}

##### [Create a Web Analytics site](https://developers.cloudflare.com/api/resources/rum/subresources/site_info/methods/create)

POST/accounts/{account\_id}/rum/site\_info

##### [Update a Web Analytics site](https://developers.cloudflare.com/api/resources/rum/subresources/site_info/methods/update)

PUT/accounts/{account\_id}/rum/site\_info/{site\_id}

##### [Delete a Web Analytics site](https://developers.cloudflare.com/api/resources/rum/subresources/site_info/methods/delete)

DELETE/accounts/{account\_id}/rum/site\_info/{site\_id}

#### RUMRules

##### [List rules in Web Analytics ruleset](https://developers.cloudflare.com/api/resources/rum/subresources/rules/methods/list)

GET/accounts/{account\_id}/rum/v2/{ruleset\_id}/rules

##### [Create a Web Analytics rule](https://developers.cloudflare.com/api/resources/rum/subresources/rules/methods/create)

POST/accounts/{account\_id}/rum/v2/{ruleset\_id}/rule

##### [Update a Web Analytics rule](https://developers.cloudflare.com/api/resources/rum/subresources/rules/methods/update)

PUT/accounts/{account\_id}/rum/v2/{ruleset\_id}/rule/{rule\_id}

##### [Delete a Web Analytics rule](https://developers.cloudflare.com/api/resources/rum/subresources/rules/methods/delete)

DELETE/accounts/{account\_id}/rum/v2/{ruleset\_id}/rule/{rule\_id}

##### [Update Web Analytics rules](https://developers.cloudflare.com/api/resources/rum/subresources/rules/methods/bulk_create)

POST/accounts/{account\_id}/rum/v2/{ruleset\_id}/rules

#### Vectorize

#### VectorizeIndexes

##### [List Vectorize Indexes](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/list)

GET/accounts/{account\_id}/vectorize/v2/indexes

##### [Get Vectorize Index](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/get)

GET/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}

##### [Create Vectorize Index](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/create)

POST/accounts/{account\_id}/vectorize/v2/indexes

##### [Delete Vectorize Index](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/delete)

DELETE/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}

##### [Insert Vectors](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/insert)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/insert

##### [Query Vectors](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/query)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/query

##### [Upsert Vectors](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/upsert)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/upsert

##### [Delete Vectors By Identifier](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/delete_by_ids)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/delete\_by\_ids

##### [Get Vectors By Identifier](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/get_by_ids)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/get\_by\_ids

##### [Get Vectorize Index Info](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/info)

GET/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/info

##### [List Vectors](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/methods/list_vectors)

GET/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/list

#### VectorizeIndexesMetadata Index

##### [List Metadata Indexes](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/subresources/metadata_index/methods/list)

GET/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/metadata\_index/list

##### [Create Metadata Index](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/subresources/metadata_index/methods/create)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/metadata\_index/create

##### [Delete Metadata Index](https://developers.cloudflare.com/api/resources/vectorize/subresources/indexes/subresources/metadata_index/methods/delete)

POST/accounts/{account\_id}/vectorize/v2/indexes/{index\_name}/metadata\_index/delete

#### URL Scanner

#### URL ScannerResponses

##### [Get raw response](https://developers.cloudflare.com/api/resources/url_scanner/subresources/responses/methods/get)

GET/accounts/{account\_id}/urlscanner/v2/responses/{response\_id}

#### URL ScannerScans

##### [Search URL scans](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/list)

GET/accounts/{account\_id}/urlscanner/v2/search

##### [Get URL scan](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/get)

GET/accounts/{account\_id}/urlscanner/v2/result/{scan\_id}

##### [Create URL Scan](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/create)

POST/accounts/{account\_id}/urlscanner/v2/scan

##### [Bulk create URL Scans](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/bulk_create)

POST/accounts/{account\_id}/urlscanner/v2/bulk

##### [Get URL scan's HAR](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/har)

GET/accounts/{account\_id}/urlscanner/v2/har/{scan\_id}

##### [Get screenshot](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/screenshot)

GET/accounts/{account\_id}/urlscanner/v2/screenshots/{scan\_id}.png

##### [Get URL scan's DOM](https://developers.cloudflare.com/api/resources/url_scanner/subresources/scans/methods/dom)

GET/accounts/{account\_id}/urlscanner/v2/dom/{scan\_id}

#### Vulnerability Scanner

#### Vulnerability ScannerCredential Sets

##### [List credential sets](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/methods/list)

GET/accounts/{account\_id}/vuln\_scanner/credential\_sets

##### [Create credential set](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/methods/create)

POST/accounts/{account\_id}/vuln\_scanner/credential\_sets

##### [Get credential set](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/methods/get)

GET/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}

##### [Update credential set](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/methods/update)

PUT/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}

##### [Edit credential set](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/methods/edit)

PATCH/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}

##### [Delete credential set](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/methods/delete)

DELETE/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}

#### Vulnerability ScannerCredential SetsCredentials

##### [List credentials](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/subresources/credentials/methods/list)

GET/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}/credentials

##### [Create credential](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/subresources/credentials/methods/create)

POST/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}/credentials

##### [Get credential](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/subresources/credentials/methods/get)

GET/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}/credentials/{credential\_id}

##### [Update credential](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/subresources/credentials/methods/update)

PUT/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}/credentials/{credential\_id}

##### [Edit credential](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/subresources/credentials/methods/edit)

PATCH/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}/credentials/{credential\_id}

##### [Delete credential](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/credential_sets/subresources/credentials/methods/delete)

DELETE/accounts/{account\_id}/vuln\_scanner/credential\_sets/{credential\_set\_id}/credentials/{credential\_id}

#### Vulnerability ScannerScans

##### [List scans](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/scans/methods/list)

GET/accounts/{account\_id}/vuln\_scanner/scans

##### [Create scan](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/scans/methods/create)

POST/accounts/{account\_id}/vuln\_scanner/scans

##### [Get scan](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/scans/methods/get)

GET/accounts/{account\_id}/vuln\_scanner/scans/{scan\_id}

#### Vulnerability ScannerTarget Environments

##### [List target environments](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/target_environments/methods/list)

GET/accounts/{account\_id}/vuln\_scanner/target\_environments

##### [Create target environment](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/target_environments/methods/create)

POST/accounts/{account\_id}/vuln\_scanner/target\_environments

##### [Get target environment](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/target_environments/methods/get)

GET/accounts/{account\_id}/vuln\_scanner/target\_environments/{target\_environment\_id}

##### [Update target environment](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/target_environments/methods/update)

PUT/accounts/{account\_id}/vuln\_scanner/target\_environments/{target\_environment\_id}

##### [Edit target environment](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/target_environments/methods/edit)

PATCH/accounts/{account\_id}/vuln\_scanner/target\_environments/{target\_environment\_id}

##### [Delete target environment](https://developers.cloudflare.com/api/resources/vulnerability_scanner/subresources/target_environments/methods/delete)

DELETE/accounts/{account\_id}/vuln\_scanner/target\_environments/{target\_environment\_id}

#### Radar

#### RadarAgent Readiness

##### [Get agent readiness summary](https://developers.cloudflare.com/api/resources/radar/subresources/agent_readiness/methods/summary)

GET/radar/agent\_readiness/summary/{dimension}

#### RadarAI

#### RadarAITo Markdown

##### [Convert Files into Markdown](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/to_markdown/methods/create)

Deprecated

POST/accounts/{account\_id}/ai/tomarkdown

#### RadarAIInference

##### [Get Workers AI inference distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/inference/methods/summary_v2)

GET/radar/ai/inference/summary/{dimension}

##### [Get time series distribution of Workers AI inference by dimension.](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/inference/methods/timeseries_groups_v2)

GET/radar/ai/inference/timeseries\_groups/{dimension}

#### RadarAIInferenceSummary

##### [Get Workers AI models summary](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/inference/subresources/summary/methods/model)

Deprecated

GET/radar/ai/inference/summary/model

##### [Get Workers AI tasks summary](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/inference/subresources/summary/methods/task)

Deprecated

GET/radar/ai/inference/summary/task

#### RadarAIInferenceTimeseries Groups

#### RadarAIInferenceTimeseries GroupsSummary

##### [Get Workers AI models time series](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/inference/subresources/timeseries_groups/subresources/summary/methods/model)

Deprecated

GET/radar/ai/inference/timeseries\_groups/model

##### [Get Workers AI tasks time series](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/inference/subresources/timeseries_groups/subresources/summary/methods/task)

Deprecated

GET/radar/ai/inference/timeseries\_groups/task

#### RadarAIBots

##### [Get AI bots HTTP requests distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/bots/methods/summary_v2)

GET/radar/ai/bots/summary/{dimension}

##### [Get AI bots HTTP requests time series](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/bots/methods/timeseries)

GET/radar/ai/bots/timeseries

##### [Get time series distribution of AI bots HTTP requests by dimension.](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/bots/methods/timeseries_groups)

GET/radar/ai/bots/timeseries\_groups/{dimension}

#### RadarAIBotsSummary

##### [Get AI user agents summary](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/bots/subresources/summary/methods/user_agent)

Deprecated

GET/radar/ai/bots/summary/user\_agent

#### RadarAITimeseries Groups

##### [Get AI user agents time series](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/timeseries_groups/methods/user_agent)

Deprecated

GET/radar/ai/bots/timeseries\_groups/user\_agent

##### [Get AI bots HTTP requests distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/timeseries_groups/methods/summary)

Deprecated

GET/radar/ai/bots/summary/{dimension}

##### [Get AI bots HTTP requests time series](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/timeseries_groups/methods/timeseries)

Deprecated

GET/radar/ai/bots/timeseries

##### [Get time series distribution of AI bots HTTP requests by dimension.](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/timeseries_groups/methods/timeseries_groups)

Deprecated

GET/radar/ai/bots/timeseries\_groups/{dimension}

#### RadarAIMarkdown For Agents

##### [Get AI markdown for agents reduction ratio summary](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/markdown_for_agents/methods/summary)

GET/radar/ai/markdown\_for\_agents/summary

##### [Get AI markdown for agents reduction ratio time series](https://developers.cloudflare.com/api/resources/radar/subresources/ai/subresources/markdown_for_agents/methods/timeseries)

GET/radar/ai/markdown\_for\_agents/timeseries

#### RadarCT

##### [Get certificate distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/ct/methods/summary)

GET/radar/ct/summary/{dimension}

##### [Get certificates time series](https://developers.cloudflare.com/api/resources/radar/subresources/ct/methods/timeseries)

GET/radar/ct/timeseries

##### [Get time series of certificate distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/ct/methods/timeseries_groups)

GET/radar/ct/timeseries\_groups/{dimension}

#### RadarCTAuthorities

##### [Get certificate authority details](https://developers.cloudflare.com/api/resources/radar/subresources/ct/subresources/authorities/methods/get)

GET/radar/ct/authorities/{ca\_slug}

##### [List certificate authorities](https://developers.cloudflare.com/api/resources/radar/subresources/ct/subresources/authorities/methods/list)

GET/radar/ct/authorities

#### RadarCTLogs

##### [Get certificate log details](https://developers.cloudflare.com/api/resources/radar/subresources/ct/subresources/logs/methods/get)

GET/radar/ct/logs/{log\_slug}

##### [List certificate logs](https://developers.cloudflare.com/api/resources/radar/subresources/ct/subresources/logs/methods/list)

GET/radar/ct/logs

#### RadarAnnotations

##### [Get latest annotations](https://developers.cloudflare.com/api/resources/radar/subresources/annotations/methods/list)

GET/radar/annotations

#### RadarAnnotationsOutages

##### [Get latest Internet outages and anomalies](https://developers.cloudflare.com/api/resources/radar/subresources/annotations/subresources/outages/methods/get)

GET/radar/annotations/outages

##### [Get the number of outages by location](https://developers.cloudflare.com/api/resources/radar/subresources/annotations/subresources/outages/methods/locations)

GET/radar/annotations/outages/locations

#### RadarBGP

##### [Get BGP time series](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/methods/timeseries)

GET/radar/bgp/timeseries

#### RadarBGPLeaks

#### RadarBGPLeaksEvents

##### [Get BGP route leak events](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/leaks/subresources/events/methods/list)

GET/radar/bgp/leaks/events

#### RadarBGPTop

##### [Get top prefixes by BGP updates](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/top/methods/prefixes)

GET/radar/bgp/top/prefixes

#### RadarBGPTopAses

##### [Get top ASes by BGP updates](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/top/subresources/ases/methods/get)

GET/radar/bgp/top/ases

##### [Get top ASes by prefix count](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/top/subresources/ases/methods/prefixes)

GET/radar/bgp/top/ases/prefixes

#### RadarBGPHijacks

#### RadarBGPHijacksEvents

##### [Get BGP hijack events](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/hijacks/subresources/events/methods/list)

GET/radar/bgp/hijacks/events

#### RadarBGPRoutes

##### [Get Multi-Origin AS (MOAS) prefixes](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/methods/moas)

GET/radar/bgp/routes/moas

##### [Get prefix-to-ASN mapping](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/methods/pfx2as)

GET/radar/bgp/routes/pfx2as

##### [Get BGP routing table stats](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/methods/stats)

GET/radar/bgp/routes/stats

##### [List ASes from global routing tables](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/methods/ases)

GET/radar/bgp/routes/ases

##### [Get real-time BGP routes for a prefix](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/methods/realtime)

GET/radar/bgp/routes/realtime

#### RadarBGPRoutesUpstreams

##### [Get upstream composition time series for an AS](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/subresources/upstreams/methods/timeseries)

GET/radar/bgp/routes/upstreams/{asn}/timeseries

#### RadarBGPRoutesPaths

##### [Get tier-1 path segments for an AS](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/routes/subresources/paths/methods/list)

GET/radar/bgp/routes/paths/{asn}

#### RadarBGPIPs

##### [Get announced IP address space time series](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/ips/methods/timeseries)

GET/radar/bgp/ips/timeseries

#### RadarBGPIPsTop

##### [Get top ASes by announced IP space](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/ips/subresources/top/methods/ases)

GET/radar/bgp/ips/top/ases

#### RadarBGPRPKI

#### RadarBGPRPKIASPA

##### [Get ASPA objects snapshot](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/rpki/subresources/aspa/methods/snapshot)

GET/radar/bgp/rpki/aspa/snapshot

##### [Get ASPA changes over time](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/rpki/subresources/aspa/methods/changes)

GET/radar/bgp/rpki/aspa/changes

##### [Get ASPA count time series](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/rpki/subresources/aspa/methods/timeseries)

GET/radar/bgp/rpki/aspa/timeseries

#### RadarBGPRPKIRoas

##### [Get RPKI ROA deployment time series](https://developers.cloudflare.com/api/resources/radar/subresources/bgp/subresources/rpki/subresources/roas/methods/timeseries)

GET/radar/bgp/rpki/roas/timeseries

#### RadarBots

##### [List bots](https://developers.cloudflare.com/api/resources/radar/subresources/bots/methods/list)

GET/radar/bots

##### [Get bot details](https://developers.cloudflare.com/api/resources/radar/subresources/bots/methods/get)

GET/radar/bots/{bot\_slug}

##### [Get bots HTTP requests distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/bots/methods/summary)

GET/radar/bots/summary/{dimension}

##### [Get bots HTTP requests time series](https://developers.cloudflare.com/api/resources/radar/subresources/bots/methods/timeseries)

GET/radar/bots/timeseries

##### [Get time series distribution of bots HTTP requests by dimension.](https://developers.cloudflare.com/api/resources/radar/subresources/bots/methods/timeseries_groups)

GET/radar/bots/timeseries\_groups/{dimension}

#### RadarBotsWeb Crawlers

##### [Get crawler HTTP request distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/bots/subresources/web_crawlers/methods/summary)

GET/radar/bots/crawlers/summary/{dimension}

##### [Get time series of crawler HTTP request distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/bots/subresources/web_crawlers/methods/timeseries_groups)

GET/radar/bots/crawlers/timeseries\_groups/{dimension}

#### RadarDatasets

##### [List datasets](https://developers.cloudflare.com/api/resources/radar/subresources/datasets/methods/list)

GET/radar/datasets

##### [Get dataset CSV stream](https://developers.cloudflare.com/api/resources/radar/subresources/datasets/methods/get)

GET/radar/datasets/{alias}

##### [Get dataset download URL](https://developers.cloudflare.com/api/resources/radar/subresources/datasets/methods/download)

POST/radar/datasets/download

#### RadarDNS

##### [Get DNS summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/dns/methods/summary_v2)

GET/radar/dns/summary/{dimension}

##### [Get DNS queries time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/methods/timeseries)

GET/radar/dns/timeseries

##### [Get DNS time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/dns/methods/timeseries_groups_v2)

GET/radar/dns/timeseries\_groups/{dimension}

#### RadarDNSTop

##### [Get top ASes by DNS queries](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/top/methods/ases)

GET/radar/dns/top/ases

##### [Get top locations by DNS queries](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/top/methods/locations)

GET/radar/dns/top/locations

#### RadarDNSSummary

##### [Get DNS queries by cache status summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/cache_hit)

Deprecated

GET/radar/dns/summary/cache\_hit

##### [Get DNS queries by DNSSEC support summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/dnssec)

Deprecated

GET/radar/dns/summary/dnssec

##### [Get DNS queries by DNSSEC awareness summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/dnssec_aware)

Deprecated

GET/radar/dns/summary/dnssec\_aware

##### [Get DNS queries by DNSSEC end-to-end summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/dnssec_e2e)

Deprecated

GET/radar/dns/summary/dnssec\_e2e

##### [Get DNS queries by IP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/ip_version)

Deprecated

GET/radar/dns/summary/ip\_version

##### [Get DNS queries by matching answer summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/matching_answer)

Deprecated

GET/radar/dns/summary/matching\_answer

##### [Get DNS queries by protocol summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/protocol)

Deprecated

GET/radar/dns/summary/protocol

##### [Get DNS queries by type summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/query_type)

Deprecated

GET/radar/dns/summary/query\_type

##### [Get DNS queries by response code summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/response_code)

Deprecated

GET/radar/dns/summary/response\_code

##### [Get DNS queries by response TTL summary](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/summary/methods/response_ttl)

Deprecated

GET/radar/dns/summary/response\_ttl

#### RadarDNSTimeseries Groups

##### [Get DNS queries by cache status time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/cache_hit)

Deprecated

GET/radar/dns/timeseries\_groups/cache\_hit

##### [Get DNS queries by DNSSEC support time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/dnssec)

Deprecated

GET/radar/dns/timeseries\_groups/dnssec

##### [Get DNS queries by DNSSEC awareness time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/dnssec_aware)

Deprecated

GET/radar/dns/timeseries\_groups/dnssec\_aware

##### [Get DNS queries by DNSSEC end-to-end time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/dnssec_e2e)

Deprecated

GET/radar/dns/timeseries\_groups/dnssec\_e2e

##### [Get DNS queries by IP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/ip_version)

Deprecated

GET/radar/dns/timeseries\_groups/ip\_version

##### [Get DNS queries by matching answer time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/matching_answer)

Deprecated

GET/radar/dns/timeseries\_groups/matching\_answer

##### [Get DNS queries by protocol time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/protocol)

Deprecated

GET/radar/dns/timeseries\_groups/protocol

##### [Get DNS queries by type time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/query_type)

Deprecated

GET/radar/dns/timeseries\_groups/query\_type

##### [Get DNS queries by response code time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/response_code)

Deprecated

GET/radar/dns/timeseries\_groups/response\_code

##### [Get DNS queries by response TTL time series](https://developers.cloudflare.com/api/resources/radar/subresources/dns/subresources/timeseries_groups/methods/response_ttl)

Deprecated

GET/radar/dns/timeseries\_groups/response\_ttl

#### RadarNetFlows

##### [Get network traffic time series](https://developers.cloudflare.com/api/resources/radar/subresources/netflows/methods/timeseries)

GET/radar/netflows/timeseries

##### [Get network traffic summary](https://developers.cloudflare.com/api/resources/radar/subresources/netflows/methods/summary)

Deprecated

GET/radar/netflows/summary

##### [Get network traffic distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/netflows/methods/summary_v2)

GET/radar/netflows/summary/{dimension}

##### [Get time series distribution of network traffic by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/netflows/methods/timeseries_groups)

GET/radar/netflows/timeseries\_groups/{dimension}

#### RadarNetFlowsTop

##### [Get top ASes by network traffic](https://developers.cloudflare.com/api/resources/radar/subresources/netflows/subresources/top/methods/ases)

GET/radar/netflows/top/ases

##### [Get top locations by network traffic](https://developers.cloudflare.com/api/resources/radar/subresources/netflows/subresources/top/methods/locations)

GET/radar/netflows/top/locations

#### RadarPost Quantum

#### RadarPost QuantumOrigin

##### [Get Origin Post-Quantum Data Summary](https://developers.cloudflare.com/api/resources/radar/subresources/post_quantum/subresources/origin/methods/summary)

GET/radar/post\_quantum/origin/summary/{dimension}

##### [Get Origin Post-Quantum Data Over Time](https://developers.cloudflare.com/api/resources/radar/subresources/post_quantum/subresources/origin/methods/timeseries_groups)

GET/radar/post\_quantum/origin/timeseries\_groups/{dimension}

#### RadarPost QuantumTLS

##### [Check Post-Quantum TLS support](https://developers.cloudflare.com/api/resources/radar/subresources/post_quantum/subresources/tls/methods/support)

GET/radar/post\_quantum/tls/support

#### RadarSearch

##### [Search for locations, ASes, reports, and more](https://developers.cloudflare.com/api/resources/radar/subresources/search/methods/global)

GET/radar/search/global

#### RadarVerified Bots

#### RadarVerified BotsTop

##### [Get top verified bots by HTTP requests](https://developers.cloudflare.com/api/resources/radar/subresources/verified_bots/subresources/top/methods/bots)

Deprecated

GET/radar/verified\_bots/top/bots

##### [Get top verified bot categories by HTTP requests](https://developers.cloudflare.com/api/resources/radar/subresources/verified_bots/subresources/top/methods/categories)

Deprecated

GET/radar/verified\_bots/top/categories

#### RadarAS112

##### [Get AS112 DNS queries time series](https://developers.cloudflare.com/api/resources/radar/subresources/as112/methods/timeseries)

GET/radar/as112/timeseries

##### [Get AS112 summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/as112/methods/summary_v2)

GET/radar/as112/summary/{dimension}

##### [Get AS112 time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/as112/methods/timeseries_groups_v2)

GET/radar/as112/timeseries\_groups/{dimension}

#### RadarAS112Summary

##### [Get AS112 DNS queries by DNSSEC summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/summary/methods/dnssec)

Deprecated

GET/radar/as112/summary/dnssec

##### [Get AS112 DNS queries by EDNS summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/summary/methods/edns)

Deprecated

GET/radar/as112/summary/edns

##### [Get AS112 DNS queries by IP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/summary/methods/ip_version)

Deprecated

GET/radar/as112/summary/ip\_version

##### [Get AS112 DNS queries by DNS protocol summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/summary/methods/protocol)

Deprecated

GET/radar/as112/summary/protocol

##### [Get AS112 DNS queries by type summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/summary/methods/query_type)

Deprecated

GET/radar/as112/summary/query\_type

##### [Get AS112 DNS queries by response code summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/summary/methods/response_codes)

Deprecated

GET/radar/as112/summary/response\_codes

#### RadarAS112Timeseries Groups

##### [Get AS112 DNS queries by DNS protocol time series](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/timeseries_groups/methods/protocol)

Deprecated

GET/radar/as112/timeseries\_groups/protocol

##### [Get AS112 DNS queries by type time series](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/timeseries_groups/methods/query_type)

Deprecated

GET/radar/as112/timeseries\_groups/query\_type

##### [Get AS112 DNS queries by response code time series](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/timeseries_groups/methods/response_codes)

Deprecated

GET/radar/as112/timeseries\_groups/response\_codes

##### [Get AS112 DNS queries by DNSSEC support time series](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/timeseries_groups/methods/dnssec)

Deprecated

GET/radar/as112/timeseries\_groups/dnssec

##### [Get AS112 DNS queries by EDNS support summary](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/timeseries_groups/methods/edns)

Deprecated

GET/radar/as112/timeseries\_groups/edns

##### [Get AS112 DNS queries by IP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/timeseries_groups/methods/ip_version)

Deprecated

GET/radar/as112/timeseries\_groups/ip\_version

#### RadarAS112Top

##### [Get top locations by AS112 DNS queries](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/top/methods/locations)

GET/radar/as112/top/locations

##### [Get top locations by AS112 DNS queries with DNSSEC support](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/top/methods/dnssec)

GET/radar/as112/top/locations/dnssec/{dnssec}

##### [Get top locations by AS112 DNS queries with EDNS support](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/top/methods/edns)

GET/radar/as112/top/locations/edns/{edns}

##### [Get top locations by AS112 DNS queries for an IP version](https://developers.cloudflare.com/api/resources/radar/subresources/as112/subresources/top/methods/ip_version)

GET/radar/as112/top/locations/ip\_version/{ip\_version}

#### RadarEmail

#### RadarEmailRouting

##### [Get email routing summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/methods/summary_v2)

GET/radar/email/routing/summary/{dimension}

##### [Get email routing time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/methods/timeseries_groups_v2)

GET/radar/email/routing/timeseries\_groups/{dimension}

#### RadarEmailRoutingSummary

##### [Get email ARC validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/summary/methods/arc)

Deprecated

GET/radar/email/routing/summary/arc

##### [Get email DKIM validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/summary/methods/dkim)

Deprecated

GET/radar/email/routing/summary/dkim

##### [Get email DMARC validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/summary/methods/dmarc)

Deprecated

GET/radar/email/routing/summary/dmarc

##### [Get email encryption status summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/summary/methods/encrypted)

Deprecated

GET/radar/email/routing/summary/encrypted

##### [Get email IP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/summary/methods/ip_version)

Deprecated

GET/radar/email/routing/summary/ip\_version

##### [Get email SPF validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/summary/methods/spf)

Deprecated

GET/radar/email/routing/summary/spf

#### RadarEmailRoutingTimeseries Groups

##### [Get email ARC validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/timeseries_groups/methods/arc)

Deprecated

GET/radar/email/routing/timeseries\_groups/arc

##### [Get email DKIM validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/timeseries_groups/methods/dkim)

Deprecated

GET/radar/email/routing/timeseries\_groups/dkim

##### [Get email DMARC validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/timeseries_groups/methods/dmarc)

Deprecated

GET/radar/email/routing/timeseries\_groups/dmarc

##### [Get email encryption status time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/timeseries_groups/methods/encrypted)

Deprecated

GET/radar/email/routing/timeseries\_groups/encrypted

##### [Get email IP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/timeseries_groups/methods/ip_version)

Deprecated

GET/radar/email/routing/timeseries\_groups/ip\_version

##### [Get email SPF validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/routing/subresources/timeseries_groups/methods/spf)

Deprecated

GET/radar/email/routing/timeseries\_groups/spf

#### RadarEmailSecurity

##### [Get email security summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/methods/summary_v2)

GET/radar/email/security/summary/{dimension}

##### [Get email security time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/methods/timeseries_groups_v2)

GET/radar/email/security/timeseries\_groups/{dimension}

#### RadarEmailSecurityTop

#### RadarEmailSecurityTopTLDs

##### [Get top TLDs by email message volume](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/top/subresources/tlds/methods/get)

GET/radar/email/security/top/tlds

#### RadarEmailSecurityTopTLDsMalicious

##### [Get top TLDs by email malicious classification](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/top/subresources/tlds/subresources/malicious/methods/get)

GET/radar/email/security/top/tlds/malicious/{malicious}

#### RadarEmailSecurityTopTLDsSpam

##### [Get top TLDs by email spam classification](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/top/subresources/tlds/subresources/spam/methods/get)

GET/radar/email/security/top/tlds/spam/{spam}

#### RadarEmailSecurityTopTLDsSpoof

##### [Get top TLDs by email spoof classification](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/top/subresources/tlds/subresources/spoof/methods/get)

GET/radar/email/security/top/tlds/spoof/{spoof}

#### RadarEmailSecuritySummary

##### [Get email ARC validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/arc)

Deprecated

GET/radar/email/security/summary/arc

##### [Get email DKIM validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/dkim)

Deprecated

GET/radar/email/security/summary/dkim

##### [Get email DMARC validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/dmarc)

Deprecated

GET/radar/email/security/summary/dmarc

##### [Get email malicious classification summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/malicious)

Deprecated

GET/radar/email/security/summary/malicious

##### [Get email spam classification summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/spam)

Deprecated

GET/radar/email/security/summary/spam

##### [Get email SPF validation summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/spf)

Deprecated

GET/radar/email/security/summary/spf

##### [Get email threat category summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/threat_category)

Deprecated

GET/radar/email/security/summary/threat\_category

##### [Get email spoof classification summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/spoof)

Deprecated

GET/radar/email/security/summary/spoof

##### [Get email TLS version summary](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/summary/methods/tls_version)

Deprecated

GET/radar/email/security/summary/tls\_version

#### RadarEmailSecurityTimeseries Groups

##### [Get email ARC validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/arc)

Deprecated

GET/radar/email/security/timeseries\_groups/arc

##### [Get email DKIM validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/dkim)

Deprecated

GET/radar/email/security/timeseries\_groups/dkim

##### [Get email DMARC validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/dmarc)

Deprecated

GET/radar/email/security/timeseries\_groups/dmarc

##### [Get email malicious classification time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/malicious)

Deprecated

GET/radar/email/security/timeseries\_groups/malicious

##### [Get email spam classification time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/spam)

Deprecated

GET/radar/email/security/timeseries\_groups/spam

##### [Get email SPF validation time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/spf)

Deprecated

GET/radar/email/security/timeseries\_groups/spf

##### [Get email threat category time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/threat_category)

Deprecated

GET/radar/email/security/timeseries\_groups/threat\_category

##### [Get email spoof classification time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/spoof)

Deprecated

GET/radar/email/security/timeseries\_groups/spoof

##### [Get email TLS version time series](https://developers.cloudflare.com/api/resources/radar/subresources/email/subresources/security/subresources/timeseries_groups/methods/tls_version)

Deprecated

GET/radar/email/security/timeseries\_groups/tls\_version

#### RadarAttacks

#### RadarAttacksLayer3

##### [Get layer 3 attacks summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/methods/summary_v2)

GET/radar/attacks/layer3/summary/{dimension}

##### [Get layer 3 attacks by bytes time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/methods/timeseries)

GET/radar/attacks/layer3/timeseries

##### [Get layer 3 attacks time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/methods/timeseries_groups_v2)

GET/radar/attacks/layer3/timeseries\_groups/{dimension}

#### RadarAttacksLayer3Summary

##### [Get layer 3 attacks by bitrate summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/bitrate)

Deprecated

GET/radar/attacks/layer3/summary/bitrate

##### [Get layer 3 attacks by duration summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/duration)

Deprecated

GET/radar/attacks/layer3/summary/duration

##### [Get layer 3 attacks by IP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/ip_version)

Deprecated

GET/radar/attacks/layer3/summary/ip\_version

##### [Get layer 3 attacks by protocol summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/protocol)

Deprecated

GET/radar/attacks/layer3/summary/protocol

##### [Get layer 3 attacks by vector summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/vector)

Deprecated

GET/radar/attacks/layer3/summary/vector

##### [Get layer 3 attacks by targeted industry summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/industry)

Deprecated

GET/radar/attacks/layer3/summary/industry

##### [Get layer 3 attacks by targeted vertical summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/summary/methods/vertical)

Deprecated

GET/radar/attacks/layer3/summary/vertical

#### RadarAttacksLayer3Timeseries Groups

##### [Get layer 3 attacks by target industries time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/industry)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/industry

##### [Get layer 3 attacks by IP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/ip_version)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/ip\_version

##### [Get layer 3 attacks by protocol time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/protocol)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/protocol

##### [Get layer 3 attacks by vector time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/vector)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/vector

##### [Get layer 3 attacks by vertical time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/vertical)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/vertical

##### [Get layer 3 attacks by bitrate time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/bitrate)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/bitrate

##### [Get layer 3 attacks by duration time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/timeseries_groups/methods/duration)

Deprecated

GET/radar/attacks/layer3/timeseries\_groups/duration

#### RadarAttacksLayer3Top

##### [Get top layer 3 attack pairs (origin and target locations)](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/top/methods/attacks)

GET/radar/attacks/layer3/top/attacks

##### [Get top industries targeted by layer 3 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/top/methods/industry)

Deprecated

GET/radar/attacks/layer3/top/industry

##### [Get top verticals targeted by layer 3 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/top/methods/vertical)

Deprecated

GET/radar/attacks/layer3/top/vertical

#### RadarAttacksLayer3TopLocations

##### [Get top origin locations of layer 3 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/top/subresources/locations/methods/origin)

GET/radar/attacks/layer3/top/locations/origin

##### [Get top target locations of layer 3 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer3/subresources/top/subresources/locations/methods/target)

GET/radar/attacks/layer3/top/locations/target

#### RadarAttacksLayer7

##### [Get layer 7 attacks summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/methods/summary_v2)

GET/radar/attacks/layer7/summary/{dimension}

##### [Get layer 7 attacks time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/methods/timeseries)

GET/radar/attacks/layer7/timeseries

##### [Get layer 7 attacks time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/methods/timeseries_groups_v2)

GET/radar/attacks/layer7/timeseries\_groups/{dimension}

#### RadarAttacksLayer7Summary

##### [Get layer 7 attacks by IP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/ip_version)

Deprecated

GET/radar/attacks/layer7/summary/ip\_version

##### [Get layer 7 attacks by HTTP method summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/http_method)

Deprecated

GET/radar/attacks/layer7/summary/http\_method

##### [Get layer 7 attacks by HTTP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/http_version)

Deprecated

GET/radar/attacks/layer7/summary/http\_version

##### [Get layer 7 attacks by managed rules summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/managed_rules)

Deprecated

GET/radar/attacks/layer7/summary/managed\_rules

##### [Get layer 7 attacks by mitigation product summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/mitigation_product)

Deprecated

GET/radar/attacks/layer7/summary/mitigation\_product

##### [Get layer 7 attacks by targeted industry summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/industry)

Deprecated

GET/radar/attacks/layer7/summary/industry

##### [Get layer 7 attacks by targeted vertical summary](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/summary/methods/vertical)

Deprecated

GET/radar/attacks/layer7/summary/vertical

#### RadarAttacksLayer7Timeseries Groups

##### [Get layer 7 attacks by target industries time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/industry)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/industry

##### [Get layer 7 attacks by IP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/ip_version)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/ip\_version

##### [Get layer 7 attacks by vertical time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/vertical)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/vertical

##### [Get layer 7 attacks by HTTP method time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/http_method)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/http\_method

##### [Get layer 7 attacks by HTTP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/http_version)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/http\_version

##### [Get layer 7 attacks by managed rules time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/managed_rules)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/managed\_rules

##### [Get layer 7 attacks by mitigation product time series](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/timeseries_groups/methods/mitigation_product)

Deprecated

GET/radar/attacks/layer7/timeseries\_groups/mitigation\_product

#### RadarAttacksLayer7Top

##### [Get top layer 7 attack pairs (origin and target locations)](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/top/methods/attacks)

GET/radar/attacks/layer7/top/attacks

##### [Get top industries targeted by layer 7 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/top/methods/industry)

Deprecated

GET/radar/attacks/layer7/top/industry

##### [Get top verticals targeted by layer 7 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/top/methods/vertical)

Deprecated

GET/radar/attacks/layer7/top/vertical

#### RadarAttacksLayer7TopLocations

##### [Get top origin locations of layer 7 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/top/subresources/locations/methods/origin)

GET/radar/attacks/layer7/top/locations/origin

##### [Get top target locations of layer 7 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/top/subresources/locations/methods/target)

GET/radar/attacks/layer7/top/locations/target

#### RadarAttacksLayer7TopAses

##### [Get top origin ASes of layer 7 attacks](https://developers.cloudflare.com/api/resources/radar/subresources/attacks/subresources/layer7/subresources/top/subresources/ases/methods/origin)

GET/radar/attacks/layer7/top/ases/origin

#### RadarEntities

##### [Get IP address details](https://developers.cloudflare.com/api/resources/radar/subresources/entities/methods/get)

GET/radar/entities/ip

#### RadarEntitiesASNs

##### [List autonomous systems](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/asns/methods/list)

GET/radar/entities/asns

##### [Get AS details by ASN](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/asns/methods/get)

GET/radar/entities/asns/{asn}

##### [Get AS-level relationships by ASN](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/asns/methods/rel)

GET/radar/entities/asns/{asn}/rel

##### [Get IRR AS-SETs that an AS is a member of](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/asns/methods/as_set)

GET/radar/entities/asns/{asn}/as\_set

##### [Get AS details by IP address](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/asns/methods/ip)

GET/radar/entities/asns/ip

##### [Get AS rankings by botnet threat feed activity](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/asns/methods/botnet_threat_feed)

GET/radar/entities/asns/botnet\_threat\_feed

#### RadarEntitiesLocations

##### [List locations](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/locations/methods/list)

GET/radar/entities/locations

##### [Get location details](https://developers.cloudflare.com/api/resources/radar/subresources/entities/subresources/locations/methods/get)

GET/radar/entities/locations/{location}

#### RadarGeolocations

##### [List Geolocations](https://developers.cloudflare.com/api/resources/radar/subresources/geolocations/methods/list)

GET/radar/geolocations

##### [Get Geolocation details](https://developers.cloudflare.com/api/resources/radar/subresources/geolocations/methods/get)

GET/radar/geolocations/{geo\_id}

#### RadarHTTP

##### [Get HTTP requests summary by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/http/methods/summary_v2)

GET/radar/http/summary/{dimension}

##### [Get HTTP requests time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/methods/timeseries)

GET/radar/http/timeseries

##### [Get HTTP requests time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/http/methods/timeseries_groups_v2)

GET/radar/http/timeseries\_groups/{dimension}

#### RadarHTTPLocations

##### [Get top locations by HTTP requests](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/methods/get)

GET/radar/http/top/locations

#### RadarHTTPLocationsBot Class

##### [Get top locations by HTTP requests for a bot class](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/bot_class/methods/get)

GET/radar/http/top/locations/bot\_class/{bot\_class}

#### RadarHTTPLocationsDevice Type

##### [Get top locations by HTTP requests for a device type](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/device_type/methods/get)

GET/radar/http/top/locations/device\_type/{device\_type}

#### RadarHTTPLocationsHTTP Protocol

##### [Get top locations by HTTP requests for an HTTP protocol](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/http_protocol/methods/get)

GET/radar/http/top/locations/http\_protocol/{http\_protocol}

#### RadarHTTPLocationsHTTP Method

##### [Get top locations by HTTP requests for an HTTP version](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/http_method/methods/get)

GET/radar/http/top/locations/http\_version/{http\_version}

#### RadarHTTPLocationsIP Version

##### [Get top locations by HTTP requests for an IP version](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/ip_version/methods/get)

GET/radar/http/top/locations/ip\_version/{ip\_version}

#### RadarHTTPLocationsOS

##### [Get top locations by HTTP requests for an OS](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/os/methods/get)

GET/radar/http/top/locations/os/{os}

#### RadarHTTPLocationsTLS Version

##### [Get top locations by HTTP requests for a TLS version](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/tls_version/methods/get)

GET/radar/http/top/locations/tls\_version/{tls\_version}

#### RadarHTTPLocationsBrowser Family

##### [Get top locations by HTTP requests for a browser family](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/locations/subresources/browser_family/methods/get)

GET/radar/http/top/locations/browser\_family/{browser\_family}

#### RadarHTTPAses

##### [Get top ASes by HTTP requests](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/methods/get)

GET/radar/http/top/ases

#### RadarHTTPAsesBot Class

##### [Get top ASes by HTTP requests for a bot class](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/bot_class/methods/get)

GET/radar/http/top/ases/bot\_class/{bot\_class}

#### RadarHTTPAsesDevice Type

##### [Get top ASes by HTTP requests for a device type](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/device_type/methods/get)

GET/radar/http/top/ases/device\_type/{device\_type}

#### RadarHTTPAsesHTTP Protocol

##### [Get top ASes by HTTP requests for an HTTP protocol](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/http_protocol/methods/get)

GET/radar/http/top/ases/http\_protocol/{http\_protocol}

#### RadarHTTPAsesHTTP Method

##### [Get top ASes by HTTP requests for an HTTP version](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/http_method/methods/get)

GET/radar/http/top/ases/http\_version/{http\_version}

#### RadarHTTPAsesIP Version

##### [Get top ASes by HTTP requests for an IP version](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/ip_version/methods/get)

GET/radar/http/top/ases/ip\_version/{ip\_version}

#### RadarHTTPAsesOS

##### [Get top ASes by HTTP requests for an OS](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/os/methods/get)

GET/radar/http/top/ases/os/{os}

#### RadarHTTPAsesTLS Version

##### [Get top ASes by HTTP requests for a TLS version](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/tls_version/methods/get)

GET/radar/http/top/ases/tls\_version/{tls\_version}

#### RadarHTTPAsesBrowser Family

##### [Get top ASes by HTTP requests for a browser family](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/ases/subresources/browser_family/methods/get)

GET/radar/http/top/ases/browser\_family/{browser\_family}

#### RadarHTTPSummary

##### [Get HTTP requests by bot class summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/bot_class)

Deprecated

GET/radar/http/summary/bot\_class

##### [Get HTTP requests by device type summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/device_type)

Deprecated

GET/radar/http/summary/device\_type

##### [Get HTTP requests by HTTP/HTTPS summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/http_protocol)

Deprecated

GET/radar/http/summary/http\_protocol

##### [Get HTTP requests by HTTP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/http_version)

Deprecated

GET/radar/http/summary/http\_version

##### [Get HTTP requests by IP version summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/ip_version)

Deprecated

GET/radar/http/summary/ip\_version

##### [Get HTTP requests by OS summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/os)

Deprecated

GET/radar/http/summary/os

##### [Get HTTP requests by TLS version summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/tls_version)

Deprecated

GET/radar/http/summary/tls\_version

##### [Get HTTP requests by post-quantum support summary](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/summary/methods/post_quantum)

Deprecated

GET/radar/http/summary/post\_quantum

#### RadarHTTPTimeseries Groups

##### [Get HTTP requests by TLS version time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/tls_version)

Deprecated

GET/radar/http/timeseries\_groups/tls\_version

##### [Get HTTP requests by bot class time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/bot_class)

Deprecated

GET/radar/http/timeseries\_groups/bot\_class

##### [Get HTTP requests by user agent time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/browser)

Deprecated

GET/radar/http/timeseries\_groups/browser

##### [Get HTTP requests by user agent family time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/browser_family)

Deprecated

GET/radar/http/timeseries\_groups/browser\_family

##### [Get HTTP requests by device type time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/device_type)

Deprecated

GET/radar/http/timeseries\_groups/device\_type

##### [Get HTTP requests by HTTP/HTTPS time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/http_protocol)

Deprecated

GET/radar/http/timeseries\_groups/http\_protocol

##### [Get HTTP requests by HTTP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/http_version)

Deprecated

GET/radar/http/timeseries\_groups/http\_version

##### [Get HTTP requests by IP version time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/ip_version)

Deprecated

GET/radar/http/timeseries\_groups/ip\_version

##### [Get HTTP requests by OS time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/os)

Deprecated

GET/radar/http/timeseries\_groups/os

##### [Get HTTP requests by post-quantum support time series](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/timeseries_groups/methods/post_quantum)

Deprecated

GET/radar/http/timeseries\_groups/post\_quantum

#### RadarHTTPTop

##### [Get top user agents by HTTP requests](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/top/methods/browser)

Deprecated

GET/radar/http/top/browser

##### [Get top user agent families by HTTP requests](https://developers.cloudflare.com/api/resources/radar/subresources/http/subresources/top/methods/browser_family)

Deprecated

GET/radar/http/top/browser\_family

#### RadarOrigins

##### [List Origins](https://developers.cloudflare.com/api/resources/radar/subresources/origins/methods/list)

GET/radar/origins

##### [Get Origin details](https://developers.cloudflare.com/api/resources/radar/subresources/origins/methods/get)

GET/radar/origins/{slug}

##### [Get origin metrics time series](https://developers.cloudflare.com/api/resources/radar/subresources/origins/methods/timeseries)

GET/radar/origins/timeseries

##### [Get origin metrics distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/origins/methods/summary)

GET/radar/origins/summary/{dimension}

##### [Get origin metrics time series grouped by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/origins/methods/timeseries_groups)

GET/radar/origins/timeseries\_groups/{dimension}

#### RadarQuality

#### RadarQualityIQI

##### [Get Internet Quality Index (IQI) summary](https://developers.cloudflare.com/api/resources/radar/subresources/quality/subresources/iqi/methods/summary)

GET/radar/quality/iqi/summary

##### [Get Internet Quality Index (IQI) time series](https://developers.cloudflare.com/api/resources/radar/subresources/quality/subresources/iqi/methods/timeseries_groups)

GET/radar/quality/iqi/timeseries\_groups

#### RadarQualitySpeed

##### [Get speed tests summary](https://developers.cloudflare.com/api/resources/radar/subresources/quality/subresources/speed/methods/summary)

GET/radar/quality/speed/summary

##### [Get speed tests histogram](https://developers.cloudflare.com/api/resources/radar/subresources/quality/subresources/speed/methods/histogram)

GET/radar/quality/speed/histogram

#### RadarQualitySpeedTop

##### [Get top ASes by speed test results](https://developers.cloudflare.com/api/resources/radar/subresources/quality/subresources/speed/subresources/top/methods/ases)

GET/radar/quality/speed/top/ases

##### [Get top locations by speed test results](https://developers.cloudflare.com/api/resources/radar/subresources/quality/subresources/speed/subresources/top/methods/locations)

GET/radar/quality/speed/top/locations

#### RadarRanking

##### [Get domains rank time series](https://developers.cloudflare.com/api/resources/radar/subresources/ranking/methods/timeseries_groups)

GET/radar/ranking/timeseries\_groups

##### [Get top or trending domains](https://developers.cloudflare.com/api/resources/radar/subresources/ranking/methods/top)

GET/radar/ranking/top

#### RadarRankingDomain

##### [Get domain rank details](https://developers.cloudflare.com/api/resources/radar/subresources/ranking/subresources/domain/methods/get)

GET/radar/ranking/domain/{domain}

#### RadarRankingInternet Services

##### [Get Internet services rank time series](https://developers.cloudflare.com/api/resources/radar/subresources/ranking/subresources/internet_services/methods/timeseries_groups)

GET/radar/ranking/internet\_services/timeseries\_groups

##### [Get top Internet services](https://developers.cloudflare.com/api/resources/radar/subresources/ranking/subresources/internet_services/methods/top)

GET/radar/ranking/internet\_services/top

##### [List Internet services categories](https://developers.cloudflare.com/api/resources/radar/subresources/ranking/subresources/internet_services/methods/categories)

GET/radar/ranking/internet\_services/categories

#### RadarTraffic Anomalies

##### [Get latest Internet traffic anomalies](https://developers.cloudflare.com/api/resources/radar/subresources/traffic_anomalies/methods/get)

GET/radar/traffic\_anomalies

#### RadarTraffic AnomaliesLocations

##### [Get top locations by total traffic anomalies](https://developers.cloudflare.com/api/resources/radar/subresources/traffic_anomalies/subresources/locations/methods/get)

GET/radar/traffic\_anomalies/locations

#### RadarTCP Resets Timeouts

##### [Get TCP resets and timeouts summary](https://developers.cloudflare.com/api/resources/radar/subresources/tcp_resets_timeouts/methods/summary)

GET/radar/tcp\_resets\_timeouts/summary

##### [Get TCP resets and timeouts time series](https://developers.cloudflare.com/api/resources/radar/subresources/tcp_resets_timeouts/methods/timeseries_groups)

GET/radar/tcp\_resets\_timeouts/timeseries\_groups

#### RadarTLDs

##### [List TLDs](https://developers.cloudflare.com/api/resources/radar/subresources/tlds/methods/list)

GET/radar/tlds

##### [Get TLD details](https://developers.cloudflare.com/api/resources/radar/subresources/tlds/methods/get)

GET/radar/tlds/{tld}

#### RadarTLDsPerformance

##### [Get TLD Performance Summary](https://developers.cloudflare.com/api/resources/radar/subresources/tlds/subresources/performance/methods/summary)

GET/radar/tlds/performance/summary/{dimension}

##### [Get TLD Performance Over Time](https://developers.cloudflare.com/api/resources/radar/subresources/tlds/subresources/performance/methods/timeseries_groups)

GET/radar/tlds/performance/timeseries\_groups/{dimension}

#### RadarRobots TXT

#### RadarRobots TXTTop

##### [Get top domain categories by robots.txt files parsed](https://developers.cloudflare.com/api/resources/radar/subresources/robots_txt/subresources/top/methods/domain_categories)

GET/radar/robots\_txt/top/domain\_categories

#### RadarRobots TXTTopUser Agents

##### [Get top user agents on robots.txt files](https://developers.cloudflare.com/api/resources/radar/subresources/robots_txt/subresources/top/subresources/user_agents/methods/directive)

GET/radar/robots\_txt/top/user\_agents/directive

#### RadarLeaked Credentials

##### [Get HTTP authentication requests distribution by dimension](https://developers.cloudflare.com/api/resources/radar/subresources/leaked_credentials/methods/summary_v2)

GET/radar/leaked\_credential\_checks/summary/{dimension}

##### [Get time series distribution of HTTP authentication requests by dimension.](https://developers.cloudflare.com/api/resources/radar/subresources/leaked_credentials/methods/timeseries_groups_v2)

GET/radar/leaked\_credential\_checks/timeseries\_groups/{dimension}

#### RadarLeaked CredentialsSummary

##### [Get HTTP authentication requests by bot class summary](https://developers.cloudflare.com/api/resources/radar/subresources/leaked_credentials/subresources/summary/methods/bot_class)

Deprecated

GET/radar/leaked\_credential\_checks/summary/bot\_class

##### [Get HTTP authentication requests by compromised credential status summary](https://developers.cloudflare.com/api/resources/radar/subresources/leaked_credentials/subresources/summary/methods/compromised)

Deprecated

GET/radar/leaked\_credential\_checks/summary/compromised

#### RadarLeaked CredentialsTimeseries Groups

##### [Get HTTP authentication requests by bot class time series](https://developers.cloudflare.com/api/resources/radar/subresources/leaked_credentials/subresources/timeseries_groups/methods/bot_class)

Deprecated

GET/radar/leaked\_credential\_checks/timeseries\_groups/bot\_class

##### [Get HTTP authentication requests by compromised credential status time series](https://developers.cloudflare.com/api/resources/radar/subresources/leaked_credentials/subresources/timeseries_groups/methods/compromised)

Deprecated

GET/radar/leaked\_credential\_checks/timeseries\_groups/compromised

#### Bot Management

##### [Get Zone Bot Management Config](https://developers.cloudflare.com/api/resources/bot_management/methods/get)

GET/zones/{zone\_id}/bot\_management

##### [Update Zone Bot Management Config](https://developers.cloudflare.com/api/resources/bot_management/methods/update)

PUT/zones/{zone\_id}/bot\_management

#### Bot ManagementFeedback

##### [List zone feedback reports](https://developers.cloudflare.com/api/resources/bot_management/subresources/feedback/methods/list)

GET/zones/{zone\_id}/bot\_management/feedback

##### [Submit a feedback report](https://developers.cloudflare.com/api/resources/bot_management/subresources/feedback/methods/create)

POST/zones/{zone\_id}/bot\_management/feedback

#### Fraud

##### [Get Fraud Detection Settings](https://developers.cloudflare.com/api/resources/fraud/methods/get)

GET/zones/{zone\_id}/fraud\_detection/settings

##### [Update Fraud Detection Settings](https://developers.cloudflare.com/api/resources/fraud/methods/update)

PUT/zones/{zone\_id}/fraud\_detection/settings

#### Precursor

##### [Get Zone Precursor Config](https://developers.cloudflare.com/api/resources/precursor/methods/get)

GET/zones/{zone\_id}/precursor

##### [Update Zone Precursor Config](https://developers.cloudflare.com/api/resources/precursor/methods/update)

PUT/zones/{zone\_id}/precursor

#### Origin Post Quantum Encryption

##### [Get Origin Post-Quantum Encryption setting](https://developers.cloudflare.com/api/resources/origin_post_quantum_encryption/methods/get)

Deprecated

GET/zones/{zone\_id}/cache/origin\_post\_quantum\_encryption

##### [Change Origin Post-Quantum Encryption setting](https://developers.cloudflare.com/api/resources/origin_post_quantum_encryption/methods/update)

Deprecated

PUT/zones/{zone\_id}/cache/origin\_post\_quantum\_encryption

#### Origin TLS Compliance Modes

##### [Get Origin TLS Compliance Modes setting](https://developers.cloudflare.com/api/resources/origin_tls_compliance_modes/methods/get)

GET/zones/{zone\_id}/settings/origin\_tls\_compliance\_modes

##### [Replace Origin TLS Compliance Modes setting](https://developers.cloudflare.com/api/resources/origin_tls_compliance_modes/methods/update)

PUT/zones/{zone\_id}/settings/origin\_tls\_compliance\_modes

##### [Change Origin TLS Compliance Modes setting](https://developers.cloudflare.com/api/resources/origin_tls_compliance_modes/methods/edit)

PATCH/zones/{zone\_id}/settings/origin\_tls\_compliance\_modes

##### [Delete Origin TLS Compliance Modes setting](https://developers.cloudflare.com/api/resources/origin_tls_compliance_modes/methods/delete)

DELETE/zones/{zone\_id}/settings/origin\_tls\_compliance\_modes

#### Google Tag Gateway

#### Google Tag GatewayConfig

##### [Get Google Tag Gateway configuration](https://developers.cloudflare.com/api/resources/google_tag_gateway/subresources/config/methods/get)

GET/zones/{zone\_id}/settings/google-tag-gateway/config

##### [Update Google Tag Gateway configuration](https://developers.cloudflare.com/api/resources/google_tag_gateway/subresources/config/methods/update)

PUT/zones/{zone\_id}/settings/google-tag-gateway/config

#### Zaraz

##### [Update Zaraz workflow](https://developers.cloudflare.com/api/resources/zaraz/methods/update)

PUT/zones/{zone\_id}/settings/zaraz/workflow

#### ZarazConfig

##### [Get Zaraz configuration](https://developers.cloudflare.com/api/resources/zaraz/subresources/config/methods/get)

GET/zones/{zone\_id}/settings/zaraz/config

##### [Update Zaraz configuration](https://developers.cloudflare.com/api/resources/zaraz/subresources/config/methods/update)

PUT/zones/{zone\_id}/settings/zaraz/config

#### ZarazDefault

##### [Get default Zaraz configuration](https://developers.cloudflare.com/api/resources/zaraz/subresources/default/methods/get)

GET/zones/{zone\_id}/settings/zaraz/default

#### ZarazExport

##### [Export Zaraz configuration](https://developers.cloudflare.com/api/resources/zaraz/subresources/export/methods/get)

GET/zones/{zone\_id}/settings/zaraz/export

#### ZarazHistory

##### [List Zaraz historical configuration records](https://developers.cloudflare.com/api/resources/zaraz/subresources/history/methods/list)

GET/zones/{zone\_id}/settings/zaraz/history

##### [Restore Zaraz historical configuration by ID](https://developers.cloudflare.com/api/resources/zaraz/subresources/history/methods/update)

PUT/zones/{zone\_id}/settings/zaraz/history

#### ZarazHistoryConfigs

##### [Get Zaraz historical configurations by ID(s)](https://developers.cloudflare.com/api/resources/zaraz/subresources/history/subresources/configs/methods/get)

GET/zones/{zone\_id}/settings/zaraz/history/configs

#### ZarazPublish

##### [Publish Zaraz preview configuration](https://developers.cloudflare.com/api/resources/zaraz/subresources/publish/methods/create)

POST/zones/{zone\_id}/settings/zaraz/publish

#### ZarazWorkflow

##### [Get Zaraz workflow](https://developers.cloudflare.com/api/resources/zaraz/subresources/workflow/methods/get)

GET/zones/{zone\_id}/settings/zaraz/workflow

#### Speed

#### SpeedSchedule

##### [Get a page test schedule](https://developers.cloudflare.com/api/resources/speed/subresources/schedule/methods/get)

GET/zones/{zone\_id}/speed\_api/schedule/{url}

##### [Create scheduled page test](https://developers.cloudflare.com/api/resources/speed/subresources/schedule/methods/create)

POST/zones/{zone\_id}/speed\_api/schedule/{url}

##### [Delete scheduled page test](https://developers.cloudflare.com/api/resources/speed/subresources/schedule/methods/delete)

DELETE/zones/{zone\_id}/speed\_api/schedule/{url}

#### SpeedAvailabilities

##### [Get quota and availability](https://developers.cloudflare.com/api/resources/speed/subresources/availabilities/methods/list)

GET/zones/{zone\_id}/speed\_api/availabilities

#### SpeedPages

##### [List tested webpages](https://developers.cloudflare.com/api/resources/speed/subresources/pages/methods/list)

GET/zones/{zone\_id}/speed\_api/pages

##### [List core web vital metrics trend](https://developers.cloudflare.com/api/resources/speed/subresources/pages/methods/trend)

GET/zones/{zone\_id}/speed\_api/pages/{url}/trend

#### SpeedPagesTests

##### [List page test history](https://developers.cloudflare.com/api/resources/speed/subresources/pages/subresources/tests/methods/list)

GET/zones/{zone\_id}/speed\_api/pages/{url}/tests

##### [Get a page test result](https://developers.cloudflare.com/api/resources/speed/subresources/pages/subresources/tests/methods/get)

GET/zones/{zone\_id}/speed\_api/pages/{url}/tests/{test\_id}

##### [Start page test](https://developers.cloudflare.com/api/resources/speed/subresources/pages/subresources/tests/methods/create)

POST/zones/{zone\_id}/speed\_api/pages/{url}/tests

##### [Delete all page tests](https://developers.cloudflare.com/api/resources/speed/subresources/pages/subresources/tests/methods/delete)

DELETE/zones/{zone\_id}/speed\_api/pages/{url}/tests

#### DCV Delegation

##### [Retrieve the DCV Delegation unique identifier.](https://developers.cloudflare.com/api/resources/dcv_delegation/methods/get)

GET/zones/{zone\_id}/dcv\_delegation/uuid

#### Hostnames

#### HostnamesSettings

#### HostnamesSettingsTLS

##### [List TLS setting for hostnames](https://developers.cloudflare.com/api/resources/hostnames/subresources/settings/subresources/tls/methods/list)

GET/zones/{zone\_id}/hostnames/settings/{setting\_id}

##### [Get TLS setting for hostname](https://developers.cloudflare.com/api/resources/hostnames/subresources/settings/subresources/tls/methods/get)

GET/zones/{zone\_id}/hostnames/settings/{setting\_id}/{hostname}

##### [Edit TLS setting for hostname](https://developers.cloudflare.com/api/resources/hostnames/subresources/settings/subresources/tls/methods/update)

PUT/zones/{zone\_id}/hostnames/settings/{setting\_id}/{hostname}

##### [Delete TLS setting for hostname](https://developers.cloudflare.com/api/resources/hostnames/subresources/settings/subresources/tls/methods/delete)

DELETE/zones/{zone\_id}/hostnames/settings/{setting\_id}/{hostname}

#### Snippets

##### [List zone snippets](https://developers.cloudflare.com/api/resources/snippets/methods/list)

GET/zones/{zone\_id}/snippets

##### [Get a zone snippet](https://developers.cloudflare.com/api/resources/snippets/methods/get)

GET/zones/{zone\_id}/snippets/{snippet\_name}

##### [Update a zone snippet](https://developers.cloudflare.com/api/resources/snippets/methods/update)

PUT/zones/{zone\_id}/snippets/{snippet\_name}

##### [Delete a zone snippet](https://developers.cloudflare.com/api/resources/snippets/methods/delete)

DELETE/zones/{zone\_id}/snippets/{snippet\_name}

#### SnippetsContent

##### [Get a zone snippet content](https://developers.cloudflare.com/api/resources/snippets/subresources/content/methods/get)

GET/zones/{zone\_id}/snippets/{snippet\_name}/content

#### SnippetsRules

##### [List zone snippet rules](https://developers.cloudflare.com/api/resources/snippets/subresources/rules/methods/get)

GET/zones/{zone\_id}/snippets/snippet\_rules

##### [List zone snippet rules](https://developers.cloudflare.com/api/resources/snippets/subresources/rules/methods/list)

GET/zones/{zone\_id}/snippets/snippet\_rules

##### [Update zone snippet rules](https://developers.cloudflare.com/api/resources/snippets/subresources/rules/methods/update)

PUT/zones/{zone\_id}/snippets/snippet\_rules

##### [Delete zone snippet rules](https://developers.cloudflare.com/api/resources/snippets/subresources/rules/methods/delete)

DELETE/zones/{zone\_id}/snippets/snippet\_rules

#### Realtime Kit

#### Realtime KitApps

##### [Fetch all apps](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/apps/methods/get)

GET/accounts/{account\_id}/realtime/kit/apps

##### [Create App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/apps/methods/post)

POST/accounts/{account\_id}/realtime/kit/apps

#### Realtime KitMeetings

##### [Fetch all meetings for an App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/get)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/meetings

##### [Create a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/create)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings

##### [Fetch a meeting for an App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/get_meeting_by_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}

##### [Update a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/update_meeting_by_id)

PATCH/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}

##### [Replace a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/replace_meeting_by_id)

PUT/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}

##### [Fetch all participants of a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/get_meeting_participants)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/participants

##### [Add a participant](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/add_participant)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/participants

##### [Fetch a participant's detail](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/get_meeting_participant)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/participants/{participant\_id}

##### [Edit a participant's detail](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/edit_participant)

PATCH/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/participants/{participant\_id}

##### [Delete a participant](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/delete_meeting_participant)

DELETE/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/participants/{participant\_id}

##### [Refresh participant's authentication token](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/meetings/methods/refresh_participant_token)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/participants/{participant\_id}/token

#### Realtime KitPresets

##### [Fetch all presets](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/presets/methods/get)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/presets

##### [Create a preset](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/presets/methods/create)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/presets

##### [Fetch details of a preset](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/presets/methods/get_preset_by_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/presets/{preset\_id}

##### [Delete a preset](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/presets/methods/delete)

DELETE/accounts/{account\_id}/realtime/kit/{app\_id}/presets/{preset\_id}

##### [Update a preset](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/presets/methods/update)

PATCH/accounts/{account\_id}/realtime/kit/{app\_id}/presets/{preset\_id}

##### [Replace a preset](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/presets/methods/replace_preset_by_id)

PUT/accounts/{account\_id}/realtime/kit/{app\_id}/presets/{preset\_id}

#### Realtime KitSessions

##### [Fetch all sessions of an App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_sessions)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions

##### [Fetch details of a session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_session_details)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}

##### [Fetch participants list of a session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_session_participants)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}/participants

##### [Fetch details of a participant](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_session_participant_details)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}/participants/{participant\_id}

##### [Fetch all chat messages of a session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_session_chat)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}/chat

##### [Fetch the complete transcript for a session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_session_transcripts)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}/transcript

##### [Fetch summary of transcripts for a session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_session_summary)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}/summary

##### [Generate summary of Transcripts for the session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/generate_summary_of_transcripts)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/{session\_id}/summary

##### [Fetch details of peer](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/sessions/methods/get_participant_data_from_peer_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/sessions/peer-report/{peer\_id}

#### Realtime KitRecordings

##### [Fetch all recordings for an App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/recordings/methods/get_recordings)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/recordings

##### [Start recording a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/recordings/methods/start_recordings)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/recordings

##### [Fetch active recording](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/recordings/methods/get_active_recordings)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/recordings/active-recording/{meeting\_id}

##### [Fetch details of a recording](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/recordings/methods/get_one_recording)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/recordings/{recording\_id}

##### [Pause/Resume/Stop recording](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/recordings/methods/pause_resume_stop_recording)

PUT/accounts/{account\_id}/realtime/kit/{app\_id}/recordings/{recording\_id}

##### [Start recording participant audio tracks](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/recordings/methods/start_track_recording)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/recordings/track

#### Realtime KitWebhooks

##### [Fetch all webhooks details](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/webhooks/methods/get_webhooks)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/webhooks

##### [Add a webhook](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/webhooks/methods/create_webhook)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/webhooks

##### [Fetch details of a webhook](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/webhooks/methods/get_webhook_by_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/webhooks/{webhook\_id}

##### [Replace a webhook](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/webhooks/methods/replace_webhook)

PUT/accounts/{account\_id}/realtime/kit/{app\_id}/webhooks/{webhook\_id}

##### [Edit a webhook](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/webhooks/methods/edit_webhook)

PATCH/accounts/{account\_id}/realtime/kit/{app\_id}/webhooks/{webhook\_id}

##### [Delete a webhook](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/webhooks/methods/delete_webhook)

DELETE/accounts/{account\_id}/realtime/kit/{app\_id}/webhooks/{webhook\_id}

#### Realtime KitActive Session

##### [Fetch details of an active session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/active-session/methods/get_active_session)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/active-session

##### [Kick participants from an active session](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/active-session/methods/kick_participants)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/active-session/kick

##### [Kick all participants](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/active-session/methods/kick_all_participants)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/active-session/kick-all

##### [Create a poll](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/active-session/methods/create_poll)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/active-session/poll

#### Realtime KitLivestreams

##### [Fetch all livestreams](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_all_livestreams)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/livestreams

##### [Stop livestreaming a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/stop_livestreaming_a_meeting)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/active-livestream/stop

##### [Start livestreaming a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/start_livestreaming_a_meeting)

POST/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/livestreams

##### [Fetch complete analytics data for your livestreams](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_livestream_analytics_complete)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/analytics/livestreams/overall

##### [Fetch day-wise analytics data for your livestreams](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_livestream_analytics_daywise)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/analytics/livestreams/daywise

##### [Fetch day-wise session and recording analytics data for an App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_org_analytics)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/analytics/daywise

##### [Fetch active livestreams for a meeting](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_meeting_active_livestreams)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/meetings/{meeting\_id}/active-livestream

##### [Fetch livestream session details using livestream session ID](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_livestream_session_details_for_session_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/livestreams/sessions/{livestream-session-id}

##### [Fetch active livestream session details](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_active_livestreams_for_livestream_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/livestreams/{livestream\_id}/active-livestream-session

##### [Fetch livestream details using livestream ID](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/livestreams/methods/get_livestream_session_for_livestream_id)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/livestreams/{livestream\_id}

#### Realtime KitAnalytics

##### [Fetch day-wise session and recording analytics data for an App](https://developers.cloudflare.com/api/resources/realtime_kit/subresources/analytics/methods/get_org_analytics)

GET/accounts/{account\_id}/realtime/kit/{app\_id}/analytics/daywise

#### Calls

#### CallsSFU

##### [List apps](https://developers.cloudflare.com/api/resources/calls/subresources/sfu/methods/list)

GET/accounts/{account\_id}/calls/apps

##### [Retrieve SFU app details](https://developers.cloudflare.com/api/resources/calls/subresources/sfu/methods/get)

GET/accounts/{account\_id}/calls/apps/{app\_id}

##### [Create an SFU app](https://developers.cloudflare.com/api/resources/calls/subresources/sfu/methods/create)

POST/accounts/{account\_id}/calls/apps

##### [Update SFU app details](https://developers.cloudflare.com/api/resources/calls/subresources/sfu/methods/update)

PUT/accounts/{account\_id}/calls/apps/{app\_id}

##### [Delete an SFU app](https://developers.cloudflare.com/api/resources/calls/subresources/sfu/methods/delete)

DELETE/accounts/{account\_id}/calls/apps/{app\_id}

#### CallsTURN

##### [List TURN keys](https://developers.cloudflare.com/api/resources/calls/subresources/turn/methods/list)

GET/accounts/{account\_id}/calls/turn\_keys

##### [Retrieve TURN key details](https://developers.cloudflare.com/api/resources/calls/subresources/turn/methods/get)

GET/accounts/{account\_id}/calls/turn\_keys/{key\_id}

##### [Create a TURN key](https://developers.cloudflare.com/api/resources/calls/subresources/turn/methods/create)

POST/accounts/{account\_id}/calls/turn\_keys

##### [Update TURN key details](https://developers.cloudflare.com/api/resources/calls/subresources/turn/methods/update)

PUT/accounts/{account\_id}/calls/turn\_keys/{key\_id}

##### [Delete TURN key](https://developers.cloudflare.com/api/resources/calls/subresources/turn/methods/delete)

DELETE/accounts/{account\_id}/calls/turn\_keys/{key\_id}

#### MoQ

#### MoQRelays

##### [List relays](https://developers.cloudflare.com/api/resources/moq/subresources/relays/methods/list)

GET/accounts/{account\_id}/moq/relays

##### [Get a relay](https://developers.cloudflare.com/api/resources/moq/subresources/relays/methods/get)

GET/accounts/{account\_id}/moq/relays/{relay\_id}

##### [Create a relay](https://developers.cloudflare.com/api/resources/moq/subresources/relays/methods/create)

POST/accounts/{account\_id}/moq/relays

##### [Update a relay](https://developers.cloudflare.com/api/resources/moq/subresources/relays/methods/update)

PUT/accounts/{account\_id}/moq/relays/{relay\_id}

##### [Delete a relay](https://developers.cloudflare.com/api/resources/moq/subresources/relays/methods/delete)

DELETE/accounts/{account\_id}/moq/relays/{relay\_id}

#### MoQRelaysTokens

##### [Create a token](https://developers.cloudflare.com/api/resources/moq/subresources/relays/subresources/tokens/methods/create)

POST/accounts/{account\_id}/moq/relays/{relay\_id}/tokens

##### [List tokens](https://developers.cloudflare.com/api/resources/moq/subresources/relays/subresources/tokens/methods/list)

GET/accounts/{account\_id}/moq/relays/{relay\_id}/tokens

##### [Revoke a token](https://developers.cloudflare.com/api/resources/moq/subresources/relays/subresources/tokens/methods/delete)

DELETE/accounts/{account\_id}/moq/relays/{relay\_id}/tokens/{jti}

#### Cloudforce One

#### Cloudforce OneScans

#### Cloudforce OneScansResults

##### [Get the Latest Scan Result](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/scans/subresources/results/methods/get)

GET/accounts/{account\_id}/cloudforce-one/scans/results/{config\_id}

#### Cloudforce OneScansConfig

##### [List Scan Configs](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/scans/subresources/config/methods/list)

GET/accounts/{account\_id}/cloudforce-one/scans/config

##### [Create a new Scan Config](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/scans/subresources/config/methods/create)

POST/accounts/{account\_id}/cloudforce-one/scans/config

##### [Update an existing Scan Config](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/scans/subresources/config/methods/edit)

PATCH/accounts/{account\_id}/cloudforce-one/scans/config/{config\_id}

##### [Delete a Scan Config](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/scans/subresources/config/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/scans/config/{config\_id}

#### Cloudforce OneBinary Storage

##### [Retrieves a file from Binary Storage](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/binary_storage/methods/get)

GET/accounts/{account\_id}/cloudforce-one/binary/{hash}

##### [Posts a file to Binary Storage](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/binary_storage/methods/create)

POST/accounts/{account\_id}/cloudforce-one/binary

#### Cloudforce OneRequests

##### [List Requests](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/list)

POST/accounts/{account\_id}/cloudforce-one/requests

##### [Get a Request](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/get)

GET/accounts/{account\_id}/cloudforce-one/requests/{request\_id}

##### [Create a New Request.](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/create)

POST/accounts/{account\_id}/cloudforce-one/requests/new

##### [Update a Request](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/update)

PUT/accounts/{account\_id}/cloudforce-one/requests/{request\_id}

##### [Delete a Request](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/requests/{request\_id}

##### [Get Request Quota](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/quota)

GET/accounts/{account\_id}/cloudforce-one/requests/quota

##### [Get Request Types](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/types)

GET/accounts/{account\_id}/cloudforce-one/requests/types

##### [Get Request Priority, Status, and TLP constants](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/methods/constants)

GET/accounts/{account\_id}/cloudforce-one/requests/constants

#### Cloudforce OneRequestsMessage

##### [List Request Messages](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/message/methods/get)

POST/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message

##### [Create a New Request Message](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/message/methods/create)

POST/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message/new

##### [Update a Request Message](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/message/methods/update)

PUT/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message/{message\_id}

##### [Delete a Request Message](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/message/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message/{message\_id}

#### Cloudforce OneRequestsPriority

##### [Get a Priority Intelligence Requirement](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/priority/methods/get)

GET/accounts/{account\_id}/cloudforce-one/requests/priority/{priority\_id}

##### [Create a New Priority Intelligence Requirement](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/priority/methods/create)

POST/accounts/{account\_id}/cloudforce-one/requests/priority/new

##### [Update a Priority Intelligence Requirement](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/priority/methods/update)

PUT/accounts/{account\_id}/cloudforce-one/requests/priority/{priority\_id}

##### [Delete a Priority Intelligence Requirement](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/priority/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/requests/priority/{priority\_id}

##### [Get Priority Intelligence Requirement Quota](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/priority/methods/quota)

GET/accounts/{account\_id}/cloudforce-one/requests/priority/quota

#### Cloudforce OneRequestsAssets

##### [Get a Request Asset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/assets/methods/get)

GET/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset/{asset\_id}

##### [List Request Assets](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/assets/methods/create)

POST/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset

##### [Update a Request Asset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/assets/methods/update)

PUT/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset/{asset\_id}

##### [Delete a Request Asset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/requests/subresources/assets/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset/{asset\_id}

#### Cloudforce OneThreat Events

##### [Filter and list events](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events

##### [Reads an event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/methods/get)

Deprecated

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}

##### [Creates a new event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/create

##### [Updates an event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/methods/edit)

PATCH/accounts/{account\_id}/cloudforce-one/events/{event\_id}

##### [Creates bulk events](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/methods/bulk_create)

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk

##### [Creates bulk DOS event with relationships and indicators](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/methods/bulk_create_relationships)

Deprecated

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk/relationships

#### Cloudforce OneThreat EventsAggregate

##### [Aggregate events by single or multiple columns with optional date filtering](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/aggregate/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/aggregate

#### Cloudforce OneThreat EventsGraphql

##### [GraphQL endpoint for event aggregation](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/graphql/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/graphql

#### Cloudforce OneThreat EventsGraph

##### [Query graph neighborhood from R2 Data Catalog](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/graph/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/graph

#### Cloudforce OneThreat EventsQueries

##### [List all saved event queries](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/queries

##### [Create a saved event query](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/queries/create

##### [Read a saved event query](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/get)

GET/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### [Update a saved event query](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/edit)

PATCH/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### [Delete a saved event query](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

#### Cloudforce OneThreat EventsRelationships

##### [Filter and list events related to specific event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/relationships/methods/list)

Deprecated

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}/relationships

#### Cloudforce OneThreat EventsIndicators

##### [Lists indicators across multiple datasets](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/indicators/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/indicators

#### Cloudforce OneThreat EventsIndicatorsAggregate

##### [Aggregate indicators by column(s)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/aggregate/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/indicators/aggregate

#### Cloudforce OneThreat EventsIndicatorsTypes

##### [Lists indicator types across multiple datasets](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/types/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/indicator-types

#### Cloudforce OneThreat EventsIndicatorsBy Dataset

##### [Lists indicators](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/methods/list)

Deprecated

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators

##### [Reads an indicator](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/methods/get)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators/{indicator\_id}

#### Cloudforce OneThreat EventsIndicatorsBy DatasetTags

##### [List mirrored tags for an indicator dataset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/subresources/tags/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators/tags

#### Cloudforce OneThreat EventsAttackers

##### [Lists attackers across multiple datasets](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/attackers/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/attackers

#### Cloudforce OneThreat EventsCategories

##### [Lists categories across multiple datasets](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/categories

##### [Reads a category](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/get)

Deprecated

GET/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### [Creates a new category](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/categories/create

##### [Updates a category](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/edit)

Deprecated

PATCH/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### [Deletes a category](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/delete)

Deprecated

DELETE/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

#### Cloudforce OneThreat EventsCategoriesCatalog

##### [Lists categories](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/categories/subresources/catalog/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/categories/catalog

#### Cloudforce OneThreat EventsCountries

##### [Retrieves countries information for all countries](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/countries/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/countries

#### Cloudforce OneThreat EventsCrons

#### Cloudforce OneThreat EventsDatasets

##### [Lists all datasets in an account](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/dataset

##### [Reads a dataset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/get)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Creates a dataset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/dataset/create

##### [Updates an existing dataset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/edit)

PATCH/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Delete a dataset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Reads raw data for an event by UUID](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/raw)

Deprecated

GET/accounts/{account\_id}/cloudforce-one/events/raw/{dataset\_id}/{event\_id}

#### Cloudforce OneThreat EventsDatasetsHealth

#### Cloudforce OneThreat EventsDatasetsEvents

##### [Reads an event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/subresources/events/methods/get)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/events/{event\_id}

#### Cloudforce OneThreat EventsRaw

##### [Reads data for a raw event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/raw/methods/get)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}/raw/{raw\_id}

##### [Updates a raw event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/raw/methods/edit)

PATCH/accounts/{account\_id}/cloudforce-one/events/{event\_id}/raw/{raw\_id}

#### Cloudforce OneThreat EventsRelate

##### [Removes an event reference](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/relate/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/events/relate/{event\_id}

#### Cloudforce OneThreat EventsTags

##### [Lists all tags (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/tags

##### [Creates a new tag](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/tags/create

##### [Updates a tag (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/edit)

PATCH/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}

##### [Deletes a tag (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}

#### Cloudforce OneThreat EventsTagsCategories

##### [Lists all tag categories (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/tags/categories

##### [Creates a new tag category (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/tags/categories/create

##### [Updates a tag category (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/edit)

Deprecated

PATCH/accounts/{account\_id}/cloudforce-one/events/tags/categories/{category\_uuid}

##### [Deletes a tag category (SoT)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/delete)

Deprecated

DELETE/accounts/{account\_id}/cloudforce-one/events/tags/categories/{category\_uuid}

#### Cloudforce OneThreat EventsTagsIndicators

##### [List indicators related to a tag](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/indicators/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}/indicators

#### Cloudforce OneThreat EventsTagsIndicatorsBy Dataset

##### [List indicators related to a tag within a dataset (deprecated)](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/indicators/subresources/by_dataset/methods/list)

Deprecated

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/tags/{tag\_uuid}/indicators

#### Cloudforce OneThreat EventsEvent Tags

##### [Adds a tag to an event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/event_tags/methods/create)

POST/accounts/{account\_id}/cloudforce-one/events/event\_tag/{event\_id}/create

##### [Removes a tag from an event](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/event_tags/methods/delete)

DELETE/accounts/{account\_id}/cloudforce-one/events/event\_tag/{event\_id}

#### Cloudforce OneThreat EventsTarget Industries

##### [Lists target industries across multiple datasets](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/targetIndustries

#### Cloudforce OneThreat EventsTarget IndustriesBy Dataset

##### [Lists all target industries for a specific dataset](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/subresources/by_dataset/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/targetIndustries

#### Cloudforce OneThreat EventsTarget IndustriesCatalog

##### [Lists all target industries from industry map catalog](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/subresources/catalog/methods/list)

GET/accounts/{account\_id}/cloudforce-one/events/targetIndustries/catalog

#### Cloudforce OneThreat EventsInsights

#### AI Gateway

##### [List Gateways](https://developers.cloudflare.com/api/resources/ai_gateway/methods/list)

GET/accounts/{account\_id}/ai-gateway/gateways

##### [Fetch a Gateway](https://developers.cloudflare.com/api/resources/ai_gateway/methods/get)

GET/accounts/{account\_id}/ai-gateway/gateways/{id}

##### [Create a new Gateway](https://developers.cloudflare.com/api/resources/ai_gateway/methods/create)

POST/accounts/{account\_id}/ai-gateway/gateways

##### [Update a Gateway](https://developers.cloudflare.com/api/resources/ai_gateway/methods/update)

PUT/accounts/{account\_id}/ai-gateway/gateways/{id}

##### [Delete a Gateway](https://developers.cloudflare.com/api/resources/ai_gateway/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/gateways/{id}

#### AI GatewayEvaluation Types

##### [List Evaluators](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/evaluation_types/methods/list)

GET/accounts/{account\_id}/ai-gateway/evaluation-types

#### AI GatewayCustom Providers

##### [List Account Providers](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/custom_providers/methods/list)

GET/accounts/{account\_id}/ai-gateway/custom-providers

##### [Fetch a Account Provider](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/custom_providers/methods/get)

GET/accounts/{account\_id}/ai-gateway/custom-providers/{id}

##### [Create a new Account Provider](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/custom_providers/methods/create)

POST/accounts/{account\_id}/ai-gateway/custom-providers

##### [Delete a Account Provider](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/custom_providers/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/custom-providers/{id}

#### AI GatewayLogs

##### [List Gateway Logs](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/logs/methods/list)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/logs

##### [Get Gateway Log Detail](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/logs/methods/get)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/logs/{id}

##### [Patch Gateway Log](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/logs/methods/edit)

PATCH/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/logs/{id}

##### [Delete Gateway Logs](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/logs/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/logs

##### [Get Gateway Log Request](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/logs/methods/request)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/logs/{id}/request

##### [Get Gateway Log Response](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/logs/methods/response)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/logs/{id}/response

#### AI GatewayDatasets

##### [List Datasets](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/datasets/methods/list)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/datasets

##### [Fetch a Dataset](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/datasets/methods/get)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/datasets/{id}

##### [Create a new Dataset](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/datasets/methods/create)

POST/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/datasets

##### [Update a Dataset](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/datasets/methods/update)

PUT/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/datasets/{id}

##### [Delete a Dataset](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/datasets/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/datasets/{id}

#### AI GatewayEvaluations

##### [List Evaluations](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/evaluations/methods/list)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/evaluations

##### [Fetch a Evaluation](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/evaluations/methods/get)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/evaluations/{id}

##### [Create a new Evaluation](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/evaluations/methods/create)

POST/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/evaluations

##### [Delete a Evaluation](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/evaluations/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/evaluations/{id}

#### AI GatewayDynamic Routing

##### [List all AI Gateway Dynamic Routes.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/list)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes

##### [Get an AI Gateway Dynamic Route.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/get)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}

##### [Create a new AI Gateway Dynamic Route.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/create)

POST/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes

##### [Update an AI Gateway Dynamic Route.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/update)

PATCH/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}

##### [Delete an AI Gateway Dynamic Route.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}

##### [List all AI Gateway Dynamic Route Deployments.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/list_deployments)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}/deployments

##### [Create a new AI Gateway Dynamic Route Deployment.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/create_deployment)

POST/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}/deployments

##### [List all AI Gateway Dynamic Route Versions.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/list_versions)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}/versions

##### [Create a new AI Gateway Dynamic Route Version.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/create_version)

POST/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}/versions

##### [Get an AI Gateway Dynamic Route Version.](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/dynamic_routing/methods/get_version)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/routes/{id}/versions/{version\_id}

#### AI GatewayProvider Configs

##### [List Provider Configs](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/provider_configs/methods/list)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/provider\_configs

##### [Create a new Provider Configs](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/provider_configs/methods/create)

POST/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/provider\_configs

#### AI GatewayURLs

##### [Get Gateway URL](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/urls/methods/get)

GET/accounts/{account\_id}/ai-gateway/gateways/{gateway\_id}/url/{provider}

#### AI GatewayBilling

##### [Get credit balance](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/methods/credit_balance)

GET/accounts/{account\_id}/ai-gateway/billing/credit-balance

##### [Get usage history](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/methods/usage_history)

GET/accounts/{account\_id}/ai-gateway/billing/usage-history

##### [Get invoice history](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/methods/invoice_history)

GET/accounts/{account\_id}/ai-gateway/billing/invoice-history

##### [Get invoice preview](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/methods/invoice_preview)

GET/accounts/{account\_id}/ai-gateway/billing/invoice-preview

#### AI GatewayBillingTopup

##### [Create a top-up](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/topup/methods/create)

POST/accounts/{account\_id}/ai-gateway/billing/topup

##### [Check top-up status](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/topup/methods/status)

POST/accounts/{account\_id}/ai-gateway/billing/topup/status

#### AI GatewayBillingTopupConfig

##### [Get auto top-up configuration](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/topup/subresources/config/methods/get)

GET/accounts/{account\_id}/ai-gateway/billing/topup/config

##### [Set auto top-up configuration](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/topup/subresources/config/methods/create)

POST/accounts/{account\_id}/ai-gateway/billing/topup/config

##### [Delete auto top-up configuration](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/topup/subresources/config/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/billing/topup/config

#### AI GatewayBillingSpending Limit

##### [Get spending limit](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/spending_limit/methods/get)

GET/accounts/{account\_id}/ai-gateway/billing/spending-limit

##### [Set spending limit (deprecated)](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/spending_limit/methods/create)

Deprecated

POST/accounts/{account\_id}/ai-gateway/billing/spending-limit

##### [Delete spending limit](https://developers.cloudflare.com/api/resources/ai_gateway/subresources/billing/subresources/spending_limit/methods/delete)

DELETE/accounts/{account\_id}/ai-gateway/billing/spending-limit

#### Flagship

#### FlagshipApps

##### [List apps](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/methods/list)

GET/accounts/{account\_id}/flagship/apps

##### [Get app](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/methods/get)

GET/accounts/{account\_id}/flagship/apps/{app\_id}

##### [Create app](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/methods/create)

POST/accounts/{account\_id}/flagship/apps

##### [Update app](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/methods/update)

PUT/accounts/{account\_id}/flagship/apps/{app\_id}

##### [Delete app](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/methods/delete)

DELETE/accounts/{account\_id}/flagship/apps/{app\_id}

#### FlagshipAppsFlags

##### [List flags](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/flags/methods/list)

GET/accounts/{account\_id}/flagship/apps/{app\_id}/flags

##### [Get flag](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/flags/methods/get)

GET/accounts/{account\_id}/flagship/apps/{app\_id}/flags/{flag\_key}

##### [Create flag](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/flags/methods/create)

POST/accounts/{account\_id}/flagship/apps/{app\_id}/flags

##### [Update flag](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/flags/methods/update)

PUT/accounts/{account\_id}/flagship/apps/{app\_id}/flags/{flag\_key}

##### [Delete flag](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/flags/methods/delete)

DELETE/accounts/{account\_id}/flagship/apps/{app\_id}/flags/{flag\_key}

#### FlagshipAppsFlagsChangelog

##### [Get flag changelog](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/flags/subresources/changelog/methods/list)

GET/accounts/{account\_id}/flagship/apps/{app\_id}/flags/{flag\_key}/changelog

#### FlagshipAppsEvaluate

##### [Evaluate flag](https://developers.cloudflare.com/api/resources/flagship/subresources/apps/subresources/evaluate/methods/get)

GET/accounts/{account\_id}/flagship/apps/{app\_id}/evaluate

#### IAM

#### IAMPermission Groups

##### [List Account Permission Groups](https://developers.cloudflare.com/api/resources/iam/subresources/permission_groups/methods/list)

GET/accounts/{account\_id}/iam/permission\_groups

##### [Permission Group Details](https://developers.cloudflare.com/api/resources/iam/subresources/permission_groups/methods/get)

GET/accounts/{account\_id}/iam/permission\_groups/{permission\_group\_id}

#### IAMResource Groups

##### [List Resource Groups](https://developers.cloudflare.com/api/resources/iam/subresources/resource_groups/methods/list)

GET/accounts/{account\_id}/iam/resource\_groups

##### [Resource Group Details](https://developers.cloudflare.com/api/resources/iam/subresources/resource_groups/methods/get)

GET/accounts/{account\_id}/iam/resource\_groups/{resource\_group\_id}

##### [Create Resource Group](https://developers.cloudflare.com/api/resources/iam/subresources/resource_groups/methods/create)

POST/accounts/{account\_id}/iam/resource\_groups

##### [Update Resource Group](https://developers.cloudflare.com/api/resources/iam/subresources/resource_groups/methods/update)

PUT/accounts/{account\_id}/iam/resource\_groups/{resource\_group\_id}

##### [Remove Resource Group](https://developers.cloudflare.com/api/resources/iam/subresources/resource_groups/methods/delete)

DELETE/accounts/{account\_id}/iam/resource\_groups/{resource\_group\_id}

#### IAMUser Groups

##### [List User Groups](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/methods/list)

GET/accounts/{account\_id}/iam/user\_groups

##### [User Group Details](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/methods/get)

GET/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}

##### [Create User Group](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/methods/create)

POST/accounts/{account\_id}/iam/user\_groups

##### [Update User Group](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/methods/update)

PUT/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}

##### [Remove User Group](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/methods/delete)

DELETE/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}

#### IAMUser GroupsMembers

##### [List User Group Members](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/subresources/members/methods/list)

GET/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}/members

##### [Get User Group Member](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/subresources/members/methods/get)

GET/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}/members/{member\_id}

##### [Add User Group Members](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/subresources/members/methods/create)

POST/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}/members

##### [Update User Group Members](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/subresources/members/methods/update)

PUT/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}/members

##### [Remove User Group Member](https://developers.cloudflare.com/api/resources/iam/subresources/user_groups/subresources/members/methods/delete)

DELETE/accounts/{account\_id}/iam/user\_groups/{user\_group\_id}/members/{member\_id}

#### IAMSSO

##### [Get all SSO connectors](https://developers.cloudflare.com/api/resources/iam/subresources/sso/methods/list)

GET/accounts/{account\_id}/sso\_connectors

##### [Get single SSO connector](https://developers.cloudflare.com/api/resources/iam/subresources/sso/methods/get)

GET/accounts/{account\_id}/sso\_connectors/{sso\_connector\_id}

##### [Initialize new SSO connector](https://developers.cloudflare.com/api/resources/iam/subresources/sso/methods/create)

POST/accounts/{account\_id}/sso\_connectors

##### [Update SSO connector state](https://developers.cloudflare.com/api/resources/iam/subresources/sso/methods/update)

PATCH/accounts/{account\_id}/sso\_connectors/{sso\_connector\_id}

##### [Delete SSO connector](https://developers.cloudflare.com/api/resources/iam/subresources/sso/methods/delete)

DELETE/accounts/{account\_id}/sso\_connectors/{sso\_connector\_id}

##### [Begin SSO connector verification](https://developers.cloudflare.com/api/resources/iam/subresources/sso/methods/begin_verification)

POST/accounts/{account\_id}/sso\_connectors/{sso\_connector\_id}/begin\_verification

#### IAMOAuth Clients

##### [List OAuth Clients](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/list)

GET/accounts/{account\_id}/oauth\_clients

##### [OAuth Client Details](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/get)

GET/accounts/{account\_id}/oauth\_clients/{oauth\_client\_id}

##### [Create OAuth Client](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/create)

POST/accounts/{account\_id}/oauth\_clients

##### [Update OAuth Client](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/update)

PATCH/accounts/{account\_id}/oauth\_clients/{oauth\_client\_id}

##### [Delete OAuth Client](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/delete)

DELETE/accounts/{account\_id}/oauth\_clients/{oauth\_client\_id}

##### [Rotate OAuth Client Secret](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/rotate_secret)

POST/accounts/{account\_id}/oauth\_clients/{oauth\_client\_id}/rotate\_secret

##### [Delete Rotated OAuth Client Secret](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_clients/methods/delete_rotated_secret)

DELETE/accounts/{account\_id}/oauth\_clients/{oauth\_client\_id}/rotate\_secret

#### IAMOAuth Scopes

##### [List OAuth Scopes](https://developers.cloudflare.com/api/resources/iam/subresources/oauth_scopes/methods/list)

GET/oauth/scopes

#### Cloud Connector

#### Cloud ConnectorRules

##### [Rules](https://developers.cloudflare.com/api/resources/cloud_connector/subresources/rules/methods/list)

GET/zones/{zone\_id}/cloud\_connector/rules

##### [Put Rules](https://developers.cloudflare.com/api/resources/cloud_connector/subresources/rules/methods/update)

PUT/zones/{zone\_id}/cloud\_connector/rules

#### Botnet Feed

#### Botnet FeedASN

##### [Get daily report](https://developers.cloudflare.com/api/resources/botnet_feed/subresources/asn/methods/day_report)

GET/accounts/{account\_id}/botnet\_feed/asn/{asn\_id}/day\_report

##### [Get full report](https://developers.cloudflare.com/api/resources/botnet_feed/subresources/asn/methods/full_report)

GET/accounts/{account\_id}/botnet\_feed/asn/{asn\_id}/full\_report

#### Botnet FeedConfigs

#### Botnet FeedConfigsASN

##### [Get list of ASNs](https://developers.cloudflare.com/api/resources/botnet_feed/subresources/configs/subresources/asn/methods/get)

GET/accounts/{account\_id}/botnet\_feed/configs/asn

##### [Delete an ASN](https://developers.cloudflare.com/api/resources/botnet_feed/subresources/configs/subresources/asn/methods/delete)

DELETE/accounts/{account\_id}/botnet\_feed/configs/asn/{asn\_id}

#### Security TXT

##### [Retrieves security.txt](https://developers.cloudflare.com/api/resources/security_txt/methods/get)

GET/zones/{zone\_id}/security-center/securitytxt

##### [Updates security.txt](https://developers.cloudflare.com/api/resources/security_txt/methods/update)

PUT/zones/{zone\_id}/security-center/securitytxt

##### [Deletes security.txt](https://developers.cloudflare.com/api/resources/security_txt/methods/delete)

DELETE/zones/{zone\_id}/security-center/securitytxt

#### Workflows

##### [List all Workflows](https://developers.cloudflare.com/api/resources/workflows/methods/list)

GET/accounts/{account\_id}/workflows

##### [Get Workflow details](https://developers.cloudflare.com/api/resources/workflows/methods/get)

GET/accounts/{account\_id}/workflows/{workflow\_name}

##### [Create/modify Workflow](https://developers.cloudflare.com/api/resources/workflows/methods/update)

PUT/accounts/{account\_id}/workflows/{workflow\_name}

##### [Deletes a Workflow](https://developers.cloudflare.com/api/resources/workflows/methods/delete)

DELETE/accounts/{account\_id}/workflows/{workflow\_name}

#### WorkflowsInstances

##### [List of workflow instances](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/methods/list)

GET/accounts/{account\_id}/workflows/{workflow\_name}/instances

##### [Get logs and status from instance](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/methods/get)

GET/accounts/{account\_id}/workflows/{workflow\_name}/instances/{instance\_id}

##### [Create a new workflow instance](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/methods/create)

POST/accounts/{account\_id}/workflows/{workflow\_name}/instances

##### [Batch create new Workflow instances](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/methods/bulk)

POST/accounts/{account\_id}/workflows/{workflow\_name}/instances/batch

##### [Get full step output from instance](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/methods/step)

GET/accounts/{account\_id}/workflows/{workflow\_name}/instances/{instance\_id}/step

#### WorkflowsInstancesStatus

##### [Change status of instance](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/subresources/status/methods/edit)

PATCH/accounts/{account\_id}/workflows/{workflow\_name}/instances/{instance\_id}/status

#### WorkflowsInstancesEvents

##### [Send event to instance](https://developers.cloudflare.com/api/resources/workflows/subresources/instances/subresources/events/methods/create)

POST/accounts/{account\_id}/workflows/{workflow\_name}/instances/{instance\_id}/events/{event\_type}

#### WorkflowsVersions

##### [List deployed Workflow versions](https://developers.cloudflare.com/api/resources/workflows/subresources/versions/methods/list)

GET/accounts/{account\_id}/workflows/{workflow\_name}/versions

##### [Get Workflow version details](https://developers.cloudflare.com/api/resources/workflows/subresources/versions/methods/get)

GET/accounts/{account\_id}/workflows/{workflow\_name}/versions/{version\_id}

##### [Get Workflow version graph](https://developers.cloudflare.com/api/resources/workflows/subresources/versions/methods/graph)

GET/accounts/{account\_id}/workflows/{workflow\_name}/versions/{version\_id}/graph

#### Workers Builds

##### [Get latest builds by script IDs](https://developers.cloudflare.com/api/resources/workers_builds/methods/get_latest_builds)

GET/accounts/{account\_id}/builds/builds/latest

##### [Get builds by Worker version](https://developers.cloudflare.com/api/resources/workers_builds/methods/get_builds_by_version)

GET/accounts/{account\_id}/builds/builds

##### [Get build-minute availability](https://developers.cloudflare.com/api/resources/workers_builds/methods/get_account_limits)

GET/accounts/{account\_id}/builds/account/limits

#### Workers BuildsTriggers

##### [List triggers for a Worker](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/methods/list)

GET/accounts/{account\_id}/builds/workers/{external\_script\_id}/triggers

##### [Create a build trigger](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/methods/create)

POST/accounts/{account\_id}/builds/triggers

##### [Update a build trigger](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/methods/update)

PATCH/accounts/{account\_id}/builds/triggers/{trigger\_uuid}

##### [Delete a build trigger](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/methods/delete)

DELETE/accounts/{account\_id}/builds/triggers/{trigger\_uuid}

##### [Purge a trigger's build cache](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/methods/purge_cache)

POST/accounts/{account\_id}/builds/triggers/{trigger\_uuid}/purge\_build\_cache

##### [Start a Workers build](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/methods/create_build)

POST/accounts/{account\_id}/builds/triggers/{trigger\_uuid}/builds

#### Workers BuildsTriggersEnvironment Variables

##### [List build variables](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/subresources/environment_variables/methods/list)

GET/accounts/{account\_id}/builds/triggers/{trigger\_uuid}/environment\_variables

##### [Set build variables](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/subresources/environment_variables/methods/upsert)

PATCH/accounts/{account\_id}/builds/triggers/{trigger\_uuid}/environment\_variables

##### [Delete a build variable](https://developers.cloudflare.com/api/resources/workers_builds/subresources/triggers/subresources/environment_variables/methods/delete)

DELETE/accounts/{account\_id}/builds/triggers/{trigger\_uuid}/environment\_variables/{environment\_variable\_key}

#### Workers BuildsDeploy Hooks

##### [List deploy hooks](https://developers.cloudflare.com/api/resources/workers_builds/subresources/deploy_hooks/methods/list)

GET/accounts/{account\_id}/builds/workers/{script\_name}/deploy\_hooks

##### [Create a deploy hook](https://developers.cloudflare.com/api/resources/workers_builds/subresources/deploy_hooks/methods/create)

POST/accounts/{account\_id}/builds/workers/{script\_name}/deploy\_hooks

##### [Get a deploy hook](https://developers.cloudflare.com/api/resources/workers_builds/subresources/deploy_hooks/methods/get)

GET/accounts/{account\_id}/builds/workers/{script\_name}/deploy\_hooks/{deploy\_hook\_uuid}

##### [Update a deploy hook](https://developers.cloudflare.com/api/resources/workers_builds/subresources/deploy_hooks/methods/update)

PUT/accounts/{account\_id}/builds/workers/{script\_name}/deploy\_hooks/{deploy\_hook\_uuid}

##### [Delete a deploy hook](https://developers.cloudflare.com/api/resources/workers_builds/subresources/deploy_hooks/methods/delete)

DELETE/accounts/{account\_id}/builds/workers/{script\_name}/deploy\_hooks/{deploy\_hook\_uuid}

##### [Trigger deploy hook](https://developers.cloudflare.com/api/resources/workers_builds/subresources/deploy_hooks/methods/trigger)

POST/workers/builds/deploy\_hooks/{deploy\_hook\_uuid}

#### Workers BuildsTokens

##### [Create build token](https://developers.cloudflare.com/api/resources/workers_builds/subresources/tokens/methods/create)

POST/accounts/{account\_id}/builds/tokens

##### [List build tokens](https://developers.cloudflare.com/api/resources/workers_builds/subresources/tokens/methods/list)

GET/accounts/{account\_id}/builds/tokens

##### [Delete a build token](https://developers.cloudflare.com/api/resources/workers_builds/subresources/tokens/methods/delete)

DELETE/accounts/{account\_id}/builds/tokens/{build\_token\_uuid}

#### Workers BuildsRepos

#### Workers BuildsReposConnections

##### [Create or update a repository connection](https://developers.cloudflare.com/api/resources/workers_builds/subresources/repos/subresources/connections/methods/upsert)

PUT/accounts/{account\_id}/builds/repos/connections

##### [Delete a repository connection](https://developers.cloudflare.com/api/resources/workers_builds/subresources/repos/subresources/connections/methods/delete)

DELETE/accounts/{account\_id}/builds/repos/connections/{repo\_connection\_uuid}

#### Workers BuildsReposConfig Autofill

##### [Get repository configuration autofill](https://developers.cloudflare.com/api/resources/workers_builds/subresources/repos/subresources/config_autofill/methods/get)

GET/accounts/{account\_id}/builds/repos/{provider\_type}/{provider\_account\_id}/{repo\_id}/config\_autofill

#### Workers BuildsBuilds

##### [List builds for a Worker](https://developers.cloudflare.com/api/resources/workers_builds/subresources/builds/methods/list)

GET/accounts/{account\_id}/builds/workers/{external\_script\_id}/builds

##### [Get a Workers build](https://developers.cloudflare.com/api/resources/workers_builds/subresources/builds/methods/get)

GET/accounts/{account\_id}/builds/builds/{build\_uuid}

##### [Cancel a Workers build](https://developers.cloudflare.com/api/resources/workers_builds/subresources/builds/methods/cancel)

PUT/accounts/{account\_id}/builds/builds/{build\_uuid}/cancel

#### Workers BuildsBuildsLogs

##### [Get Workers build logs](https://developers.cloudflare.com/api/resources/workers_builds/subresources/builds/subresources/logs/methods/get)

GET/accounts/{account\_id}/builds/builds/{build\_uuid}/logs

#### Resource Sharing

##### [List account shares](https://developers.cloudflare.com/api/resources/resource_sharing/methods/list)

GET/accounts/{account\_id}/shares

##### [Get account share by ID](https://developers.cloudflare.com/api/resources/resource_sharing/methods/get)

GET/accounts/{account\_id}/shares/{share\_id}

##### [Create a new share](https://developers.cloudflare.com/api/resources/resource_sharing/methods/create)

POST/accounts/{account\_id}/shares

##### [Update a share](https://developers.cloudflare.com/api/resources/resource_sharing/methods/update)

PUT/accounts/{account\_id}/shares/{share\_id}

##### [Delete a share](https://developers.cloudflare.com/api/resources/resource_sharing/methods/delete)

DELETE/accounts/{account\_id}/shares/{share\_id}

#### Resource SharingRecipients

##### [List share recipients by share ID](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/recipients/methods/list)

GET/accounts/{account\_id}/shares/{share\_id}/recipients

##### [Get share recipient by ID](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/recipients/methods/get)

GET/accounts/{account\_id}/shares/{share\_id}/recipients/{recipient\_id}

##### [Create a new share recipient](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/recipients/methods/create)

POST/accounts/{account\_id}/shares/{share\_id}/recipients

##### [Delete a share recipient](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/recipients/methods/delete)

DELETE/accounts/{account\_id}/shares/{share\_id}/recipients/{recipient\_id}

#### Resource SharingResources

##### [List share resources by share ID](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/resources/methods/list)

GET/accounts/{account\_id}/shares/{share\_id}/resources

##### [Get share resource by ID](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/resources/methods/get)

GET/accounts/{account\_id}/shares/{share\_id}/resources/{share\_resource\_id}

##### [Create a new share resource](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/resources/methods/create)

POST/accounts/{account\_id}/shares/{share\_id}/resources

##### [Update a share resource](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/resources/methods/update)

PUT/accounts/{account\_id}/shares/{share\_id}/resources/{share\_resource\_id}

##### [Delete a share resource](https://developers.cloudflare.com/api/resources/resource_sharing/subresources/resources/methods/delete)

DELETE/accounts/{account\_id}/shares/{share\_id}/resources/{share\_resource\_id}

#### Resource Tagging

##### [List tagged resources](https://developers.cloudflare.com/api/resources/resource_tagging/methods/list)

GET/accounts/{account\_id}/tags/resources

#### Resource TaggingAccount Tags

##### [Get tags for an account-level resource](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/account_tags/methods/get)

GET/accounts/{account\_id}/tags

##### [Set tags for an account-level resource](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/account_tags/methods/update)

PUT/accounts/{account\_id}/tags

##### [Delete tags from an account-level resource](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/account_tags/methods/delete)

DELETE/accounts/{account\_id}/tags

#### Resource TaggingZone Tags

##### [Get tags for a zone-level resource](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/zone_tags/methods/get)

GET/zones/{zone\_id}/tags

##### [Set tags for a zone-level resource](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/zone_tags/methods/update)

PUT/zones/{zone\_id}/tags

##### [Delete tags from a zone-level resource](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/zone_tags/methods/delete)

DELETE/zones/{zone\_id}/tags

#### Resource TaggingKeys

##### [List tag keys](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/keys/methods/list)

GET/accounts/{account\_id}/tags/keys

#### Resource TaggingValues

##### [List tag values](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/values/methods/list)

GET/accounts/{account\_id}/tags/values/{tag\_key}

#### Resource TaggingSummary

##### [List tag key summary](https://developers.cloudflare.com/api/resources/resource_tagging/subresources/summary/methods/get)

GET/accounts/{account\_id}/tags/summary

#### Leaked Credential Checks

##### [Get the Leaked Credential Checks status for a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/methods/get)

GET/zones/{zone\_id}/leaked-credential-checks

##### [Update the Leaked Credential Checks status for a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/methods/create)

POST/zones/{zone\_id}/leaked-credential-checks

#### Leaked Credential ChecksDetections

##### [List the custom detection locations of a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/subresources/detections/methods/list)

GET/zones/{zone\_id}/leaked-credential-checks/detections

##### [Create a custom detection location for a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/subresources/detections/methods/create)

POST/zones/{zone\_id}/leaked-credential-checks/detections

##### [Get a custom detection location of a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/subresources/detections/methods/get)

GET/zones/{zone\_id}/leaked-credential-checks/detections/{detection\_id}

##### [Update a custom detection location of a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/subresources/detections/methods/update)

PUT/zones/{zone\_id}/leaked-credential-checks/detections/{detection\_id}

##### [Delete a custom detection location from a zone.](https://developers.cloudflare.com/api/resources/leaked_credential_checks/subresources/detections/methods/delete)

DELETE/zones/{zone\_id}/leaked-credential-checks/detections/{detection\_id}

#### Content Scanning

##### [Enable Content Scanning for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/methods/enable)

POST/zones/{zone\_id}/content-upload-scan/enable

##### [Disable Content Scanning for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/methods/disable)

POST/zones/{zone\_id}/content-upload-scan/disable

##### [Update the Content Scanning status for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/methods/create)

PUT/zones/{zone\_id}/content-upload-scan/settings

##### [Update the Content Scanning status for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/methods/update)

PUT/zones/{zone\_id}/content-upload-scan/settings

##### [Get the Content Scanning status for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/methods/get)

GET/zones/{zone\_id}/content-upload-scan/settings

#### Content ScanningPayloads

##### [List the Content Scanning custom expressions of a zone.](https://developers.cloudflare.com/api/resources/content_scanning/subresources/payloads/methods/list)

GET/zones/{zone\_id}/content-upload-scan/payloads

##### [Create Content Scanning custom expressions for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/subresources/payloads/methods/create)

POST/zones/{zone\_id}/content-upload-scan/payloads

##### [Delete a Content Scanning custom expression from a zone.](https://developers.cloudflare.com/api/resources/content_scanning/subresources/payloads/methods/delete)

DELETE/zones/{zone\_id}/content-upload-scan/payloads/{expression\_id}

##### [Update a Content Scanning custom expression for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/subresources/payloads/methods/update)

PATCH/zones/{zone\_id}/content-upload-scan/payloads/{expression\_id}

#### Content ScanningSettings

##### [Get the Content Scanning status for a zone.](https://developers.cloudflare.com/api/resources/content_scanning/subresources/settings/methods/get)

GET/zones/{zone\_id}/content-upload-scan/settings

#### AI Security

##### [Get the AI Security for Apps status for a zone.](https://developers.cloudflare.com/api/resources/ai_security/methods/get)

GET/zones/{zone\_id}/ai-security/settings

##### [Update the AI Security for Apps status for a zone.](https://developers.cloudflare.com/api/resources/ai_security/methods/update)

PUT/zones/{zone\_id}/ai-security/settings

#### AI SecurityCustom Topics

##### [Get the AI Security for Apps custom topics of a zone.](https://developers.cloudflare.com/api/resources/ai_security/subresources/custom_topics/methods/get)

GET/zones/{zone\_id}/ai-security/custom-topics

##### [Update the AI Security for Apps custom topics of a zone.](https://developers.cloudflare.com/api/resources/ai_security/subresources/custom_topics/methods/update)

PUT/zones/{zone\_id}/ai-security/custom-topics

#### Csam Scanner

##### [Get CSAM Scanner setting](https://developers.cloudflare.com/api/resources/csam_scanner/methods/get)

GET/zones/{zone\_id}/settings/csam\_scanner\_third\_party

##### [Update CSAM Scanner setting](https://developers.cloudflare.com/api/resources/csam_scanner/methods/edit)

PATCH/zones/{zone\_id}/settings/csam\_scanner\_third\_party

#### Abuse Reports

##### [Submit an abuse report](https://developers.cloudflare.com/api/resources/abuse_reports/methods/create)

POST/accounts/{account\_id}/abuse-reports/{report\_param}

##### [Abuse Report Details](https://developers.cloudflare.com/api/resources/abuse_reports/methods/get)

GET/accounts/{account\_id}/abuse-reports/{report\_param}

##### [List abuse reports](https://developers.cloudflare.com/api/resources/abuse_reports/methods/list)

GET/accounts/{account\_id}/abuse-reports

#### Abuse ReportsSubmitted

##### [List submitted abuse reports](https://developers.cloudflare.com/api/resources/abuse_reports/subresources/submitted/methods/list)

GET/accounts/{account\_id}/abuse-reports/submitted

##### [Get a submitted abuse report](https://developers.cloudflare.com/api/resources/abuse_reports/subresources/submitted/methods/get)

GET/accounts/{account\_id}/abuse-reports/submitted/{report\_id}

#### Abuse ReportsSubmittedEmails

##### [List emails sent to an abuse report submitter](https://developers.cloudflare.com/api/resources/abuse_reports/subresources/submitted/subresources/emails/methods/list)

GET/accounts/{account\_id}/abuse-reports/submitted/{report\_id}/emails

#### Abuse ReportsMitigations

##### [List abuse report mitigations](https://developers.cloudflare.com/api/resources/abuse_reports/subresources/mitigations/methods/list)

GET/accounts/{account\_id}/abuse-reports/{report\_id}/mitigations

##### [Request review on mitigations](https://developers.cloudflare.com/api/resources/abuse_reports/subresources/mitigations/methods/review)

POST/accounts/{account\_id}/abuse-reports/{report\_id}/mitigations/appeal

#### AI

##### [Execute AI model](https://developers.cloudflare.com/api/resources/ai/methods/run)

POST/accounts/{account\_id}/ai/run/{model\_name}

#### AIFinetunes

##### [List Finetunes](https://developers.cloudflare.com/api/resources/ai/subresources/finetunes/methods/list)

GET/accounts/{account\_id}/ai/finetunes

##### [Create a new Finetune](https://developers.cloudflare.com/api/resources/ai/subresources/finetunes/methods/create)

POST/accounts/{account\_id}/ai/finetunes

#### AIFinetunesAssets

##### [Upload a Finetune Asset](https://developers.cloudflare.com/api/resources/ai/subresources/finetunes/subresources/assets/methods/create)

POST/accounts/{account\_id}/ai/finetunes/{finetune\_id}/finetune-assets

#### AIFinetunesPublic

##### [List Public Finetunes](https://developers.cloudflare.com/api/resources/ai/subresources/finetunes/subresources/public/methods/list)

GET/accounts/{account\_id}/ai/finetunes/public

#### AIAuthors

##### [Author Search](https://developers.cloudflare.com/api/resources/ai/subresources/authors/methods/list)

GET/accounts/{account\_id}/ai/authors/search

#### AITasks

##### [Task Search](https://developers.cloudflare.com/api/resources/ai/subresources/tasks/methods/list)

GET/accounts/{account\_id}/ai/tasks/search

#### AIModels

##### [Model Search](https://developers.cloudflare.com/api/resources/ai/subresources/models/methods/list)

GET/accounts/{account\_id}/ai/models/search

#### AIModelsSchema

##### [Get Model Schema](https://developers.cloudflare.com/api/resources/ai/subresources/models/subresources/schema/methods/get)

GET/accounts/{account\_id}/ai/models/schema

#### AITo Markdown

##### [Convert Files into Markdown](https://developers.cloudflare.com/api/resources/ai/subresources/to_markdown/methods/transform)

POST/accounts/{account\_id}/ai/tomarkdown

##### [Get all converted formats supported](https://developers.cloudflare.com/api/resources/ai/subresources/to_markdown/methods/supported)

GET/accounts/{account\_id}/ai/tomarkdown/supported

#### AI Audit

#### AI AuditRobots

##### [Get robots.txt rules](https://developers.cloudflare.com/api/resources/ai_audit/subresources/robots/methods/get)

GET/zones/{zone\_id}/ai-audit/robots

##### [Bulk get robots.txt rules](https://developers.cloudflare.com/api/resources/ai_audit/subresources/robots/methods/bulk_get)

POST/zones/{zone\_id}/ai-audit/robots/bulk

#### AI Search

#### AI SearchNamespaces

##### [List namespaces](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/list)

GET/accounts/{account\_id}/ai-search/namespaces

##### [Create a namespace](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/create)

POST/accounts/{account\_id}/ai-search/namespaces

##### [Get a namespace](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/read)

GET/accounts/{account\_id}/ai-search/namespaces/{name}

##### [Update a namespace](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/update)

PUT/accounts/{account\_id}/ai-search/namespaces/{name}

##### [Delete a namespace](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/delete)

DELETE/accounts/{account\_id}/ai-search/namespaces/{name}

##### [Multi-Instance Search](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/search)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/search

##### [Multi-Instance Chat Completions](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/methods/chat_completions)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/chat/completions

#### AI SearchNamespacesInstances

##### [List AI Search instances.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/list)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances

##### [Create an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/create)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/instances

##### [Get an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/read)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}

##### [Update an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/update)

PUT/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}

##### [Delete an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/delete)

DELETE/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}

##### [Get instance statistics.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/stats)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/stats

##### [Search](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/search)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/search

##### [Chat Completions](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/methods/chat_completions)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/chat/completions

#### AI SearchNamespacesInstancesJobs

##### [List Jobs](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/jobs/methods/list)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/jobs

##### [Create new job](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/jobs/methods/create)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/jobs

##### [Get a Job Details](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/jobs/methods/get)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/jobs/{job\_id}

##### [Cancel an indexing job.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/jobs/methods/update)

PATCH/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/jobs/{job\_id}

##### [List Job Logs](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/jobs/methods/logs)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/jobs/{job\_id}/logs

#### AI SearchNamespacesInstancesItems

##### [Items List.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/list)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items

##### [Upload Item.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/upload)

POST/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items

##### [Create or Update Item.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/create_or_update)

PUT/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items

##### [Get Item.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/get)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items/{item\_id}

##### [Sync Item.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/sync)

PATCH/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items/{item\_id}

##### [Delete Item.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/delete)

DELETE/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items/{item\_id}

##### [Download Item Content.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/download)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items/{item\_id}/download

##### [Item Logs.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/logs)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items/{item\_id}/logs

##### [List Item Chunks.](https://developers.cloudflare.com/api/resources/ai_search/subresources/namespaces/subresources/instances/subresources/items/methods/chunks)

GET/accounts/{account\_id}/ai-search/namespaces/{name}/instances/{id}/items/{item\_id}/chunks

#### AI SearchInstances

##### [List AI Search instances.](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/list)

Deprecated

GET/accounts/{account\_id}/ai-search/instances

##### [Create an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/create)

Deprecated

POST/accounts/{account\_id}/ai-search/instances

##### [Get an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/read)

Deprecated

GET/accounts/{account\_id}/ai-search/instances/{id}

##### [Update an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/update)

Deprecated

PUT/accounts/{account\_id}/ai-search/instances/{id}

##### [Delete an AI Search instance.](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/delete)

Deprecated

DELETE/accounts/{account\_id}/ai-search/instances/{id}

##### [Get instance statistics.](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/stats)

Deprecated

GET/accounts/{account\_id}/ai-search/instances/{id}/stats

##### [Search](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/search)

Deprecated

POST/accounts/{account\_id}/ai-search/instances/{id}/search

##### [Chat Completions](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/methods/chat_completions)

Deprecated

POST/accounts/{account\_id}/ai-search/instances/{id}/chat/completions

#### AI SearchInstancesJobs

##### [List Jobs](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/subresources/jobs/methods/list)

Deprecated

GET/accounts/{account\_id}/ai-search/instances/{id}/jobs

##### [Create new job](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/subresources/jobs/methods/create)

Deprecated

POST/accounts/{account\_id}/ai-search/instances/{id}/jobs

##### [Get a Job Details](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/subresources/jobs/methods/get)

Deprecated

GET/accounts/{account\_id}/ai-search/instances/{id}/jobs/{job\_id}

##### [List Job Logs](https://developers.cloudflare.com/api/resources/ai_search/subresources/instances/subresources/jobs/methods/logs)

Deprecated

GET/accounts/{account\_id}/ai-search/instances/{id}/jobs/{job\_id}/logs

#### AI SearchTokens

##### [List tokens](https://developers.cloudflare.com/api/resources/ai_search/subresources/tokens/methods/list)

GET/accounts/{account\_id}/ai-search/tokens

##### [Create a token](https://developers.cloudflare.com/api/resources/ai_search/subresources/tokens/methods/create)

POST/accounts/{account\_id}/ai-search/tokens

##### [Get a token](https://developers.cloudflare.com/api/resources/ai_search/subresources/tokens/methods/read)

GET/accounts/{account\_id}/ai-search/tokens/{id}

##### [Update a token](https://developers.cloudflare.com/api/resources/ai_search/subresources/tokens/methods/update)

PUT/accounts/{account\_id}/ai-search/tokens/{id}

##### [Delete a token](https://developers.cloudflare.com/api/resources/ai_search/subresources/tokens/methods/delete)

DELETE/accounts/{account\_id}/ai-search/tokens/{id}

#### AutoRAG

##### [AI Search](https://developers.cloudflare.com/api/resources/autorag/methods/ai_search)

Deprecated

POST/accounts/{account\_id}/autorag/rags/{id}/ai-search

##### [Search](https://developers.cloudflare.com/api/resources/autorag/methods/search)

Deprecated

POST/accounts/{account\_id}/autorag/rags/{id}/search

##### [Sync](https://developers.cloudflare.com/api/resources/autorag/methods/sync)

Deprecated

PATCH/accounts/{account\_id}/autorag/rags/{id}/sync

##### [Files](https://developers.cloudflare.com/api/resources/autorag/methods/files)

Deprecated

GET/accounts/{account\_id}/autorag/rags/{id}/files

#### AutoRAGJobs

##### [List Jobs](https://developers.cloudflare.com/api/resources/autorag/subresources/jobs/methods/list)

Deprecated

GET/accounts/{account\_id}/autorag/rags/{id}/jobs

##### [Get a Job Details](https://developers.cloudflare.com/api/resources/autorag/subresources/jobs/methods/get)

Deprecated

GET/accounts/{account\_id}/autorag/rags/{id}/jobs/{job\_id}

##### [List Job Logs](https://developers.cloudflare.com/api/resources/autorag/subresources/jobs/methods/logs)

Deprecated

GET/accounts/{account\_id}/autorag/rags/{id}/jobs/{job\_id}/logs

#### Security Center

#### Security CenterInsights

##### [Retrieves Security Center Insights](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights

##### [Archives Security Center Insight](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/methods/dismiss)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/{issue\_id}/dismiss

#### Security CenterInsightsClass

##### [Retrieves Security Center Insight Counts by Class](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/class/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/class

#### Security CenterInsightsSeverity

##### [Retrieves Security Center Insight Counts by Severity](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/severity/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/severity

#### Security CenterInsightsType

##### [Retrieves Security Center Insight Counts by Type](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/type/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/type

#### Security CenterInsightsAudit Logs

##### [Retrieves account or zone Audit Log](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/audit_logs/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/audit-log

##### [Retrieves Issue Audit Log](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/audit_logs/methods/list_by_insight)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/{issue\_id}/audit-log

#### Security CenterInsightsClassification

##### [Updates Security Center Insight Classification](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/classification/methods/update)

PATCH/{accounts\_or\_zones}/{account\_or\_zone\_id}/security-center/insights/{issue\_id}/classification

#### Security CenterInsightsContext

##### [Retrieves Security Center Insight Context](https://developers.cloudflare.com/api/resources/security_center/subresources/insights/subresources/context/methods/get)

GET/accounts/{account\_id}/security-center/insights/{issue\_id}/context

#### Browser Rendering

#### Browser RenderingContent

##### [Get HTML content.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/content/methods/create)

POST/accounts/{account\_id}/browser-rendering/content

#### Browser RenderingPDF

##### [Get PDF.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/pdf/methods/create)

POST/accounts/{account\_id}/browser-rendering/pdf

#### Browser RenderingScrape

##### [Scrape elements.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/scrape/methods/create)

POST/accounts/{account\_id}/browser-rendering/scrape

#### Browser RenderingScreenshot

##### [Get screenshot.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/screenshot/methods/create)

POST/accounts/{account\_id}/browser-rendering/screenshot

#### Browser RenderingSnapshot

##### [Get HTML content and screenshot.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/snapshot/methods/create)

POST/accounts/{account\_id}/browser-rendering/snapshot

#### Browser RenderingJson

##### [Get json.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/json/methods/create)

POST/accounts/{account\_id}/browser-rendering/json

#### Browser RenderingLinks

##### [Get Links.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/links/methods/create)

POST/accounts/{account\_id}/browser-rendering/links

#### Browser RenderingMarkdown

##### [Get markdown.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/markdown/methods/create)

POST/accounts/{account\_id}/browser-rendering/markdown

#### Browser RenderingAccessibility Tree

##### [Get accessibility tree page](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/accessibility_tree/methods/create)

POST/accounts/{account\_id}/browser-rendering/accessibilityTree

#### Browser RenderingCrawl

##### [Crawl websites.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/crawl/methods/create)

POST/accounts/{account\_id}/browser-rendering/crawl

##### [Get crawl result.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/crawl/methods/get)

GET/accounts/{account\_id}/browser-rendering/crawl/{job\_id}

##### [Cancel a crawl job.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/crawl/methods/delete)

DELETE/accounts/{account\_id}/browser-rendering/crawl/{job\_id}

#### Browser RenderingDevtools

#### Browser RenderingDevtoolsSession

##### [List sessions.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/session/methods/list)

GET/accounts/{account\_id}/browser-rendering/devtools/session

##### [Get session details.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/session/methods/get)

GET/accounts/{account\_id}/browser-rendering/devtools/session/{session\_id}

#### Browser RenderingDevtoolsBrowser

##### [Get a browser session ID.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/methods/create)

POST/accounts/{account\_id}/browser-rendering/devtools/browser

##### [Acquire and connect to browser session.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/methods/launch)

GET/accounts/{account\_id}/browser-rendering/devtools/browser

##### [Connect to browser session.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/methods/connect)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}

##### [Close browser session.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/methods/delete)

DELETE/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}

##### [Get browser version metadata.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/methods/version)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/version

##### [Get Chrome DevTools Protocol schema.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/methods/protocol)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/protocol

#### Browser RenderingDevtoolsBrowserLive View

##### [Mint live view URLs for a browser session](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/live_view/methods/create)

POST/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/live\_view

#### Browser RenderingDevtoolsBrowserPage

##### [Connect to a specific Chrome DevTools page.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/page/methods/get)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/page/{target\_id}

#### Browser RenderingDevtoolsBrowserTargets

##### [Open a new browser tab.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/targets/methods/create)

PUT/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/new

##### [List targets.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/targets/methods/list)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/list

##### [Get a target by ID.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/targets/methods/get)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/list/{target\_id}

##### [Activate a browser target.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/targets/methods/activate)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/activate/{target\_id}

##### [Close a browser target.](https://developers.cloudflare.com/api/resources/browser_rendering/subresources/devtools/subresources/browser/subresources/targets/methods/close)

GET/accounts/{account\_id}/browser-rendering/devtools/browser/{session\_id}/json/close/{target\_id}

#### Custom Pages

##### [List custom pages](https://developers.cloudflare.com/api/resources/custom_pages/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages

##### [Get a custom page](https://developers.cloudflare.com/api/resources/custom_pages/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/{identifier}

##### [Update a custom page](https://developers.cloudflare.com/api/resources/custom_pages/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/{identifier}

#### Custom PagesAssets

##### [List custom assets](https://developers.cloudflare.com/api/resources/custom_pages/subresources/assets/methods/list)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/assets

##### [Get a custom asset](https://developers.cloudflare.com/api/resources/custom_pages/subresources/assets/methods/get)

GET/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/assets/{asset\_name}

##### [Create a custom asset](https://developers.cloudflare.com/api/resources/custom_pages/subresources/assets/methods/create)

POST/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/assets

##### [Update a custom asset](https://developers.cloudflare.com/api/resources/custom_pages/subresources/assets/methods/update)

PUT/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/assets/{asset\_name}

##### [Delete a custom asset](https://developers.cloudflare.com/api/resources/custom_pages/subresources/assets/methods/delete)

DELETE/{accounts\_or\_zones}/{account\_or\_zone\_id}/custom\_pages/assets/{asset\_name}

#### Secrets Store

#### Secrets StoreStores

##### [List account stores](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/methods/list)

GET/accounts/{account\_id}/secrets\_store/stores

##### [Get a store by ID](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/methods/get)

GET/accounts/{account\_id}/secrets\_store/stores/{store\_id}

##### [Create a store](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/methods/create)

POST/accounts/{account\_id}/secrets\_store/stores

##### [Delete a store](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/methods/delete)

DELETE/accounts/{account\_id}/secrets\_store/stores/{store\_id}

#### Secrets StoreStoresSecrets

##### [List store secrets](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/list)

GET/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets

##### [Get a secret by ID](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/get)

GET/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets/{secret\_id}

##### [Create a secret](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/create)

POST/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets

##### [Patch a secret](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/edit)

PATCH/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets/{secret\_id}

##### [Delete a secret](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/delete)

DELETE/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets/{secret\_id}

##### [Delete secrets](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/bulk_delete)

DELETE/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets

##### [Duplicate Secret](https://developers.cloudflare.com/api/resources/secrets_store/subresources/stores/subresources/secrets/methods/duplicate)

POST/accounts/{account\_id}/secrets\_store/stores/{store\_id}/secrets/{secret\_id}/duplicate

#### Secrets StoreQuota

##### [View secret usage](https://developers.cloudflare.com/api/resources/secrets_store/subresources/quota/methods/get)

GET/accounts/{account\_id}/secrets\_store/quota

#### Pipelines

##### [\[DEPRECATED\] List Pipelines](https://developers.cloudflare.com/api/resources/pipelines/methods/list)

Deprecated

GET/accounts/{account\_id}/pipelines

##### [\[DEPRECATED\] Get Pipeline](https://developers.cloudflare.com/api/resources/pipelines/methods/get)

Deprecated

GET/accounts/{account\_id}/pipelines/{pipeline\_name}

##### [\[DEPRECATED\] Create Pipeline](https://developers.cloudflare.com/api/resources/pipelines/methods/create)

Deprecated

POST/accounts/{account\_id}/pipelines

##### [\[DEPRECATED\] Update Pipeline](https://developers.cloudflare.com/api/resources/pipelines/methods/update)

Deprecated

PUT/accounts/{account\_id}/pipelines/{pipeline\_name}

##### [\[DEPRECATED\] Delete Pipeline](https://developers.cloudflare.com/api/resources/pipelines/methods/delete)

Deprecated

DELETE/accounts/{account\_id}/pipelines/{pipeline\_name}

##### [List Pipelines](https://developers.cloudflare.com/api/resources/pipelines/methods/list_v1)

GET/accounts/{account\_id}/pipelines/v1/pipelines

##### [Get Pipeline Details](https://developers.cloudflare.com/api/resources/pipelines/methods/get_v1)

GET/accounts/{account\_id}/pipelines/v1/pipelines/{pipeline\_id}

##### [Create Pipeline](https://developers.cloudflare.com/api/resources/pipelines/methods/create_v1)

POST/accounts/{account\_id}/pipelines/v1/pipelines

##### [Delete Pipeline](https://developers.cloudflare.com/api/resources/pipelines/methods/delete_v1)

DELETE/accounts/{account\_id}/pipelines/v1/pipelines/{pipeline\_id}

##### [Validate SQL](https://developers.cloudflare.com/api/resources/pipelines/methods/validate_sql)

POST/accounts/{account\_id}/pipelines/v1/validate\_sql

#### PipelinesSinks

##### [List Sinks](https://developers.cloudflare.com/api/resources/pipelines/subresources/sinks/methods/list)

GET/accounts/{account\_id}/pipelines/v1/sinks

##### [Get Sink Details](https://developers.cloudflare.com/api/resources/pipelines/subresources/sinks/methods/get)

GET/accounts/{account\_id}/pipelines/v1/sinks/{sink\_id}

##### [Create Sink](https://developers.cloudflare.com/api/resources/pipelines/subresources/sinks/methods/create)

POST/accounts/{account\_id}/pipelines/v1/sinks

##### [Delete Sink](https://developers.cloudflare.com/api/resources/pipelines/subresources/sinks/methods/delete)

DELETE/accounts/{account\_id}/pipelines/v1/sinks/{sink\_id}

#### PipelinesStreams

##### [List Streams](https://developers.cloudflare.com/api/resources/pipelines/subresources/streams/methods/list)

GET/accounts/{account\_id}/pipelines/v1/streams

##### [Get Stream Details](https://developers.cloudflare.com/api/resources/pipelines/subresources/streams/methods/get)

GET/accounts/{account\_id}/pipelines/v1/streams/{stream\_id}

##### [Create Stream](https://developers.cloudflare.com/api/resources/pipelines/subresources/streams/methods/create)

POST/accounts/{account\_id}/pipelines/v1/streams

##### [Update Stream](https://developers.cloudflare.com/api/resources/pipelines/subresources/streams/methods/update)

PATCH/accounts/{account\_id}/pipelines/v1/streams/{stream\_id}

##### [Delete Stream](https://developers.cloudflare.com/api/resources/pipelines/subresources/streams/methods/delete)

DELETE/accounts/{account\_id}/pipelines/v1/streams/{stream\_id}

#### Schema Validation

#### Schema ValidationSchemas

##### [List all uploaded schemas](https://developers.cloudflare.com/api/resources/schema_validation/subresources/schemas/methods/list)

GET/zones/{zone\_id}/schema\_validation/schemas

##### [Get details of a schema](https://developers.cloudflare.com/api/resources/schema_validation/subresources/schemas/methods/get)

GET/zones/{zone\_id}/schema\_validation/schemas/{schema\_id}

##### [Upload a schema](https://developers.cloudflare.com/api/resources/schema_validation/subresources/schemas/methods/create)

POST/zones/{zone\_id}/schema\_validation/schemas

##### [Set schema validation state](https://developers.cloudflare.com/api/resources/schema_validation/subresources/schemas/methods/edit)

PATCH/zones/{zone\_id}/schema\_validation/schemas/{schema\_id}

##### [Delete a schema](https://developers.cloudflare.com/api/resources/schema_validation/subresources/schemas/methods/delete)

DELETE/zones/{zone\_id}/schema\_validation/schemas/{schema\_id}

#### Schema ValidationSettings

##### [Get global schema validation settings](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/methods/get)

GET/zones/{zone\_id}/schema\_validation/settings

##### [Update global schema validation settings](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/methods/update)

PUT/zones/{zone\_id}/schema\_validation/settings

##### [Edit global schema validation settings](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/methods/edit)

PATCH/zones/{zone\_id}/schema\_validation/settings

#### Schema ValidationSettingsOperations

##### [List per-operation schema validation settings](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/subresources/operations/methods/list)

GET/zones/{zone\_id}/schema\_validation/settings/operations

##### [Get per-operation schema validation setting](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/subresources/operations/methods/get)

GET/zones/{zone\_id}/schema\_validation/settings/operations/{operation\_id}

##### [Update per-operation schema validation setting](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/subresources/operations/methods/update)

PUT/zones/{zone\_id}/schema\_validation/settings/operations/{operation\_id}

##### [Bulk edit per-operation schema validation settings](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/subresources/operations/methods/bulk_edit)

PATCH/zones/{zone\_id}/schema\_validation/settings/operations

##### [Delete per-operation schema validation setting](https://developers.cloudflare.com/api/resources/schema_validation/subresources/settings/subresources/operations/methods/delete)

DELETE/zones/{zone\_id}/schema\_validation/settings/operations/{operation\_id}

#### Token Validation

#### Token ValidationConfiguration

##### [List token validation configurations](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/methods/list)

GET/zones/{zone\_id}/token\_validation/config

##### [Get a token validation configuration](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/methods/get)

GET/zones/{zone\_id}/token\_validation/config/{config\_id}

##### [Create a token validation configuration](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/methods/create)

POST/zones/{zone\_id}/token\_validation/config

##### [Edit a token validation configuration](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/methods/edit)

PATCH/zones/{zone\_id}/token\_validation/config/{config\_id}

##### [Delete a token validation configuration](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/methods/delete)

DELETE/zones/{zone\_id}/token\_validation/config/{config\_id}

#### Token ValidationConfigurationCredentials

##### [Replace token validation credentials](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/subresources/credentials/methods/update)

PUT/zones/{zone\_id}/token\_validation/config/{config\_id}/credentials

##### [Edit token validation credentials](https://developers.cloudflare.com/api/resources/token_validation/subresources/configuration/subresources/credentials/methods/edit)

PATCH/zones/{zone\_id}/token\_validation/config/{config\_id}/credentials

#### Token ValidationRules

##### [List token validation rules](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/list)

GET/zones/{zone\_id}/token\_validation/rules

##### [Create a token validation rule](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/create)

POST/zones/{zone\_id}/token\_validation/rules

##### [Create token validation rules](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/bulk_create)

POST/zones/{zone\_id}/token\_validation/rules/bulk

##### [Edit token validation rules](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/bulk_edit)

PATCH/zones/{zone\_id}/token\_validation/rules/bulk

##### [Get a token validation rule](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/get)

GET/zones/{zone\_id}/token\_validation/rules/{rule\_id}

##### [Delete a token validation rule](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/delete)

DELETE/zones/{zone\_id}/token\_validation/rules/{rule\_id}

##### [Edit a token validation rule](https://developers.cloudflare.com/api/resources/token_validation/subresources/rules/methods/edit)

PATCH/zones/{zone\_id}/token\_validation/rules/{rule\_id}

#### Field Extractors

##### [Get Field Extractor](https://developers.cloudflare.com/api/resources/field_extractors/methods/get)

GET/accounts/{account\_id}/field\_extractors/{extractor}

##### [Update Field Extractor](https://developers.cloudflare.com/api/resources/field_extractors/methods/update)

PUT/accounts/{account\_id}/field\_extractors/{extractor}

##### [Delete Field Extractor](https://developers.cloudflare.com/api/resources/field_extractors/methods/delete)

DELETE/accounts/{account\_id}/field\_extractors/{extractor}
---

---
description: Use Cloudflare API SDKs for Go, TypeScript, and Python to integrate Cloudflare services into your applications.
title: SDKs
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# SDKs

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/reference/sdks/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers language software development kits (SDKs) as well as `curl` examples to demonstrate how to use the Cloudflare API. The SDK libraries allow you to interact with the Cloudflare API in language-specific syntax and more easily integrate with your existing applications.

Cloudflare currently offers the following SDKs:

- [Go ↗](https://github.com/cloudflare/cloudflare-go)
- [TypeScript ↗](https://github.com/cloudflare/cloudflare-typescript)
- [Python ↗](https://github.com/cloudflare/cloudflare-python)

## When to use cURL vs SDK

There is no definite answer on which you should use. Instead, consider your use case and determine whether cURL or an SDK is the best fit.

| Use case | cURL | SDK |
| --- | --- | --- |
| Quick testing within the CLI | ✅ | ❌ |
| Use within bash scripts or CI | ✅ | ❌\* |
| Usage from within an existing application or framework | ❌ | ✅ |
| More complex usage where you need to chain together outputs | ❌ | ✅ |

\* It is possible, although not straight forward, to use the SDKs within bash scripts or CI environments with additional runtime dependencies and setup.

## Example

The following are examples of how you would query all of the Cloudflare zones you have access to.

### With cURL:

```bash
curl "https://api.cloudflare.com/client/v4/zones" \
--header "Authorization: Bearer <API_TOKEN>"
```

### With the TypeScript SDK:

```js
const client = new Cloudflare({
	apiToken: process.env["CLOUDFLARE_API_TOKEN"],
});

const zones = await client.zones.list();

console.log(zones);
```

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/reference/sdks/#page","headline":"SDKs","description":"Use Cloudflare API SDKs for Go, TypeScript, and Python to integrate Cloudflare services into your applications.","url":"https://developers.cloudflare.com/fundamentals/api/reference/sdks/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Explore Cloudflare's API token templates to efficiently manage permissions. Start with a template and customize token permissions and resources as needed.
title: API token templates
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# API token templates

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/reference/template/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Below is a table of the currently available API token templates and the default [token permissions](https://developers.cloudflare.com/fundamentals/api/reference/permissions/) they grant. You can start creating a token with one of these templates and modify the permissions and resources from there.

| Template Name | Permission | Resource |
| --- | --- | --- |
| Edit Zone DNS | DNS Write | Zone |
| Read billing info | Billing Read | Account |
| Account resources: Include all accounts | |
| Read analytics and logs | Analytics Read | Zone |
| Logs Read | Zone |
| Edit Cloudflare Workers | Workers Routes Write | Zone |
| Workers Scripts Write | Account |
| Workers KV Storage Write | Account |
| Workers Tail Read | Account |
| Workers R2 Storage Write | Account |
| Account Settings Read | Account |
| User Details Read | User |
| User Memberships Read | User |
| Edit load balancing configuration | Load Balancing: Monitors and Pools Write | Account |
| Load Balancers Write | Zone |
| WordPress | Analytics Read | Zone |
| Zone Read | Zone |
| Zone Settings Write | Zone |
| Account Settings Read | Account |
| DNS Read | Zone |
| Cache Purge | Zone |
| Account resources: Include all accounts | |
| Zone resources: Include all zones | |
| Create Additional Tokens | API Tokens Write | User |
| Read All Resources | *(All read permissions)* | Account, Zone, User |
| Account resources: Include all accounts | |
| Zone resources: Include all zones | |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/reference/template/#page","headline":"API token templates","description":"Explore Cloudflare's API token templates to efficiently manage permissions. Start with a template and customize token permissions and resources as needed.","url":"https://developers.cloudflare.com/fundamentals/api/reference/template/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: A set of programmatic APIs that can be integrated with local Cloudflare Workers-related workflows.
title: API
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/workers/llms.txt  
> Use this file to discover all available pages before exploring further.

# API

Last updated Jul 27, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/workers/wrangler/api/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Wrangler offers APIs to programmatically interact with your Cloudflare Workers.

- [`createTestHarness`](#createtestharness) - Start one or more Workers for integration tests in any Node.js test runner.
- [`experimental_generateTypes`](#experimental_generatetypes) - Generate TypeScript type definitions from your Worker configuration.
- [`unstable_startWorker`](#unstable_startworker) - Start a server for running integration tests against your Worker.
- [`unstable_dev`](#unstable_dev) - Start a server for running either end-to-end (e2e) or integration tests against your Worker.
- [`getPlatformProxy`](#getplatformproxy) - Get proxies and values for emulating the Cloudflare Workers platform in a Node.js process.

## `createTestHarness`

`createTestHarness()` starts one or more Workers for integration tests from any Node.js test runner. It runs production build output from Wrangler configuration files, Vite-generated configuration files, or inline Wrangler configuration objects. The API wraps Miniflare and provides methods for dispatching requests and scheduled events.

For setup guidance and examples, refer to [Integration test harness](https://developers.cloudflare.com/workers/testing/test-harness/).

### Syntax

```js
import { createTestHarness } from "wrangler";

const server = createTestHarness(options);
```

```ts
import { createTestHarness } from "wrangler";

const server = createTestHarness(options);
```

### Parameters

- `options` `object` optional
  - Test harness options. If you call `createTestHarness()` without options, call `server.update(options)` before `server.listen()`.
    - `root` `string` optional

      Base directory used to resolve relative Worker configuration paths. Defaults to `process.cwd()`.
    - `workers` `WorkerInput[]`

      Workers to run in the test server. The first Worker is the primary Worker.

Each `WorkerInput` can load a Worker from a Wrangler configuration file:

```js
const server = createTestHarness({
	workers: [
		{ configPath: "./wrangler.web.jsonc" },
		{ configPath: "./wrangler.api.jsonc" },
	],
});
```

```ts
const server = createTestHarness({
	workers: [
		{ configPath: "./wrangler.web.jsonc" },
		{ configPath: "./wrangler.api.jsonc" },
	],
});
```

Configuration file inputs support these fields:

- `configPath` `string | URL`
  - Path to a Wrangler configuration file. Relative paths resolve from `root`.
- `env` `string` optional
  - Wrangler environment to load from the configuration file.
- `vars` `Record<string, Json>` optional
  - Test-only variables that override variables from the Wrangler configuration file.
- `secrets` `Record<string, string>` optional
  - Test-only secrets that override values loaded from `.dev.vars` and `.env` files.
- `bindingOverrides` `Record<string, string>` optional
  - Test-only service binding overrides. Keys are binding names in this Worker's environment. Values are Worker names in this test harness.

Each `WorkerInput` can also use `config` to provide an inline Wrangler configuration object:

```js
const server = createTestHarness({
	workers: [
		{
			config: {
				name: "api-worker",
				main: "src/api.ts",
				compatibility_date: "YYYY-MM-DD",
			},
		},
	],
});
```

```ts
const server = createTestHarness({
	workers: [
		{
			config: {
				name: "api-worker",
				main: "src/api.ts",
				compatibility_date: "YYYY-MM-DD",
			},
		},
	],
});
```

### Return type

`createTestHarness()` returns a `TestHarness` object with these methods:

- `listen()` `Promise<{ url: URL }>`
  - Starts the server and returns its current URL. Repeated calls return the same session until the server is closed or reset.
- `fetch(input, init)` `Promise<Response>`
  - Dispatches a fetch request through the server. Relative URLs resolve against the current server URL. Absolute URLs follow the configured Worker routes and fall back to the primary Worker.
- `getWorker(name?)` `WorkerHandle`
  - Returns a handle for dispatching events directly to a Worker. When no name is provided, this returns the primary Worker.
- `getLogs()` `WorkerdStructuredLog[]`
  - Returns captured Workers runtime logs since the current server session started or `clearLogs()` was last called.
- `clearLogs()` `void`
  - Clears captured Workers runtime logs.
- `debug()` `void`
  - Prints a diagnostic timeline for this test server, including server events and captured Workers runtime logs. This is useful in a test runner failure or cleanup hook.
- `update(optionsOrUpdater)` `Promise<void>`
  - Updates the server configuration with a `TestHarnessOptions` object or a function that receives the current options and returns the next options. If the server has not started yet, this configures the options used by `listen()`. If the server is running, this reloads the running Workers. Updating the number of Workers in a running server is not supported.
- `reset()` `Promise<void>`
  - Restores the server to the options used when the current session first started. Storage is recreated, and the server URL may change after reset.
- `close()` `Promise<void>`
  - Stops the server and releases all runtime resources.

`getWorker(name?)` returns a `WorkerHandle` object with these methods:

- `fetch(input, init)` `Promise<Response>`
  - Dispatches a fetch event directly to this Worker.
- `scheduled(options)` `Promise<{ outcome: "ok" | "canceled" | "exception"; noRetry: boolean }>`
  - Dispatches a scheduled event directly to this Worker.
- `getEnv()` `Promise<Env>`
  - Returns the full environment object configured for this Worker, including variables, secrets, and bindings.
- `getExport()` `Promise<Service<Module['default']>>`
  - Returns the default Worker export, including RPC methods.
- `applyD1Migrations(bindingName)` `Promise<void>`
  - Applies local D1 migration files that have not already run to a D1 binding on this Worker.
- `getDurableObjectStorage(classNameOrBindingName, options)` `Promise<DurableObjectStorageHandle>`
  - Returns SQL storage access for a Durable Object instance.
- `introspectWorkflow(bindingName)` `Promise<WorkflowIntrospector>`
  - Creates an introspector for Workflow instances created after this method is called.
- `introspectWorkflowInstance(bindingName, instanceId)` `Promise<WorkflowInstanceIntrospector>`
  - Creates an introspector for a specific Workflow instance.

### Usage

This example uses the Node.js built-in test runner:

```js
import assert from "node:assert/strict";
import { after, afterEach, before, describe, test } from "node:test";
import { createTestHarness } from "wrangler";

const server = createTestHarness({
	workers: [
		{ configPath: "./wrangler.web.jsonc" },
		{ configPath: "./wrangler.api.jsonc" },
	],
});

const apiWorker = server.getWorker("api-worker");

describe("Worker", () => {
	before(async () => {
		await server.listen();
	});

	afterEach(async () => {
		await server.reset();
	});

	after(async () => {
		await server.close();
	});

	test("dispatches through configured routes", async () => {
		const response = await server.fetch("http://example.com/users/123");
		assert.equal(response.status, 200);
	});

	test("calls a specific Worker directly", async () => {
		const response = await apiWorker.fetch(
			"http://api.example.com/v1/users/123",
		);
		assert.equal(response.status, 200);
	});

	test("triggers a scheduled handler", async () => {
		const result = await apiWorker.scheduled({
			cron: "0 0 * * *",
			scheduledTime: new Date(),
		});
		assert.equal(result.outcome, "ok");
	});
});
```

```ts
import assert from "node:assert/strict";
import { after, afterEach, before, describe, test } from "node:test";
import { createTestHarness } from "wrangler";

const server = createTestHarness({
	workers: [
		{ configPath: "./wrangler.web.jsonc" },
		{ configPath: "./wrangler.api.jsonc" },
	],
});

const apiWorker = server.getWorker("api-worker");

describe("Worker", () => {
	before(async () => {
		await server.listen();
	});

	afterEach(async () => {
		await server.reset();
	});

	after(async () => {
		await server.close();
	});

	test("dispatches through configured routes", async () => {
		const response = await server.fetch("http://example.com/users/123");
		assert.equal(response.status, 200);
	});

	test("calls a specific Worker directly", async () => {
		const response = await apiWorker.fetch(
			"http://api.example.com/v1/users/123",
		);
		assert.equal(response.status, 200);
	});

	test("triggers a scheduled handler", async () => {
		const result = await apiWorker.scheduled({
			cron: "0 0 * * *",
			scheduledTime: new Date(),
		});
		assert.equal(result.outcome, "ok");
	});
});
```

## `experimental_generateTypes`

Generate TypeScript type definitions from your Worker configuration. This API uses the same core logic as the `wrangler types` CLI command, so outputs stay aligned between the CLI and programmatic API.

Unlike the CLI command, `experimental_generateTypes` does not write to disk automatically. Instead, it returns the generated type content as structured strings for you to handle as needed.

Note

The `experimental_generateTypes()` function has an `experimental_` prefix because the API is experimental and may change in the future.

### Syntax

```ts
import { experimental_generateTypes } from "wrangler";

const result = await experimental_generateTypes(options);
```

### Parameters

- `options` `object` optional
  - Optional options object mirroring the `wrangler types` CLI flags:
    - `config` `string | string[]`

      Path to the Wrangler configuration file to use. Can be an array for multi-config type resolution.
    - `env` `string`

      Name of the Wrangler environment to generate types for.
    - `envFile` `string[]`

      Paths to `.env` files to load when inferring local variables and secrets.
    - `envInterface` `string`

      Name of the generated environment interface. Defaults to `Env`.
    - `includeEnv` `boolean`

      Whether to include environment and bindings types in the output. Defaults to `true`.
    - `includeRuntime` `boolean`

      Whether to include runtime types in the output. Defaults to `true`.
    - `path` `string`

      Path to the declaration file for generated types. Defaults to `worker-configuration.d.ts`.
    - `strictVars` `boolean`

      Whether to generate strict literal and union types for variables. Defaults to `true`.

### Return Type

`experimental_generateTypes()` returns a `Promise` resolving to an object containing the following fields:

- `content` `string`
  - Combined formatted output containing all generated sections, including headers and both env and runtime types.
- `env` `string | null`
  - Generated environment and bindings types, or `null` when env types are excluded.
- `path` `string`
  - Target declaration file path associated with this generation run.
- `runtime` `string | null`
  - Generated runtime types, or `null` when runtime types are excluded.

### Usage

You can use `experimental_generateTypes` to generate types programmatically and write them to disk yourself, or pass them to other tools:

```ts
import { experimental_generateTypes } from "wrangler";
import * as fs from "node:fs";

const result = await experimental_generateTypes({
	config: "wrangler.json",
	includeRuntime: true,
	includeEnv: true,
});

// Write the combined content to the path specified in options
fs.writeFileSync(result.path, result.content, "utf-8");
```

To generate only env types without runtime types:

```ts
const result = await experimental_generateTypes({
	includeRuntime: false,
});
```

To generate types for a specific environment with a custom interface name:

```ts
const result = await experimental_generateTypes({
	env: "staging",
	envInterface: "StagingEnv",
	path: "./types/staging.d.ts",
});
```

## `unstable_startWorker`

Caution

`unstable_startWorker()` is deprecated. Cloudflare recommends [`createTestHarness()`](#createtestharness) for integration testing. To start a development server programmatically, use the Vite [`createServer()` ↗](https://vite.dev/guide/api-javascript.html#createserver) API with the [Cloudflare Vite plugin](https://developers.cloudflare.com/workers/vite-plugin/).

This API exposes the internals of Wrangler's dev server, and allows you to customise how it runs. For example, you could use `unstable_startWorker()` to run integration tests against your Worker. This example uses `node:test`, but should apply to any testing framework:

```js
import assert from "node:assert";
import test, { after, before, describe } from "node:test";
import { unstable_startWorker } from "wrangler";

describe("worker", () => {
	let worker;

	before(async () => {
		worker = await unstable_startWorker({ config: "wrangler.json" });
	});

	test("hello world", async () => {
		assert.strictEqual(
			await (await worker.fetch("http://example.com")).text(),
			"Hello world",
		);
	});

	after(async () => {
		await worker.dispose();
	});
});
```

## `unstable_dev`

Caution

`unstable_dev()` is deprecated. Cloudflare recommends [`createTestHarness()`](#createtestharness) for integration testing. To start a development server programmatically, use the Vite [`createServer()` ↗](https://vite.dev/guide/api-javascript.html#createserver) API with the [Cloudflare Vite plugin](https://developers.cloudflare.com/workers/vite-plugin/).

Start an HTTP server for testing your Worker.

Once called, `unstable_dev` will return a `fetch()` function for invoking your Worker without needing to know the address or port, as well as a `stop()` function to shut down the HTTP server.

By default, `unstable_dev` will perform integration tests against a local server. If you wish to perform an e2e test against a preview Worker, pass `local: false` in the `options` object when calling the `unstable_dev()` function. Note that e2e tests can be significantly slower than integration tests.

### Constructor

```js
const worker = await unstable_dev(script, options);
```

### Parameters

- `script` `string`
  - A string containing a path to your Worker script, relative to your Worker project's root directory.
- `options` `object` optional
  - Optional options object containing `wrangler dev` configuration settings.
  - Include an `experimental` object inside `options` to access experimental features such as `disableExperimentalWarning`.
    - Set `disableExperimentalWarning` to `true` to disable Wrangler's warning about using `unstable_` prefixed APIs.

### Return Type

`unstable_dev()` returns an object containing the following methods:

- `fetch()` `Promise<Response>`
  - Send a request to your Worker. Returns a Promise that resolves with a [`Response`](https://developers.cloudflare.com/workers/runtime-apis/response) object.
  - Refer to [`Fetch`](https://developers.cloudflare.com/workers/runtime-apis/fetch/).
- `stop()` `Promise<void>`
  - Shuts down the dev server.

### Usage

When initiating each test suite, use a `beforeAll()` function to start `unstable_dev()`. The `beforeAll()` function is used to minimize overhead: starting the dev server takes a few hundred milliseconds, starting and stopping for each individual test adds up quickly, slowing your tests down.

In each test case, call `await worker.fetch()`, and check that the response is what you expect.

To wrap up a test suite, call `await worker.stop()` in an `afterAll` function.

#### Single Worker example

```js
const { unstable_dev } = require("wrangler");

describe("Worker", () => {
	let worker;

	beforeAll(async () => {
		worker = await unstable_dev("src/index.js", {
			experimental: { disableExperimentalWarning: true },
		});
	});

	afterAll(async () => {
		await worker.stop();
	});

	it("should return Hello World", async () => {
		const resp = await worker.fetch();
		const text = await resp.text();
		expect(text).toMatchInlineSnapshot(`"Hello World!"`);
	});
});
```

```ts
import { unstable_dev } from "wrangler";
import type { UnstableDevWorker } from "wrangler";

describe("Worker", () => {
	let worker: UnstableDevWorker;

	beforeAll(async () => {
		worker = await unstable_dev("src/index.ts", {
			experimental: { disableExperimentalWarning: true },
		});
	});

	afterAll(async () => {
		await worker.stop();
	});

	it("should return Hello World", async () => {
		const resp = await worker.fetch();
		const text = await resp.text();
		expect(text).toMatchInlineSnapshot(`"Hello World!"`);
	});
});
```

#### Multi-Worker example

You can test Workers that call other Workers. In the below example, we refer to the Worker that calls other Workers as the parent Worker, and the Worker being called as a child Worker.

If you shut down the child Worker prematurely, the parent Worker will not know the child Worker exists and your tests will fail.

```js
import { unstable_dev } from "wrangler";

describe("multi-worker testing", () => {
	let childWorker;
	let parentWorker;

	beforeAll(async () => {
		childWorker = await unstable_dev("src/child-worker.js", {
			config: "src/child-wrangler.toml",
			experimental: { disableExperimentalWarning: true },
		});
		parentWorker = await unstable_dev("src/parent-worker.js", {
			config: "src/parent-wrangler.toml",
			experimental: { disableExperimentalWarning: true },
		});
	});

	afterAll(async () => {
		await childWorker.stop();
		await parentWorker.stop();
	});

	it("childWorker should return Hello World itself", async () => {
		const resp = await childWorker.fetch();
		const text = await resp.text();
		expect(text).toMatchInlineSnapshot(`"Hello World!"`);
	});

	it("parentWorker should return Hello World by invoking the child worker", async () => {
		const resp = await parentWorker.fetch();
		const parsedResp = await resp.text();
		expect(parsedResp).toEqual("Parent worker sees: Hello World!");
	});
});
```

```ts
import { unstable_dev } from "wrangler";
import type { UnstableDevWorker } from "wrangler";

describe("multi-worker testing", () => {
	let childWorker: UnstableDevWorker;
	let parentWorker: UnstableDevWorker;

	beforeAll(async () => {
		childWorker = await unstable_dev("src/child-worker.js", {
			config: "src/child-wrangler.toml",
			experimental: { disableExperimentalWarning: true },
		});
		parentWorker = await unstable_dev("src/parent-worker.js", {
			config: "src/parent-wrangler.toml",
			experimental: { disableExperimentalWarning: true },
		});
	});

	afterAll(async () => {
		await childWorker.stop();
		await parentWorker.stop();
	});

	it("childWorker should return Hello World itself", async () => {
		const resp = await childWorker.fetch();
		const text = await resp.text();
		expect(text).toMatchInlineSnapshot(`"Hello World!"`);
	});

	it("parentWorker should return Hello World by invoking the child worker", async () => {
		const resp = await parentWorker.fetch();
		const parsedResp = await resp.text();
		expect(parsedResp).toEqual("Parent worker sees: Hello World!");
	});
});
```

## `getPlatformProxy`

The `getPlatformProxy` function provides a way to obtain an object containing proxies (to **local** `workerd` bindings) and emulations of Cloudflare Workers specific values, allowing the emulation of such in a Node.js process.

Caution

`getPlatformProxy` is, by design, to be used exclusively in Node.js applications. `getPlatformProxy` cannot be run inside the Workers runtime.

One general use case for getting a platform proxy is for emulating bindings in applications targeting Workers, but running outside the Workers runtime (for example, framework local development servers running in Node.js), or for testing purposes (for example, ensuring code properly interacts with a type of binding).

Note

Binding proxies provided by this function are a best effort emulation of the real production bindings. Although they are designed to be as close as possible to the real thing, there might be slight differences and inconsistencies between the two.

### Syntax

```js
const platform = await getPlatformProxy(options);
```

### Parameters

- `options` `object` optional
  - Optional options object containing preferences for the bindings:
    - `environment` string

      The environment to use.
    - `configPath` string

      The path to the config file to use.

      If no path is specified, the default behavior is to search from the current directory up the filesystem for a [Wrangler configuration file](https://developers.cloudflare.com/workers/wrangler/configuration/) to use.

      **Note:** this field is optional but if a path is specified it must point to a valid file on the filesystem.
    - `persist` boolean | `{ path: string }`

      Indicates if and where to persist the bindings data. If `true` or `undefined`, defaults to the same location used by Wrangler, so data can be shared between it and the caller. If `false`, no data is persisted to or read from the filesystem.

      **Note:** If you use `wrangler`'s `--persist-to` option, note that this option adds a subdirectory called `v3` under the hood while `getPlatformProxy`'s `persist` does not. For example, if you run `wrangler dev --persist-to ./my-directory`, to reuse the same location using `getPlatformProxy`, you will have to specify: `persist: { path: "./my-directory/v3" }`.
    - `remoteBindings` boolean optional (default: \`true\`)

      Whether or not [remote bindings](https://developers.cloudflare.com/workers/local-development/#remote-bindings) should be enabled.

### Return Type

`getPlatformProxy()` returns a `Promise` resolving to an object containing the following fields.

- `env` `Record<string, unknown>`
  - Object containing proxies to bindings that can be used in the same way as production bindings. This matches the shape of the `env` object passed as the second argument to modules-format workers. These proxy to binding implementations run inside `workerd`.
  - TypeScript Tip: `getPlatformProxy<Env>()` is a generic function. You can pass the shape of the bindings record as a type argument to get proper types without `unknown` values.
- `cf` IncomingRequestCfProperties read-only
  - Mock of the `Request`'s `cf` property, containing data similar to what you would see in production.
- `ctx` object
  - Mock object containing implementations of the [`waitUntil`](https://developers.cloudflare.com/workers/runtime-apis/context/#waituntil) and [`passThroughOnException`](https://developers.cloudflare.com/workers/runtime-apis/context/#passthroughonexception) functions that do nothing.
- `caches` object
  - Emulation of the [Workers `caches` runtime API](https://developers.cloudflare.com/workers/runtime-apis/cache/).
  - For the time being, all cache operations do nothing. A more accurate emulation will be made available soon.
- `dispose()` () => `Promise<void>`
  - Terminates the underlying `workerd` process.
  - Call this after the platform proxy is no longer required by the program. If you are running a long running process (such as a dev server) that can indefinitely make use of the proxy, you do not need to call this function.

### Usage

The `getPlatformProxy` function uses bindings found in the [Wrangler configuration file](https://developers.cloudflare.com/workers/wrangler/configuration/). For example, if you have an [environment variable](https://developers.cloudflare.com/workers/configuration/environment-variables/#add-environment-variables-via-wrangler) configuration set up in the Wrangler configuration file:

```jsonc
{
	"vars": {
		"MY_VARIABLE": "test"
	}
}
```

```toml
[vars]
MY_VARIABLE = "test"
```

You can access the bindings by importing `getPlatformProxy` like this:

```js
import { getPlatformProxy } from "wrangler";

const { env } = await getPlatformProxy();
```

To access the value of the `MY_VARIABLE` binding add the following to your code:

```js
console.log(`MY_VARIABLE = ${env.MY_VARIABLE}`);
```

This will print the following output: `MY_VARIABLE = test`.

### Supported bindings

All supported bindings found in your [Wrangler configuration file](https://developers.cloudflare.com/workers/wrangler/configuration/) are available to you via `env`.

The bindings supported by `getPlatformProxy` are:

- [Environment variables](https://developers.cloudflare.com/workers/configuration/environment-variables/)
- [Service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/)
- [KV namespace bindings](https://developers.cloudflare.com/kv/api/)
- [R2 bucket bindings](https://developers.cloudflare.com/r2/api/workers/workers-api-reference/)
- [Queue bindings](https://developers.cloudflare.com/queues/configuration/javascript-apis/)
- [D1 database bindings](https://developers.cloudflare.com/d1/worker-api/)
- [Hyperdrive bindings](https://developers.cloudflare.com/hyperdrive)

  Hyperdrive values are simple passthrough ones

  Values provided by hyperdrive bindings such as `connectionString` and `host` do not have a valid meaning outside of a `workerd` process. This means that Hyperdrive proxies return passthrough values, which are values corresponding to the database connection provided by the user. Otherwise, it would return values which would be unusable from within node.js.
- [Workers AI bindings](https://developers.cloudflare.com/workers-ai/get-started/workers-wrangler/#2-connect-your-worker-to-workers-ai)

  Workers AI local development usage charges

  Using Workers AI always accesses your Cloudflare account in order to run AI models and will incur usage charges even in local development.
- [Durable Object bindings](https://developers.cloudflare.com/durable-objects/api/)
  - To use a Durable Object binding with `getPlatformProxy`, always specify a [`script_name`](https://developers.cloudflare.com/workers/wrangler/configuration/#durable-objects).

    For example, you might have the following binding in a Wrangler configuration file read by `getPlatformProxy`.

    ```jsonc
    {
      "durable_objects": {
        "bindings": [
          {
            "name": "MyDurableObject",
            "class_name": "MyDurableObject",
            "script_name": "external-do-worker"
          }
        ]
      }
    }
    ```

    ```toml
    [[durable_objects.bindings]]
    name = "MyDurableObject"
    class_name = "MyDurableObject"
    script_name = "external-do-worker"
    ```

    You will need to declare your Durable Object `"MyDurableObject"` in another Worker, called `external-do-worker` in this example.

    *./external-do-worker/src/index.tsts*

    

    ```ts
    export class MyDurableObject extends DurableObject {
    	// Your DO code goes here
    }

    export default {
    	fetch() {
    		// Doesn't have to do anything, but a DO cannot be the default export
    		return new Response("Hello, world!");
    	},
    };
    ```

    That Worker also needs a Wrangler configuration file that looks like this:

    ```jsonc
    {
    	"name": "external-do-worker",
    	"main": "src/index.ts",
    	"compatibility_date": "XXXX-XX-XX"
    }
    ```

    ```toml
    name = "external-do-worker"
    main = "src/index.ts"
    compatibility_date = "XXXX-XX-XX"
    ```

    If you are not using RPC with your Durable Object, you can run a separate Wrangler dev session alongside your framework development server.

    Otherwise, you can build your application and run both Workers in the same Wrangler dev session.

    If you are using Pages run:npmyarnpnpm

    ```
    npx wrangler pages dev -c path/to/pages/wrangler.jsonc -c path/to/external-do-worker/wrangler.jsonc
    ```

    ```
    yarn wrangler pages dev -c path/to/pages/wrangler.jsonc -c path/to/external-do-worker/wrangler.jsonc
    ```

    ```
    pnpm wrangler pages dev -c path/to/pages/wrangler.jsonc -c path/to/external-do-worker/wrangler.jsonc
    ```

    If you are using Workers with Assets run:npmyarnpnpm

    ```
    npx wrangler dev -c path/to/workers-assets/wrangler.jsonc -c path/to/external-do-worker/wrangler.jsonc
    ```

    ```
    yarn wrangler dev -c path/to/workers-assets/wrangler.jsonc -c path/to/external-do-worker/wrangler.jsonc
    ```

    ```
    pnpm wrangler dev -c path/to/workers-assets/wrangler.jsonc -c path/to/external-do-worker/wrangler.jsonc
    ```



Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/workers/wrangler/api/#page","headline":"API","description":"A set of programmatic APIs that can be integrated with local Cloudflare Workers-related workflows.","url":"https://developers.cloudflare.com/workers/wrangler/api/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-27","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Resolve common Cloudflare API token issues including verification failures, incorrect permissions, and syntax errors.
title: Troubleshooting
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Troubleshooting

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/api/troubleshooting/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## The token is not verified

Ensure the token has been verified by running the following `curl` command and confirming that the response returns `"status": "active"`.

```bash
curl "https://api.cloudflare.com/client/v4/user/tokens/verify" \
--header "Authorization: Bearer <API_TOKEN>"
```

```json
{
  "success": true,
  "errors": [],
  "messages": [],
  "result": {
    "id": "f267e341f3dd4697bd3b9f71dd96247f",
    "status": "active",
    "not_before": "2018-07-01T05:20:00Z",
    "expires_on": "2020-01-01T00:00:00Z"
  }
}
```

## The token has incorrect permissions

Review the permissions groups for your token in the [Cloudflare dashboard ↗](https://dash.cloudflare.com/profile/api-tokens). Refer to [API token permissions](https://developers.cloudflare.com/fundamentals/api/reference/permissions/) for more information.

## The incorrect syntax is used

Occasionally customers will attempt to use an API token with an API key syntax. Ensure you are using the Bearer option rather than the email and API key pair.

## You have the incorrect user permissions

You cannot create a token that exceeds the permission granted to you on your account. For example, if you have been granted an **Admin (Read only)** role, you would need your Super Administrator to update your role so that you could create a token for yourself.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/api/troubleshooting/#page","headline":"Troubleshooting","description":"Resolve common Cloudflare API token issues including verification failures, incorrect permissions, and syntax errors.","url":"https://developers.cloudflare.com/fundamentals/api/troubleshooting/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how Cloudflare organizes resources into user profiles, accounts, and zones, and where settings and products apply.
title: Accounts, zones, and profiles
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Accounts, zones, and profiles

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/concepts/accounts-and-zones/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Within the Cloudflare ecosystem, there are three organizing concepts that control where specific settings live: user profiles, accounts, and zones.

```
flowchart LR
accTitle: Accounts contain zones and user profiles contain user settings
subgraph Account
    subgraph Zone - example.com
        A[WAF]
        B[DNS]
    end
    subgraph Zone - example2.com
        C[Cache rules]
        D[Waiting Room]
    end
    Workers
    K[Account members]
end
subgraph User profile
    G[Email address]
    H[Language]
    I[Communication preferences]
end

```

---

## User profiles

Each user has a profile that contains several settings, such as [Communication preferences](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#notifications) and [Language preferences](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#language).

To access your profile, select the user icon and then **My Profile** from any page within the [Cloudflare dashboard ↗](https://dash.cloudflare.com).

## Accounts

An account refers to an organization account, which contains one or more users and zones. Users can belong to multiple accounts, and each account maintains its own settings, including [billing profiles](https://developers.cloudflare.com/billing/get-started/create-billing-profile/), [account members](https://developers.cloudflare.com/fundamentals/manage-members/), [lists](https://developers.cloudflare.com/waf/tools/lists/), and other configurations.

Several account-level products - such as [Workers](https://developers.cloudflare.com/workers/), [Pages](https://developers.cloudflare.com/pages/), [Security Center](https://developers.cloudflare.com/security-center/), and [Bulk redirects](https://developers.cloudflare.com/rules/url-forwarding/bulk-redirects/) - can affect some or all zones contained within that account.

After you [log in ↗](https://dash.cloudflare.com) and select an account - but before you select a zone - the sidebar will list account-level products.

When you log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com), you can access all accounts where your user is a member. To access account settings and account-level products from within a zone, use the **Accounts** option from the navigation sidebar.

## Zones

Domains (or [subdomains](https://developers.cloudflare.com/dns/zone-setups/subdomain-setup/)) that are added to Cloudflare become zones<sup>[1](#user-content-fn-1)</sup>, which have a direct impact on the security and performance of your website, application, or API. Use your zone to monitor security and performance, update configurations, and apply zone-level products and services.

Zone-level services - such as [Load Balancers](https://developers.cloudflare.com/load-balancing/) and [Cache rules](https://developers.cloudflare.com/cache/how-to/cache-rules/) - only affect your website, application, or API for that zone and not other zones, even if they are contained within the same account.

When you log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com) and choose an account, you can view a list of all zones within that account.

Once you are within a zone, items within the sidebar will be zone-related products. If you need to change to another zone, use the forward arrow next to the zone name or by go back to the homepage of your account.

## Footnotes

1. Similar to [DNS zones ↗](https://www.cloudflare.com/learning/dns/glossary/dns-zone/), but with additional capabilities. [↩](#user-content-fnref-1)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/concepts/accounts-and-zones/#page","headline":"Accounts, zones, and profiles","description":"Understand how Cloudflare organizes resources into user profiles, accounts, and zones, and where settings and products apply.","url":"https://developers.cloudflare.com/fundamentals/concepts/accounts-and-zones/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Allow Cloudflare IP addresses at your origin server and configure your firewall to prevent accidental blocking of proxied traffic.
title: Cloudflare IP addresses
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare IP addresses

Last updated Apr 21, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

When you add a domain to Cloudflare and [proxy its DNS records](https://developers.cloudflare.com/dns/proxy-status/), visitors who look up your domain receive a Cloudflare IP address instead of your origin server's real IP address. This hides your origin server's IP address and allows Cloudflare to optimize, cache, and protect all requests before forwarding them to you.

Cloudflare has several [IP address ranges ↗](https://www.cloudflare.com/ips/) which are shared by all proxied hostnames. Together, these IP addresses form the backbone of Cloudflare's anycast network — a routing method where the same IP address is announced from data centers worldwide, so each visitor's request is routed to a nearby data center.

Note

Cloudflare uses other IP ranges for various products and services, but these addresses will not make connections to your origin.

## Allow Cloudflare IP addresses

All traffic to [proxied DNS records](https://developers.cloudflare.com/dns/proxy-status/) passes through Cloudflare before reaching your origin server. This means that your origin server will stop receiving traffic from individual visitor IP addresses and instead receive traffic from [Cloudflare IP addresses ↗](https://www.cloudflare.com/ips), which are shared by all proxied hostnames.

To your origin server's firewall, this can look like a limited number of sources sending a high volume of traffic — which may trigger automatic blocking or rate limiting. Because all visitor traffic appears to come from Cloudflare IP addresses, blocking these IPs — even accidentally — will prevent visitor traffic from reaching your application.

The guidance above applies to domains that use Cloudflare's HTTP proxy. [Magic Transit](https://developers.cloudflare.com/magic-transit/) works differently — instead of proxying web requests, it protects entire IP networks at the network layer. Cloudflare announces your IP address ranges (prefixes) via BGP so that all traffic destined for your network passes through Cloudflare for inspection and DDoS filtering before being forwarded to your infrastructure.

## Configure origin server

### Allowlist Cloudflare IP addresses

To avoid blocking Cloudflare IP addresses unintentionally, you also want to allow Cloudflare IP addresses at your origin web server.

You can explicitly allow these IP addresses with a [.htaccess file ↗](https://httpd.apache.org/docs/trunk/mod/mod_authz_core.html#require) or by using [iptables ↗](https://www.linode.com/docs/security/firewalls/control-network-traffic-with-iptables/#block-or-allow-traffic-by-port-number-to-create-an-iptables-firewall).

The following example demonstrates how you could use an iptables rule to allow a Cloudflare IP address range. Replace `$ip` below with one of the [Cloudflare IP address ranges ↗](https://www.cloudflare.com/ips). You will need to run this command once for each IP range listed on that page.

```bash
# For IPv4 addresses
iptables -I INPUT -p tcp -m multiport --dports http,https -s $ip -j ACCEPT

# For IPv6 addresses
ip6tables -I INPUT -p tcp -m multiport --dports http,https -s $ip -j ACCEPT
```

For more specific guidance, contact your hosting provider or website administrator.

### Block other IP addresses (recommended)

If someone discovers your origin server's IP address — for example, through historical DNS records or mail server configuration — they could send traffic directly to your server, bypassing Cloudflare's security protections entirely. To prevent this, block all traffic that does not come from Cloudflare IP addresses or the IP addresses of your trusted partners, vendors, or applications.

For example, you might [update your iptables ↗](https://www.linode.com/docs/guides/control-network-traffic-with-iptables/#block-or-allow-traffic-by-port-number-to-create-an-iptables-firewall) with the following commands:

```sh
# For IPv4 addresses
iptables -A INPUT -p tcp -m multiport --dports http,https -j DROP
# For IPv6 addresses
ip6tables -A INPUT -p tcp -m multiport --dports http,https -j DROP
```

For more specific guidance, contact your hosting provider or website administrator.

## Review external tools

To avoid blocking Cloudflare IP addresses unintentionally, review your external tools to check that:

- Any security plugins — such as those for WordPress — allow Cloudflare IP addresses.
- The [ModSecurity ↗](https://github.com/SpiderLabs/ModSecurity) plugin is up to date.

### Further protection

For further recommendations on securing your origin server, refer to our guide on [protecting your origin server](https://developers.cloudflare.com/fundamentals/security/protect-your-origin-server/).

### Customize Cloudflare IP addresses

Enterprise customers who do not want to use Cloudflare IP addresses — which are shared by all proxied hostnames — have two potential alternatives:

- [**Bring Your Own IP (BYOIP)**](https://developers.cloudflare.com/byoip/): Cloudflare announces your IPs (an IP address range you lease/own) in all of our [locations ↗](https://www.cloudflare.com/network/).
- **Static IP addresses**: Cloudflare sets static IP addresses for your domain. For more details, contact your account team.

Business and Enterprise customers can also reduce the number of Cloudflare IPs that their domain shares with other Cloudflare customer domains by [uploading a Custom SSL certificate](https://developers.cloudflare.com/ssl/edge-certificates/custom-certificates/).

### IP range updates

Cloudflare's IP ranges do not change frequently. When they do change, they are added to our [list of IP ranges ↗](https://www.cloudflare.com/en-in/ips/) before being put into production. You can also use the Cloudflare API to programmatically keep your configuration updated.

## AWS VPC routing conflict with Cloudflare IP ranges

Cloudflare uses **172.64.0.0/13** (172.64.0.0–172.71.255.255) as public egress IP space. This range is **not RFC 1918 private space**. RFC 1918 covers 172.16.0.0/12 (172.16.0.0–172.31.255.255), which does not overlap with 172.64.0.0/13.

AWS VPC route tables sometimes include a route covering `172.16.0.0/12` (or a broader supernet such as `172.16.0.0/8`) for Transit Gateway or VPN connectivity. If this route points to an internal target rather than an Internet Gateway, it can capture Cloudflare's 172.64.x.x traffic before it reaches the Internet Gateway, causing connection errors (521, 522) from Cloudflare data centers that use this range.

**To resolve:**

1. Check your AWS VPC route table for any route covering a `172.x.x.x` range that routes to an internal target (Transit Gateway, VPN Gateway, NAT Gateway, or VPC peering connection).
2. Add a more-specific route with destination `172.64.0.0/13` targeting your Internet Gateway. More-specific routes take precedence in AWS routing.
3. Alternatively, narrow the broad route to exactly `172.16.0.0/12` (the RFC 1918 range), which does not include 172.64.0.0/13.

This issue does not appear in security group audits because security groups are evaluated at the instance level, not the routing layer.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/#page","headline":"Cloudflare IP addresses","description":"Allow Cloudflare IP addresses at your origin server and configure your firewall to prevent accidental blocking of proxied traffic.","url":"https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-21","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how Cloudflare acts as your authoritative DNS provider and reverse proxy to optimize, cache, and protect your web traffic.
title: How Cloudflare DNS works
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# How Cloudflare DNS works

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

To optimize your website or web application, Cloudflare provides [DNS ↗](https://www.cloudflare.com/learning/dns/what-is-dns/) and [CDN ↗](https://www.cloudflare.com/learning/cdn/what-is-a-cdn/) services, so we can [reverse proxy ↗](https://www.cloudflare.com/learning/cdn/glossary/reverse-proxy/) the web traffic to and from your domain.

## DNS explained

The Domain Name System (DNS) acts as the Internet's phonebook, translating domain names (for example, `cloudflare.com`) into numerical Internet Protocol (IP) addresses (for example, `103.21.244.0`).

The IP address is like a home address of where a website lives, and the domain name is the human-readable name.

A DNS query is like asking for directions to a place, and the DNS records are the source-of-truth for what exists where. DNS records live in authoritative [DNS servers ↗](https://www.cloudflare.com/learning/dns/dns-server-types/) and provide information about a domain, such as the [IP addresses ↗](https://www.cloudflare.com/learning/dns/glossary/what-is-my-ip-address/) of the servers that host the web content and services on that domain. With this information, Internet browsers know where to find a website or app, so they can render it for visitors using [HTTP ↗](https://www.cloudflare.com/learning/ddos/glossary/hypertext-transfer-protocol-http/).

## Cloudflare as a DNS provider

When you onboard your website or application to Cloudflare, Cloudflare becomes the primary authoritative DNS provider for your domain. As the primary authoritative DNS provider, Cloudflare responds to DNS queries for your domain, and you manage your domain's DNS records via the Cloudflare dashboard or API.

Note

Cloudflare only becomes the primary authoritative DNS provider when you use the default, full DNS setup. For alternative options, refer to [DNS setups](https://developers.cloudflare.com/dns/zone-setups/).

If your [domain's status](https://developers.cloudflare.com/dns/zone-setups/reference/domain-status/) is active and the queried DNS record is set to `proxied`, Cloudflare responds with an [anycast IP address](https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/), instead of the origin IP address defined in your DNS table.

Your domain status is active when your [nameservers are updated](https://developers.cloudflare.com/dns/nameservers/update-nameservers/) to point to Cloudflare and have been authenticated. The [proxy status](https://developers.cloudflare.com/dns/proxy-status/) defines how Cloudflare treats queries for specific DNS records. The [anycast IP address](https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/) is used to distribute traffic amongst Cloudflare's network, which protects your website or app from [DDoS ↗](https://www.cloudflare.com/learning/ddos/what-is-a-ddos-attack/) and other attacks, while optimizing site speed.

## Cloudflare as a reverse proxy

A reverse proxy is a network of servers that sits in front of web servers and either forwards requests to those web servers, or handles requests on behalf of the web servers. Reverse proxies are typically implemented to help increase security, performance, and reliability of websites and web applications.

![The flow of a request from a server through Cloudflare to the origin server when Cloudflare is a reverse proxy.](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1293,height=305,format=webp/_astro/reverse-proxy.BUdeHa1B.png)

When Cloudflare receives a DNS query for your domain, the response is determined by the configuration [set in your DNS table](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/), including the [type of the record](https://developers.cloudflare.com/dns/manage-dns-records/reference/dns-record-types/), the record's [proxy eligibility](https://developers.cloudflare.com/dns/proxy-status/limitations/#proxy-eligibility), and its [proxy status](https://developers.cloudflare.com/dns/proxy-status/#proxied-records).

When DNS records in your DNS table have a `proxied` status, the record's HTTP/HTTPS traffic will route through Cloudflare on its way between the client and the origin server. If the domain's status is active, all HTTP/HTTPS requests for proxied DNS records route through Cloudflare.

Using Cloudflare as a reverse proxy has several benefits, including:

- **Load balancing** A reverse proxy can provide a load balancing solution which distributes incoming traffic evenly among different servers to prevent any single server from becoming overloaded. In the event that a server fails completely, other servers can step up to handle the traffic.
- **Protection from attacks.** With a reverse proxy in place, a web site or service never needs to reveal the IP address of their origin servers, which makes it much harder for attackers to leverage a targeted attack against them, such as a DDoS attack. Instead the attackers will only be able to target the reverse proxy, such as Cloudflare's CDN, which will have tighter security and more resources to fend off a cyber attack.
- **Caching.** A reverse proxy can also cache content, resulting in faster performance. For example, if a user in Paris visits a reverse-proxied website with web servers in Los Angeles, the user might actually connect to a local reverse proxy server in Paris, which will then have to communicate with an origin server in L.A. The proxy server can then cache (or temporarily save) the response data. Subsequent Parisian users who browse the site will then get the locally cached version from the Parisian reverse proxy server, resulting in much faster performance.
- **SSL encryption.** SSL/TLS is essential. Without an SSL/TLS certificate, your visitors will find a warning on their browser stating your website or application is not secure. However, encrypting and decrypting SSL (or TLS) communications for each client can be computationally expensive for an origin server. A reverse proxy can be configured to decrypt all incoming requests and encrypt all outgoing responses, freeing up valuable resources on the origin server.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#page","headline":"How Cloudflare DNS works","description":"Understand how Cloudflare acts as your authoritative DNS provider and reverse proxy to optimize, cache, and protect your web traffic.","url":"https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how public and private traffic on-ramps to and off-ramps from Cloudflare's global network for security and performance.
title: Traffic flow through Cloudflare
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Traffic flow through Cloudflare

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/concepts/traffic-flow-cloudflare/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Internet traffic is made up of people, services, and agents requesting online resources from wherever they are hosted. Your resources may be publicly available, like a website or application that anyone on the Internet can access. Or your resources may be privately available, like an internal app or network that only your employees and partners should be able to access.

Both public and private resources can be connected to the Cloudflare network to ensure only good actors can access what they are supposed to be able to access with high performance.

For example, you may not always want the direct traffic because it can come from malicious sources, like hackers, or in the form of [DDoS attacks ↗](https://www.cloudflare.com/learning/ddos/ddos-attack-tools/how-to-ddos/). Additionally, depending on the location where the request originated, you want to ensure the traffic is [routed through the most efficient and fastest path](https://developers.cloudflare.com/argo-smart-routing/).

## Cloudflare's network

[Cloudflare's global network ↗](https://www.cloudflare.com/network/), coupled with [Anycast ↗](https://www.cloudflare.com/learning/dns/what-is-anycast-dns/) IP addressing, ensures that requests are handled by a Cloudflare server that is as close to the source as possible.

If you want to protect your traffic and ensure it travels efficiently, you need to configure Cloudflare to be in front of whatever you are trying to protect, such as your application, service, or server. How you put your resources behind Cloudflare's network will depend on the type of traffic and how you want to control it.

Note

Cloudflare supports all HTTP methods, with the exception of `CONNECT`, `TRACE`, and `PURGE`, which are restricted. Requests that use restricted methods are not proxied through Cloudflare's network. Note that other Cloudflare products may apply different restrictions on HTTP methods, and behavior can vary depending on the service.

## On-ramp and off-ramp traffic

Traffic that enters Cloudflare's network is referred to as "on-ramping," and traffic that exits Cloudflare's network is referred to as "off-ramping." You may also know this as ingress and egress or "routing your traffic" through a network.

### On-ramp traffic to Cloudflare

When you on-ramp traffic to Cloudflare, this allows Cloudflare to act on, secure, and increase performance of that traffic.

One example of on-ramping traffic to Cloudflare is updating your public website to use Cloudflare as the primary authoritative [DNS provider](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-dns-provider) for your domain.

However, maybe you need to protect a private application that is not directly available on the Internet. In this scenario, you can:

- Connect your private application to Cloudflare using [secure tunnels](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/), and use a [device agent](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to connect as a user.
- For users already connected to a private company network, connect the entire network to Cloudflare using secure tunnels, and any request from a user device will access the private application through those tunnels.

With these options, any request from a user device can access internal private applications via the secure private tunnels.

Refer to the list below for products you can use to on-ramp traffic to Cloudflare.

- [Anycast routing ↗](https://www.cloudflare.com/learning/cdn/glossary/anycast-network/) uses Anycast IP addressing to route traffic to the nearest Cloudflare data center. Selective routing allows an Anycast network to be resilient in the face of high traffic volume, network congestion, and [ DDoS attacks ↗](https://www.cloudflare.com/learning/ddos/what-is-a-ddos-attack/).
- [DNS-based](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-dns-provider) traffic resolves domains onboarded to [Cloudflare's CDN](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/). Cloudflare's DNS directs traffic to Cloudflare's global network of servers instead of a website's origin server.
- [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) connects your resources to Cloudflare without a publicly routable IP address so that your origins can serve traffic through Cloudflare without being vulnerable to attacks that bypass Cloudflare.
- [Magic Transit](https://developers.cloudflare.com/magic-transit/about/) offers DDoS protection, traffic acceleration, and more for on-premise, cloud-hosted, and hybrid networks by accepting IP packets destined for your network, processing them, and outputting the packets to your origin infrastructure.
- The [Cloudflare One Client](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) securely and privately sends traffic from corporate devices to Cloudflare's global network while also applying advanced Zero Trust policies that check for a device's health before it connects to corporate applications.

### Off-ramp traffic from Cloudflare

If you need to ensure traffic leaves Cloudflare's network in a specific way, you can manage how traffic is off-ramped.

For example, if you need to adhere to [regional laws](https://developers.cloudflare.com/data-localization/regional-services/) that dictate user traffic and require data never leaves your country, you can configure off-ramp and on-ramp traffic on servers in the same geographical area.

Or maybe you want to force traffic to off-ramp in a certain country to maintain your user's experience. For example, if you have employees in India who travel frequently, you can configure the off-ramp traffic to always appear to come from India so websites they visit maintain their language and preferences.

You can also utilize [caching](https://developers.cloudflare.com/cache/) to help with performance. Instead of off-ramp traffic going to a server across the globe, Cloudflare can cache that content locally for the user to reduce the overall time for their request.

Refer to the list below for products you can use to off-ramp traffic from Cloudflare.

- [Argo Smart Routing](https://developers.cloudflare.com/argo-smart-routing/) detects real-time network issues and routes your web traffic across the most efficient network path, avoiding congestion.
- [Cache](https://developers.cloudflare.com/cache/) works with cached content to avoid off-ramping to origin servers and instead serving directly from Cloudflare's global network.
- [Regional services](https://developers.cloudflare.com/data-localization/regional-services/) lets you choose which subset of data centers decrypt and service HTTPS traffic, which can help customers who have to meet regional compliance or have preferences for maintaining regional control over their data.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/concepts/traffic-flow-cloudflare/#page","headline":"Traffic flow through Cloudflare","description":"Understand how public and private traffic on-ramps to and off-ramps from Cloudflare's global network for security and performance.","url":"https://developers.cloudflare.com/fundamentals/concepts/traffic-flow-cloudflare/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Read about the various RSS feeds available for Cloudflare's changelogs.
title: Available RSS Feeds
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Available RSS Feeds

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/new-features/available-rss-feeds/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers various RSS feeds as part of our [changelog](https://developers.cloudflare.com/changelog/), which helps you stay up to date on new features and functionality.

For more details on how these feeds are structured, refer to [Consuming RSS Feeds](https://developers.cloudflare.com/fundamentals/new-features/consuming-rss-feeds/).

## Feeds

### Global feed

This feed contains entries for all Cloudflare products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/index.xml)

### Area-specific feeds

Cloudflare also offers RSS feeds scoped to specific product areas or products in the [changelog](https://developers.cloudflare.com/changelog/).

#### Application performance

This feed is for all Application performance products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/application-performance.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/automatic-platform-optimization/">Automatic Platform Optimization</a><a href="https://developers.cloudflare.com/changelog/rss/automatic-platform-optimization.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cache/">Cache / CDN</a><a href="https://developers.cloudflare.com/changelog/rss/cache.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/">Cloudflare for SaaS</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-for-saas.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/dns/">DNS</a><a href="https://developers.cloudflare.com/changelog/rss/dns.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/load-balancing/">Load Balancing</a><a href="https://developers.cloudflare.com/changelog/rss/load-balancing.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/speed/">Speed</a><a href="https://developers.cloudflare.com/changelog/rss/speed.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/ssl/">SSL/TLS</a><a href="https://developers.cloudflare.com/changelog/rss/ssl.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/web-analytics/">Cloudflare Web Analytics</a><a href="https://developers.cloudflare.com/changelog/rss/web-analytics.xml">Subscribe to RSS</a>

</details>

#### Application security

This feed is for all Application security products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/application-security.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/api-shield/">API Shield</a><a href="https://developers.cloudflare.com/changelog/rss/api-shield.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/bots/">Bots</a><a href="https://developers.cloudflare.com/changelog/rss/bots.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/secrets-store/">Secrets Store</a><a href="https://developers.cloudflare.com/changelog/rss/secrets-store.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/security-center/">Security Center</a><a href="https://developers.cloudflare.com/changelog/rss/security-center.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/security/overview/">Security Overview</a><a href="https://developers.cloudflare.com/changelog/rss/security-overview.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/turnstile/">Turnstile</a><a href="https://developers.cloudflare.com/changelog/rss/turnstile.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/waf/">WAF</a><a href="https://developers.cloudflare.com/changelog/rss/waf.xml">Subscribe to RSS</a>

</details>

DDoS ruleset feeds

For [DDoS Protection](https://developers.cloudflare.com/ddos-protection/) updates to managed rulesets, please refer to their independent feeds:

- [Network-layer DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/change-log/network/) [Subscribe to RSS](https://developers.cloudflare.com/ddos-protection/change-log/network/index.xml)
- [HTTP DDoS managed ruleset](https://developers.cloudflare.com/ddos-protection/change-log/http/) [Subscribe to RSS](https://developers.cloudflare.com/ddos-protection/change-log/http/index.xml)

#### Cloudflare One

This feed is for all Cloudflare One products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/cloudflare-one.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/cloudflare-one/access-controls/policies/">Access</a><a href="https://developers.cloudflare.com/changelog/rss/access.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/remote-browser-isolation/">Browser Isolation</a><a href="https://developers.cloudflare.com/changelog/rss/browser-isolation.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/integrations/cloud-and-saas/">CASB</a><a href="https://developers.cloudflare.com/changelog/rss/casb.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-network-firewall/">Cloudflare Network Firewall</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-network-firewall.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/">Cloudflare One</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-one.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-wan/configuration/appliance/">Cloudflare One Appliance</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-one-appliance.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/">Cloudflare One Client</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-one-client.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/">Cloudflare Tunnel for SASE</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-tunnel-sase.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-wan/">Cloudflare WAN</a><a href="https://developers.cloudflare.com/changelog/rss/cloudflare-wan.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/data-localization/">Data Localization Suite</a><a href="https://developers.cloudflare.com/changelog/rss/data-localization.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/insights/dex/">Digital Experience Monitoring</a><a href="https://developers.cloudflare.com/changelog/rss/dex.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/data-loss-prevention/">Data Loss Prevention</a><a href="https://developers.cloudflare.com/changelog/rss/dlp.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/email-security/">Email security</a><a href="https://developers.cloudflare.com/changelog/rss/email-security-cf1.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/traffic-policies/">Gateway</a><a href="https://developers.cloudflare.com/changelog/rss/gateway.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/mesh/">Cloudflare Mesh</a><a href="https://developers.cloudflare.com/changelog/rss/mesh.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/multi-cloud-networking/">Multi-Cloud Networking</a><a href="https://developers.cloudflare.com/changelog/rss/multi-cloud-networking.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/risk-score/">Risk Score</a><a href="https://developers.cloudflare.com/changelog/rss/risk-score.xml">Subscribe to RSS</a>

</details>

#### Consumer services

This feed is for all Consumer services products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/consumer-services.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/1.1.1.1/">1.1.1.1 (DNS Resolver)</a><a href="https://developers.cloudflare.com/changelog/rss/1.1.1.1.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/radar/">Radar</a><a href="https://developers.cloudflare.com/changelog/rss/radar.xml">Subscribe to RSS</a>

</details>

#### Core platform

This feed is for all Core platform products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/core-platform.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/ai-crawl-control/">AI Crawl Control</a><a href="https://developers.cloudflare.com/changelog/rss/ai-crawl-control.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/analytics/">Analytics</a><a href="https://developers.cloudflare.com/changelog/rss/analytics.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/fundamentals/account/account-security/review-audit-logs/">Audit Logs</a><a href="https://developers.cloudflare.com/changelog/rss/audit-logs.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/billing/">Billing</a><a href="https://developers.cloudflare.com/changelog/rss/billing.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/fundamentals/">Cloudflare Fundamentals</a><a href="https://developers.cloudflare.com/changelog/rss/fundamentals.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/fundamentals/api/reference/sdks/">Go SDK</a><a href="https://developers.cloudflare.com/changelog/rss/go-sdk.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/log-explorer/">Log Explorer</a><a href="https://developers.cloudflare.com/changelog/rss/log-explorer.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/logs/">Logs</a><a href="https://developers.cloudflare.com/changelog/rss/logs.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/fundamentals/organizations/">Organizations</a><a href="https://developers.cloudflare.com/changelog/rss/organizations.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/registrar/">Registrar</a><a href="https://developers.cloudflare.com/changelog/rss/registrar.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/resource-tagging/">Resource Tagging</a><a href="https://developers.cloudflare.com/changelog/rss/resource-tagging.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/rules/">Rules</a><a href="https://developers.cloudflare.com/changelog/rss/rules.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/fundamentals/api/reference/sdks/">SDK</a><a href="https://developers.cloudflare.com/changelog/rss/sdk.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/support/">Support</a><a href="https://developers.cloudflare.com/changelog/rss/support.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/terraform/">Terraform</a><a href="https://developers.cloudflare.com/changelog/rss/terraform.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/tunnel/">Cloudflare Tunnel</a><a href="https://developers.cloudflare.com/changelog/rss/tunnel.xml">Subscribe to RSS</a>

</details>

API deprecations feed

Cloudflare also maintains a separate [API deprecations page.](https://developers.cloudflare.com/fundamentals/api/reference/deprecations/)  
[Subscribe to RSS](https://developers.cloudflare.com/fundamentals/api/reference/deprecations/index.xml)

#### Developer platform

This feed is for all Developer platform products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/developer-platform.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/agents/">Agents</a><a href="https://developers.cloudflare.com/changelog/rss/agents.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/ai-gateway/">AI Gateway</a><a href="https://developers.cloudflare.com/changelog/rss/ai-gateway.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/ai-search/">AI Search</a><a href="https://developers.cloudflare.com/changelog/rss/ai-search.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/artifacts/">Artifacts</a><a href="https://developers.cloudflare.com/changelog/rss/artifacts.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/browser-run/">Browser Run</a><a href="https://developers.cloudflare.com/changelog/rss/browser-run.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/containers/">Containers</a><a href="https://developers.cloudflare.com/changelog/rss/containers.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/d1/">D1</a><a href="https://developers.cloudflare.com/changelog/rss/d1.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/durable-objects/">Durable Objects</a><a href="https://developers.cloudflare.com/changelog/rss/durable-objects.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/email-service/">Email Service</a><a href="https://developers.cloudflare.com/changelog/rss/email-service.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/flagship/">Flagship</a><a href="https://developers.cloudflare.com/changelog/rss/flagship.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/hyperdrive/">Hyperdrive</a><a href="https://developers.cloudflare.com/changelog/rss/hyperdrive.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/images/">Cloudflare Images</a><a href="https://developers.cloudflare.com/changelog/rss/images.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/kv/">KV</a><a href="https://developers.cloudflare.com/changelog/rss/kv.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/pages/">Pages</a><a href="https://developers.cloudflare.com/changelog/rss/pages.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/pipelines/">Pipelines</a><a href="https://developers.cloudflare.com/changelog/rss/pipelines.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/privacy-proxy/">Privacy Proxy</a><a href="https://developers.cloudflare.com/changelog/rss/privacy-proxy.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/queues/">Queues</a><a href="https://developers.cloudflare.com/changelog/rss/queues.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/r2/">R2</a><a href="https://developers.cloudflare.com/changelog/rss/r2.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/r2-data-catalog/">R2 Data Catalog</a><a href="https://developers.cloudflare.com/changelog/rss/r2-data-catalog.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/r2-sql/">R2 SQL</a><a href="https://developers.cloudflare.com/changelog/rss/r2-sql.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/realtime/">Realtime</a><a href="https://developers.cloudflare.com/changelog/rss/realtime.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/sandbox/">Sandbox SDK</a><a href="https://developers.cloudflare.com/changelog/rss/sandbox.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/stream/">Stream</a><a href="https://developers.cloudflare.com/changelog/rss/stream.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/vectorize/">Vectorize</a><a href="https://developers.cloudflare.com/changelog/rss/vectorize.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/workers/">Workers</a><a href="https://developers.cloudflare.com/changelog/rss/workers.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/workers-ai/">Workers AI</a><a href="https://developers.cloudflare.com/changelog/rss/workers-ai.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/analytics/analytics-engine/">Workers Analytics Engine</a><a href="https://developers.cloudflare.com/changelog/rss/workers-analytics-engine.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/cloudflare-for-platforms/workers-for-platforms/">Workers for Platforms</a><a href="https://developers.cloudflare.com/changelog/rss/workers-for-platforms.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/workers-vpc/">Workers VPC</a><a href="https://developers.cloudflare.com/changelog/rss/workers-vpc.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/workflows/">Workflows</a><a href="https://developers.cloudflare.com/changelog/rss/workflows.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/zaraz/">Zaraz</a><a href="https://developers.cloudflare.com/changelog/rss/zaraz.xml">Subscribe to RSS</a>

</details>

#### Network security

This feed is for all Network security products in the changelog: [Subscribe to RSS](https://developers.cloudflare.com/changelog/rss/network-security.xml)

<details>

<summary>

Included products

</summary>

- <a href="https://developers.cloudflare.com/magic-transit/">Magic Transit</a><a href="https://developers.cloudflare.com/changelog/rss/magic-transit.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/network-flow/">Network Flow</a><a href="https://developers.cloudflare.com/changelog/rss/network-flow.xml">Subscribe to RSS</a>
- <a href="https://developers.cloudflare.com/network-interconnect/">Network Interconnect</a><a href="https://developers.cloudflare.com/changelog/rss/network-interconnect.xml">Subscribe to RSS</a>

</details>

## Related resources

- [Planned maintenance windows](https://developers.cloudflare.com/support/disruptive-maintenance/)
- [Subscribe to Cloudflare Status](https://developers.cloudflare.com/support/cloudflare-status/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/new-features/available-rss-feeds/#page","headline":"Available RSS Feeds","description":"Read about the various RSS feeds available for Cloudflare's changelogs.","url":"https://developers.cloudflare.com/fundamentals/new-features/available-rss-feeds/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to consume our changelog RSS feeds.
title: Consuming RSS Feeds
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Consuming RSS Feeds

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/new-features/consuming-rss-feeds/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Our [changelogs](https://developers.cloudflare.com/changelog/) are published to [various RSS feeds](https://developers.cloudflare.com/fundamentals/new-features/available-rss-feeds/) with HTML in the `<description>` tag.

In feeds with multiple products, such as the global or product-area feeds, the products associated with a given entry are in the `<category>` tag.

A single product will also appear in the custom `<product>` tag for legacy reasons, but we recommend you use the `<category>`

## Example XML

```xml
<rss version="2.0">
	<channel>
		<title>Cloudflare changelogs</title>
		<description>Updates to various Cloudflare products</description>
		<link>https://developers.cloudflare.com/changelog/</link>
		<item>
			<title>Agents, Workers, Workflows - Build AI Agents with Example Prompts</title>
			<link>https://developers.cloudflare.com/changelog/2025-02-14-example-ai-prompts/</link>
			<guid isPermaLink="true">https://developers.cloudflare.com/changelog/2025-02-14-example-ai-prompts/</guid>
			<description>
				<p>
					We've added an <a href="https://developers.cloudflare.com/workers/get-started/prompting/">example prompt</a> to help you get started with building AI agents and applications on Cloudflare ...
				</p>
			</description>
			<pubDate>Fri, 14 Feb 2025 19:00:00 GMT</pubDate>
			<product>Agents</product>
			<category>Agents</category>
			<category>Workers</category>
			<category>Workflows</category>
		</item>
	</channel>
</rss>
```

## Related resources

You can surface RSS feeds in several different providers, including:

- [Slack ↗](https://slack.com/help/articles/218688467-Add-RSS-feeds-to-Slack)
- [Microsoft Teams ↗](https://learn.microsoft.com/en-us/microsoftteams/m365-custom-connectors)
- [Google Chat ↗](https://developers.google.com/workspace/chat/quickstart/webhooks)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/new-features/consuming-rss-feeds/#page","headline":"Consuming RSS Feeds","description":"Learn how to consume our changelog RSS feeds.","url":"https://developers.cloudflare.com/fundamentals/new-features/consuming-rss-feeds/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Use Cloudflare features like caching, HTTPS, and Crawler Hints to improve your website's search engine rankings.
title: Improve SEO
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Improve SEO

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/performance/improve-seo/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

The goal of Search Engine Optimization (SEO) is to get your website to rank higher on various search engine providers (Google, Bing, etc.).

In practice, SEO is primarily about quality content, user experience, and not making things more difficult for search engine crawlers. While Cloudflare cannot write quality content for you, our service can help with user experience — especially related to [site speed ↗](https://www.cloudflare.com/learning/performance/how-website-speed-boosts-seo/) — and search crawlers.

Tip:

For general guidelines around SEO, refer to [Google's recommendations ↗](https://developers.google.com/search/docs/advanced/guidelines/overview).

## SEO improvements with Cloudflare

Several Cloudflare features improve Search Engine site rankings. However, meaningful and regularly updated site content is still crucial to improving SEO.

### Increase site speed

Since at least 2010, Google has publicly stated that [site speed affects your Google ranking ↗](https://webmasters.googleblog.com/2010/04/using-site-speed-in-web-search-ranking.html).

Cloudflare offers multiple features to [optimize site performance](https://developers.cloudflare.com/speed/).

### Enable HTTPS

Since search engines use HTTPS as [a ranking signal ↗](https://webmasters.googleblog.com/2014/08/https-as-ranking-signal.html), HTTPS is vital for SEO.

To make sure your domain is accessible over HTTPS:

1. Get an [SSL/TLS certificate](https://developers.cloudflare.com/ssl/get-started/) for your domain.
2. [Redirect visitors](https://developers.cloudflare.com/ssl/edge-certificates/encrypt-visitor-traffic/) to the HTTPS version of your domain.

### Enable Crawler Hints

With [Crawler Hints](https://developers.cloudflare.com/cache/advanced-configuration/crawler-hints/), search engines and other bot-powered experiences have the freshest version of your content, translating into happier users and ultimately influencing search rankings.

## Troubleshooting

Depending on your domain's security settings, you might accidentally block search engine crawlers.

If you notice SEO issues, make sure your:

- [WAF custom rules](https://developers.cloudflare.com/waf/troubleshooting/faq/#caution-about-potentially-blocking-bots) are allowing **Verified Bots**.
- [Rate limiting rules](https://developers.cloudflare.com/waf/rate-limiting-rules/) are allowing **Verified Bots**.
- [Bot protection](https://developers.cloudflare.com/bots/concepts/bot/verified-bots/) settings are not blocking **Verified Bots**.

If you still notice issues with search engine crawlers, refer to our [Troubleshooting guide](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/troubleshooting-crawl-errors/).

## Common misconceptions

The following characteristics do not affect your domain's SEO:

- **Changing your nameservers**: Using Cloudflare's nameservers does not affect your domain's SEO.
- **Server location**: According to Google, [server location ↗](http://www.seroundtable.com/seo-geo-location-server-google-17468.html) is not important for SEO.
- **Sites sharing IP addresses**: Search engines do not generally penalize domains using shared IP addresses unless several of these sites are malicious or spammy.
- **Cloudflare caching**: When Cloudflare caches your content, it actually speeds up content delivery and only improves SEO. Our caching does not create duplicate content, rewrite URLs, or create additional subdomains.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/performance/improve-seo/#page","headline":"Improve SEO","description":"Use Cloudflare features like caching, HTTPS, and Crawler Hints to improve your website's search engine rankings.","url":"https://developers.cloudflare.com/fundamentals/performance/improve-seo/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Make your website temporarily unavailable during large changes using Cloudflare Workers, Waiting Room, or Access.
title: Maintenance mode
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Maintenance mode

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/performance/maintenance-mode/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If you need to make large changes to your website, you may want to make your site temporarily unavailable.

## With code

If you are familiar with code, [create a Worker](https://developers.cloudflare.com/workers/get-started/guide/) that returns an [HTML page](https://developers.cloudflare.com/workers/examples/return-html/) to any site visitors.

![Workers maintenance page returned instead of your website](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=618,height=271,format=webp/_astro/workers-page.DnkGi-jv.png)

## Without code

### Business and Enterprise

For a maintenance page without code, Business and Enterprise uses can create a [Cloudflare Waiting Room](https://developers.cloudflare.com/waiting-room/how-to/create-waiting-room/).

Certain customization and queue options depend on your [plan](https://developers.cloudflare.com/waiting-room/plans/).

![Waiting room page returned instead of your website](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1042,height=544,format=webp/_astro/waiting-room-page.C-z8rg-V.png)

### All plans

Users on all plans can [create an Access application](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/). Make sure to limit your [Access policy](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/policy-management/#create-a-policy) to only include yourself and any collaborators.

If needed, you can also further [customize the login page](https://developers.cloudflare.com/cloudflare-one/reusable-components/custom-pages/access-login-page/).

![Example Access login page](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=618,height=510,format=webp/_astro/access-page.C47nT0tE.png)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/performance/maintenance-mode/#page","headline":"Maintenance mode","description":"Make your website temporarily unavailable during large changes using Cloudflare Workers, Waiting Room, or Access.","url":"https://developers.cloudflare.com/fundamentals/performance/maintenance-mode/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to minimize downtime while onboarding your domain onto Cloudflare.
title: Minimize downtime
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Minimize downtime

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/performance/minimize-downtime/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

When making any change to the routing of an Internet application, there is always a possibility of downtime due to certificate issuance, misconfigured settings, or limitations at your origin server. To avoid downtime when going live, it is important to review the most common configurations.

## Update and review DNS records

Before activating your domain on Cloudflare (exact steps depend on your [DNS setup](https://developers.cloudflare.com/dns/zone-setups/)), review the DNS records in your Cloudflare account.

### Start with unproxied records

With a new domain, make sure all of your DNS records have a [proxy status](https://developers.cloudflare.com/dns/proxy-status/) of **DNS-only**.

This setting prevents Cloudflare from proxying your traffic before you have an active edge certificate or before you have allowed Cloudflare IP addresses.

### Confirm record accuracy

Take extra time to confirm the accuracy of your DNS records before activating your domain, paying special attention to:

- [Zone apex records ( `example.com`)](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-zone-apex/)
- [Subdomain records ( `www.example.com` or `blog.example.com`)](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-subdomain/)
- [Email records](https://developers.cloudflare.com/dns/manage-dns-records/how-to/email-records/)

If you add DNS records to your authoritative DNS provider between onboarding your domain and activating your domain, you may need to also add these records within Cloudflare.

## Activate your domain

Finish the [DNS setup](https://developers.cloudflare.com/dns/zone-setups/) for your domain, moving the [domain status](https://developers.cloudflare.com/dns/zone-setups/reference/domain-status/) to **Active**:

- [Full setups](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/): Update the authoritative nameservers at your registrar and wait for that change to be authenticated.
- [Partial setups](https://developers.cloudflare.com/dns/zone-setups/partial-setup/setup/): Add the verification TXT record to your authoritative DNS and wait for that change to be authenticated.

## Verify SSL/TLS edge certificates

Before proxying your traffic through Cloudflare, [verify](https://developers.cloudflare.com/ssl/reference/certificate-statuses/#monitor-certificate-statuses) that Cloudflare has an active **Edge Certificate** for your domain.

For more details about timing and certificate recommendations, refer to [Certificate issuance](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/enable-universal-ssl/#full-dns-setup).

## Optional - Test configuration

You may want to test your configuration using your local machine or proxying traffic from a development domain or subdomain.

If you experience issues, you should make sure that you have [allowed Cloudflare IP addresses](https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/) at your origin server.

## Update proxy status

Once you have verified that your SSL/TLS edge certificate is active and you have allowed Cloudflare IP addresses, change the [proxy status](https://developers.cloudflare.com/dns/proxy-status/) of appropriate DNS records to **Proxied**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/performance/minimize-downtime/#page","headline":"Minimize downtime","description":"Learn how to minimize downtime while onboarding your domain onto Cloudflare.","url":"https://developers.cloudflare.com/fundamentals/performance/minimize-downtime/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Optimize your website performance with Cloudflare Speed tools and settings.
title: Speed
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/speed/llms.txt  
> Use this file to discover all available pages before exploring further.

# Speed

Last updated Jun 15, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/speed/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Improve the performance of your website or web application.

Available on all plans

Speed allows you to assess the performance of your website and get recommendations of Cloudflare products to enhance the website performance.

---

## Features

[Observatory](https://developers.cloudflare.com/speed/observatory/)

Use Observatory to conduct tests with both synthetic and real user data to identify potential website performance enhancements.

Use Observatory

[Origin Analytics](https://developers.cloudflare.com/speed/origin-analytics/)

See how your origin server responds to Cloudflare. Identify slow endpoints, monitor response times, and diagnose errors.

Use Origin Analytics

[Settings](https://developers.cloudflare.com/speed/optimization/)

Get recommendations of Cloudflare products and settings to improve your website’s performance.

Use Settings

[Aggregated Internet Measurement](https://developers.cloudflare.com/speed/aim/)

Understand your Internet quality to identify scenarios that your Internet connection is good or bad for.

Use Aggregated Internet Measurement

---

## Related products

[Cache rules](https://developers.cloudflare.com/cache/how-to/cache-rules/)

Customize the cache properties of your HTTP requests.

[Cloudflare Web Analytics](https://developers.cloudflare.com/web-analytics/)

Understand the performance of your webpages as experienced by your site visitors.

[Cloudflare Image Resizing](https://developers.cloudflare.com/images/optimization/transformations/overview/)

Transform images on Cloudflare's edge platform: resize, adjust quality, and convert images to WebP or AVIF format on demand.

[Early Hints](https://developers.cloudflare.com/cache/advanced-configuration/early-hints/)

Take advantage of "server think time" to asynchronously send instructions to the browser to begin loading resources while the origin server is compiling the full response.

---

## More resources

### [Quotas](https://developers.cloudflare.com/speed/observatory/run-speed-test/#quotas)

Learn about the quota limits for the number of tests you can run per month.

### [Community Forum](https://community.cloudflare.com/c/website-application-performance/88)

Engage with other users and explore more resources on Cloudflare support forum.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/speed/#page","headline":"Speed","description":"Optimize your website performance with Cloudflare Speed tools and settings.","url":"https://developers.cloudflare.com/speed/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-06-15","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Prepare your site for traffic surges.
title: Prerequisites
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/learning-paths/llms.txt  
> Use this file to discover all available pages before exploring further.

# Prerequisites

Last updated Sep 9, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/learning-paths/surge-readiness/concepts/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Reach out to your account team at least 30 days prior to the expected traffic surge to schedule a Security Optimization walkthrough with your Customer Solution Engineer.

To learn more about our service offerings, refer to [Customer Success offerings ↗](https://www.cloudflare.com/success-offerings/).

## Register your users

For the security and protection of your account, be sure to register all account users.

1. In the Cloudflare dashboard, go to the **Manage Account** > **Members** page. [Go to **Members** ↗](https://dash.cloudflare.com/?to=/:account/members)
2. Select more than one Super Administrator to ensure appropriate access when needed.

Note

Refer to [Manage members](https://developers.cloudflare.com/fundamentals/manage-members/) to learn how to review and update registered account users.

Failure to register account users can create issues with our ticketing system. Unverified users who contact support will be funneled to the self-serve queue rather than the Enterprise queue which can result in long wait times.

We strongly advise against credential-sharing which can jeopardize the trust and safety of your account.

## Confirm user and domain administration

- **Multi-User:** Provide role-based permissions to a group of users to better control the administration of your domains. Each user has their own role and limited API key.
- **Enforce 2FA:** Ensure your entire dashboard is secure by [enforcing 2-factor authentication](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/) for your organization.
  - To disable 2FA, submit a support ticket and allow 1-2 business days to validate your request.
- **Leverage API Access:** Work easily with our system programmatically using our [API ↗](https://api.cloudflare.com).

## Additional items

- Check when your [SSL Certificates expire (only custom and origin certificates)](https://developers.cloudflare.com/ssl/edge-certificates/custom-certificates/renewing/) Note

  Certificates managed by Cloudflare are auto-renewed.
- Review your Operational and Disaster recovery preparedness
  - Enable Load Balancing with smart cache strategies: Use [Cloudflare Load Balancing](https://developers.cloudflare.com/reference-architecture/architectures/load-balancing) to distribute traffic across multiple healthy origins, and increase cache-hit ratios by leveraging [custom cache rules](https://developers.cloudflare.com/cache/performance-review/cache-analytics) and [edge compute ↗](https://www.cloudflare.com/learning/cdn/caching-static-and-dynamic-content/) (e.g., Cloudflare Workers) to offload origin traffic during high-demand periods.
  - Configure failover pools and back up DNS with a playbook: Set up [Cloudflare Load Balancer failover pools](https://developers.cloudflare.com/reference-architecture/architectures/load-balancing) to automatically redirect traffic to healthy origins if one fails. Export DNS records for safekeeping and prepare a clear [incident response plan ↗](https://www.cloudflare.com/learning/performance/preventing-downtime) that includes steps for re-routing or recovery.
- Review and update your current users' access
- Check your domain registry validity

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/learning-paths/surge-readiness/concepts/#page","headline":"Prerequisites","description":"Prepare your site for traffic surges.","url":"https://developers.cloudflare.com/learning-paths/surge-readiness/concepts/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-09","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Test your website speed and Internet connection using Cloudflare dashboard tools and third-party services.
title: Test speed
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Test speed

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/performance/test-speed/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers several tools to test the speed of your website, as well as the speed of your Internet connection.

---

## Test website speed

### Using Cloudflare

Once your domain is [active on Cloudflare](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/), you can run speed tests within the [Cloudflare dashboard ↗](https://dash.cloudflare.com/?to=/:account/:zone/speed).

This speed test will provide information about critical loading times, performance with and without [Cloudflare's proxy](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/), and recommended optimizations.

If you experience any issues, make sure you are not blocking specific [user agents](https://developers.cloudflare.com/fundamentals/reference/cloudflare-site-crawling/#other-situations).

### Using third-party tools

If your domain is not yet active on Cloudflare or you want to measure the before and after improvements of using Cloudflare, Cloudflare recommends using the following third-party tools:

- [PageGym ↗](https://pagegym.com/)
- [GTmetrix ↗](https://gtmetrix.com/)
- [DebugBear ↗](https://www.debugbear.com/test/website-speed)
- [Lighthouse ↗](https://developer.chrome.com/docs/lighthouse/)
- [WebPageTest ↗](https://www.webpagetest.org/)

If you use these third-party tools, you should do the following to test website speed:

1. [Pause Cloudflare](https://developers.cloudflare.com/fundamentals/manage-domains/pause-cloudflare/) to remove performance and caching benefits.
2. Run a speed test.
3. Unpause Cloudflare.
4. Run a speed test<sup>[1](#user-content-fn-1)</sup>.
5. Run a second speed test to get your baseline performance with Cloudflare.

### Improve speed

Based on the results of these speed tests, you may want to explore other ways to [optimize your site speed](https://developers.cloudflare.com/speed/) using Cloudflare.

Note

Cloudflare does not consider Time to First Byte (TTFB) the most important measure of page load speed. If you are concerned about a slower TTFB while using Cloudflare, refer to our blog post about [Cloudflare and TTFB ↗](http://blog.cloudflare.com/ttfb-time-to-first-byte-considered-meaningles/).

---

## Test Internet speed

To test the speed of your home network connection (download, update, packet loss, ping measurements, and more), visit [speed.cloudflare.com ↗](https://speed.cloudflare.com).

## Footnotes

1. The results of your first speed test with Cloudflare will likely contain uncached results, which will provide inaccurate results.  
     
   One of the key ways Cloudflare speeds up your site is through [caching](https://developers.cloudflare.com/cache/), which will appear in the results of the second test. [↩](#user-content-fnref-1)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/performance/test-speed/#page","headline":"Test speed","description":"Test your website speed and Internet connection using Cloudflare dashboard tools and third-party services.","url":"https://developers.cloudflare.com/fundamentals/performance/test-speed/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Protect your Cloudflare account and domains by decentralizing access, managing billing, and planning for continuity.
title: Account and domain management best practices
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Account and domain management best practices

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/best-practices/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

More and more of our lives revolve around our online presence and maintaining access to our various online accounts, such as social media, banking, personal, and business accounts. These accounts are critical to remaining connected with our loved ones and business. As such, ensuring a level of continuity with these services is critical. Below is a list of important items to help ensure you are able to maintain access or delegate access to your Cloudflare account in the event that you are unable to manage your account.

You can lose access to your account and or domain for several reasons: Death, divorce, disgruntled employee, or simply missing an email notification.

To help prevent loss of access:

- Decentralize access to your account.
- Protect yourself by following good password management practices.
- Maintain control of your domain name.
- Save your 2FA backup keys.

## Relationships, partnerships, and business ventures

Ensuring equal access with your partner, spouse, or your business partner is important to ensuring your account or domain names remain active.

If you have a domain name or a portfolio of domain names for your business, ensuring you have a strict organization policy when it comes to vendor account creation or domain name registration is critical. The steps below will ensure your organization is the owner of the account and or domain names:

- Ensure the registrant of the domain name is your organization's name.
- Ensure the vendor account is in your organization's name.
- Ensure that access to the email address used to set up these accounts is decentralized, but can still be used to send emails. Do not use a distribution list email address.

## Email addresses

If you are operating a business, use an email address that is not tied to the domain name itself, such as `john@example.com`; instead, use one of the many well known email providers as best practice. Additionally, the email address itself should be one that is shared with your business partner with a name such as `ourbusiness@example.com`. This is important because many companies require the person who is contacting them for support have access to the email address associated with the account.

## Billing information

Most if not all online services have automated billing processes that will attempt to bill the current or default credit card on file. Maintaining your billing information to avoid any payment failure is critical, as this can cause service disruptions if there is a failed billing attempt that is not resovlved in a timely manner.

## Deceased account holder or registrant

While often overlooked, an important part of having an online presence is ensuring continuity in the event of an unexpected accident or incapacitation of the account holder. Create clear instructions for domain or account management in the event the account holder is unable to administer the account. If you learn no instructions are available on how to access the account of the deceased, Cloudflare may be able to assist you.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/best-practices/#page","headline":"Account and domain management best practices","description":"Protect your Cloudflare account and domains by decentralizing access, managing billing, and planning for continuity.","url":"https://developers.cloudflare.com/fundamentals/reference/best-practices/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand the Cloudflare-managed /cdn-cgi/ endpoint added to proxied domains and how various products use it.
title: /cdn-cgi/ endpoint
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# /cdn-cgi/ endpoint

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/cdn-cgi-endpoint/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

When you [add a domain to Cloudflare](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/), Cloudflare adds a `/cdn-cgi/` endpoint (`www.example.com/cdn-cgi/`) to that domain.

This endpoint is managed and served by Cloudflare. It cannot be modified or customized. The endpoint is not used by every Cloudflare product, but you may find some products use the endpoint in its URL.

A few examples include (but are not limited to):

- [Identify the Cloudflare data center serving your request](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#identify-the-cloudflare-data-center-serving-your-request), which is helpful for troubleshooting ( `https://<YOUR_DOMAIN>/cdn-cgi/trace`).
- [JavaScript detection](https://developers.cloudflare.com/bots/additional-configurations/javascript-detections/) used by Cloudflare bot products ( `example.com/cdn-cgi/challenge-platform/`)
- [Image transformations](https://developers.cloudflare.com/images/optimization/transformations/overview/) in the new URLs you would use for images ( `example.com/cdn-cgi/image/`)
- [Email address obfuscation](https://developers.cloudflare.com/waf/tools/scrape-shield/email-address-obfuscation/) used to hide email addresses from malicious bots ( `example.com/cdn-cgi/l/email-protection`)
- [Web analytics](https://developers.cloudflare.com/web-analytics/get-started/#sites-proxied-through-cloudflare) for a website proxied through Cloudflare ( `example.com/cdn-cgi/rum`). This endpoint returns a `204` HTTP status code.
- [Speed Brain](https://developers.cloudflare.com/speed/optimization/content/speed-brain/) adds an HTTP header called `Speculation-Rules` to web page responses. This header contains a URL that hosts an opinionated Speculation-Rules configuration, which instructs the browser to initiate prefetch requests for anticipated future navigations.

## Recommended exclusions

### Exclude from security scanners

Some scanners may display an error because certain `/cdn-cgi/` endpoints do not have an [HSTS setting](https://developers.cloudflare.com/ssl/edge-certificates/additional-options/http-strict-transport-security/) applied to it or for similar reasons. Because the endpoint is managed by Cloudflare, you can ignore the error and do not need to worry about it.

To prevent scanner errors, omit the `/cdn-cgi/` endpoint from your security scans.

### Disallow using robots.txt

`/cdn-cgi/` also can cause issues with various web crawlers.

Search engine crawlers can encounter [errors when crawling these endpoints](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/troubleshooting-crawl-errors/) and — though these errors do not impact site rankings — they may surface in your webmaster dashboard.

SEO and other web crawlers may also mistakenly crawl these endpoints, thinking that they are part of your site's content.

As a best practice, update your `robots.txt` file to include `Disallow: /cdn-cgi/`.

Note

If you serve transformations through [Images](https://developers.cloudflare.com/images/optimization/transformations/overview/), a blanket `Disallow: /cdn-cgi/` prevents search engines from indexing your transformed images served from `/cdn-cgi/image/`. To allow crawlers to discover these images, add an `Allow` rule before the `Disallow`:

```txt
Allow: /cdn-cgi/image/
Disallow: /cdn-cgi/
```

The more specific `Allow` path takes precedence over the broader `Disallow`, so crawlers will still be blocked from other `/cdn-cgi/` endpoints.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/cdn-cgi-endpoint/#page","headline":"/cdn-cgi/ endpoint","description":"Understand the Cloudflare-managed /cdn-cgi/ endpoint added to proxied domains and how various products use it.","url":"https://developers.cloudflare.com/fundamentals/reference/cdn-cgi-endpoint/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Use Cloudflare Ray IDs to identify and trace individual requests through Security Events, Log Explorer, and server logs.
title: Cloudflare Ray ID
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare Ray ID

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/cloudflare-ray-id/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

A **Cloudflare Ray ID** is an identifier given to every request that goes through Cloudflare.

Ray IDs are particularly useful when evaluating Security Events for patterns or false positives or more generally understanding your application traffic.

Ray IDs are added as a [request header, cf-ray](https://developers.cloudflare.com/fundamentals/reference/http-headers/#cf-ray), to the connection from Cloudflare to the origin web server. As such the Ray IDs can be found using the Developer Tools in your browser or using curl with the `-v` option to show the headers.

Caution

Ray IDs are not guaranteed to be unique for every request. In some situations, different requests may have the same Ray ID.

## Look up Ray IDs

### Security events

All customers can view Ray IDs and associated information — IP address, user agent, ASN, etc. — by looking through [sampled logs](https://developers.cloudflare.com/waf/analytics/security-events/#sampled-logs) in Security Events.

![Example list of events in sampled logs, with the Ray ID highlighted from one of the expanded events to show its details](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1132,height=1367,format=webp/_astro/ray-id.CkgisnhS.png)

Additionally, you can [add filters](https://developers.cloudflare.com/waf/analytics/security-events/#adjust-displayed-data) to look for specific Ray IDs.

![Example of adding a new filter in Security Events for the Block action](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=929,height=281,format=webp/_astro/events-add-filter.DDUuZ0g7.png)

Please note that Security Events may use sampled data to improve performance. If sampled data is applied to your search, you might not see all events, and filters might not return the expected results. To display more events, select a smaller timeframe.

### Log Explorer

[Log Explorer](https://developers.cloudflare.com/log-explorer/) provides access to Cloudflare logs with all the context available within the Cloudflare platform. You can monitor security and performance issues with custom dashboards or investigate and troubleshoot issues with log search. Log explorer allows you to [build queries](https://developers.cloudflare.com/log-explorer/log-search/) for filtering specific Ray IDs.

### Logs

Enterprise customers can enable Ray ID as a field in their [Cloudflare Logs](https://developers.cloudflare.com/logs/).

### Server logs

For more details about sending Ray IDs to your server logs, refer to the [Cf-Ray](https://developers.cloudflare.com/fundamentals/reference/http-headers/#cf-ray) header.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/cloudflare-ray-id/#page","headline":"Cloudflare Ray ID","description":"Use Cloudflare Ray IDs to identify and trace individual requests through Security Events, Log Explorer, and server logs.","url":"https://developers.cloudflare.com/fundamentals/reference/cloudflare-ray-id/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the user agents and situations in which Cloudflare crawls or makes HTTP requests to your site.
title: Cloudflare crawlers
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare crawlers

Last updated Aug 6, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/cloudflare-site-crawling/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare may crawl or make HTTP requests to your site to make sure its protected and performing properly.

## Crawling situations

### Specific products

Cloudflare will crawl your site when you have specific products enabled:

- [**Always Online**](https://developers.cloudflare.com/cache/how-to/always-online/)
  - *User-Agent*: `Mozilla/5.0 (compatible; CloudFlare-AlwaysOnline/1.0; +http://www.cloudflare.com/always-online)`
- [**Health checks**](https://developers.cloudflare.com/health-checks/)
  - *User-Agent*: `Mozilla/5.0 (compatible; Cloudflare-Healthchecks/1.0; +https://www.cloudflare.com/; healthcheck-id: <HEALTHCHECK_ID>)`
  - `HEALTHCHECK_ID` is a 16-character string associated with the health check ID.
- [**Load balancing monitors**](https://developers.cloudflare.com/load-balancing/monitors/)
  - *User-Agent*: `Mozilla/5.0 (compatible; Cloudflare-Traffic-Manager/1.0; +https://www.cloudflare.com/traffic-manager/; pool-id: <POOL_ID>)`
  - `POOL_ID` is a 16-character string associated with the load balancing pool ID being monitored.
- [**Prefetch URLs**](https://developers.cloudflare.com/speed/optimization/content/prefetch-urls/)
  - *User-Agent*: `Mozilla/5.0 (compatible; CloudFlare-Prefetch/0.1; +http://www.cloudflare.com/)`
- [**SSL/TLS recommender**](https://developers.cloudflare.com/ssl/origin-configuration/ssl-tls-recommender/)
  - *User-Agent*: `Cloudflare-SSLDetector`
  - This crawler ignores your `robots.txt` file unless there are rules explicitly targeting the user agent.
- [**Security Insights**](https://developers.cloudflare.com/security/security-insights/review-insights/)
  - *User-Agent*: `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36 (compatible; +https://developers.cloudflare.com/security-center/)`

### Other situations

Cloudflare will also crawl your site in other, specific situations:

- **Speed tests**
  - *User-Agent*: `Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36 PTST/190628.140653`
  - *Triggered when*: You launch a speed test from within [the Cloudflare dashboard](https://developers.cloudflare.com/speed/observatory/run-speed-test/).
- **Support diagnostics**:
  - *User-Agent*: `Cloudflare-diagnostics`
  - *Triggered when*: Cloudflare Support Engineers perform error checks and by continuous monitoring used to raise intelligent alerts in the Cloudflare dashboard.
- **Custom Hostname validation**:
  - *User-Agent*: `Cloudflare Custom Hostname Verification`
  - *Triggered when*: You choose to validate a custom hostname with an [HTTP ownership token](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/domain-support/hostname-validation/pre-validation/#http-tokens).

## Developer product crawlers

[**Browser Run**](https://developers.cloudflare.com/browser-run/) is a Cloudflare developer product that can crawl third-party websites on behalf of Cloudflare customers. Unlike the crawlers in the Crawling situations section, it does not crawl your site as part of a Cloudflare service you have enabled. It is used by developers building applications with Cloudflare's platform.

The [**Browser Run /crawl endpoint**](https://developers.cloudflare.com/browser-run/quick-actions/crawl-endpoint/) uses a *User-Agent* of `CloudflareBrowserRenderingCrawler/1.0`. For non-configurable headers, bot detection IDs, and cryptographic verification methods you can use to identify or block Browser Run traffic, refer to [Automatic request headers](https://developers.cloudflare.com/browser-run/reference/automatic-request-headers/).

[**AI Search**](https://developers.cloudflare.com/ai-search/) is a Cloudflare developer product that indexes your website content so it can be searched. The AI Search crawler only crawls a website you own (the domain must exist in the same Cloudflare account) that you select as your data source in AI Search.

The crawler uses a *User-Agent* of `Cloudflare-AI-Search`. You can allow or block it with WAF rules using its [bot detection ID](https://developers.cloudflare.com/ai-search/configuration/data-source/website/#allow-ai-search-through-waf).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/cloudflare-site-crawling/#page","headline":"Cloudflare crawlers","description":"Review the user agents and situations in which Cloudflare crawls or makes HTTP requests to your site.","url":"https://developers.cloudflare.com/fundamentals/reference/cloudflare-site-crawling/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-06","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Cloudy is Cloudflare's AI agent that helps you understand and optimize your Cloudflare configurations across multiple products.
title: Cloudy AI agent (beta)
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudy AI agent (beta)

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/cloudy-ai-agent/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudy is Cloudflare's first version of an AI agent, with assistant-like functionality designed to help users understand and improve their Cloudflare configurations in multiple areas of the product suite.

Cloudy is powered by [Workers AI](https://developers.cloudflare.com/workers-ai/) and helps identify and solve issues such as identifying redundant rules, optimizing execution order, analyzing conflicting rules, and identifying disabled rules. Cloudy can also help investigate threat events and provide actionable recommendations.

## Availability

Cloudy, currently in beta, is available in several Cloudflare products such as WAF, Zero Trust, and Analytics. Throughout the rest of 2025, Cloudflare plans to roll out additional AI agent capabilities across other areas of Cloudflare.

Send us your feedback

We want to hear your thoughts as you get to meet Cloudy and try out these new AI features. You can send feedback to us at [cloudyfeedback@cloudflare.com](mailto:cloudyfeedback@cloudflare.com). Your feedback will help shape our roadmap for AI enhancement, and bring our users smarter, more efficient tooling that helps everyone get more secure.

## What data does Cloudy have access to?

Cloudy has access to your Cloudflare configuration. It combines this data with a purpose-built LLM prompt.

Additionally, Cloudy takes Role-Based Access Control (RBAC) restrictions into account: it can only access the same Cloudflare configuration settings as the currently logged in user, based on their [roles and permissions](https://developers.cloudflare.com/fundamentals/manage-members/roles/).

All your configuration information is only included in the purpose-built prompt — it is not used to train Cloudy or the LLM model(s) powering it.

## Is Cloudy trained on user or customer data?

No. Your Cloudflare configuration is used in the purpose-built prompt that enables Cloudy to turn raw configuration data into consistent, clear summaries and actionable recommendations.

Cloudy does not share your Cloudflare configuration with other customers. Your configuration is also not used for LLM model training.

Cloudy brings the same enterprise-grade security as the rest of Cloudflare's offerings. You can learn more about Cloudflare's approach to responsible AI in the [Trust Hub ↗](https://www.cloudflare.com/trust-hub/responsible-ai/).

## Can I opt out of Cloudy?

Currently, Cloudflare does not provide an opt out mechanism that completely disables all possible use of Cloudy. You can only opt out of the chat interface available in the Cloudflare dashboard.

However, Cloudy is an entirely optional tool that you can choose not to use. By not using Cloudy, you will not get summaries based on your current configuration or any actionable recommendations.

To opt out of the chat interface, do the following:

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and select your account.
2. Go to **Manage Account** > **Configurations**.
3. Turn off the **Cloudy features** setting.

As noted above, Cloudy is not trained on user or customer data and does not share your Cloudflare setup with other customers.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/cloudy-ai-agent/#page","headline":"Cloudy AI agent (beta)","description":"Cloudy is Cloudflare's AI agent that helps you understand and optimize your Cloudflare configurations across multiple products.","url":"https://developers.cloudflare.com/fundamentals/reference/cloudy-ai-agent/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review TCP and HTTP connection timeouts between clients, Cloudflare, and origin servers, including keep-alive and request limits.
title: Connection limits
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Connection limits

Last updated Jul 23, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/connection-limits/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

When HTTP/HTTPS traffic is [proxied through Cloudflare](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-reverse-proxy), there are often two established [TCP connections](https://developers.cloudflare.com/fundamentals/reference/tcp-connections/): the first is between the requesting client to Cloudflare and the second is between Cloudflare and the origin server. Each connection has their own set of TCP and HTTP limits, which are documented below.

## Between client and Cloudflare

| Type | Limit (seconds) | HTTP status code at limit | Configurable |
| --- | --- | --- | --- |
| Connection Keep-Alive HTTP/1.1 | 400 | TCP connection closed | No |
| Connection Idle HTTP/2 | 400 | TCP connection closed | No |

## Between Cloudflare and origin server

Note

If you are using [Cloudflare tunnels](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/), refer to [Origin configuration](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/origin-parameters/) to view or modify your connection settings.

| Type | Limit (seconds) | HTTP status code at limit | [Configurable](https://developers.cloudflare.com/fundamentals/reference/connection-limits/#configurable-limits) |
| --- | --- | --- | --- |
| Complete TCP Connection | 19 | [522](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-522/) | No |
| TCP ACK Timeout | 90 | [522](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-522/) | No |
| TCP Keep-Alive Interval | 30 | [520](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-520/) | No |
| Proxy Idle Timeout | 900 | [520](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-520/) | No |
| Proxy Read Timeout | 125 | [524](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-524/) | [Yes, for Enterprise zones](https://developers.cloudflare.com/api/resources/zones/subresources/settings/methods/edit/) |
| Proxy Write Timeout | 30 | [524](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-524/) | No |
| HTTP/2 Pings to Origin | Off | - | Yes |
| HTTP/2 Connection Idle | 900 | No | No |

## Configurable limits

Some TCP connections can be customized for Enterprise customers. Reach out to your account team for more details.

## Keep-Alives

Cloudflare maintains keep-alive connections to improve performance and reduce cost of recurring TCP connects in the request transaction as Cloudflare proxies customer traffic from its global network to the site's origin server.

Ensure HTTP keep-alive connections are enabled on your origin. Cloudflare reuses open TCP connections up to the `Proxy Idle Timeout` limit after the last HTTP request. Origin web servers close TCP connections if too many are open. HTTP keep-alive helps avoid connection resets for requests proxied by Cloudflare.

## Request limits

URLs have a limit of 16 KB. Request headers have a total limit of 128 KB.

## Response limits

Response headers observe a total limit of 128 KB.

## Cache limits

Refer to the [Cache documentation](https://developers.cloudflare.com/cache/concepts/default-cache-behavior/#customization-options-and-limits) for more details about the max upload size and the cacheable file size limits.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/connection-limits/#page","headline":"Connection limits","description":"Review TCP and HTTP connection timeouts between clients, Cloudflare, and origin servers, including keep-alive and request limits.","url":"https://developers.cloudflare.com/fundamentals/reference/connection-limits/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-23","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Cloudflare's Cryptographic Attestation of Personhood (CAP) lets visitors prove they are human using a hardware key instead of a CAPTCHA.
title: Cryptographic Attestation of Personhood
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cryptographic Attestation of Personhood

Last updated Sep 4, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/cryptographic-personhood/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare developed an [alternative ↗](https://blog.cloudflare.com/introducing-cryptographic-attestation-of-personhood/) to CAPTCHA authentication, the Cryptographic Attestation of Personhood (CAP).

CAP lets you prove that you are a legitimate website visitor by touching a hardware key, instead of solving a CAPTCHA puzzle.

This article provides answers to common questions about usability and privacy concerns.

You can also test CAP by going to the [demo site ↗](https://cloudflarechallenge.com/).

## Privacy questions

The answer to most privacy concerns are summarized in this table:

| Property | Cloudflare could | Cloudflare does |
| --- | --- | --- |
| Collect biometrics (fingerprints or face pictures) | No | N/A |
| Collect information about your hardware authenticator | Yes, limited to the number of keys in your batch | Yes, when available |

No, Cloudflare cannot collect biometrics. Our CAP process uses the WebAuthn API, which prevents the collection of [biometrics by default ↗](https://www.w3.org/TR/webauthn-2/#sctn-biometric-privacy). When your device asks for a biometric authentication — such as via a fingerprint sensor — it all happens locally. 

As such, we never see your biometric data: that remains on your device. Once your device confirms a match, it sends only a basic attestation message. In effect, your device sends a message proving “yes, someone correctly entered a fingerprint on this trustworthy device” and never sends the fingerprint itself.

Yes, Cloudflare does collect a limited amount of data about your key. We store the manufacturer of your key and batch identifier ([minimum of 100,000 ↗](https://fidoalliance.org/specs/fido-uaf-v1.1-ps-20170202/fido-uaf-protocol-v1.1-ps-20170202.html#full-basic-attestation) keys per batch) for verification purposes. From our perspective, your key looks like all other keys in the batch.

Some self-signed keys and keys from certain manufacturers have been found to [not meet this requirement ↗](https://www.chromium.org/security-keys) and should be avoided if you are minimizing your online privacy risk.

---

For more details on how we set up Cryptographic Attestation of Personhood, refer to the [introductory blog post ↗](https://blog.cloudflare.com/introducing-cryptographic-attestation-of-personhood/).

---

## What devices are and are not allowed?

### Allowed devices

CAP supports a wide variety of hardware authenticators:

- **Roaming (cross-platform) authenticators**:
  - *Supported*: All security keys found in the [FIDO Metadata Service 3.0 ↗](https://fidoalliance.org/metadata/), unless they have been revoked for security reasons.
  - *Examples*: YubiKeys, HyperFIDO keys, Thetis FIDO U2F keys
- **Platform authenticators:**
  - *Examples*: Apple Touch ID and Face ID on iOS mobile devices and macOS laptops; Android mobile devices with fingerprint readers; Windows Hello

### Known limitations

Most combinations of web browsers and WebAuthn-capable authenticators will work, but there are some known compatibility issues with WebAuthn attestation that may prevent CAP from working successfully:

- **Basic CAP**:
  - *macOS desktop*: For TouchID, browser must be Safari
  - *Android*: Browser must be Chrome
- **CAP with Zero-Knowledge Proof**:
  - *Apple platform authenticators* (e.g., iPhone with Touch ID/Face ID) are incompatible with the [zero-knowledge proof system ↗](https://blog.cloudflare.com/introducing-zero-knowledge-proofs-for-private-web-attestation-with-cross-multi-vendor-hardware/). If this fails, you will immediately be redirected to basic CAP route without having to take any further action. Since Apple uses a privacy-preserving [Apple Anonymous Attestation ↗](https://www.w3.org/TR/webauthn/#sctn-apple-anonymous-attestation) to show that an authenticator is valid while blocking tracking, this method maintains a high standard of privacy.

We are updating this list as the ecosystem evolves and as we continue to test different combinations.

## Can hackers bypass the Cryptographic Attestation of Personhood?

CAP is one of many techniques to identify and block bots. To date, we have seen some attempts to test CAP’s security system, such as [one thoughtfully-executed, well-documented test ↗](https://betterappsec.com/building-a-webauthn-click-farm-are-captchas-obsolete-bfab07bb798c). The blog post discussing the test specifically calls out that this method does not break the Cloudflare threat model.

This does not mean that CAP is broken, but rather shows that it raises the cost of an attack over the current CAPTCHA model.

## What happens if I lose my key?

If you do not have the necessary hardware (such as a Yubikey), you can still solve a regular CAPTCHA challenge (e.g., selecting pictures).

## What are the common error codes and what do they mean?

- **Unsupported\_att\_fmt**:
  - *Cause*: Your authenticator is using an unsupported attestation format (combination of browser and key). Also occurs when you use *Firefox* and select the option to "anonymise your key".
  - *Solution:* If this error occurs during [zero-knowledge version of CAP ↗](https://blog.cloudflare.com/introducing-zero-knowledge-proofs-for-private-web-attestation-with-cross-multi-vendor-hardware/), you will automatically be redirected to the basic CAP flow. If basic CAP fails, try a different combination of supported hardware device and browser or opt for a CAPTCHA.
- **Unsupported\_issuer**:
  - *Cause*: Your key is currently not supported.
  - *Solution*: Use a [supported key](#allowed-devices).

## Related resources

- [https://cloudflarechallenge.com ↗](https://cloudflarechallenge.com/) (demo site)
- [Introducing Cryptographic Attestation of Personhood ↗](https://blog.cloudflare.com/introducing-cryptographic-attestation-of-personhood/) (blog)
- [Expanding Crypotgraphic Attestation of Personhood ↗](https://blog.cloudflare.com/cap-expands-support/) (blog)
- [Introducing Zero-Knowledge Proofs ↗](https://blog.cloudflare.com/introducing-zero-knowledge-proofs-for-private-web-attestation-with-cross-multi-vendor-hardware/) (blog)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/cryptographic-personhood/#page","headline":"Cryptographic Attestation of Personhood","description":"Cloudflare's Cryptographic Attestation of Personhood (CAP) lets visitors prove they are human using a hardware key instead of a CAPTCHA.","url":"https://developers.cloudflare.com/fundamentals/reference/cryptographic-personhood/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-04","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: How Cloudflare formats error responses, including structured JSON and Markdown for agents and API clients, and how they interact with Custom Errors.
title: Error responses
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Error responses

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/error-responses/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

When Cloudflare cannot complete a request, it generates an error response. The format depends on what the client requests via the `Accept` header and on the zone's [Custom Errors](https://developers.cloudflare.com/rules/custom-errors/) configuration.

By default, error responses are HTML. Clients that request a structured format (such as `application/json`, `application/problem+json`, or `text/markdown`) receive a machine-readable response instead. This machine-readable response covers all [1xxx error codes](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/) (which return HTTP 4xx or 5xx status codes depending on the error) and Cloudflare-generated [5xx errors](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/) (500, 502, 504, 520-526). Responses for 5xx errors generated by the origin server are passed through by Cloudflare to the client and are not affected.

Note

This page covers the format of Cloudflare-generated error responses. For converting origin page content to Markdown, refer to [Markdown for Agents](https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/). For replacing default error pages with custom content, refer to [Custom Errors](https://developers.cloudflare.com/rules/custom-errors/).

---

## Content negotiation

Cloudflare selects the response format based on the client's `Accept` header, following standard [HTTP content negotiation ↗](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Content_negotiation). When multiple formats are acceptable, quality factors (`q` values) determine precedence. At the same quality value, the first-listed type wins.

| `Accept` header sent | Response format |
| --- | --- |
| `application/json` | JSON (`application/json; charset=utf-8`) |
| `application/problem+json` | JSON (`application/problem+json; charset=utf-8`) |
| `application/json, text/markdown;q=0.9` | JSON (higher quality factor) |
| `text/markdown` | Markdown (`text/markdown; charset=utf-8`) |
| `text/markdown, application/json` | Markdown (equal quality, first-listed wins) |
| `text/*` | Markdown |
| `text/html` | HTML |
| `*/*` | HTML |
| Not set | HTML |

Structured error responses are available on all plans, including the Free plan. [Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/#custom-error-rules) for overriding these responses require a Cloudflare paid plan.

---

## Interaction with Custom Errors

Structured error responses are the default for zones with no custom error configuration. Zones that use [Custom Errors](https://developers.cloudflare.com/rules/custom-errors/) retain full control over what clients receive.

What a client receives depends on which custom error features your zone has configured. Refer to the following sections for details.

### No custom error page, no custom error rules

This is the default for most zones. Cloudflare serves its default error response in the format the client requests.

| Client sends | Response |
| --- | --- |
| `Accept: application/json` | Default Cloudflare structured JSON response |
| `Accept: text/markdown` | Default Cloudflare structured Markdown response |
| `Accept: text/html` | Default Cloudflare HTML error page |
| No `Accept` header | Default Cloudflare HTML error page |

### Error Page configured, no custom error rules

The zone has an Error Page uploaded via the Cloudflare dashboard. No Custom Error Rules are configured. The Error Page is served to all clients regardless of `Accept` header — Error Pages do not perform content negotiation.

| Client sends | Response |
| --- | --- |
| `Accept: application/json` | Your custom HTML error page |
| `Accept: text/markdown` | Your custom HTML error page |
| `Accept: text/html` | Your custom HTML error page |
| No `Accept` header | Your custom HTML error page |

If you want agents to receive structured responses while keeping your custom HTML for browsers, add a Custom Error Rule that matches on the `Accept` header. Refer to the next section for details.

### Custom Error Rules configured

The zone has one or more [Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/#custom-error-rules) (available on paid plans). These take priority over Error Pages. You control what gets served, to whom, and under what conditions.

| Client sends | Response |
| --- | --- |
| `Accept: application/json` | If a Custom Error Rule matches, the rule's content is served. If no rule matches, falls back to the Error Page (if configured) or the structured JSON response. |
| `Accept: text/markdown` | If a Custom Error Rule matches, the rule's content is served. If no rule matches, falls back to the Error Page (if configured) or the structured Markdown response. |
| `Accept: text/html` | If a Custom Error Rule matches, the rule's content is served. If no rule matches, falls back to the Error Page or the default HTML. |
| No `Accept` header | Same fallback chain |

Custom Error Rules can match on any request header including `Accept`, and can target specific error codes. You can serve JSON to API clients, Markdown to agents, and HTML to browsers, all from the same zone.

<details>

<summary>

Example: Serve custom JSON to API clients on a 522 error

</summary>

This Custom Error Rule matches 522 errors where the client requests JSON:

**Expression:** <code>(http.response.code eq 522) and (any(http.request.headers["accept"][*] contains "application/json"))</code>

**Action:** Serve a custom JSON response with your own error format.

This rule takes priority over both the default structured JSON response and any configured Error Page. Clients that do not match the rule (for example, browsers requesting HTML) fall through to the Error Page or the default Cloudflare response.

</details>

<details>

<summary>

Example: Serve structured responses to agents and a custom HTML page to browsers

</summary>

If your zone has an Error Page configured, it is served to all clients, including agents requesting JSON or Markdown. To let agents receive Cloudflare's default structured responses instead, remove the Error Page. Without an Error Page, Cloudflare respects the <code>Accept</code> header automatically: agents get structured JSON or Markdown and browsers get HTML.

If you need to keep the Error Page for browsers but want to serve custom structured content to agents, create Custom Error Rules that match on the <code>Accept</code> header and serve your own JSON or Markdown content. Browsers that do not match either rule continue to receive your custom HTML Error Page.

</details>

### Priority order

When Cloudflare generates an error response, the following priority order determines what the client receives:

1. **[Custom Error Rules](https://developers.cloudflare.com/rules/custom-errors/#custom-error-rules)** — If a rule matches the error and request conditions, the rule's content is served.
2. **[Error Pages](https://developers.cloudflare.com/rules/custom-errors/#error-pages)** — If an Error Page is configured for the error type and no Custom Error Rule matched, the Error Page is served as HTML regardless of the `Accept` header.
3. **Structured error responses** — If no Custom Error Rule matched and no Error Page is configured, Cloudflare serves its default response in the format the client requested (JSON, Markdown, or HTML).

For the full priority order including account-level versus zone-level rules, WAF custom block responses, and security challenge pages, refer to the [Custom Errors](https://developers.cloudflare.com/rules/custom-errors/) documentation.

---

## Examples

### JSON: 522 Connection timed out

```json
{
	"type": "https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-522/",
	"title": "Error 522: Connection timed out",
	"status": 522,
	"detail": "Cloudflare could not establish a TCP connection to the origin server. The TCP handshake timed out, which may indicate the origin is overloaded, firewalling Cloudflare, or unreachable at the network level.",
	"instance": "9f140b785e57c458",
	"error_code": 522,
	"error_name": "connection_timeout",
	"error_category": "origin",
	"ray_id": "9f140b785e57c458",
	"timestamp": "2026-04-24T09:22:40Z",
	"zone": "example.com",
	"cloudflare_error": true,
	"retryable": true,
	"retry_after": 120,
	"owner_action_required": true,
	"what_you_should_do": "**Wait and retry.** Back off for at least 120 seconds. If the error persists, the website operator should verify firewall rules and ensure the origin accepts connections from Cloudflare IP ranges.",
	"footer": "This error was generated by Cloudflare on behalf of the website owner."
}
```

### Markdown: 522 Connection timed out

```markdown
---
error_code: 522
error_name: connection_timeout
error_category: origin
status: 522
ray_id: 9f140b785e57c458
timestamp: 2026-04-24T09:22:40Z
zone: example.com
cloudflare_error: true
retryable: true
retry_after: 120
owner_action_required: true
---

# Error 522: Connection timed out

## What Happened

Cloudflare could not establish a TCP connection to the origin server. The TCP handshake timed out, which may indicate the origin is overloaded, firewalling Cloudflare, or unreachable at the network level.

## What You Should Do

**Wait and retry.** Back off for at least 120 seconds. If the error persists, the website operator should verify firewall rules and ensure the origin accepts connections from Cloudflare IP ranges.

---

This error was generated by Cloudflare on behalf of the website owner.
```

---

## Test structured error responses

Fetch the structured JSON response for a 522 error:

```bash
curl --silent --compressed --header "Accept: application/json" \
  --user-agent "TestAgent/1.0" --header "Accept-Encoding: gzip, deflate" \
  "https://example.com/cdn-cgi/error/522" | jq .
```

Fetch the structured Markdown response:

```bash
curl --silent --compressed --header "Accept: text/markdown" \
  --user-agent "TestAgent/1.0" --header "Accept-Encoding: gzip, deflate" \
  "https://example.com/cdn-cgi/error/522"
```

Check for the `Retry-After` header on a retryable error:

```bash
curl --silent --compressed --dump-header - --output /dev/null \
  --header "Accept: application/json" --user-agent "TestAgent/1.0" \
  --header "Accept-Encoding: gzip, deflate" \
  "https://example.com/cdn-cgi/error/521" | grep -i retry-after
```

---

## Response fields

Both JSON and Markdown responses contain the same set of fields. JSON responses return them as a flat object; Markdown responses place them in YAML frontmatter followed by prose sections. The field definitions below apply to both formats.

JSON responses follow [RFC 9457 (Problem Details for HTTP APIs) ↗](https://www.rfc-editor.org/rfc/rfc9457). Any HTTP client that understands Problem Details can parse the five standard members (`type`, `title`, `status`, `detail`, `instance`) without Cloudflare-specific code.

### RFC 9457 standard members

| Field | Type | Description |
| --- | --- | --- |
| `type` | string | URI pointing to Cloudflare documentation for this error code. |
| `title` | string | Short summary, for example, `"Error 522: Connection timed out"`. |
| `status` | integer | HTTP status code of the response. |
| `detail` | string | Plain-text explanation of what went wrong and which party is responsible. |
| `instance` | string | Ray ID identifying this specific error occurrence. |

### Cloudflare extension members

| Field | Type | Description |
| --- | --- | --- |
| `error_code` | integer | Cloudflare error code (for example, `522`, `1015`). |
| `error_name` | string | Machine-readable name in `snake_case` (for example, `connection_timeout`, `rate_limited`). Stable — suitable for programmatic matching. |
| `error_category` | string | Fault classification. Refer to [Error categories](#error-categories). Stable — suitable for programmatic matching. |
| `ray_id` | string | Same value as `instance`. Included for compatibility with existing Cloudflare tooling. |
| `timestamp` | string | ISO 8601 timestamp of when the error was generated. |
| `zone` | string | The requested hostname. |
| `cloudflare_error` | boolean | Always `true`. Confirms this error was generated by Cloudflare, not the origin. |
| `retryable` | boolean | Whether the error is transient and the request can be retried. |
| `retry_after` | integer or null | Seconds to wait before retrying. Present only when `retryable` is `true`. Matches the `Retry-After` HTTP header value. |
| `owner_action_required` | boolean | Whether the site operator needs to take action to resolve the error. |
| `what_you_should_do` | string | Actionable guidance for the client: what to do next, whether to retry, and who can fix the problem. |
| `footer` | string | Attribution line. |

### Markdown-specific structure

Markdown responses place these fields in YAML frontmatter (between `---` delimiters), followed by three prose sections:

- **`# Error {code}: {description}`** — heading with the error code and short description.
- **`## What Happened`** — corresponds to the `detail` field.
- **`## What You Should Do`** — corresponds to the `what_you_should_do` field.

The frontmatter omits the RFC 9457 standard members (`type`, `title`, `instance`) and the `footer` field since these are either redundant with the prose or not applicable to the Markdown format.

---

## Error categories

The `error_category` field classifies the fault so that clients can route retry and escalation behavior without parsing the prose fields.

### 5xx error categories

| Category | Codes | Meaning | Retry? |
| --- | --- | --- | --- |
| `origin` | 502, 504, 520-524 | The origin server is responsible. Transient infrastructure failure. | Yes. Back off using `retry_after`. |
| `cloudflare` | 500 | Cloudflare encountered an internal error. The origin was not necessarily involved. | Yes. Short retry (30s). |
| `ssl` | 525, 526 | The origin's TLS configuration is broken (handshake failure or invalid certificate). | No. Retrying will not help until the operator fixes the TLS configuration. |

### 1xxx error categories

| Category | Meaning | Example codes |
| --- | --- | --- |
| `access_denied` | IP blocks, country blocks, firewall rules | 1005, 1006, 1007, 1008, 1010, 1012, 1106-1109 |
| `rate_limit` | Rate limiting | 1015, 1025, 1027, 1200 |
| `dns` | DNS resolution errors | 1001, 1016 |
| `config` | Zone or origin configuration errors | 1004, 1014, 1033, 1043, 1047, 1049 |
| `tls` | Client TLS errors (version, cipher, certificate) | 1017, 1028, 1029, 1044 |
| `legal` | Legal restrictions (DMCA, country blocks) | 1026, 1039 |
| `worker` | Worker script errors | 1042, 1100, 1101, 1102, 1103, 1104, 1105 |
| `rewrite` | URL rewrite rule errors | 1036, 1037 |
| `snippet` | Snippet configuration errors | 1201, 1202, 1203, 1204, 1205, 1206 |
| `unsupported` | Unsupported features or protocols | 1045 |

---

## Retry-After header

Retryable error codes include a standard [`Retry-After` ↗](https://www.rfc-editor.org/rfc/rfc9110#section-10.2.3) HTTP response header. The header value in seconds matches the `retry_after` field in the response body.

### 5xx Retry-After values

| Code | `retry_after` (in seconds) |
| --- | --- |
| 500 | 30 |
| 502 | 60 |
| 504 | 120 |
| 520 | 60 |
| 521 | 120 |
| 522 | 120 |
| 523 | 120 |
| 524 | 120 |
| 525 | N/A (not retryable) |
| 526 | N/A (not retryable) |

Non-retryable codes (525, 526) do not include the `Retry-After` header.

### 1xxx Retry-After values

Six retryable 1xxx error codes emit `Retry-After`:

| Code | `retry_after` (in seconds) | Error name |
| --- | --- | --- |
| 1004 | 120 | DNS resolution error |
| 1015 | 30 | Rate limited |
| 1033 | 120 | Argo Tunnel error |
| 1038 | 60 | HTTP headers limit exceeded |
| 1200 | 60 | Cache connection limit |
| 1205 | 5 | Too many redirects |

All other 1xxx error codes are non-retryable and do not include the `Retry-After` header.

If a WAF rate limiting rule has already set a dynamic `Retry-After` value on the response, that value takes precedence over the default.

---

## More resources

- [Cloudflare 1xxx errors](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-1xxx-errors/)
- [Cloudflare 5xx errors](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/)
- [Custom Errors](https://developers.cloudflare.com/rules/custom-errors/)
- [Connection limits](https://developers.cloudflare.com/fundamentals/reference/connection-limits/)
- [Markdown for Agents](https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/) (content conversion)
- [RFC 9457 — Problem Details for HTTP APIs ↗](https://www.rfc-editor.org/rfc/rfc9457)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/error-responses/#page","headline":"Error responses","description":"How Cloudflare formats error responses, including structured JSON and Markdown for agents and API clients, and how they interact with Custom Errors.","url":"https://developers.cloudflare.com/fundamentals/reference/error-responses/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review definitions for terms used across Cloudflare products and documentation.
title: Glossary
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Glossary

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/glossary/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Review the definitions for terms used across Cloudflare's documentation.

| Term | Definition | Product |
| --- | --- | --- |
| account | Accounts group one or more members together with specific roles or permissions. Accounts can be associated with any number of domains. | Fundamentals |
| ACK (Acknowledge) | The final step in the TCP three-way handshake, confirming the establishment of a connection. | Spectrum |
| active zone | A DNS zone that is active on Cloudflare requires changing its nameservers to Cloudflare's for management. | DNS |
| address map | A data structure enabling customers with BYOIP prefixes or account-level static IPs to specify which IP addresses should be mapped to DNS records when they are proxied through Cloudflare. | BYOIP |
| AI crawler | A bot which scrapes content from websites in support of an AI model, including by scraping content for indexing, retrieval augmented generation, or training. | AI Crawl Control |
| AI models | [An AI model](https://developers.cloudflare.com/workers-ai/models) is a trained system that processes input data to generate predictions, decisions, or outputs based on patterns it has learned. | Workers AI |
| alarm | A Durable Object alarm is a mechanism that allows you to schedule the Durable Object to be woken up at a time in the future. | Durable Objects |
| allowlist | An allowlist is a list of items (usually websites, IP addresses, email addresses, etc.) that are permitted to access a system. | WAF |
| anycast | Anycast is a network addressing and routing method in which incoming requests can be routed to a variety of different locations. Anycast typically routes incoming traffic to the nearest data center with the capacity to process the request efficiently. | Cloudflare WAN |
| apex domain | Apex domain is used to refer to a domain that does not contain a subdomain part, such as `example.com` (without `www.`). It is also known as "root domain" or "naked domain". | DNS |
| API call | Also known as an API request. An API call is a message sent to a server asking an API to provide a service or information. | API Shield |
| API endpoint | The API endpoint is the location where API calls or requests are fulfilled. API Shield defines endpoints as a host, method, and path tuple. | API Shield |
| API key | An API key is unique to each Cloudflare user and used to confirm identity when using the [Cloudflare API](https://developers.cloudflare.com/api/). | Fundamentals |
| API schema | The API schema defines which API requests are valid based on several request properties like target endpoint, path or query variable format, and HTTP method. | API Shield |
| API token | API tokens authorize access to specific Cloudflare dashboard pages, accounts, and zones. API tokens are associated to the user that created them. | Fundamentals |
| API Tokens | [API Tokens](https://developers.cloudflare.com/workers-ai/get-started/rest-api/) are authentication credentials used to securely access and manage Workers AI resources via the REST API. | Workers AI |
| App Launcher | The App Launcher portal provides end users with a single dashboard to open applications secured by Cloudflare One. | Cloudflare One |
| application | The resource protected by Cloudflare One, which can be a subdomain, a path, or a SaaS application. | Cloudflare One |
| application token | A piece of data that grants a user access to a specific Access application for a period of time. Can be stored in a browser cookie or passed to the application in place of a normal password. | Cloudflare One |
| attack score | A number from 1 (likely malicious) to 99 (likely clean) classifying how likely an incoming request is malicious or not. Allows you to detect new attack techniques before they are publicly known. | WAF |
| attribute | Traffic that flows through Area 1 can receive one or more attributes, which indicate that a specific condition has been met. | Area 1 |
| Authenticated Origin Pulls | Authenticated Origin Pulls allow origin web servers to validate that a web request came from Cloudflare using TLS client certificate authentication. | SSL/TLS |
| autonomous system numbers (ASNs) | A large network or group of networks that has a unified routing policy. Every computer or device that connects to the Internet is connected to an autonomous system. | BYOIP |
| Auxiliary Worker | A Worker created locally via the [Workers Vitest integration](https://developers.cloudflare.com/workers/testing/vitest-integration/) that runs in a separate isolate to the test runner, with a different global scope. | Workers |
| backup codes | Backup codes allow restoration of Cloudflare account access outside the normal [two-factor authentication process](https://developers.cloudflare.com/fundamentals/user-profiles/2fa/). A backup code becomes invalid after use. | Fundamentals |
| bandwidth | The maximum rate of data transfer across a network. | Speed |
| binding | [Bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/) allow your Workers to interact with resources on the Cloudflare Developer Platform. | Workers |
| bit field matching | Matches raw bits in a packet to certain values specified in your rules. | Cloudflare Network Firewall |
| blocklist | A blocklist is a list of items (usually websites, IP addresses, email addresses, etc.) that are prevented from accessing a system. | WAF |
| bookmark | A bookmark represents the state of a database at a specific point in time.<ul><li>Bookmarks are lexicographically sortable. Sorting orders a list of bookmarks from oldest-to-newest.</li></ul> | D1 |
| bookmark | A bookmark is a mostly alphanumeric string like `0000007b-0000b26e-00001538-0c3e87bb37b3db5cc52eedb93cd3b96b` which represents a specific state of a SQLite database at a certain point in time. Bookmarks are designed to be lexically comparable: a bookmark representing an earlier point in time compares less than one representing a later point, using regular string comparison. | Durable Objects |
| Border Gateway Protocol (BGP) | The routing protocol for the Internet, which is responsible for picking the most efficient routes to deliver Internet traffic. | BYOIP |
| bot | A software application programmed to do tasks that can be used for good (chatbots, search engine crawlers) or for evil (inventory hoarding, credential stuffing). | Bots |
| bot score | A score from 1 to 99 that indicates how likely that request came from a bot, in which 1 to 29 is likely automated and 30 to 99 is likely human. | Bots |
| bot tags | Additional information about a bot request, such as why Cloudflare has given it a bot score and whether the request came from a verified bot or a category of verified bots. | Bots |
| brotli compression | Brotli compression is a data compression algorithm developed by Google, optimized for web content, and designed to achieve higher compression ratios than traditional algorithms like Gzip. | Speed |
| C3 | [C3](https://developers.cloudflare.com/learning-paths/workers/get-started/c3-and-wrangler/) is a command-line tool designed to help you set up and deploy new applications to Cloudflare. | Workers |
| cache | A temporary storage area where frequently accessed data is stored for quick retrieval. | Cache |
| cache hit | When a requested piece of content is found in the cache, reducing the need to fetch it from the origin server. | Cache |
| cache lock | Cache lock (or mutex) is a mechanism employed by CDN data centers, comprising numerous servers, to prevent the overloading of origin servers. This mechanism ensures that only one server can request a specific file from the origin at any given time, facilitating efficient coordination among the servers. | Cache |
| cache miss | When a requested piece of content is not found in the cache, requiring the server to fetch it from the origin server. | Cache |
| cached bandwidth (cached egress bandwidth) | The amount of bandwidth served from Cloudflare without hitting the origin server. Cached bandwidth is the sum of all `EdgeResponseBytes` where `CacheCacheStatus` equals `hit`, `stale`, `updating`, `ignored`, or `revalidated`. | Cache |
| cached requests | The number of requests served from Cloudflare without having to hit the origin server. Cached requests are the sum of all requests where `CacheCacheStatus` equals `hit`, `stale`, `updating`, `ignored`. This does not include `revalidated` since the request had to be sent to the origin server. | Cache |
| cacheTtl | CacheTtl is a parameter that defines the length of time in seconds that a KV result is cached in the global network location it is accessed from. | KV |
| caching | The process of storing copies of files or data in a cache to accelerate future requests. | Cache |
| canonical URL | The preferred version of a web page, specified by a `<link rel="canonical">` HTML tag in the page's `<head>` section. When multiple URLs serve the same or similar content, the canonical URL tells search engines and crawlers which version is authoritative. | AI Crawl Control |
| CAPTCHA | A CAPTCHA test is designed to determine if an online user is really a human and not a bot. CAPTCHA is an acronym that stands for "Completely Automated Public Turing test to tell Computers and Humans Apart." | Turnstile |
| captive portal | A login screen shown to users when they connect to a public Wi-Fi. Captive portals typically occur in places such as airports, cafes, and hotels. | Cloudflare One |
| category | A classification describing a crawler's stated purpose: "AI Crawler", "AI Search", "AI Assistant", or "Search Engine". One category per crawler. | AI Crawl Control |
| certificate | SSL certificates enable encryption over HTTPS for traffic between a client and a website. SSL certificates contain the website's public key and the website's identity along with related information. Devices attempting to communicate with the origin web server reference the SSL certificate to obtain the public key and verify the server's identity. Cloudflare provides a [Universal SSL certificate](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/) for each active Cloudflare domain. | SSL/TLS |
| Certificate Authority (CA) | A CA is a trusted third party that provides SSL certificates for encrypting network traffic. | SSL/TLS |
| certificate packs | Certificate packs allow Cloudflare to fallback to a different SSL certificate for browsers that do not support the latest standards. Certificate packs allow Custom SSL certificates to contain different signature algorithms for the same hostnames listed within the SSL certificate without taking up additional Custom SSL certificate quota for your Cloudflare account. | SSL/TLS |
| certificate pinning | A security mechanism used to prevent on-path attacks on the Internet by hardcoding information about the certificate that the application expects to receive. If the wrong certificate is received, even if it is trusted by the system, the application will refuse to connect. | SSL/TLS |
| Certification Authority Authorization (CAA) record | A CAA record declares which CAs are allowed to issue an SSL certificate for a domain. | SSL/TLS |
| cf-aig-backoff | Header to customize the backoff type for [request retries](https://developers.cloudflare.com/ai-gateway/configuration/request-handling/#request-retries) of a request. | AI Gateway |
| cf-aig-cache-key | The [cf-aig-cache-key-aig-cache-key](https://developers.cloudflare.com/ai-gateway/features/caching/#custom-cache-key-cf-aig-cache-key) let you override the default cache key in order to precisely set the cacheability setting for any resource. | AI Gateway |
| cf-aig-cache-status | [Status indicator for caching](https://developers.cloudflare.com/ai-gateway/features/caching/#default-configuration), showing if a request was served from cache. | AI Gateway |
| cf-aig-cache-ttl | Specifies the [cache time-to-live for responses](https://developers.cloudflare.com/ai-gateway/features/caching/#cache-ttl-cf-aig-cache-ttl). | AI Gateway |
| cf-aig-collect-log | The [cf-aig-collect-log](https://developers.cloudflare.com/ai-gateway/observability/logging/#collect-logs-cf-aig-collect-log) header allows you to bypass the default log setting for the gateway. | AI Gateway |
| cf-aig-custom-cost | Allows the [customization of request cost](https://developers.cloudflare.com/ai-gateway/configuration/custom-costs/#custom-cost) to reflect user-defined parameters. | AI Gateway |
| cf-aig-dlp | A response header returned when a [DLP policy](https://developers.cloudflare.com/ai-gateway/features/dlp/set-up-dlp/#dlp-response-header) matches a request or response. Contains JSON with the action taken (Flag or Block), matched policy IDs, matched profile IDs, and detection entry IDs. | AI Gateway |
| cf-aig-event-id | [cf-aig-event-id](https://developers.cloudflare.com/ai-gateway/evaluations/add-human-feedback-api/#3-retrieve-the-cf-aig-log-id) is a unique identifier for an event, used to trace specific events through the system. | AI Gateway |
| cf-aig-log-id | The [cf-aig-log-id](https://developers.cloudflare.com/ai-gateway/evaluations/add-human-feedback-api/#3-retrieve-the-cf-aig-log-id) is a unique identifier for the specific log entry to which you want to add feedback. | AI Gateway |
| cf-aig-max-attempts | Header to customize the number of max attempts for [request retries](https://developers.cloudflare.com/ai-gateway/configuration/request-handling/#request-retries) of a request. | AI Gateway |
| cf-aig-metadata | [Custom metadata](https://developers.cloudflare.com/ai-gateway/configuration/custom-metadata/)allows you to tag requests with user IDs or other identifiers, enabling better tracking and analysis of your requests. | AI Gateway |
| cf-aig-no-wholesale | Prevents [Unified Billing fallback](https://developers.cloudflare.com/ai-gateway/features/unified-billing/#prevent-unified-billing-fallback-for-byok-third-party-providers) for a third-party provider request when set to `true`. The request must use provider credentials supplied with the request or stored on the gateway. | AI Gateway |
| cf-aig-request-timeout | Header to set a [request timeout](https://developers.cloudflare.com/ai-gateway/configuration/request-handling/#request-timeouts) (measured in milliseconds). If the provider does not respond within this time, the request returns an error. | AI Gateway |
| cf-aig-retry-delay | Header to customize the retry delay for [request retries](https://developers.cloudflare.com/ai-gateway/configuration/request-handling/#request-retries) of a request. | AI Gateway |
| cf-aig-skip-cache | Header to [bypass caching for a specific request](https://developers.cloudflare.com/ai-gateway/features/caching/#skip-cache-cf-aig-skip-cache). | AI Gateway |
| cf-aig-step | The cf-aig-step response header identifies which step in a request flow successfully processed the request, useful for tracking and debugging. | AI Gateway |
| cf-cache-ttl | Deprecated: This header is replaced by `cf-aig-cache-ttl`. It specifies cache time-to-live. | AI Gateway |
| cf-skip-cache | Deprecated: This header is replaced by `cf-aig-skip-cache`. It bypasses caching for a specific request. | AI Gateway |
| Challenge solve rate (CSR) | The percentage of issued challenges that were solved. | Bots |
| CIDR | CIDR stands for Classless Inter-Domain Routing. CIDR often refers to CIDR notation, which is an IP address represented as a series of four 8-bit octets, separated by dots (e.g., 192.168.1.1). Additionally, CIDR notation includes a suffix that indicates the number of bits used for the network portion of the address. The format is typically written as "/X," where X is the number of bits in the network portion. | Fundamentals |
| cipher suite | A set of encryption algorithms for establishing a secure communications connection. There are several cipher suites in wide use, and a client and server agree on the cipher suite to use when establishing the TLS connection. Support of multiple cipher suites allows compatibility across various clients. | SSL/TLS |
| client-side resource | A file with JavaScript code loaded by your visitors' browser, or a connection made by one of the loaded scripts. | Client-side security |
| cloud | A network of remote servers used to store and maintain data. | Fundamentals |
| Cloudflare Access | Cloudflare Access replaces corporate VPNs with Cloudflare's network. It verifies attributes such as identity and device posture to grant users secure access to internal tools. | Cloudflare One |
| Cloudflare Browser Isolation | Cloudflare Browser Isolation seamlessly executes active webpage content in a secure isolated browser to protect users from zero-day attacks, malware, and phishing. | Cloudflare One |
| Cloudflare CASB | Cloudflare CASB provides comprehensive visibility and control over SaaS apps to prevent data leaks and compliance violations. It helps detect insider threats, shadow IT, risky data sharing, and bad actors. | Cloudflare One |
| Cloudflare Dashboard | [Cloudflare Dashboard](https://developers.cloudflare.com/workers-ai/get-started/dashboard/) is a web-based interface that allows users to manage Workers AI services, including model deployment and monitoring. | Workers AI |
| Cloudflare Data Loss Prevention (DLP) | Cloudflare [Data Loss Prevention](https://www.cloudflare.com/learning/access-management/what-is-dlp/) (DLP) allows you to scan your web traffic and SaaS applications for the presence of sensitive data such as social security numbers, financial information, secret keys, and source code. | Cloudflare One |
| Cloudflare DEX | Cloudflare Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Zero Trust Organization. | Cloudflare One |
| Cloudflare Gateway | Cloudflare Gateway is a modern next-generation firewall between your user, device, or network and the public Internet. It includes DNS filtering to inspect and apply policies to all Internet-bound DNS queries. | Cloudflare One |
| Cloudflare Mesh | Connects private networks, servers, and devices through Cloudflare for bidirectional, site-to-site, and mesh connectivity. Every participant receives a private Mesh IP address and can reach any other participant directly. | Cloudflare One |
| Cloudflare One | The name for Cloudflare's Secure Access Service Edge (SASE) platform, which includes Zero Trust and network services. | Cloudflare One |
| Cloudflare One Agent | The name of the Cloudflare One Client app on iOS and Android devices. | Cloudflare One |
| Cloudflare One Client | An application that connects corporate devices to Cloudflare for private network access, advanced web filtering, and other security functions. | Cloudflare One |
| Cloudflare Tunnel | Cloudflare Tunnel uses a software agent (`cloudflared`) to establish a secure connection between a private network and Cloudflare. | Cloudflare One |
| Cloudflare Zero Trust | Cloudflare Zero Trust provides the power of Cloudflare's global network to your internal teams and infrastructure. It empowers users with secure, fast, and seamless access to any device on the Internet. | Cloudflare One |
| cloudflared | The software powering Cloudflare Tunnel. It runs on origin servers to connect applications or private networks to Cloudflare. | Cloudflare One |
| cloudflared replica | An additional instance of `cloudflared` that points to the same Cloudflare Tunnel. It ensures that your network remains online in case a single host running `cloudflared` goes down. | Cloudflare One |
| CNAME setup | Also known as partial setup, a CNAME setup allows you to use Cloudflare's reverse proxy without using Cloudflare for your authoritative nameservers. | DNS |
| code example | A code example illustrates how to use a programming element to implement specific functionality | Fundamentals |
| compression | The process of reducing the size of files or data to speed up their transfer over the network. | Speed |
| consumer | A consumer is the term for a client that is subscribing to or consuming messages from a queue. | Queues |
| content delivery network (CDN) | A geographically distributed group of servers which work together to provide fast delivery of Internet content. | Fundamentals |
| content object | A content object is any binary part of a request body (as detected by Cloudflare systems) that does not match any of the following content types: `text/html`, `text/x-shellscript`, `application/json`, `text/csv`, or `text/xml`. | WAF |
| content security policy (CSP) | An added layer of security that helps detect and mitigate certain types of attacks such as cross-site scripting (XSS) attacks. | Fundamentals |
| Content Signals | An emerging IETF standard for expressing AI content preferences via HTTP headers or metadata. Aims to replace non-standard vendor signals. Refer to contentsignals.org. | AI Crawl Control |
| Context Window | In generative AI, the context window is the sum of the number of input, reasoning, and completion or response tokens a model supports. You can find the context window limit on each [model page](https://developers.cloudflare.com/workers-ai/models/). | Workers AI |
| core web vitals | Core web vitals are a set of user-centric performance metrics, including Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), and First Input Delay (FID), used by Google to assess the overall user experience of a webpage. | Speed |
| CPU time | [CPU time](https://developers.cloudflare.com/workers/platform/limits/#cpu-time) is the amount of time the central processing unit (CPU) actually spends doing work, during a given request. | Workers |
| crawl | A single HTTP request from a bot to access a page on your site. | AI Crawl Control |
| crawler | A specific bot operated by a company to access web content. One operator (like OpenAI) may run multiple crawlers (GPTBot, ChatGPT-User). | AI Crawl Control |
| credential stuffing | Credential stuffing is the automated injection of stolen username and password pairs (known as "credentials") into website login forms, trying to gain access to user accounts. | WAF |
| credit | An amount applied to a specific Cloudflare account as credit for recurring subscriptions or plan payments. The Cloudflare billing system automatically applies credits in the next billing cycle. | Fundamentals |
| Cron Triggers | [Cron Triggers](https://developers.cloudflare.com/workers/configuration/cron-triggers/) allow users to map a cron expression to a Worker using a [`scheduled()` handler](https://developers.cloudflare.com/workers/runtime-apis/handlers/scheduled/) that enables Workers to be executed on a schedule. | Workers |
| cumulative layout shift (CLS) | Cumulative layout shift (CLS) is a web performance metric that quantifies the visual stability of a webpage by measuring the sum of unexpected layout shifts of elements during the page's loading and rendering process. | Speed |
| D1 | [D1](https://developers.cloudflare.com/d1/) is Cloudflare's native serverless database. | Workers |
| D1 | [D1](https://developers.cloudflare.com/d1/) is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. | Workers AI |
| daemon | A program that performs tasks without active management or maintenance. | Cloudflare One |
| data center | A physical location where servers run and other IT operations are hosted. | Fundamentals |
| data packet | A data packet is a unit of data consisting of user and control information. Information in a network is broken down into packets, that might follow different paths to their final destination. | Cloudflare WAN |
| debugging | The process of identifying and resolving errors or issues within software applications or systems, often facilitated by analyzing log data. | Logs |
| demo application | A demo application is a functional application in GitHub that you can clone and deploy on your own. | Fundamentals |
| denial-of-service (DoS) attack | A DoS attack is a type of cyber attack in which an attacker aims to render a computer or other device unavailable to its intended users by interrupting the device's normal functioning. | Fundamentals |
| deployment | [Deployments](https://developers.cloudflare.com/workers/versions-and-deployments/#deployments) track the version(s) of your Worker that are actively serving traffic. | Workers |
| deprecation | Deprecation in software development involves officially labeling a feature as outdated. While a deprecated software feature remains within the software, users are warned and encouraged to adopt alternatives. Eventually, deprecated features may be removed. This approach ensures backward compatibility and gives programmers time to update their code. | Logs |
| detection ID | Static rules that are used to detect predictable bot behavior with no overlap with human traffic. | Bots |
| device posture | A way to evaluate the security of a user's device, for example by verifying its serial number or checking if it has the latest software updates. | Cloudflare One |
| device profile | A collection of Cloudflare One Client settings applied to a specific set of devices in your organization. | Cloudflare One |
| device registration | An individual session of the Cloudflare One Client on a physical device, with associated configuration including a unique public key, device profile, and virtual IP addresses (one IPv4 and one IPv6). | Cloudflare One |
| direct | A label applied to a verified bot or agent operated by a single, narrow operator, usually on the operator's own infrastructure. Replaces the standalone "verified bot" classification used before July 1, 2026. | Bots |
| disposition | Represents Area 1's evaluation of a specific message. For example, after evaluating an email it may get a disposition of `malicious`. Email messages with this disposition exhibit characteristics typical of malicious emails. | Area 1 |
| distributed denial-of-service (DDoS) attack | A DDoS attack is a malicious attempt to disrupt normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic. | Fundamentals |
| DNS filtering | DNS filtering uses the Domain Name System to block malicious websites and filter out harmful content, enhancing security and access control. | Cloudflare One |
| DNS location | DNS locations are a collection of DNS endpoints which can be mapped to physical entities such as offices, homes, or data centers. | Cloudflare One |
| DNS over HTTPS | DNS over HTTPS (DoH) is a standard for encrypting DNS traffic via the HTTPS protocol, preventing tracking and spoofing of DNS queries. | DNS |
| DNS over TLS | DNS over TLS (DoT) is a standard for encrypting DNS traffic using its own port (`853`) and TLS encryption. | DNS |
| DNS record | DNS records are instructions that live in authoritative DNS servers and provide information about a domain, including what IP address is associated with that domain and how to handle requests for that domain. | DNS |
| DNS server | DNS servers translate human-readable domain names into IP addresses, eliminating the need to remember complex IP addresses. | DNS |
| DNS zone | A portion of the DNS namespace that is managed by a specific organization or administrator. | DNS |
| DoH subdomain | A unique DoH subdomain for each DNS location in Cloudflare One used in Cloudflare One Client settings. | Cloudflare One |
| domain | The domain name of your application on Cloudflare. | Fundamentals |
| domain control validation (DCV) | Process by which a certificate authority (CA) can verify domain ownership before issuing an SSL/TLS certificate. | SSL/TLS |
| Domain Name System (DNS) | The Domain Name System (DNS) is the phonebook of the Internet. DNS translates domain names to IP addresses. | DNS |
| downtime | Downtime is the duration during which a system, service, or equipment is not operational or unavailable for use. | Waiting Room |
| Durable Execution | "Durable Execution" is a programming model that allows applications to execute reliably, automatically persist state, retry, and be resistant to errors caused by API, network or even machine/infrastructure failures. Cloudflare Workflows provide a way to build and deploy applications that align with this model. | Workflows |
| Durable Object | A Durable Object is an individual instance of a Durable Object class. A Durable Object is globally unique (referenced by ID), provides a global point of coordination for all methods/requests sent to it, and has private, persistent storage that is not shared with other Durable Objects within a namespace. | Durable Objects |
| Durable Object class | The JavaScript class that defines the methods (RPC) and handlers (`fetch`, `alarm`) as part of your Durable Object, and/or an optional `constructor`. All Durable Objects within a single namespace share the same class definition. | Durable Objects |
| Durable Objects | The product name, or the collective noun referring to more than one Durable Object. | Durable Objects |
| Durable Objects | [Durable Objects](https://developers.cloudflare.com/durable-objects/) is a globally distributed coordination API with strongly consistent storage. | Workers |
| duration | [Duration](https://developers.cloudflare.com/workers/platform/limits/#duration) is a measurement of wall-clock time — the total amount of time from the start to end of an invocation of a Worker. | Workers |
| dynamic content | Dynamic content refers to website content that changes based on factors specific to the user such as time of visit, location, and device. News websites or social media are examples of this type of content. For this type of website, content has to be fetched from the origin server every time it is requested. | Cache |
| edge certificate | The SSL/TLS certificates that Cloudflare presents to clients visiting your website or application. Because of [how Cloudflare works](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/), there can actually be [two certificates involved in a single request](https://developers.cloudflare.com/ssl/concepts/): an edge certificate and an origin certificate. | SSL/TLS |
| edge response status code | HTTP response code sent from Cloudflare to the client (end user). The Cloudflare dashboard **Analytics** app uses the edge response status code. | Fundamentals |
| edge server | A server located at the edge of a network, typically within a CDN, that serves content to end-users. | Cache |
| EDNS Client Subnet (ECS) | ECS is a DNS extension that enables recursive DNS resolvers to include client IP address information in their DNS queries. Not all resolvers use ECS but, if they do, usually a part of the IP address is omitted. Sending ECS headers is generally intended to reduce latency and speed up content delivery in connection to [CDNs](https://developers.cloudflare.com/glossary/?term=cdn) and [load balancers](https://www.cloudflare.com/learning/performance/what-is-load-balancing/). The ECS mechanism is specified in [RFC 7871](https://www.rfc-editor.org/rfc/rfc7871.html). | DNS |
| encryption algorithm | An encryption algorithm is a set of mathematical operations performed on data to ensure the data is only understood by the intended recipient. | SSL/TLS |
| endpoint | Any service or hardware that intercepts and processes incoming public or private traffic. Examples of endpoints include origins, hostnames, private or public IP addresses, virtual IP addresses (VIPs), servers, and other dedicated hardware boxes. | Load Balancing |
| environment | [Environments](https://developers.cloudflare.com/workers/wrangler/environments/) allow you to deploy the same Worker application with different configuration for each environment. Only available for use with a [Wrangler configuration file](https://developers.cloudflare.com/workers/wrangler/configuration/). | Workers |
| environment variable | [Environment variables](https://developers.cloudflare.com/workers/configuration/environment-variables/) are a type of binding that allow you to attach text strings or JSON values to your Worker. | Workers |
| Environment Variables | [Environment Variables](https://developers.cloudflare.com/workers-ai/configuration/bindings/) are dynamic values that can be used within Workers to manage configuration settings, including those related to AI integrations. | Workers AI |
| equal-cost multi-path routing | A technique that uses hashes calculated from packet data to determine the route chosen. | Cloudflare WAN |
| error page | An error page is a webpage shown to users when they try to access a specific webpage or resource that is unavailable due to a server error, broken link, or other issues. It typically includes details about the encountered error and offers potential solutions or guidance to help users navigate the problem. | Waiting Room |
| event | An occurrence or happening that is significant and worthy of being recorded in a log. | Logs |
| Event | The event that triggered the Workflow instance. A `WorkflowEvent` may contain optional parameters (data) that a Workflow can operate on. | Workflows |
| example | Hello, world! You can use **Markdown** features inside of your `tooltips`. | Style Guide |
| Extended Validation (EV) certificate | EV certificates provide maximum trust to visitors, but require the most validation effort by the CA. EV certificates show the name of the company or organization in the address bar of the visitor’s browser. An EV certificate requires additional documentation by the company or organization in order for the CA to approve the certificate. | SSL/TLS |
| feature | A feature is a setting in the Cloudflare dashboard that corresponds to functionality within a Cloudflare product or API. | Fundamentals |
| Fine-Tuning | [Fine-Tuning](https://developers.cloudflare.com/workers-ai/fine-tunes/) is a general term for modifying an AI model by continuing to train it with additional data. | Workers AI |
| firewall | A firewall is a security system that monitors and controls network traffic based on a set of security rules. | WAF |
| firewall-as-a-service | Also known as cloud firewall. A security product that is hosted in the cloud. | Cloudflare Network Firewall |
| first contentful paint (FCP) | First contentful paint (FCP) is a web performance metric that measures the time it takes for the first piece of content to be rendered on the screen during the loading of a web page. | Speed |
| first input delay (FID) | First input delay (FID) is a web performance metric that measures the delay between a user's first interaction with a page (for example, clicking a button) and the moment the browser responds, indicating the page's interactivity and responsiveness. | Speed |
| fleet | A fleet is a collection of user devices. All devices in a fleet have the Cloudflare One Client installed and are connected to a [Zero Trust Organization](https://developers.cloudflare.com/cloudflare-one/setup/#create-a-zero-trust-organization). | Cloudflare One |
| flow data | Represents records of communication between devices. There are a number of flow data protocols, such as NetFlow or sFlow. | Network Flow |
| FTP (File Transfer Protocol) | A standard network protocol used for transferring files from one host to another over a TCP-based network. | Spectrum |
| FTPS (File Transfer Protocol Secure) | An extension of FTP that adds support for the Transport Layer Security (TLS) or Secure Sockets Layer (SSL) cryptographic protocols. | Spectrum |
| Function Calling | [Function Calling](https://developers.cloudflare.com/workers-ai/function-calling/) enables people to take Large Language Models (LLMs) and use the model response to execute functions or interact with external APIs. | Workers AI |
| GRE tunnel | Stands for generic routing encapsulation. It is a protocol wrapping one data packet within another type of data packet. This is useful for enabling protocols that are not normally supported by a network. | Cloudflare WAN |
| handler | [Handlers](https://developers.cloudflare.com/workers/runtime-apis/handlers/) are methods on Workers that can receive and process external inputs, and can be invoked from outside your Worker. | Workers |
| health check | Requests issued by a monitor at regular interval and — depending on the monitor settings — return a **pass** or **fail** value to make sure an endpoint is still able to receive traffic. Each health monitor request is trying to answer two questions:<ol><li>**Is the endpoint offline?**: Does the endpoint respond to the health monitor request at all? If so, does it respond quickly enough (as specified in the monitor's **Timeout** field)?</li><li>**Is the endpoint working as expected?**: Does the endpoint respond with the expected HTTP response codes? Does it include specific information in the response body?</li></ol>If the answer to either of these questions is "No", then the endpoint fails the health monitor request. | Load Balancing |
| Hops | Hops refer to the stops an email makes as it travels from the sender to the recipient. | Cloudflare One |
| hostname | The name given to a server or node on a network, often the public DNS name of a server. | DNS |
| HTTP request | An HTTP request is the way Internet communications platforms such as web browsers ask for the information they need to load a website. | Fundamentals |
| ICMP | Internet Control Message Protocol (ICMP) is used by network devices to send error messages and other operational information. ICMP is useful for diagnostic purposes, for example. | Cloudflare WAN |
| identity provider | An identity provider (IdP) stores and manages users' digital identities, enabling single sign-on and authentication for multiple applications. | Cloudflare One |
| idle connection | When a TCP connection is in an idle state, it means that the connection has been established, but neither endpoint is sending any data. In the context of HTTP, an idle connection is when an established connection between a client and a server is not currently transmitting any HTTP requests or responses. | Fundamentals |
| iFrame | An iFrame, short for Inline Frame, is an HTML element used to embed and display external content within a webpage, allowing the incorporation of another document or web page seamlessly within the main document. | Waiting Room |
| In-band pricing | Pricing transmitted in HTTP response headers alongside content. In Pay Per Crawl, the origin sets prices via the `crawler-price` header. | AI Crawl Control |
| Inference | [Inference](https://developers.cloudflare.com/workers-ai/fine-tunes/public-loras/#running-inference-with-public-loras) refers to the process of using a trained machine learning model to make predictions or generate outputs based on new data. | Workers AI |
| initial resolved IP | A unique, ephemeral IP address that Gateway assigns to DNS queries when filtering network traffic by hostname. The IP is randomly selected from an IPv4 range (`172.64.128.0/20` by default, configurable per account) or an IPv6 range (`2606:4700:0cf1:4000::/64`, not configurable). | Cloudflare One |
| input gate | While a storage operation is executing, no events shall be delivered to a Durable Object except for storage completion events. Any other events will be deferred until such a time as the object is no longer executing JavaScript code and is no longer waiting for any storage operations. We say that these events are waiting for the "input gate" to open. | Durable Objects |
| instance | See "Durable Object". | Durable Objects |
| instance | A specific instance (running, paused, errored) of a Workflow. A Workflow can have a potentially infinite number of instances. | Workflows |
| interaction to next paint (INP) | Interaction to next paint (INP) is a web performance metric that measures the time it takes for a web page to become interactive and respond to user input after the initial paint, providing insights into the user experience during the interaction phase of page loading. | Speed |
| intermediary | A label applied to a verified agent that a wide range of end users can operate, such as a browser-use or agentic service. Replaces the "signed agent" classification used before July 1, 2026. | Bots |
| intermediate certificate | For security purposes, CAs issue intermediate certificates for signing website certificates. Intermediate certificates provide a means for the CA to revoke a single intermediate certificate, thus affecting only a small subset of website certificates. | SSL/TLS |
| Internet | The Internet is a global system of computer networks that provides a wide range of information and communication facilities. | Fundamentals |
| Internet key exchange (IKE) | The protocol Cloudflare uses to create the IPsec tunnel between Cloudflare WAN and the customer's device. | Cloudflare WAN |
| Internet Routing Registry (IRR) | A globally distributed database of routing information which contains announced routes and routing policies in a common format. Network operators use this information, as well as [RPKI](https://developers.cloudflare.com/byoip/concepts/route-filtering-rpki/), to configure backbone routers. | BYOIP |
| IP address | IP stands for Internet Protocol, which is the set of rules that makes it possible for devices to communicate over the Internet. With billions of people accessing the Internet every day, unique identifiers are necessary to keep track of who is doing what. The Internet Protocol solves this by assigning IP numbers to every device accessing the Internet. Every assigned number is an IP address. | Fundamentals |
| IP spoofing | IP spoofing is the creation of Internet Protocol (IP) packets which have a modified source address to hide the identity of the sender, impersonate another computer system, or both. | DDoS Protection |
| IPsec tunnel | Stands for Internet Protocol secure. It is a group of protocols for securing connections between devices, by encrypting IP packets. | Cloudflare WAN |
| isolate | [Isolates](https://developers.cloudflare.com/workers/reference/how-workers-works/#isolates) are lightweight contexts that provide your code with variables it can access and a safe environment to be executed within. | Workers |
| JA3 fingerprint | JA3 and JA4 fingerprints profile specific SSL/TLS clients across different destination IPs, Ports, and X509 certificates. | Bots |
| JSON web token | A compact way to securely transmit information between parties as a JSON object, often used for authentication. | Cloudflare One |
| JSON web token (JWT) | A common authentication and authorization method used in web applications and APIs. | Rules |
| JSON-friendly | JSON-friendly refers to data or formats that are easily and naturally represented in JSON (JavaScript Object Notation), a lightweight data interchange format, without requiring complex transformations or modifications. | Waiting Room |
| KV | [Workers KV](https://developers.cloudflare.com/kv/) is Cloudflare's key-value data storage. | Workers |
| KV API | API methods part of Storage API that support persisting key-value data. | Durable Objects |
| KV namespace | A KV namespace is a key-value database replicated to Cloudflare’s global network. A KV namespace must require a binding and an id. | KV |
| largest contentful paint (LCP) | Largest contentful paint (LCP) is a web performance metric that measures the time it takes for the largest content element to be fully rendered and visible to the user during the loading of a web page. | Speed |
| latency | The delay between a user action and the corresponding response from the system. | Speed |
| layer 3 | The network layer in the OSI model, responsible for logical addressing, routing, and forwarding of data between devices on different networks. | Spectrum |
| layer 4 | The transport layer in the OSI model, managing end-to-end communication, error-checking, and flow control. | Spectrum |
| lazy loading | Loading images or other resources only when they are about to be displayed, rather than loading everything at once. | Speed |
| leaked credentials | Leaked credentials refers to sensitive authentication information disclosed in some way (for example, due to misconfigurations, data breaches, or simple human error), allowing other parties to gain access to digital resources. Credentials may include usernames, passwords, API keys, authentication tokens, or private keys. | WAF |
| legitimate traffic | Legitimate traffic refers to authorized and permissible network activity, data transmissions, or communications that adhere to established norms and rules within a given system or network. | Waiting Room |
| letter of agency | Sometimes referred to as a Letter of Authorization. A document that authorizes Cloudflare to advertise your prefixes. This is required so transit providers can accept the routes Cloudflare advertises on your behalf. | Magic Transit |
| LLM | A machine learning model that can comprehend and generate human language text. It works by analyzing massive data sets of language. | WAF |
| locally-managed tunnel | A Cloudflare Tunnel that was created by running `cloudflared tunnel create <NAME>` on the command line. Tunnel configuration is stored in your local `cloudflared` directory. | Cloudflare One |
| log | A chronological record of events, actions, or transactions, typically used for tracking and troubleshooting purposes. | Logs |
| log file | A file containing a collection of log entries, usually stored in a structured or semi-structured format. | Logs |
| logging | The process of recording events, actions, or transactions in a log. | Logs |
| LoRA Adapters | [LoRA Adapters](https://developers.cloudflare.com/workers-ai/fine-tunes/loras/) (Low-Rank Adaptation adapters) are used in machine learning to fine-tune models efficiently by adjusting a small number of parameters, allowing for customization of AI models in Workers AI. [Public LoRA Adapters](https://developers.cloudflare.com/workers-ai/fine-tunes/public-loras/) are pre-trained Low-Rank Adaptation adapters available for public use. | Workers AI |
| managed network | A network location, such as an office, that is associated with a specific Cloudflare One Client device profile. | Cloudflare One |
| maximum segment size (MSS) | MSS limits the size of packets, or small chunks of data, that travel across a network, such as the Internet. | Cloudflare WAN |
| Maximum Tokens | In generative AI, the user-defined property `max_tokens` defines the maximum number of tokens at which the model should stop responding. This limit cannot exceed the context window. | Workers AI |
| MCP client | A Model Context Protocol (MCP) client is an AI program that can request information and receive responses from an MCP server. Examples of MCP clients include Claude Desktop, Cursor AI, and Windsurf. | Cloudflare One |
| MCP server | A web application that allows AI agents to access third-party data sources and APIs using the Model Context Protocol (MCP). For example, you can use an MCP server to connect an AI assistant to your Google Drive account. | Cloudflare One |
| MCP server portal | A web application in Cloudflare One that serves as a gateway to multiple MCP servers. | Cloudflare One |
| MCP server tool | An integration provided by an MCP server which allows an AI agent to perform a limited set of actions on a third-party system. | Cloudflare One |
| MDM file | A Mobile Device Management (MDM) file is a configuration file that allows organizations to manage the software, settings, and certificates installed on their devices. | Cloudflare One |
| member or user | A member or user is an email account in Cloudflare that you can grant access to your organization account. Members belonging to multiple accounts can select which account to manage via the Cloudflare dashboard. | Fundamentals |
| Merchant of Record | The entity who facilitates "buying and selling". For pay per crawl, Cloudflare is the merchant of record. | AI Crawl Control |
| Mesh IP | A private IP address assigned to each device and node enrolled in Cloudflare Mesh from the `100.96.0.0/12` CGNAT range. Mesh IPs are the same as Cloudflare One Client device IPs. | Cloudflare One |
| metadata | A metadata is a serializable value you append to each KV entry. | KV |
| MFA | Multi-factor authentication (MFA) checks multiple aspects of a user's identity, not only their username and password, before allowing them access to an application. | Cloudflare One |
| migration | A Durable Object migration is a mapping process from a class name to a runtime state. Initiate a Durable Object migration when you need to:<ul><li>Create a new Durable Object class.</li><li>Rename a Durable Object class.</li><li>Delete a Durable Object class.</li><li>Transfer an existing Durable Objects class.</li></ul> | Durable Objects |
| minification | The process of removing unnecessary characters from code (such as whitespace or comments) to reduce file size and improve loading times. | Speed |
| mitigated request | A request to which Cloudflare applied a terminating action such as block or challenge. | WAF |
| Model Catalog | [Model Catalog](https://developers.cloudflare.com/workers-ai/models/) is a curated collection of AI models available within Workers AI, providing developers with a variety of pre-trained models for different tasks. | Workers AI |
| module Worker | Refers to a Worker written in [module syntax](https://developers.cloudflare.com/workers/reference/migrate-to-module-workers/). | Workers |
| monitor | A monitor issues health monitor requests at regular intervals to evaluate the health of each endpoint within a [pool](https://developers.cloudflare.com/load-balancing/pools/). When a pool [becomes unhealthy](https://developers.cloudflare.com/load-balancing/understand-basics/health-details/), your load balancer takes that pool out of the endpoint rotation. | Load Balancing |
| MQTT (Message Queuing Telemetry Transport) | A lightweight, publish-subscribe messaging protocol often used for communication in the Internet of Things (IoT) and other resource-constrained scenarios. | Spectrum |
| mTLS (mutual TLS) | [Mutual TLS (mTLS)](https://www.cloudflare.com/learning/access-management/what-is-mutual-tls/) authentication is a common security practice that uses client certificates to ensure traffic between client and server is bidirectionally secure and trusted. mTLS also allows requests that do not authenticate via an identity provider — such as Internet-of-things (IoT) devices — to demonstrate they can reach a given resource. | SSL/TLS |
| nameserver | A nameserver is a dedicated server that translates human readable hostnames (`www.example.com`) into IP addresses. Nameservers like root servers, TLD servers, and [authoritative nameservers](https://developers.cloudflare.com/dns/nameservers/) are fundamental components of the Domain Name System (DNS). | DNS |
| namespace | A logical collection of Durable Objects that all share the same Durable Object (class) definition. A single namespace can have (tens of) millions of Durable Objects. Metrics are scoped per namespace.<ul><li>The binding name of the namespace (as it will be exposed inside Worker code) is defined in the Wrangler file under the `durable_objects.bindings.name` key. Note that the binding name may not uniquely identify a namespace within an account. Instead, each namespace has a unique namespace ID, which you can view from the Cloudflare dashboard.</li><li>You can instantiate a unique Durable Object within a namespace using [Durable Object namespace methods](https://developers.cloudflare.com/durable-objects/api/namespace/#methods).</li></ul> | Durable Objects |
| NetFlow | Network protocol developed by Cisco to collect and monitor network traffic flow data. | Network Flow |
| non-browser traffic | Non-browser traffic refers to data exchanges and communication occurring between devices or systems that do not involve web browsers, such as a mobile app or web apps. | Waiting Room |
| OAuth | A protocol for authorizing users, allowing them to perform actions and view data on different platforms without sharing credentials. | Cloudflare One |
| OIDC | OpenID Connect (OIDC) is an identity authentication protocol built on top of OAuth 2.0. It is used verifying user identity and obtaining basic profile information. | Cloudflare One |
| on-ramp | Refers to a way of connecting a business network to Cloudflare. Examples of on-ramps, or ways to connect to Cloudflare, are Anycast GRE tunnels, Anycast IPsec tunnels, Cloudflare Network Interconnect (CNI), Cloudflare Tunnel, and the Cloudflare One Client. | Cloudflare One |
| on-ramp | Refers to a way of connecting a business network to Cloudflare. Examples of on-ramps, or ways to connect to Cloudflare, are Anycast GRE tunnels, Anycast IPsec tunnels, Cloudflare Network Interconnect (CNI), Cloudflare Tunnel, and WARP. | Cloudflare WAN |
| operator | The company or organization that owns and operates an AI crawler. Examples include OpenAI, Microsoft, Google, ByteDance, Anthropic, and Meta. In AI Crawl Control, crawlers are grouped by their operators. | AI Crawl Control |
| Organization Validated (OV) certificate | OV certificates are used by corporations or governments to portray an extra layer of confidence for their visitors. Rather than just validating domain ownership, the CA also validates the company’s registration using qualified independent information sources. The organization’s name is listed in the certificate. | SSL/TLS |
| origin | [Origin](https://www.cloudflare.com/learning/cdn/glossary/origin-server/) generally refers to the web server behind Cloudflare where your application is hosted. | Workers |
| origin bandwidth (origin egress bandwidth) | The amount of data transferred from the origin server to Cloudflare within a certain period of time. Origin bandwidth is the sum of all `EdgeResponseBytes` where `OriginResponseStatus` does not equal `0`. | Cache |
| origin certificate | A Cloudflare Origin Certificate is a free SSL/TLS certificate issued by Cloudflare that can be installed on your origin server to facilitate making sure your data is encrypted in transit from Cloudflare to your origin server using HTTPS. | SSL/TLS |
| origin request | An origin request is a request served from the origin server. | Fundamentals |
| origin response status code | An origin response status code is an HTTP response code sent from the origin server to Cloudflare. | Fundamentals |
| origin server | The original server where the web content is hosted before it is distributed to edge servers in a CDN. | Cache |
| origin/host server | The server where the website content is hosted. | Fundamentals |
| OSI model (Open Systems Interconnection model) | A conceptual framework that standardizes the functions of a telecommunication or computing system into seven abstraction layers. | Spectrum |
| output gate | When a storage write operation is in progress, any new outgoing network messages will be held back until the write has completed. We say that these messages are waiting for the "output gate" to open. If the write ultimately fails, the outgoing network messages will be discarded and replaced with errors, while the Durable Object will be shut down and restarted from scratch. | Durable Objects |
| PAC file | A file containing a JavaScript function which can instruct a browser to forward traffic to a proxy server instead of directly to the destination server. | Cloudflare One |
| page load time | The time it takes for a web page to fully load in a user's browser. | Speed |
| Pages | [Cloudflare Pages](https://developers.cloudflare.com/pages/) is Cloudflare's product offering for building and deploying full-stack applications. | Workers |
| paranoia level | Classifies rules of the OWASP managed ruleset according to their aggressiveness. | WAF |
| phishing | The practice of trying to acquire sensitive data through fraudulent emails or other means. Usually, the perpetrators try to pass for a legitimate company when asking for sensitive data. | Area 1 |
| plan | Plans distinguish the breadth of Cloudflare features accessible to a specific domain. Plan options include [Free, Pro, Business, or Enterprise](https://www.cloudflare.com/plans/). | Fundamentals |
| policy | A set of rules that regulate network activity, such as login access and website reachability. | Cloudflare One |
| policy-based routing | Policy-based routing (PBR) is a technique used to make routing decisions based on policies set by your administrador. | Magic Transit |
| pool | Within Cloudflare, pools represent your endpoints and how they are organized. As such, a pool can be a group of several endpoints, or you could also have only one endpoint (an origin server, for example) per pool. If you are familiar with DNS terminology, think of a pool as a “record set,” except Cloudflare only returns addresses that are considered healthy. You can attach health monitors to individual pools for customized monitoring. A pool can have either a single monitor or a monitor group attached — but not both. | Load Balancing |
| prefix | A number that identifies the network portion of an IP address. It tells devices if an IP address is on the same network or not. It is shown as a number after a slash (for example, `/31`) at the end of the IP address. Using an analogy, the prefix is like a street address. If an IP is in the same street, it belongs to the same network of devices. | Magic Transit |
| primary certificate / secondary certificate | Primary and secondary indicates the order in which Custom SSL certificates were uploaded to Cloudflare. The primary certificate is the first certificate added to a pack. The primary certificate defines the hostnames covered by the certificate. | SSL/TLS |
| primary database instance | The primary database instance is the original instance of a database. This database instance only exists in one location in the world. | D1 |
| producer | A producer is the term for a client that is publishing or producing messages on to a queue. | Queues |
| Prompt Engineering | [Prompt Engineering](https://developers.cloudflare.com/workers-ai/guides/prompting/) is the practice of designing and refining input prompts to effectively elicit desired responses from AI models. | Workers AI |
| prompt injection | The process of overwriting the system prompt for a large language model (LLM), which instructs the LLM on how to respond to user input. | WAF |
| Prompt Templates | [Prompt Templates](https://developers.cloudflare.com/workers-ai/guides/prompting/) are predefined structures that guide the input provided to AI models, enhancing consistency and effectiveness in responses. | Workers AI |
| protocol | A protocol is a set of rules governing the exchange or transmission of data between devices. | Fundamentals |
| proxy protocol | A protocol used by network proxies to convey client connection information to the destination server, facilitating proper handling of client requests. | Spectrum |
| proxy read timeout | A proxy read timeout is the maximum amount of time a proxy server waits for a response from the origin server before terminating the connection. | Fundamentals |
| proxy read timeout config | Enterprise customers can increase the a proxy read timeout using a [cache rule](https://developers.cloudflare.com/cache/how-to/cache-rules/settings/#proxy-read-timeout-enterprise-only) or the [edit zone setting API endpoint](https://developers.cloudflare.com/api/resources/zones/subresources/rate_plans/methods/get/). | Fundamentals |
| proxy server | The server that sits between the origin server and the client. Cloudflare is a proxy server for example. | Fundamentals |
| proxy status | The proxy status of a DNS record defines whether requests for your domain will route through Cloudflare (`proxied`) or not (`DNS-only`). When a [DNS record is proxied](https://developers.cloudflare.com/dns/proxy-status/), requests are processed according to your configurations, and Cloudflare can optimize, cache, and protect your domain. Refer to [How Cloudflare works](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/) for details. | DNS |
| proxy write timeout | A proxy write timeout is the maximum amount of time a proxy server allows for sending data to the client before terminating the connection. | Fundamentals |
| public key / private key | SSL public and private keys are essentially long strings of characters used for encrypting and decrypting data. Data encrypted with the public key can only be decrypted with the private key, and vice versa. Private keys are kept secret and unshared. | SSL/TLS |
| purge | The process of removing outdated content from the cache to make room for updated content and ensure the delivery of the latest content. | Cache |
| Quarantine policies | Policies that block specific types of emails (usually malicious and suspicious emails), preventing emails from reaching the end-user or the next mail service provider. Emails that are quarantined are reviewed by administrators and potentially released if falsely flagged. | Cloudflare One |
| query planner | A component in a database management system which takes a user query and generates the most efficient plan of executing that query (the query plan). For example, the query planner decides which indices to use, or which table to access first. | D1 |
| queue | A queue is a buffer or list that automatically scales as messages are written to it, and allows a consumer Worker to pull messages from that same queue. | Queues |
| Queues | [Queues](https://developers.cloudflare.com/queues/) integrates with Cloudflare Workers and enables you to build applications that can guarantee delivery. | Workers |
| R2 | [R2](https://developers.cloudflare.com/r2/) is an S3-compatible distributed object storage designed to eliminate the obstacles of sharing data across clouds. | Workers |
| rate limiting | Rate limiting is a technique used in computer systems to control the rate at which requests are processed. It can be used as a security measure to prevent attacks, or to limit resource usage in your origin servers. | WAF |
| RDP | Remote Desktop Protocol (RDP) allows remote desktop connections to a computer, often used on Windows and Mac operating systems. | Cloudflare One |
| read replica | A read replica is an eventually-replicated copy of the primary database instance which only serve read requests. There may be multiple read replicas for a single primary database instance. | D1 |
| real user monitoring (RUM) | Real user monitoring (RUM) is a web performance monitoring technique that collects and analyzes data based on actual user interactions and experiences, providing insights into how users interact with a website or application in real-time. | Speed |
| redirect | URL redirects navigate the user from a source URL to a target URL using a given HTTP status code. URL redirection is also known as URL forwarding. | Fundamentals |
| reference architecture | A reference architecture provides a high-level view of how all or part of the Cloudflare platform is built and how Cloudflare products would fit into a customer's existing infrastructure. | Fundamentals |
| Referrer | The site a user was on before visiting your domain, tracked via the HTTP Referer header. In AI Crawl Control, referrer data shows traffic arriving from AI platforms like ChatGPT or Perplexity. | AI Crawl Control |
| remotely-managed tunnel | A Cloudflare Tunnel whose configuration is stored on Cloudflare rather than on your local machine. You can manage the tunnel in the dashboard or by using the API. | Cloudflare One |
| render time | The time it takes for a browser to display a fully rendered web page after receiving the necessary resources. | Speed |
| replica lag | The time it takes for the primary database instance to replicate its changes to a specific read replica. | D1 |
| request | A request is a message that is sent between a client, or web browser, to a server. Each request that has been processed through the Cloudflare network generates a record. | Fundamentals |
| Resource Public Key Infrastructure (RPKI) | A cryptographic method of signing records that associate a route with an originating autonomous system number. | BYOIP |
| REST API | [REST API](https://developers.cloudflare.com/workers-ai/get-started/rest-api/) is an application programming interface that allows developers to interact with Workers AI services over HTTP, enabling model management and inference requests. | Workers AI |
| reverse proxy | A server that handles requests on behalf of clients, forwarding them to backend servers and managing tasks like load balancing and security. | Spectrum |
| robots.txt | A text file at the root of a website that instructs crawlers which pages they should or should not access. Compliance is voluntary. AI Crawl Control helps monitor which crawlers violate your robots.txt rules. | AI Crawl Control |
| roles | Authorize which Cloudflare products and features a member is allowed to access in a Cloudflare account. Learn more about [roles](https://developers.cloudflare.com/fundamentals/manage-members/roles/). | Fundamentals |
| rollback | [Rollbacks](https://developers.cloudflare.com/workers/versions-and-deployments/rollbacks/) are a way to deploy an older deployment to the Cloudflare global network. | Workers |
| root certificate | A root certificate is generated by a CA and is used to sign certificates. Every browser includes a root store of trusted root certificates. Any certificate signed with the private key of a root certificate is automatically trusted by a browser. | SSL/TLS |
| Route Origin Authorization (ROA) | The RPKI-signed object that states an autonomous system is authorized to originate a particular IP address prefix or set of prefixes. | BYOIP |
| rule characteristics | The set of parameters of a rate limiting rule that define how Cloudflare tracks the rate for the rule. | WAF |
| Rule group | A set of Access rules that can be configured once and then quickly applied across many Access policies. | Cloudflare One |
| SafeSearch | SafeSearch is a feature of search engines that filters explicit or offensive content from search results. | Cloudflare One |
| SAML | Security Assertion Markup Language (SAML) enables single sign-on and authentication for multiple applications. | Cloudflare One |
| sampling | In the context of Network Flow, sampling is the process of taking samples of packets for a specific period to identify potential attacks. | Network Flow |
| SASE | Secure Access Service Edge (SASE) is a cloud-based security model bundling networking and security functions. | Cloudflare One |
| saved bandwidth (saved egress bandwidth) | The percentage of bandwidth saved by caching on the Cloudflare network. | Cache |
| SCIM | System for Cross-domain Identity Management (SCIM) is an open standard protocol that allows identity providers (such as Okta or Microsoft Entra ID) to synchronize user identity information with cloud applications and services. | Cloudflare One |
| search engine optimization (SEO) | SEO, or search engine optimization, is the practice of optimizing online content to improve its visibility and ranking in search engine results, thereby increasing organic traffic and relevance. | Speed |
| seat | A unique, billable user within your Zero Trust organization who has performed [an authentication event](https://developers.cloudflare.com/cloudflare-one/team-and-resources/users/seat-management/#authentication-events). Service tokens do not consume seats. | Cloudflare One |
| secret | [Secrets](https://developers.cloudflare.com/workers/configuration/secrets/) are a type of binding that allow you to attach encrypted text values to your Worker. | Workers |
| secret key | The secret key allows communication between your application backend and the Cloudflare Turnstile server to validate the widget response. | Turnstile |
| Secure Sockets Layer (SSL) | SSL was a widely used cryptographic protocol for providing data security for Internet communications. SSL was superseded by TLS; however, most people still refer to Internet cryptographic protocols as SSL. | SSL/TLS |
| SEO crawlers | SEO crawlers, or web crawlers, are automated programs employed by search engines to systematically browse and index web content, gathering information about the structure and relevance of pages to determine search result rankings. | Waiting Room |
| Server Name Indication (SNI) | SNI allows a server to host multiple TLS Certificates for multiple websites using a single IP address. SNI adds the website hostname in the TLS handshake to inform the server which website to present when using shared IPs. Cloudflare uses SNI for all Universal SSL certificates. | SSL/TLS |
| server response time | The time it takes for a server to respond to a request from a user's browser. | Speed |
| Serverless GPUs | [Serverless GPUs](https://developers.cloudflare.com/workers-ai/) are graphics processing units provided by Cloudflare in a serverless environment, enabling scalable and efficient execution of machine learning models without the need for managing underlying hardware. | Workers AI |
| Service Level Agreement (SLA) | An SLA is a contractual obligation for Cloudflare to maintain a specific level of service. Read the [Service Level Agreement (SLA) for the Cloudflare Business plan](https://www.cloudflare.com/business-sla/). Enterprise customers refer to the Enterprise SLA provided with their contract. | Fundamentals |
| service provider (SP) | A service provider (SP) provides federated access to an application for a user from an identity provider (IdP). | Cloudflare One |
| service token | Authentication credentials generated by Cloudflare Access which enable automated systems to access protected applications. | Cloudflare One |
| service Worker | Refers to a Worker written in [service worker](https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API) [syntax](https://developers.cloudflare.com/workers/reference/migrate-to-module-workers/). | Workers |
| session | An event generated when a user logs in to an Access application. | Cloudflare One |
| session | A session encapsulates all the queries from one logical session for your application. For example, a session may correspond to all queries coming from a particular web browser session. | D1 |
| session identifier | A session identifier is a unique identifier that a website assigns to identify a specific user for the duration of their visit. | API Shield |
| Set-Cookie | Set-Cookie is an HTTP header used by web servers to send a cookie to a user's browser during an HTTP response, enabling the server to store information on the client side, often used for session management and user preferences. | Waiting Room |
| sFlow | An industry standard packet sampling protocol to monitor network devices. | Network Flow |
| SFTP (Secure File Transfer Protocol) | A secure file transfer protocol that uses the Secure Socket Shell (SSH) protocol for encryption and authentication. | Spectrum |
| shadow IT | Shadow IT is the unsanctioned use of software, hardware, or other systems and services within an organization, often without the knowledge of that organization's information technology (IT) department. For more information, refer to the [Cloudflare Learning Center](https://www.cloudflare.com/learning/access-management/what-is-shadow-it/). | Cloudflare One |
| SIEM | A Security Information and Event Management (SIEM) solution collects, analyzes, and correlates data to help manage security incidents, detect anomalies, and meet compliance requirements. | WAF |
| signed agent | A deprecated classification (retired July 1, 2026) for end-user-controlled agents that self-identify with Web Bot Auth. These agents are now verified bots labeled as intermediary. | Bots |
| sitekey | The sitekey is used to invoke Turnstile on your site. | Turnstile |
| SMB | Secure Messaging Block (SMB) is a network file sharing protocol used for accessing files and services on a network. | Cloudflare One |
| SMTP | Stands for Simple Mail Transfer Protocol. It is an Internet standard based on TCP/IP to send and receive email. | Area 1 |
| SMTP Server (Simple Mail Transfer Protocol Server) | A server responsible for sending, receiving, and relaying email messages over a network, following the SMTP protocol. | Spectrum |
| Snippets subrequest | Any request that a Snippet makes to either Internet resources using the Fetch API or requests to other Cloudflare services. | Rules |
| source endpoint | The source endpoint is the endpoint managed by API Shield in Endpoint Management by its routing feature. | API Shield |
| speed index | Speed index is a web performance metric that quantifies how quickly a user perceives a webpage to load by measuring the visual progression of content rendering over time, providing a comprehensive assessment of the overall user experience during page loading. | Speed |
| SQL API | API methods part of Storage API that support SQL querying. | Durable Objects |
| SSH | Secure Shell (SSH) protocol allows users to connect to infrastructure remotely and execute commands. | Cloudflare One |
| SSO | Single Sign-On (SSO) is a technology that combines multiple application logins into one, requiring users to enter credentials only once. | Cloudflare One |
| static content | Static content, like images, stylesheets, and JavaScript, remains the same for all users. It can be directly served from the cache without fetching from the origin server because it does not change without manual intervention. | Cache |
| static route | A fixed configuration to route traffic through Anycast tunnels from Cloudflare global network to the customer's locations. | Cloudflare WAN |
| step | A step is self-contained, individually retryable component of a Workflow. Steps may emit (optional) state that allows a Workflow to persist and continue from that step, even if a Workflow fails due to a network or infrastructure issue. A Workflow can have one or more steps up to the [step limit](https://developers.cloudflare.com/workflows/reference/limits/). | Workflows |
| Storage API | The transactional and strongly consistent (serializable) [Storage API](https://developers.cloudflare.com/durable-objects/api/sqlite-storage-api/) for persisting data within each Durable Object. State stored within a unique Durable Object is "private" to that Durable Object, and not accessible from other Durable Objects. Storage API includes key-value (KV) API, SQL API, and point-in-time-recovery (PITR) API.<ul><li>Durable Object classes with the key-value storage backend can use KV API.</li><li>Durable Object classes with the SQLite storage backend can use KV API, SQL API, and PITR API.</li></ul> | Durable Objects |
| Storage Backend | By default, a Durable Object class can use Storage API that leverages a key-value storage backend. New Durable Object classes can opt-in to using a [SQLite storage backend](https://developers.cloudflare.com/durable-objects/best-practices/access-durable-objects-storage/#sqlite-storage-backend). | Durable Objects |
| stub | An object that refers to a unique Durable Object within a namespace and allows you to call into that Durable Object via RPC methods or the `fetch` API. For example, `let stub = env.MY_DURABLE_OBJECT.get(id)` | Durable Objects |
| Subject Alternative Names (SANs) | The SAN field of an SSL certificate specifies additional hostnames (sites, IP addresses, common names, subdomains, apex domains, etc.) protected by a single SSL Certificate. | SSL/TLS |
| subnet | Also known as subnetwork. It refers to a network that is part of another network. | Cloudflare WAN |
| subrequest | A subrequest is any request that a Worker makes to either Internet resources using the [Fetch API](https://developers.cloudflare.com/workers/runtime-apis/fetch/) or requests to other Cloudflare services like [R2](https://developers.cloudflare.com/r2/), [KV](https://developers.cloudflare.com/kv/), or [D1](https://developers.cloudflare.com/d1/). | Workers |
| SYN (Synchronize) | The initial step in establishing a TCP connection, where a device requests a connection with another by sending a SYN packet. | Spectrum |
| SYN-ACK (Synchronize-Acknowledge) | The second step in the TCP three-way handshake, where the server responds to a SYN request with a SYN-ACK packet. | Spectrum |
| synthetic test | A synthetic test is an artificial simulation of user interactions and system behaviors designed to evaluate and measure the performance, responsiveness, and functionality of a website or application under controlled conditions. | Speed |
| Tail Worker | A [Tail Worker](https://developers.cloudflare.com/workers/observability/logs/tail-workers/) receives information about the execution of other Workers (known as producer Workers), such as HTTP statuses, data passed to `console.log()` or uncaught exceptions. | Workers |
| target | A resource with an IP address or hostname that is reachable by Cloudflare, such as a server or web application. | Cloudflare One |
| target endpoint | The target endpoint is the ultimate destination that a request is sent to by API Shield's routing feature. | API Shield |
| target hostname | A label used to identify a set of targets in an Access for Infrastructure application. | Cloudflare One |
| TCP (Transmission Control Protocol) | A connection-oriented protocol in the transport layer of the Internet Protocol Suite, providing reliable and ordered delivery of data between devices. | Spectrum |
| TCP Fast Open (TFO) | TCP Fast Open (TFO) is a protocol extension that can significantly improve the speed of establishing TCP connections by allowing data to be sent in the initial SYN packet, rather than requiring a separate handshake before data transmission begins. | Fundamentals |
| TCP Keep-Alive | A TCP keep-alive is used to maintain a connection between two endpoints by sending packets to check if the connection is still active. This helps prevent idle connections from being prematurely closed. If a response is not received after a defined period, the connection is terminated. | Fundamentals |
| TCP RST (reset) | A TCP Reset (RST) packet is used by a TCP sender to close a connection. | Fundamentals |
| TCP three-way handshake | TCP uses a three-way handshake to establish a reliable connection (SYN, SYN-ACK, ACK) over an IP based connection. SYN is short for synchronize, and ACK is short for acknowledgement. | Fundamentals |
| team domain | A unique subdomain assigned to your Cloudflare account (for example, `<your-team-name>.cloudflareaccess.com`), where users will find the apps you have secured behind Cloudflare One. | Cloudflare One |
| team name | The customizable portion of your team domain (`<your-team-name>.cloudflareaccess.com`). You can view your team name in Cloudflare One under **Settings**. | Cloudflare One |
| terminating action | A rule action like *Block* that stops the evaluation of remaining rules. | Ruleset Engine |
| Terraform | An infrastructure as code software tool that allows you to deploy services from different providers using a standardized configuration syntax. | Cloudflare One |
| threat score | The threat score was a score from `0` (zero risk) to `100` (high risk) classifying the IP reputation of a visitor. Currently, the threat score is always `0` (zero). | WAF |
| time to first byte (TTFB) | Time to first byte (TTFB) is the duration measured from the initiation of a web page request to the moment the first byte of data is received by the user's browser from the web server, indicating the server's initial response time. | Speed |
| time to interactive (TTI) | Time to interactive (TTI) is a web performance metric that measures the time it takes for a web page to become fully interactive and responsive to user input, indicating when users can effectively engage with and use the page. | Speed |
| time-to-live (TTL) | The duration for which a cached copy of a resource is considered valid before it needs to be refreshed or revalidated. | Cache |
| timestamp | A data field indicating the date and time when an event occurred, often used for sequencing and analysis. | Logs |
| TLS (Transport Layer Security) | TLS is a cryptographic protocol that ensures data security over a computer network, such as the Internet. It encrypts the data that is transmitted between a user's computer and a web server. | SSL/TLS |
| total bandwidth (total egress bandwidth, edge bandwidth) | Total bandwidth is the amount of data transferred from Cloudflare to end users within a certain period of time. Total bandwidth equals the sum of all `EdgeResponseBytes` for a certain period of time. | Cache |
| total blocking time (TBT) | Total blocking time (TBT) is a web performance metric that measures the total amount of time between First Contentful Paint (FCP) and Time to Interactive (TTI) where the main thread was blocked for long enough to prevent input responsiveness. | Speed |
| traffic | Traffic is the data sent and received by visitors to a website. Cloudflare serves and protects this data as it passes through the Cloudflare network. | Fundamentals |
| traffic management | The process of controlling and optimizing the flow of network data to ensure efficient and reliable communication. | Waiting Room |
| traffic steering | Cloudflare evaluates your route's health and steers traffic according to priorities defined by you and / or tunnel health. | Cloudflare WAN |
| tunnel | A secure pathway for network traffic to flow between a device and Cloudflare's global network. | Cloudflare One |
| tunnel health-check | A probe sent by Cloudflare to check for tunnel health. If a tunnel is not considered healthy, Cloudflare reroutes traffic to one that is considered healthy. | Cloudflare WAN |
| tutorial | A tutorial is a practical lesson that takes you from a clear starting to ending point. The goal is to connect products to real-world scenarios to meet a user’s goal. | Fundamentals |
| two-factor authentication (2FA) | Two-factor authentication (2FA) is a security process in which a user provides two different authentication factors to verify their identity. In addition to something you know, typically your password, 2FA adds an extra layer of security to user logins by requiring users to also present something they have, such as Yubikey or a one-time login code, or something you are, such as a fingerprint. It adds an extra layer of security to user logins by requiring users to present two or more separate pieces of evidence (factors) that establish their identity. | Fundamentals |
| UDP (User Datagram Protocol) | UDP (User Datagram Protocol) is a connectionless transport layer protocol that provides fast and lightweight data transmission between devices on a network, prioritizing speed over reliability. | Spectrum |
| uncached bandwidth (uncached egress bandwidth) | Uncached bandwidth is the amount of bandwidth that is not cached and therefore is served from the origin. Uncached bandwidth is the sum of all `EdgeResponseBytes` where `CacheCacheStatus` does not equal `hit`, `stale`, `updating`, `ignored`, or `revalidated`. | Cache |
| uncached requests | Uncached requests are requests that are not cached and therefore are served from the origin server. Uncached requests are the sum of all requests where `CacheCacheStatus` does not equal to `hit`, `stale`, `updating`, or `ignored`. | Cache |
| Unicast Reverse Path Forwarding (uRPF) | A security feature that can prevent spoofing attacks. | BYOIP |
| Universal SSL certificate | By default, Cloudflare issues — and [renews](https://developers.cloudflare.com/ssl/reference/certificate-validity-periods/#universal-ssl) — free, unshared, publicly trusted SSL certificates to all domains [added to](https://developers.cloudflare.com/fundamentals/manage-domains/add-site/) and [activated on](https://developers.cloudflare.com/dns/zone-setups/reference/domain-status/) Cloudflare. | SSL/TLS |
| URL normalization | The process of modifying the URLs of incoming requests so that they conform to a consistent formatting standard. | Rules |
| URL rewrite | An operation performed by a server that converts a source URL into a target URL. | Rules |
| User risk score | Ranks the likelihood of a user to introduce risk to your organization's systems and data based on the detection of security risk behaviors. Risk scores add user and entity behavior analytics (UEBA) to the Cloudflare One platform. | Cloudflare One |
| User risk score level | Cloudflare One assigns a risk score of Low, Medium or High based on detections of users' activities, posture, and settings. A user's risk score is equal to the highest-level risk behavior they trigger. | Cloudflare One |
| V8 | Chrome V8 is a [JavaScript engine](https://www.cloudflare.com/learning/serverless/glossary/what-is-chrome-v8/), which means that it [executes JavaScript code](https://developers.cloudflare.com/workers/reference/how-workers-works/). | Workers |
| validation level | The level to which a certificate authority validates domain ownership before issuing an SSL/TLS certificate. The different certificate validation levels are DV (Domain Validated), OV (Organization Validated), or EV (Extended Validation). | SSL/TLS |
| verified bot | A bot or agent that Cloudflare has confirmed is transparent about who it is and what it does: it represents itself honestly and does not abuse the access that honesty earns. | Bots |
| version | A [version](https://developers.cloudflare.com/workers/versions-and-deployments/#versions) is defined by the state of code as well as the state of configuration in a Worker's Wrangler file. | Workers |
| Virtual network | A software abstraction that allows you to logically segregate resources on a private network. Virtual networks are especially useful for exposing resources which have overlapping IP routes. | Cloudflare One |
| Virtual Private Cloud | A logically isolated section of cloud infrastructure that provides secure, private networking within a public cloud environment. | Workers VPC |
| Virtual Private Cloud (VPC) | A secure, isolated private network hosted on public cloud infrastructure. Examples of public cloud providers include Google Cloud, AWS, and Microsoft Azure. | Cloudflare One |
| Virtual Private Network (VPN) | A tool that allows users to send and receive data across shared or public networks as if their devices were directly connected to the private network. For example, employees working from home can use a VPN to access files on the corporate network. | Cloudflare One |
| virtual waiting room | A virtual waiting room is an online system or feature that manages and controls access to a website or service during periods of high traffic, preventing server overload by placing users in a queue until they can be accommodated, ensuring a more equitable and efficient user experience. | Waiting Room |
| wall-clock time | [Wall-clock time](https://developers.cloudflare.com/workers/platform/limits/#duration) is the total amount of time from the start to end of an invocation of a Worker. | Workers |
| WAN | Stands for Wide Area Network. It refers to a computer network that connects groups of computers over large distances. WANs are often used by businesses to connect their office networks. The objective is to make each of the local area networks (LANs) be remotely connected and accessible. | Cloudflare WAN |
| WARP CGNAT IP | A unique, virtual IP address assigned to each Cloudflare One Client device from the `100.96.0.0/12` range. | Cloudflare One |
| WARP client | The previous name for the Cloudflare One Client, an application that connects corporate devices to Cloudflare for private network access, advanced web filtering, and other security functions. | Cloudflare One |
| WARP Connector | The previous name for Cloudflare Mesh, a networking product that connects private networks, servers, and devices through Cloudflare for bidirectional, site-to-site, and mesh connectivity. | Cloudflare One |
| website | A website is a collection of web pages and related content that is identified by a common domain name and published on at least one web server. | Fundamentals |
| Worker Bindings | [Worker Bindings](https://developers.cloudflare.com/workers-ai/configuration/bindings/) are configurations that connect Workers scripts to external resources, such as AI models, enabling seamless integration and functionality. | Workers AI |
| workerd | [`workerd`](https://github.com/cloudflare/workerd?cf_target_id=D15F29F105B3A910EF4B2ECB12D02E2A) is a JavaScript / Wasm server runtime based on the same code that powers Cloudflare Workers. | Workers |
| Workers AI | [Workers AI](https://developers.cloudflare.com/workers-ai/) is a Cloudflare service that enables running machine learning models on Cloudflare's global network, utilizing serverless GPUs. It allows developers to integrate AI capabilities into their applications using Workers, Pages, or via the REST API. | Workers AI |
| Workers KV | [Workers KV](https://developers.cloudflare.com/kv/)is a data storage that allows you to store and retrieve data globally. | Workers AI |
| Workflow | The named Workflow definition, associated with a single Workers script. | Workflows |
| Wrangler | [Wrangler](https://developers.cloudflare.com/learning-paths/workers/get-started/c3-and-wrangler/) is the Cloudflare Developer Platform command-line interface (CLI) that allows you to manage projects, such as Workers, created from the Cloudflare Developer Platform product offering. | Workers |
| Wrangler CLI | [Wrangler CLI](https://developers.cloudflare.com/workers-ai/get-started/workers-wrangler/) is a command-line tool for building and deploying Cloudflare Workers, facilitating the integration of AI models into applications. | Workers AI |
| wrangler.toml / wrangler.json / wrangler.jsonc | The [configuration](https://developers.cloudflare.com/workers/wrangler/configuration/) used to customize the development and deployment setup for a Worker or a Pages Function. | Workers |
| Zero Trust Security | Zero Trust Security is an IT security model that requires strict identity verification for every person and device accessing resources on a network. | Cloudflare One |
| zero-shot classification model | A pretrained machine learning model capable of categorizing data (text or images) into classes it has never seen during training. | WAF |
| zone | A zone is a portion of DNS namespace that is managed by a specific organization or administrator. | Fundamentals |
| zone apex | Zone apex refers to the domain or subdomain on which the control of DNS records starts. | DNS |

View more terms

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/glossary/#page","headline":"Glossary","description":"Review definitions for terms used across Cloudflare products and documentation.","url":"https://developers.cloudflare.com/fundamentals/reference/glossary/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how Cloudflare's proxy interacts with Google Analytics tracking and how to use GA with Zaraz.
title: Cloudflare and Google Analytics
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare and Google Analytics

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/google-analytics/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Using Cloudflare does not affect Google Analytics (GA) tracking if it is added to the website [in one of ways recommended by Google ↗](https://support.google.com/analytics/answer/9304153#add-tag).

## Standard GA setup

Cloudflare proxies traffic to your origin web server, but the GA JavaScript code never actually sends traffic to your server. Instead, it executes directly in a user's browser and does not interact with Cloudflare.

Cloudflare only affects analytics tools that read logs directly from your web server (like awstats).

Note

To troubleshoot potential issues with Google Analytics, refer to [Common GA setup mistakes ↗](https://support.google.com/analytics/answer/1009683).

## Zaraz

As an alternative to the standard setup of Google Analytics with tag/snippet, Cloudflare offers a way to use Google Analytics with [Zaraz](https://developers.cloudflare.com/zaraz/). Zaraz is a solution that allows Google Analytics to collect data without its script loaded on the website. If GA is set up this way, then not all features may be available.

Note

Details about features of Google Analytics that are unavailable with Zaraz can be found in [Zaraz FAQ](https://developers.cloudflare.com/zaraz/faq/#tools)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/google-analytics/#page","headline":"Cloudflare and Google Analytics","description":"Understand how Cloudflare's proxy interacts with Google Analytics tracking and how to use GA with Zaraz.","url":"https://developers.cloudflare.com/fundamentals/reference/google-analytics/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the HTTP request and response headers that Cloudflare adds or modifies for proxied traffic.
title: Cloudflare HTTP headers
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare HTTP headers

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/http-headers/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Request headers

Cloudflare passes all HTTP request headers to your origin web server and adds additional headers as specified below.

Note

Cloudflare may remove HTTP request headers with names considered invalid [according to NGINX ↗](https://nginx.org/en/docs/http/ngx_http_core_module.html#ignore_invalid_headers) — for example, header names containing a `.` (dot) character.

### Accept-Encoding

For incoming requests, the value of this header will always be set to `accept-encoding: br, gzip`. If the client set a different value, such as `accept-encoding: deflate`, it will be overwritten and the original value will be available in `request.cf.clientAcceptEncoding`.

### CF-Connecting-IP

`CF-Connecting-IP` provides the client IP address connecting to Cloudflare to the origin web server. This header will only be sent on the traffic from Cloudflare's edge to your origin web server.

For guidance on logging your visitor's original IP address, refer to [Restoring original visitor IPs](https://developers.cloudflare.com/support/troubleshooting/restoring-visitor-ips/restoring-original-visitor-ips/).

Alternatively, if you do not wish to receive the `CF-Connecting-IP` header or any HTTP header that may contain the visitor's IP address, [enable the **Remove visitor IP headers** Managed Transform](https://developers.cloudflare.com/rules/transform/managed-transforms/configure/).

#### CF-Connecting-IP in Worker subrequests

In same-zone Worker subrequests, the value of `CF-Connecting-IP` reflects the value of `x-real-ip` (the client's IP). `x-real-ip` can be altered by the user in their Worker script.

In cross-zone subrequests from one Cloudflare zone to another Cloudflare zone, the `CF-Connecting-IP` value will be set to the Worker client IP address `'2a06:98c0:3600::103'` for security reasons.

For Worker subrequests destined for a non-Cloudflare customer zone, the `CF-Connecting-IP` and `x-real-ip` headers will both reflect the client's IP address, with only the `x-real-ip` header able to be altered.

When no Worker subrequest is triggered, `cf-connecting-ip` reflects the client's IP address and the `x-real-ip` header is stripped.

### CF-Connecting-IPv6

Cloudflare provides [free IPv6 support](https://developers.cloudflare.com/network/ipv6-compatibility/) to all domains without requiring additional configuration or hardware. To support migrating to IPv6, Cloudflare's [Pseudo IPv4](https://developers.cloudflare.com/network/pseudo-ipv4/) provides an IPv6 to IPv4 translation service for all Cloudflare domains.

If **Pseudo IPv4** is set to `Overwrite Headers` - Cloudflare overwrites the existing `Cf-Connecting-IP` and `X-Forwarded-For` headers with a pseudo IPv4 address while preserving the real IPv6 address in `CF-Connecting-IPv6` header.

  

### CF-EW-Via

This header is used for loop detection, similar to the `CDN-Loop` [header ↗](https://blog.cloudflare.com/preventing-request-loops-using-cdn-loop/).

### CF-Pseudo-IPv4

If [Pseudo IPv4](https://developers.cloudflare.com/network/pseudo-ipv4/) is set to `Add Header` - Cloudflare automatically adds the `CF-Pseudo-IPv4` header with a Class E IPv4 address hashed from the original IPv6 address.

### True-Client-IP (Enterprise plan only)

`True-Client-IP` provides the original client IP address to the origin web server. `True-Client-IP` is only available on an Enterprise plan. In the example below, `203.0.113.1` is the original visitor IP address. For example: `True-Client-IP: 203.0.113.1`

There is no difference between the `True-Client-IP` and `CF-Connecting-IP` headers besides the name of the header. Some Enterprise customers with legacy devices need `True-Client-IP` to avoid updating firewalls or load-balancers to read a custom header name.

To add a `True-Client-IP` HTTP header to requests, [enable the **Add "True-Client-IP" header** Managed Transform](https://developers.cloudflare.com/rules/transform/managed-transforms/configure/).

Alternatively, if you do not wish to receive the `True-Client-IP` header or any HTTP header that may contain the visitor's IP address, [enable the **Remove visitor IP headers** Managed Transform](https://developers.cloudflare.com/rules/transform/managed-transforms/configure/).

Caution

If you are using Cloudflare in a stacked CDN and authenticating HTTP requests based on the IP address value in the `True-Client-IP` header, you must add a `True-Client-IP` header to your requests. If you do not add this header, its value can be spoofed to any value.

### X-Forwarded-For

`X-Forwarded-For` maintains proxy server and original visitor IP addresses. If there was no existing `X-Forwarded-For`header in the request sent to Cloudflare, `X-Forwarded-For` has an identical value to the `CF-Connecting-IP` header.

For example, if the original visitor IP address is `203.0.113.1` and the request sent to Cloudflare does not contain an `X-Forwarded-For` header, then Cloudflare will send `X-Forwarded-For: 203.0.113.1` to the origin.

If, on the other hand, an `X-Forwarded-For` header was already present in the request to Cloudflare, Cloudflare will append the IP address of the HTTP proxy connecting to Cloudflare to the header. For example, if the original visitor IP address is `203.0.113.1` and a request is proxied through two proxies: proxy A with an IP address of `198.51.100.101` and proxy B with an IP address of `198.51.100.102` before being proxied to Cloudflare, then Cloudflare will send `X-Forwarded-For: 203.0.113.1,198.51.100.101,198.51.100.102` to the origin. Proxy A will append the original visitor's IP address (`203.0.113.1`) to `X-Forwarded-For` before proxying the request to proxy B which, in turn, will append Proxy A's IP address (`198.51.100.101`) to `X-Forwarded-For` before proxying the request to Cloudflare. And finally, Cloudflare will append proxy B's IP address (`198.51.100.102`) to `X-Forwarded-For` before proxying the request to the origin.

If you do not wish to receive the visitor's IP address (and other intermediate proxy IP addresses) in the `X-Forwarded-For` header, or any HTTP header that may contain the visitor's IP address, [enable the **Remove visitor IP headers** Managed Transform](https://developers.cloudflare.com/rules/transform/managed-transforms/configure/). For the `X-Forwarded-For` header specifically, this Managed Transform will only remove the visitor IP from the header value when Cloudflare receives a request proxied by at least another CDN. In this case, Cloudflare will only keep the IP address of the last proxy.

Using the previous example where a request was proxied twice (proxies A and B) before being proxied through Cloudflare, with **Remove visitor IP headers** enabled, Cloudflare would send `X-Forwarded-For: 198.51.100.102` to the origin, keeping only proxy B's IP address (the last proxy before Cloudflare). Refer to [Visitor IP address in the `x-forwarded-for` HTTP header](https://developers.cloudflare.com/rules/transform/managed-transforms/reference/#visitor-ip-address-in-the-x-forwarded-for-http-header) for more details.

Note

To restore the original visitor IP address at your origin web server, Cloudflare recommends that your logs or applications look at `CF-Connecting-IP` or `True-Client-IP` instead of `X-Forwarded-For`. `CF-Connecting-IP` and `True-Client-IP` both have a consistent format containing only one IP address.

### X-Forwarded-Proto

`X-Forwarded-Proto` is used to identify the protocol (HTTP or HTTPS) that a visitor used to connect to Cloudflare. By default, the protocol used is `https`, unless the visitor selected a different [encryption mode](https://developers.cloudflare.com/ssl/origin-configuration/ssl-modes/#custom-ssltls).

For incoming requests, the value of this header will be set to the protocol the client used (`http` or `https`). If the client set a different value, it will be overwritten.

### Cf-Ray

The `Cf-Ray` header (otherwise known as a [Ray ID](https://developers.cloudflare.com/fundamentals/reference/cloudflare-ray-id/)) is a hashed value that encodes information about the data center and the visitor's request. For example: `Cf-Ray: 230b030023ae2822-SJC`.

The Cf-Ray header identifies the data center processing the request when displayed as a response header. This is represented by a three-letter code corresponding to the data center's location.

The Cf-Ray header is also sent to upstream origins and may be modified to reflect the connecting data center. This occurs when a request is routed through [Argo Smart Routing](https://developers.cloudflare.com/argo-smart-routing/) or [Argo Tiered Caching](https://developers.cloudflare.com/cache/how-to/tiered-cache/). In such cases, the three-letter code in the Cf-Ray header will indicate the data center connecting to the origin, not the ingress data center.

Add the [`Cf-Ray` header to your origin web server logs](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#add-the-cf-ray-header-to-your-logs) to match requests proxied to Cloudflare to requests in your server logs.

Enterprise customers can see all requests via [Cloudflare Logs](https://developers.cloudflare.com/logs/), including data related to the ingress data center.

### CF-IPCountry

The `CF-IPCountry` header contains a two-character country code of the originating visitor's country.

Besides the [ISO-3166-1 alpha-2 codes ↗](https://www.iso.org/iso-3166-country-codes.html), Cloudflare uses the following special country codes:

- `XX` - Used for clients without country code data.
- `T1` - Used for clients using the Tor network.

To add this header to requests, along with other HTTP headers with location information for the visitor's IP address, [enable the **Add visitor location headers** Managed Transform](https://developers.cloudflare.com/rules/transform/managed-transforms/configure/).

Note

The `CF-IPCountry` header is removed from requests made from a Worker to an origin that is not proxied behind Cloudflare.

### CF-Visitor

Currently, this header is a JSON object, containing only one key called `scheme`. The header will be either HTTP or HTTPS, and it is only relevant if you need to enable Flexible SSL in your Cloudflare settings. For example: `CF-Visitor: { \"scheme\":\"https\"}`.

### CDN-Loop

`CDN-Loop` allows Cloudflare to specify how many times a request can enter Cloudflare's network before it is blocked as a looping request. For example: `CDN-Loop: cloudflare`.

### CF-Connecting-O2O

If [SSL for SaaS](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/) is used for [the SaaS provider-owned zone](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/saas-customers/how-it-works/), a HTTP header will be set to `cf-connecting-o2o: 1`.

### CF-Worker

The `CF-Worker` request header is added to an edge Worker subrequest that identifies the host that spawned the subrequest. For example: `CF-Worker: example.com`.

You can add `CF-Worker` header on server logs similar to the way you add the [`CF-RAY`](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#add-the-cf-ray-header-to-your-logs) header. To do that, add `$http_cf_worker` in the log format file: `log_format cf_custom "CF-Worker:$http_cf_worker"'`

`CF-Worker` is added to all Worker subrequests sent via `fetch()`. It is set to the name of the zone which owns the Worker making the subrequest. For example, a Worker script on route for `foo.example.com/*` from `example.com` will have all subrequests with the header:

```txt
CF-Worker: example.com
```

The intended purpose of this header is to provide a means for recipients (for example, origins, load balancers, other Workers) to recognize, filter, and route traffic generated by Workers on specific zones.

Note

When configuring WAF custom rules, do not match on this header. These rules are applied before Cloudflare adds the `CF-Worker` header. Instead, use the [`cf.worker.upstream_zone`](https://developers.cloudflare.com/ruleset-engine/rules-language/fields/reference/cf.worker.upstream_zone/) field, which contains the same value and exists for the same purpose.

To block a specific Worker, add a `Block` action triggered by the expression `cf.worker.upstream_zone eq "example.com"`.

To block all Worker subrequests except those from your own zone's Worker, add a `Block` action triggered by the expression `not (cf.worker.upstream_zone in {"" "customer-zone.com"})`.

### Connection

For incoming requests, the value of this header will always be set to `Keep-Alive`. If the client set a different value, such as `close`, it will be overwritten. Note that is also the case when the client uses HTTP/2 or HTTP/3 to connect.

### Considerations for Spectrum

When using Spectrum with a TCP application, these headers are not visible at the origin as they are HTTP headers. If you wish to utilize these in your application, there are two options:

- Use an HTTP or HTTPS Spectrum app instead of TCP
- Use the [Proxy Protocol feature](https://developers.cloudflare.com/spectrum/how-to/enable-proxy-protocol/)

## Response headers

Cloudflare will remove some HTTP headers from the response sent back to the visitor and add some Cloudflare-specific HTTP headers.

### Removed response headers

Cloudflare passes all HTTP headers in the response from the origin server back to the visitor with the exception of the following headers:

- `X-Accel-Buffering`
- `X-Accel-Charset`
- `X-Accel-Limit-Rate`
- `X-Accel-Redirect`
- `Alt-Svc`

### Added response headers

Cloudflare adds the HTTP headers specified below to the response sent to the visitor.

#### Cf-Ray

The `Cf-Ray` value returned to the visitor will be the same `Cf-Ray` value that was sent to the origin server.

#### Cf-Cache-Status

A list of all possible `Cf-Cache-Status` values is contained in [Cloudflare cache responses](https://developers.cloudflare.com/cache/concepts/cache-responses/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/http-headers/#page","headline":"Cloudflare HTTP headers","description":"Review the HTTP request and response headers that Cloudflare adds or modifies for proxied traffic.","url":"https://developers.cloudflare.com/fundamentals/reference/http-headers/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Cloudflare's Markdown for Agents converts HTML to Markdown at the edge, allowing AI systems to request content in text/markdown format.
title: Markdown for Agents
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Markdown for Agents

Last updated Jul 13, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## What is Markdown for Agents

Markdown has quickly become the lingua franca for agents and AI systems as a whole. The format’s explicit structure makes it ideal for AI processing, ultimately resulting in better results while minimizing token waste.

Cloudflare's network supports real-time content conversion at the source, for enabled zones using [content negotiation ↗](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Content_negotiation) headers. When AI systems request pages from any website that uses Cloudflare and has Markdown for Agents enabled, they can express the preference for `text/markdown` in the request and our network will automatically and efficiently convert the HTML to Markdown, when possible, on the fly.

Read the [announcement ↗](https://blog.cloudflare.com/markdown-for-agents/) in our blog for more information.

## How to use

To fetch the Markdown version of any page from a zone with Markdown for Agents enabled, the client needs to add the `Accept` negotiation header with `text/markdown` as one of the options. Cloudflare will detect this, fetch the original HTML version from the origin, and convert it to Markdown before serving it to the client.

Here's a curl example with the `Accept` negotiation header requesting this page from our developer documentation:

```bash
curl https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/ \
  -H "Accept: text/markdown"
```

Or if you’re building an AI Agent using Workers, you can use TypeScript:

```js
const r = await fetch(
	`https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/`,
	{
		headers: {
			Accept: "text/markdown",
		},
	},
);
const tokenCount = r.headers.get("x-markdown-tokens");
const originalTokenCount = r.headers.get("x-original-tokens");
const markdown = await r.text();
```

```ts
const r = await fetch(
	`https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/`,
	{
		headers: {
			Accept: "text/markdown",
		},
	},
);
const tokenCount = r.headers.get("x-markdown-tokens");
const originalTokenCount = r.headers.get("x-original-tokens");
const markdown = await r.text();
```

The response to this request is now formatting in markdown:

```http
HTTP/2 200
date: Wed, 11 Feb 2026 11:44:48 GMT
content-type: text/markdown; charset=utf-8
content-length: 2899
vary: accept
cache-control: public, max-age=3600
strict-transport-security: max-age=63072000; includeSubDomains
x-markdown-tokens: 725
x-original-tokens: 12345
content-signal: ai-train=yes, search=yes, ai-input=yes

---
title: Markdown for Agents · Cloudflare Agents docs
---

## What is Markdown for Agents

Markdown has quickly become the lingua franca for agents and AI systems
as a whole. The format’s explicit structure makes it ideal for AI processing,
ultimately resulting in better results while minimizing token waste.
...
```

### Response headers

Markdown for Agents preserves the headers from your origin response on the converted response, so security- and cache-relevant headers survive conversion. This includes headers such as `Strict-Transport-Security` (HSTS), `Content-Security-Policy` (CSP), `X-Frame-Options`, `Set-Cookie`, CORS headers (for example, `Access-Control-Allow-Origin`), and caching headers (`Cache-Control`, `Expires`, `Age`).

Because the body is replaced with converted Markdown, the following changes are applied:

- `Content-Type` is set to `text/markdown; charset=utf-8`.
- `Vary` includes `Accept` (any `Vary` dimensions your origin already declared are preserved) so that caches store separate variants for Markdown and HTML.
- `Content-Length` is recalculated to match the size of the Markdown response.
- Headers that describe the original body are removed, because they no longer match the converted response: `Content-Encoding`, `Content-Range`, `Transfer-Encoding`, `ETag`, and `Last-Modified`. `ETag` and `Last-Modified` are dropped because conditional requests ( `If-None-Match`, `If-Modified-Since`) cannot be honored for converted responses.

Markdown for Agents also adds the token count headers described below.

### Token count headers

Note that we include token count headers with the converted response. `x-markdown-tokens` indicates the estimated number of tokens in the Markdown document, and `x-original-tokens` indicates the estimated number of tokens in the original HTML document before conversion. You can use these values in your flow, for example to calculate the size of a context window, estimate the token savings from Markdown conversion, or decide on your chunking strategy.

### Content Signals Policy

[Content Signals ↗](https://contentsignals.org/) is a framework that allows anyone to express their preferences for how their content can be used after it has been accessed.

If your origin already sets a `content-signal` header, Markdown for Agents preserves that value on the converted response — your origin's policy is authoritative. This lets you define custom Content Signal policies by setting the `content-signal` header at your origin.

When the origin response does not include a `content-signal` header, Markdown for Agents adds a default `Content-Signal: ai-train=yes, search=yes, ai-input=yes`, signaling that the content can be used for AI Training, Search results, and AI Input, which includes agentic use.

## Output format

Markdown for Agents returns a Markdown document with a consistent, predictable structure so AI systems can rely on it without per-site parsing logic. The response always follows this layout:

1. **YAML frontmatter** with metadata extracted from the page's `<meta>` tags. Only emitted when at least one supported meta tag is present.
2. **Body Markdown** converted from the document body. Non-content elements (such as headers, footers, navigation, scripts, and styles) are stripped during pre-processing. For the full list of elements that are removed, refer to [HTML pre-processing](https://developers.cloudflare.com/workers-ai/features/markdown-conversion/how-it-works/#html) in the Workers AI Markdown Conversion documentation.
3. **JSON-LD** structured data preserved as a fenced `json` code block at the end of the document. Only emitted when the source HTML contains JSON-LD.

### YAML frontmatter

When the source HTML contains supported `<meta>` tags, Markdown for Agents prepends a YAML frontmatter block to the response. The block uses the following fields:

| Field | Source `<meta>` tag |
| --- | --- |
| `title` | `<meta name="title">`, with fallback to `<meta property="og:title">` |
| `description` | `<meta name="description">`, with fallback to `<meta property="og:description">` |
| `image` | `<meta property="og:image">` |

Only fields with a value are emitted. If the source HTML does not contain any of the supported meta tags, the frontmatter block is omitted entirely.

For `title` and `description`, the standard `<meta name="...">` form always takes priority over the Open Graph `<meta property="og:...">` form, regardless of the order they appear in the HTML. Open Graph values are used only as fallbacks when the standard form is missing.

Example output:

```markdown
---
title: My Page Title
description: A short summary of the page.
image: https://example.com/cover.png
---

# Page heading

...
```

### JSON-LD

[JSON-LD ↗](https://json-ld.org/) is a structured-data format used by search engines and AI systems to interpret a page's semantic content. Markdown for Agents preserves any `<script type="application/ld+json">` blocks from the source HTML by appending them at the end of the converted Markdown inside a single fenced `json` code block.

If the source HTML contains multiple JSON-LD scripts, all of them are concatenated within the same code block, each on its own line.

JSON-LD is the only `<script>` content preserved in the output — all other `<script>` and `<style>` content is stripped during [HTML pre-processing](https://developers.cloudflare.com/workers-ai/features/markdown-conversion/how-it-works/#html).

Example output:

````markdown
... main markdown content ...

```json
{
	"@context": "https://schema.org",
	"@type": "Article",
	"headline": "Article Title",
	"author": { "@type": "Person", "name": "Jane Doe" }
}
```
````

## How to enable

To enable Markdown for Agents for your zone in the dashboard:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and select your account (you need a Pro or Business plan).
2. Select the zone you want to configure.
3. Visit the [AI Crawl Control ↗](https://dash.cloudflare.com/?to=/:account/:zone/ai) section.
4. Enable **Markdown for Agents**.

### Enable for specific subdomains or paths

To enable Markdown for Agents for specific subdomains or paths instead of your entire zone, create a [configuration rule](https://developers.cloudflare.com/rules/configuration-rules/):

1. Log in to the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and select your account.
2. Select the zone you want to configure.
3. Go to **Rules** > **Overview** and select **Create rule** > **Configuration Rules**.
4. Under **When incoming requests match**, build an expression to match your subdomain (for example, `http.host eq "docs.example.com"`) or path.
5. Under **Then the settings are**, select **Add setting** > **Markdown for Agents** and set it to **On**.
6. Select **Deploy**.

To enable Markdown for Agents for your zone using APIs, send a `PATCH` to `/client/v4/zones/{zone_tag}/settings/content_converter` with the payload `{"value": "on"}` to the Cloudflare API.

You will need to create an API token with the Zone Settings edit permissions enabled.

Example:

*Enable Markdown for Agentsbash*

```bash
curl -X PATCH 'https://api.cloudflare.com/client/v4/zones/{zone_tag}/settings/content_converter' \
  --header 'Content-Type: application/json' \
  --header "Authorization: Bearer {api_token}" --data-raw '{"value": "on"}'
```

### Enable for specific subdomains or paths

To enable Markdown for Agents for specific subdomains or paths instead of your entire zone, create a [configuration rule](https://developers.cloudflare.com/rules/configuration-rules/create-api/):

*Enable Markdown for Agents for a subdomainbash*

```bash
curl --request PUT \
  --url "https://api.cloudflare.com/client/v4/zones/{zone_id}/rulesets/phases/http_config_settings/entrypoint" \
  --header "Authorization: Bearer {api_token}" \
  --header "Content-Type: application/json" \
  --data '{
    "rules": [{
      "expression": "http.host eq \"docs.example.com\"",
      "action": "set_config",
      "action_parameters": {
        "content_converter": true
      },
      "description": "Enable Markdown for Agents for docs subdomain"
    }]
  }'
```

You can also use path-based expressions like `starts_with(http.request.uri.path, "/blog/")`. For more information on building expressions, refer to [Rules language](https://developers.cloudflare.com/ruleset-engine/rules-language/).

If you are using [Cloudflare for SaaS](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/) and want to enable Markdown for Agents for your [custom hostnames](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/domain-support/), you have two options:

### Enable for all custom hostnames

To enable Markdown for Agents for all custom hostnames on your SaaS zone:

1. Log into the [Cloudflare dashboard ↗](https://dash.cloudflare.com/) and select your account.
2. Select your SaaS zone.
3. Look for **Quick Actions**.
4. Toggle the **Markdown for Agents** button to enable.

### Enable for specific custom hostnames

Enabling Markdown for Agents for specific custom hostnames requires an [advanced subscription](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/plans/) with access to [custom metadata](https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/domain-support/custom-metadata/).

#### Step 1: Set custom metadata on the custom hostname

When creating or updating a custom hostname via API, add `content_converter` to the `custom_metadata` object:

```bash
curl --request PATCH \
  --url "https://api.cloudflare.com/client/v4/zones/{zone_id}/custom_hostnames/{custom_hostname_id}" \
  --header "Authorization: Bearer {api_token}" \
  --header "Content-Type: application/json" \
  --data '{
    "custom_metadata": {
      "content_converter": "enabled"
    }
  }'
```

#### Step 2: Create a Configuration Rule

Create a Configuration Rule on your SaaS zone that matches custom hostnames with the metadata and enables content conversion:

```bash
curl --request PUT \
  --url "https://api.cloudflare.com/client/v4/zones/{zone_id}/rulesets/phases/http_config_settings/entrypoint" \
  --header "Authorization: Bearer {api_token}" \
  --header "Content-Type: application/json" \
  --data '{
    "rules": [{
      "expression": "lookup_json_string(cf.hostname.metadata, \"content_converter\") eq \"enabled\"",
      "action": "set_config",
      "action_parameters": {
        "content_converter": true
      },
      "description": "Enable content converter for opted-in custom hostnames"
    }]
  }'
```

This will enable the feature on custom hostnames that have the `content_converter` custom metadata tag set.

## Availability and Pricing

Markdown for Agents is available to Pro, Business and Enterprise plans, and SSL for SaaS customers at no cost.

## Try it with Cloudflare

We have enabled this feature in our [Developer Documentation ↗](https://developers.cloudflare.com/) and our [Blog ↗](https://blog.cloudflare.com/), inviting all AI crawlers and agents to consume our content using markdown instead of HTML.

```bash
curl https://blog.cloudflare.com/markdown-for-agents/ \
  -H "Accept: text/markdown"
```

## Limitations

- We only convert from HTML, other types of documents may be included in the future.
- The origin response cannot exceed 2 MB (2,097,152 bytes).

## Other Markdown conversion APIs

If you’re building AI systems that require arbitrary document conversion from outside Cloudflare or Markdown for Agents is not available from the content source, we provide other ways to convert documents to Markdown for your applications:

- Workers AI [AI.toMarkdown()](https://developers.cloudflare.com/workers-ai/features/markdown-conversion/) supports multiple document types and summarization.
- The Browser Run [/markdown](https://developers.cloudflare.com/browser-run/quick-actions/markdown-endpoint/) endpoint supports markdown conversion if you need to render a dynamic page or application in a real browser before converting it.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/#page","headline":"Markdown for Agents","description":"Cloudflare's Markdown for Agents converts HTML to Markdown at the edge, allowing AI systems to request content in text/markdown format.","url":"https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-07-13","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Migrate from SCIM v1 Virtual Groups to Cloudflare's GA SCIM User Groups
title: SCIM v1 to v2 Migration
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# SCIM v1 to v2 Migration

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/migration-guides/scim-virtual-groups-migration/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare's first iteration of SCIM integration introduced a concept called *Virtual Groups*, typically identified by the pattern `CF-<accountID>-<Role Name>` in your IdP. Virtual Groups were an early implementation of group-based access control: they acted as placeholders created automatically by SCIM to map IdP groups to account memberships.

While customers could add or remove members from these groups within their IdP, Virtual Groups had important limitations:

- They could not be renamed or deleted in the IdP.
- They could not be managed within Cloudflare.
- Functionally, managing a Virtual Group was equivalent to syncing users and editing each member’s policies individually.

With the GA of [User Groups](https://developers.cloudflare.com/changelog/2025-06-23-user-groups-ga/), Virtual Groups are now deprecated. Customers should migrate to [User Groups](https://developers.cloudflare.com/fundamentals/manage-members/user-groups/), which provide a more flexible and scalable way to assign and manage policies. To maintain SCIM synchronization with the Cloudflare Dashboard, we strongly recommend migrating to **SCIM User Groups**.

If you have never synced a group linked to a `CF-<accountID>-<Role Name>` Virtual Group from your IdP to Cloudflare, no action is needed.

## Migration steps

1. **Create a new SCIM integration** in your IdP using an [Account Owned Token](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/) provisioned in Cloudflare.
2. **Assign users & groups to your new Application** in your IdP, following a naming convention that aligns with your internal processes.
3. **Sync groups to Cloudflare** and verify they appear in the **User Groups** pane of the Cloudflare Dashboard.
4. **Attach permission policies** to the new User Groups so members inherit the correct access upon assignment to the group.
5. **Migrate users** into the new groups incrementally, testing synchronization of users & groups into the Cloudflare Dashboard.
6. **Clean up legacy resources** by removing SCIM v1 Virtual Groups and IdP mappings that follow the `CF-<accountID>-<Role Name>` pattern.

## More resources

- [User Groups changelog](https://developers.cloudflare.com/changelog/2025-06-02-user-groups-beta/)
- [User Groups documentation](https://developers.cloudflare.com/fundamentals/manage-members/user-groups/)
- [Create an Account Owned Token](https://developers.cloudflare.com/fundamentals/api/get-started/account-owned-tokens/#create-an-account-owned-token)
- [SCIM provisioning setup guide](https://developers.cloudflare.com/fundamentals/account/account-security/scim-setup/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/migration-guides/scim-virtual-groups-migration/#page","headline":"SCIM v1 to v2 Migration","description":"Migrate from SCIM v1 Virtual Groups to Cloudflare's GA SCIM User Groups","url":"https://developers.cloudflare.com/fundamentals/reference/migration-guides/scim-virtual-groups-migration/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Map Cloudflare products to OSI model layers, from Layer 7 application services to Layer 1 physical connections.
title: Network Layers
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Network Layers

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/network-layers/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Below is a list of the different layers that makes up the [open systems interconnection (OSI) model ↗](https://www.cloudflare.com/learning/ddos/glossary/open-systems-interconnection-model-osi/) and the associated Cloudflare products.

Note

The list of related products is representative but not comprehensive.

| Network layer | Protocol and related products |
| --- | --- |
| 7 Application layer | **HTTP, DNS**<br> [Authoritative DNS](https://developers.cloudflare.com/dns), [Bot Management](https://developers.cloudflare.com/bots), [CDN](https://developers.cloudflare.com/cache/), [Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/), [Cloudflare Gateway](https://developers.cloudflare.com/cloudflare-one/traffic-policies/) (outbound only), [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/), [Load Balancing](https://developers.cloudflare.com/load-balancing/understand-basics/proxy-modes/), [Stream](https://developers.cloudflare.com/stream/), [WAF](https://developers.cloudflare.com/waf/) |
| 6 Presentation layer | |
| 5 Session layer | |
| 4 Transport layer | **TCP/UDP**<br> [Argo Smart Routing](https://developers.cloudflare.com/argo-smart-routing/), [Cloudflare Gateway](https://developers.cloudflare.com/cloudflare-one/traffic-policies/) (outbound only), [Load Balancing](https://developers.cloudflare.com/load-balancing/understand-basics/proxy-modes/), [Spectrum](https://developers.cloudflare.com/spectrum/) |
| 3 Network layer | **IP, GRE, any packet/protocol**<br> [Cloudflare Network Firewall](https://developers.cloudflare.com/cloudflare-network-firewall/), [Magic Transit](https://developers.cloudflare.com/magic-transit), [Cloudflare WAN](https://developers.cloudflare.com/cloudflare-wan) |
| 2 Datalink layer | **Direct connection**<br> [Cloudflare Network Interconnect (CNI)](https://developers.cloudflare.com/network-interconnect) |
| 1 Physical layer | **Direct connection**<br> [Cloudflare Network Interconnect (CNI)](https://developers.cloudflare.com/network-interconnect) |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/network-layers/#page","headline":"Network Layers","description":"Map Cloudflare products to OSI model layers, from Layer 7 application services to Layer 1 physical connections.","url":"https://developers.cloudflare.com/fundamentals/reference/network-layers/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the HTTP and HTTPS ports Cloudflare proxies by default and how to enable proxy support for additional ports.
title: Network ports
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Network ports

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/network-ports/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Learn which network ports Cloudflare proxies by default and how to enable Cloudflare's proxy for additional ports.

## Network ports compatible with Cloudflare's proxy

By default, Cloudflare proxies traffic destined for the HTTP/HTTPS ports listed below.

<details>

<summary>

HTTP ports supported by Cloudflare

</summary>

- 80
- 8080
- 8880
- 2052
- 2082
- 2086
- 2095

</details>

<details>

<summary>

HTTPS ports supported by Cloudflare

</summary>

- 443
- 2053
- 2083
- 2087
- 2096
- 8443

</details>

<details>

<summary>

Ports supported by Cloudflare, but with caching disabled

</summary>

- 2052
- 2053
- 2082
- 2083
- 2086
- 2087
- 2095
- 2096
- 8880
- 8443

Note

Enterprise customers that want to enable caching on these ports can do so by creating a <a href="https://developers.cloudflare.com/cache/how-to/cache-rules/settings/#caching-on-port-enterprise-only">cache rule</a>.

</details>

## How to enable Cloudflare's proxy for additional ports

If traffic for your domain is destined for a different port than the ones listed above, for example you have an SSH server that listens for incoming connections on port 22, either:

- Change your subdomain to be [gray-clouded](https://developers.cloudflare.com/dns/proxy-status/), via your Cloudflare DNS app, to bypass the Cloudflare network and connect directly to your origin.
- Configure a [Spectrum application](https://developers.cloudflare.com/spectrum/get-started/) for the hostname running the server. Spectrum supports all ports. Spectrum for all TCP and UDP ports is only available on the Enterprise plan. If you would like to know more about Cloudflare plans, please reach out to your Cloudflare account team.

## How to block traffic on additional ports

Block traffic on ports other than 80 and 443 in Cloudflare paid plans by doing one of the following:

- If you are using [WAF managed rules (previous version)](https://developers.cloudflare.com/waf/reference/legacy/old-waf-managed-rules/), enable rule ID `100015` ( `Anomaly:Port - Non Standard Port (not 80 or 443)`).
- If you are using the new [Cloudflare Web Application Firewall (WAF)](https://developers.cloudflare.com/waf/), enable rule ID ...664ed6fe ( `Anomaly:Port - Non Standard Port (not 80 or 443)`), which is disabled by default. This rule is part of the Cloudflare Managed Ruleset.

Ports 80 and 443 are the only ports compatible with:

- HTTP/HTTPS traffic within China data centers for domains that have the **China Network** enabled

Due to the nature of Cloudflare's anycast network, ports other than `80` and `443` will be open so that Cloudflare can serve traffic for other customers on these ports. In general, Cloudflare makes available several different products on [Cloudflare IPs ↗](https://www.cloudflare.com/ips), so you can expect tools like Netcat and security scanners to report these non-standard ports as open in specific conditions. If you have questions on security compliance, review [Cloudflare's certifications and compliance resources ↗](https://www.cloudflare.com/en-gb/trust-hub/compliance-resources/) and contact your Cloudflare enterprise account manager for more information.

  

The WAF's [Cloudflare Managed Ruleset](https://developers.cloudflare.com/waf/managed-rules/reference/cloudflare-managed-ruleset/) includes a rule that will block traffic at the application layer (layer 7 in the [OSI model ↗](https://www.cloudflare.com/learning/ddos/glossary/open-systems-interconnection-model-osi/)), preventing HTTP/HTTPS requests over non-standard ports from reaching the origin server.

Note

[Cloudflare Access](https://developers.cloudflare.com/cloudflare-one/) does not support port numbers in URLs. Port numbers are stripped from requests for URLs protected through Cloudflare Access.

## Related resources

- [Managing DNS records at Cloudflare](https://developers.cloudflare.com/dns/manage-dns-records/how-to/create-dns-records/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/network-ports/#page","headline":"Network ports","description":"Review the HTTP and HTTPS ports Cloudflare proxies by default and how to enable proxy support for additional ports.","url":"https://developers.cloudflare.com/fundamentals/reference/network-ports/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Explore Cloudflare Technology Partner integrations for analytics, networking, Zero Trust, and logging.
title: Partners
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Partners

Last updated Apr 21, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/partners/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

[Cloudflare Technology Partners ↗](https://www.cloudflare.com/partners/technology-partners/) offer purpose-built integrations with our products, providing expanded functionality for our users. Learn how to configure these integrations with our tutorials and how-to guides.

## Analytics integrations

Learn how to configure a variety of products with Cloudflare Analytics:

- [Datadog](https://developers.cloudflare.com/analytics/analytics-integrations/datadog/)
- [Prometheus](https://developers.cloudflare.com/analytics/analytics-integrations/prometheus/)
- [Graylog](https://developers.cloudflare.com/analytics/analytics-integrations/graylog/)
- [New Relic](https://developers.cloudflare.com/analytics/analytics-integrations/new-relic/)
- [Splunk](https://developers.cloudflare.com/analytics/analytics-integrations/splunk/)
- [Sentinel](https://developers.cloudflare.com/analytics/analytics-integrations/sentinel/)

## Cloudflare Network Interconnect

Connect your network infrastructure with Cloudflare [network connectivity partners](https://developers.cloudflare.com/network-interconnect/get-started/#connectivity-partners) for increased reliability and security.

## Cloudflare Zero Trust Technology Partners

Our third-party integrations allow you to deploy the Cloudflare One Client application and configure devices remotely.

- [Fleet](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/fleet/)
- [Hexnode](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/hexnode/)
- [Intune](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/intune/)
- [Jamf](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/jamf/)
- [JumpCloud](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/jumpcloud/)
- [Kandji](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/kandji/)

## Cloudflare Logs

Enterprise customers have access to detailed logs of the metadata generated by our products, and logs from Cloudflare solutions can be pushed to a variety of log management providers and storage services.

- [Enable Cloudflare R2](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/r2/)
- [Enable Cloudflare Pipelines](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/pipelines/)
- [Enable HTTP destination](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/http/)
- [Enable Amazon S3](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/aws-s3/)
- [Enable S3-compatible endpoints](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/s3-compatible-endpoints/)
- [Enable Datadog](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/datadog/)
- [Enable Elastic](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/elastic/)
- [Enable Google Cloud Storage](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/google-cloud-storage/)
- [Enable Google BigQuery](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/bigquery/)
- [Enable Microsoft Azure](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/azure/)
- [Enable New Relic](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/new-relic/)
- [Enable SentinelOne](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/sentinelone/)
- [Enable Splunk](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/splunk/)
- [Enable Sumo Logic](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/sumo-logic/)
- [Enable Amazon Kinesis](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/kinesis/)
- [Enable IBM QRadar](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/ibm-qradar/)
- [Enable IBM Cloud Logs](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/ibm-cloud-logs/)
- [Enable other providers](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/other-providers/)
- [Third-party integrations](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/third-party/)
- [Dedicated Egress IP for Logpush](https://developers.cloudflare.com/logs/logpush/logpush-job/enable-destinations/egress-ip/)

## Cloudflare Technology Partners for Cloudflare WAN

Cloudflare WAN (formerly Magic WAN) integrates with a number of third-party partners, which enables our users to securely route their Internet traffic.

- [Alibaba Cloud VPN Gateway](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/alibaba-cloud/)
- [Amazon AWS Transit Gateway](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/aws/)
- [Aruba EdgeConnect Enterprise](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/aruba-edgeconnect/)
- [Cisco IOS XE](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/cisco-ios-xe/)
- [Cisco Meraki MX (static routing)](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/cisco-meraki-static/)
- [Cisco SD-WAN](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/viptela/)
- [Fortinet](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/fortinet/)
- [Furukawa Electric FITELnet](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/fitelnet/)
- [Google Cloud VPN](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/google/)
- [HPE Juniper Networking SRX Series Firewalls](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/juniper/)
- [Microsoft Azure](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/azure/)
- [Oracle Cloud](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/oracle/)
- [Palo Alto Networks NGFW](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/palo-alto/)
- [pfSense](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/pfsense/)
- [SonicWall](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/sonicwall/)
- [Sophos Firewall](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/sophos-firewall/)
- [strongSwan](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/strongswan/)
- [Ubiquiti](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/ubiquiti/)
- [Velocloud](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/velocloud/)
- [VyOS](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/vyos/)
- [Yamaha RTX Router](https://developers.cloudflare.com/cloudflare-wan/configuration/third-party/yamaha/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/partners/#page","headline":"Partners","description":"Explore Cloudflare Technology Partner integrations for analytics, networking, Zero Trust, and logging.","url":"https://developers.cloudflare.com/fundamentals/reference/partners/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-21","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the cookies Cloudflare sets for load balancing, bot management, challenges, and other product features.
title: Cloudflare Cookies
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Cloudflare Cookies

Last updated May 5, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare uses various cookies to maximize network resources, manage traffic, and protect our customers’ sites from malicious traffic.

## Understanding the Cloudflare Cookies

As defined in our [Privacy Policy ↗](https://www.cloudflare.com/privacypolicy/), all the cookies listed below are strictly necessary to provide the services requested by our customers, unless otherwise stated.

As mentioned in our Privacy Policy, Cloudflare encourages our customers to disclose the use of these cookies to their end users. In some jurisdictions, customers may be required by law to disclose these cookies to their end users.

By default, cookie data may be processed in Cloudflare's data center in the United States and is subject to the cross-border data transfer section 7 of the Cloudflare [Privacy Policy ↗](https://www.cloudflare.com/privacypolicy/). Customers who use the [Data Localization Suite](https://developers.cloudflare.com/data-localization/) can control where cookie data is processed (with [Regional Services](https://developers.cloudflare.com/data-localization/regional-services/)) and logged (using the [Customer Metadata Boundary](https://developers.cloudflare.com/data-localization/metadata-boundary/)).

### \_\_cflb cookie for Cloudflare Load Balancer session affinity

When enabling session affinity with [Cloudflare Load Balancer](https://developers.cloudflare.com/load-balancing/understand-basics/session-affinity/), Cloudflare sets a `__cflb` cookie with a unique value on the first response to the requesting client. Cloudflare routes future requests to the same origin, optimizing network resource usage. In the event of a failover, Cloudflare sets a new `__cflb` cookie to direct future requests to the failover pool.

The `__cflb` cookie allows Cloudflare to return an end user to the same customer origin for a specific period of time configured by the customer. This allows the end user to have a seamless experience (for example, this cookie is used for keeping an end user’s items in a shopping cart while they continue to navigate around the website). This cookie is a session cookie that lasts from several seconds up to 24 hours.

Note

Currently Cloudflare only supports Session Affinity in "orange-cloud" (proxied) mode.

### \_\_cf\_bm cookie for Cloudflare bot products

Cloudflare's [bot products](https://developers.cloudflare.com/bots/) identify and mitigate automated traffic to protect your site from bad bots. Cloudflare places the `__cf_bm` cookie on end-user devices that access customer sites protected by Bot Management or Bot Fight Mode. The `__cf_bm` cookie is necessary for these bot solutions to function properly.

This cookie expires after 30 minutes of continuous inactivity by the end user. The cookie contains information related to the calculation of Cloudflare's proprietary bot score and, when Anomaly Detection is enabled on Bot Management, a session identifier. The information in the cookie (other than time-related information) is encrypted and can only be decrypted by Cloudflare.

Note

The `Set-Cookie` header attributes for the `__cf_bm` cookie may use different casing depending on infrastructure version. For example, the expiration attribute may appear as `expires` or `Expires`. If you parse cookie headers programmatically, use case-insensitive matching for attribute names.

A separate `__cf_bm` cookie is generated for each site that an end user visits, as Cloudflare does not track users from site to site or from session to session. The `__cf_bm` cookie is generated independently by Cloudflare, and does not correspond to any user ID or other identifiers in a customer's web application.

Note

Bot Management is available to Enterprise customers as an add-on service. Contact your Cloudflare account team to enable Bot Management for your site. Non-Enterprise customers can enable [Bot Fight Mode or Super Bot Fight Mode](https://developers.cloudflare.com/bots/).

You can disable the `__cf_bm` cookie using the `bm_cookie_enabled` field [via the API](https://developers.cloudflare.com/api/resources/bot_management/methods/update/).

### \_\_cfseq cookie for Cloudflare bot products

[Sequence rules](https://developers.cloudflare.com/bots/additional-configurations/sequence-rules/) uses cookies to track the order of requests a user has made and the time between requests and makes them available via [Cloudflare Rules](https://developers.cloudflare.com/rules/). This allows you to write rules that match valid or invalid sequences. The specific cookies used to validate sequences are called sequence cookies.

### cf\_clearance cookie for Cloudflare bot products

The `cf_clearance` cookie is required for [JavaScript detections](https://developers.cloudflare.com/bots/additional-configurations/javascript-detections/). JavaScript detections are stored in the `cf_clearance` cookie.

The `cf_clearance` cookie is set with `SameSite=None; Secure; Partitioned` so that challenge state is preserved across cross-site requests while complying with [CHIPS ↗ ↗](https://developers.google.com/privacy-sandbox/cookies/chips). When the cookie is issued inside a third-party context, it is stored in a partition keyed to the top-level site and is not shared across embedding sites. For details, refer to [Partitioned cookies (CHIPS) and `cf_clearance`](https://developers.cloudflare.com/waf/troubleshooting/samesite-cookie-interaction/#partitioned-cookies-chips-and-cf_clearance).

### cf\_ob\_info and cf\_use\_ob cookie for Cloudflare Always Online

The `cf_ob_info` cookie provides information on:

- The HTTP Status Code returned by the origin web server
- The Ray ID of the original failed request
- The data center serving the traffic

The `cf_use_ob` cookie informs Cloudflare to fetch the requested resource from the Always Online cache on the designated port. Applicable values are: 0, 80, and 443. The `cf_ob_info` and `cf_use_ob` cookies are persistent cookies that expire after 30 seconds.

### \_\_cfwaitingroom for Cloudflare Waiting Room

[Cloudflare's Waiting Room](https://developers.cloudflare.com/waiting-room/) product enables a waiting room for a particular host and path combination within a zone. Visitors are put in the waiting room and provided an estimate of when they will be allowed to access the application, if not immediately available.

The `__cfwaitingroom` cookie is only used to track visitors that access a waiting room enabled host and path combination for a zone. Visitors using a browser that does not accept cookies cannot visit the host and path combination while the waiting room is active. For more details, refer to [Waiting Room cookies](https://developers.cloudflare.com/waiting-room/reference/waiting-room-cookie/).

### \_\_cfruid to support Cloudflare Rate Limiting (previous version)

The `__cfruid` cookie is strictly necessary to support Cloudflare Rate Limiting products. As part of our Rate Limiting solution, this cookie is required to manage incoming traffic and to have better visibility on the origin of a particular request.

### \_cfuvid for Rate Limiting Rules

The Rate Limiting Rules product uses a number of techniques for applying rate limits to traffic where multiple unique visitors share the same IP address, such as traffic from behind a NAT. These techniques can be enabled by using the `cf.unique_visitor_id` field in the rate limiting configuration.

The `_cfuvid` cookie is only set when a site uses this option in a Rate Limiting Rule, and is only used to allow the Cloudflare WAF to distinguish individual users who share the same IP address. Visitors who do not provide the cookie are likely to be grouped together and may not be able to access the site if there are many other visitors from the same IP address.

### Additional cookies used by the Challenge Platform

The table below shows additional cookies used by the Challenge Platform.

| Cookie Name | Description |
| --- | --- |
| `cf_clearance` | Clearance Cookie stores the proof of challenge passed. It is used to no longer issue a challenge if present. It is required to reach an origin server. |
| `cf_chl_rc_i`; `cf_chl_rc_ni`; `cf_chl_rc_m` | These cookies are for internal use which allows Cloudflare to identify production issues on clients. |

Caution

If your website is not [using HTTPS](https://developers.cloudflare.com/ssl/edge-certificates/encrypt-visitor-traffic/), you may experience issues with the [`cf_clearance` cookie](https://developers.cloudflare.com/waf/troubleshooting/samesite-cookie-interaction/#known-issues-with-samesite-and-cf_clearance-cookies).

### Cloudflare Access cookies

To review Cloudflare Access cookies and their behavior, refer to [Access cookies](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/#access-cookies).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/#page","headline":"Cloudflare Cookies","description":"Review the cookies Cloudflare sets for load balancing, bot management, challenges, and other product features.","url":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-05","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Access and download Cloudflare compliance documents such as PCI, SOC 2, and ISO certifications from the dashboard.
title: Compliance documentation
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Compliance documentation

Last updated Apr 28, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Super Administrators can access common compliance documentation, such as PCI, SOC 2, ISO, and more, through the Cloudflare dashboard.

To access compliance documentation:

1. Visit [Compliance Documents ↗](https://dash.cloudflare.com/?to=/:account/compliance-docs) and select your account where you are a **Super Administrator**.
2. If you have not accessed this page before, read the confidentiality statement and select **I Agree**.
3. Choose the document you need and select **Download**.

Note

For confidentiality purposes, only **Super Administrators** for an account can access compliance documentation.

## Public data protection and compliance documentation

Information and documents about Cloudflare's privacy & data protection are available at the Cloudflare [Trust Hub ↗](https://www.cloudflare.com/trust-hub/).

## Tax documentation

Super Administrators, Billing Administrators, and Administrators can access tax documentation, such W-9 and Tax Certificates, through the Cloudflare dashboard.

To access tax documentation:

1. Visit [Tax Documents ↗](https://dash.cloudflare.com/?to=/:account/tax-docs) and select your account where you are a **Super Administrator**, **Billing Administrator** or **Administrator**.
2. Choose the document you need and select **Download**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/#page","headline":"Compliance documentation","description":"Access and download Cloudflare compliance documents such as PCI, SOC 2, and ISO certifications from the dashboard.","url":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-28","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how Cloudflare interacts with Content Security Policies (CSPs) and which headers to update for specific Cloudflare features.
title: Content Security Policies (CSPs)
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Content Security Policies (CSPs)

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/content-security-policies/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

A **Content Security Policy (CSP)** is an added layer of security that helps detect and mitigate certain types of attacks, including:

- Content/code injection
- Cross-site scripting (XSS)
- Embedding malicious resources
- Malicious iframes (clickjacking)

To learn more about configuring a CSP in general, refer to the [Mozilla documentation ↗](https://developer.mozilla.org/docs/web/http/csp).

## Using a CSP with Cloudflare

Cloudflare's [CDN](https://developers.cloudflare.com/cache/) is compatible with CSP.

Cloudflare does not:

- Modify CSP headers from the origin web server (except when using Zaraz, to ensure the [Zaraz script is always running ↗](https://blog.cloudflare.com/cloudflare-zaraz-supports-csp/)).
- Require changes to acceptable sources for first or third-party content.
- Modify URLs (besides adding the [`/cdn-cgi/` endpoint](https://developers.cloudflare.com/fundamentals/reference/cdn-cgi-endpoint/) and [Cloudflare Fonts](https://developers.cloudflare.com/speed/optimization/content/fonts/) that rewrites Google Fonts urls).
- Interfere with locations specified in your CSP.

If you require the CSP headers to be changed or added, you can change them using some Cloudflare products:

- If your website is [proxied](https://developers.cloudflare.com/dns/proxy-status/) through Cloudflare, you can use a [response header transform rule](https://developers.cloudflare.com/rules/transform/response-header-modification/) to replace or add CSP headers.
- If your website is hosted using [Cloudflare Pages](https://developers.cloudflare.com/pages/), you can set a [`_headers file`](https://developers.cloudflare.com/pages/configuration/headers/) to modify or add CSP headers.

### Product requirements

To use certain Cloudflare features, however, you may need to update the headers in your CSP:

| Feature(s) | Updated headers |
| --- | --- |
| [Rocket Loader](https://developers.cloudflare.com/speed/optimization/content/rocket-loader/) | `script-src 'self' ajax.cloudflare.com;` |
| [Scrape Shield](https://developers.cloudflare.com/waf/tools/scrape-shield/) | `script-src 'self' 'unsafe-inline'` |
| [Web Analytics](https://developers.cloudflare.com/web-analytics/) | `script-src static.cloudflareinsights.com; connect-src cloudflareinsights.com` |
| [Bot products](https://developers.cloudflare.com/bots/) | Refer to [JavaScript detections and CSPs](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/javascript-detections/#if-you-have-a-content-security-policy-csp). |
| [Client-side security](https://developers.cloudflare.com/client-side-security/) (formerly Page Shield) | Refer to [CSP header format](https://developers.cloudflare.com/client-side-security/reference/csp-header/). |
| [Zaraz](https://developers.cloudflare.com/zaraz/) | No updates required ([details ↗](https://blog.cloudflare.com/cloudflare-zaraz-supports-csp/)). |
| [Turnstile](https://developers.cloudflare.com/turnstile/) | Refer to [Turnstile CSP](https://developers.cloudflare.com/turnstile/reference/content-security-policy/). |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/content-security-policies/#page","headline":"Content Security Policies (CSPs)","description":"Understand how Cloudflare interacts with Content Security Policies (CSPs) and which headers to update for specific Cloudflare features.","url":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/content-security-policies/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Project Cybersafe Schools provides eligible schools with free Cloudflare Email Security and Gateway products to meet CIPA requirements.
title: Project Cybersafe Schools
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Project Cybersafe Schools

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cybersafe/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Project Cybersafe Schools grants eligible schools with free access to Cloudflare's [Email security](https://developers.cloudflare.com/email-security/) and [Gateway](https://developers.cloudflare.com/cloudflare-one/traffic-policies/) products.

## School Eligibility

This program is only available to eligible school districts. To be eligible, Project Cybersafe School participants must be:

- K-12 public school districts located in the United States.
- Up to 2,500 students in the district.

## Children’s Internet Protection Act (CIPA)

The [Children's Internet Protection Act (CIPA) ↗](https://www.fcc.gov/sites/default/files/childrens_internet_protection_act_cipa.pdf) is a federal law enacted by the United States Congress to address concerns about children's access to inappropriate or harmful content over the Internet. CIPA requires K-12 schools and libraries that receive certain federal funding to implement Internet safety measures to protect minors from harmful online content.

The law aims to prevent students from accessing explicit, obscene, or otherwise harmful material. It also emphasizes the use of technology protection measures, including DNS filtering, to safeguard against Internet threats such as ransomware, phishing sites, and other potentially harmful content.

### CIPA Requirements

CIPA mandates that K-12 schools and libraries adopt Internet safety policies that include measures to block or filter access to specific categories of content. These categories encompass a wide range of topics that could be harmful or inappropriate for minors. Compliance with these requirements helps ensure that students' online experiences are safer and more secure.

### Configuration

To facilitate compliance with CIPA requirements, administrators can [enable a single filtering policy option](https://developers.cloudflare.com/cloudflare-one/traffic-policies/dns-policies/common-policies/#turn-on-cipa-filter). This includes applying the required filter categories to block access to unwanted or harmful online content.

Note

It is important to note that while our recommended CIPA compliance rule covers the essential filter categories, CIPA is designed to be flexible, allowing administrators to adjust filtering policies based on local standards and requirements.

Administrators should carefully assess their specific location and userbase to determine if additional categories may need to be added or modified to ensure comprehensive protection.

Cloudflare’s recommended CIPA rule blocks the following content subcategories:

- Adult Themes
- Alcohol
- Anonymizer
- Brand Embedding
- Child Abuse
- Command and Control & Botnet
- Cryptomining
- DGA Domains
- DNS Tunneling
- Drugs
- Gambling
- Hacking
- Malware
- Militancy, Hate & Extremism
- Nudity
- P2P
- Phishing
- Pornography
- Private IP Address
- Profanity
- Questionable Activities
- School Cheating
- Spam
- Spyware
- Tobacco
- Violence
- Weapons

Review the [domain categories](https://developers.cloudflare.com/cloudflare-one/traffic-policies/domain-categories/) for more information.

### Onboarding Guide

For a comprehensive guide, refer to the [Project Cybersafe Schools Learning Path](https://developers.cloudflare.com/learning-paths/cybersafe/concepts/), which takes you step by step through the technical concepts, creating an account, onboarding your traffic, and enabling the CIPA filters.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cybersafe/#page","headline":"Project Cybersafe Schools","description":"Project Cybersafe Schools provides eligible schools with free Cloudflare Email Security and Gateway products to meet CIPA requirements.","url":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cybersafe/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand Cloudflare's video delivery policies, resolve Terms of Service redirects, and choose the right paid product for streaming video.
title: Delivering Videos with Cloudflare
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Delivering Videos with Cloudflare

Last updated Aug 25, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/delivering-videos-with-cloudflare/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Using Cloudflare's Services

Cloudflare launched in 2010 believing everyone deserves a secure, fast, reliable web presence. We did not think you should have to pay more when you came under cyber attack, so we offered free and fixed-rate pricing for websites. That worked because most websites do not consume much bandwidth, and so we could provide our services in an affordable way to everyone. From the beginning, we prohibited streaming video content using our bandwidth. While you could embed a video from another provider, we limited your ability to use our services to deliver video bits from our network to your visitors. This restriction exists because every second of a typical video requires as much bandwidth as loading a full web page.

Over time we recognized that some of our customers wanted to stream video using our network. To accommodate them, we developed our [Stream ↗](https://www.cloudflare.com/products/cloudflare-stream/) product. Stream delivers great performance at an affordable rate charged based on how much load you place on our network.

Unfortunately, while most people respect these limitations and understand they exist to ensure high quality of service for all Cloudflare customers, some users attempt to misconfigure our service to stream video in violation of our [service-specific terms ↗](https://www.cloudflare.com/service-specific-terms-application-services/#content-delivery-network-free-pro-or-business). We want to make sure our service is great for everyone, including public service initiatives we run like [Project Galileo ↗](https://www.cloudflare.com/galileo/), [The Athenian Project ↗](https://www.cloudflare.com/athenian/), and [Project Fair Shot ↗](https://www.cloudflare.com/fair-shot/). A handful of people misusing our service limits our ability to run these initiatives.

The following are some recommendations for using Cloudflare's services based on what may have brought you to this page.

Cloudflare Tunnel

Cloudflare Tunnel public hostname routes proxy traffic through Cloudflare. On Free, Pro, and Business plans, this traffic is subject to the terms described on this page.

The restriction does not apply to private network routes. Refer to [Private networks](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/) to route large-file or high-traffic workloads privately.

---

## I'm a website operator and my content was redirected for Terms of Service violations

If you are on a Free, Pro, or Business Plan and your application appears to be serving videos or a disproportionate amount of large files without using the appropriate paid service as described below, Cloudflare may redirect your content or take other actions to protect quality of service. When this happens, you will receive an email notification regarding Cloudflare's actions and your options.

## Options for web admins to remove redirects

- **Serve redirected content from a grey-clouded sub-domain**
- **Serve redirected content from a paid service as outlined below**

## Delivering videos with Cloudflare using paid products

Cloudflare permits the delivery of video content with specific paid services. If you are interested in serving video content, there are two recommended options.

### Option 1: Cloudflare Stream

[Stream ↗](https://www.cloudflare.com/products/cloudflare-stream/) is a video-on-demand platform for building video applications. Stream encodes, stores, and delivers optimized video formatted for different devices and network connections.

To get started with Stream, visit **Stream** from your Dashboard or [sign up ↗](https://dash.cloudflare.com/sign-up/stream). Your Stream videos are not attached to a domain in your Cloudflare account, and you do not need a domain on Cloudflare to use Stream.

### Option 2: Stream Delivery (Enterprise only)

[Stream Delivery ↗](https://www.cloudflare.com/products/stream-delivery/) offers caching and delivery of video content through Cloudflare data centers around the globe. This CDN feature is only available on the Cloudflare Enterprise Plan. Please [contact sales ↗](https://www.cloudflare.com/products/stream-delivery/#) if you'd like to explore this option.

---

## Getting information on the content you are delivering

If you need more information about the content your zone is serving (for example, content type), you can use the following tools:

- Cache Analytics users: Open the **Caching tab** on the Dashboard to filter by content type and identify the type of traffic you are transferring.
- Users without Cache Analytics: Open the **Analytics tab** on the Dashboard and select the **Performance** section for information about the content you are serving.

![Cache Analytics - Identify type of traffic being transferred](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1285,height=695,format=webp/_astro/traffic-types.DW2gSjnB.png)

## Still have questions? Contact support

If you have additional questions about redirection (e.g. if you believe your content was redirected in error and have supporting evidence), file a [support ticket ↗](https://dash.cloudflare.com/redirect?account=support) and include the following information:

- Name of your domain
- Description of the problem
- Description of the content you're serving through Cloudflare's network

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/delivering-videos-with-cloudflare/#page","headline":"Delivering Videos with Cloudflare","description":"Understand Cloudflare's video delivery policies, resolve Terms of Service redirects, and choose the right paid product for streaming video.","url":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/delivering-videos-with-cloudflare/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-08-25","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the open-source licenses that apply to Cloudflare documentation content and code contributions.
title: Licenses
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Licenses

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/licenses/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

All documentation in the Cloudflare Workers documentation website, including reference documentation and tutorials, are licensed under the [CC-BY-SA 4.0 ↗](https://creativecommons.org/licenses/by-sa/4.0/) license. Any contributions to the [GitHub repository ↗](https://github.com/cloudflare/cloudflare-docs) for this project will be licensed under CC-BY-SA 4.0: thanks for your contributions!

Code contributions, such as snippets in the [Template Gallery](https://developers.cloudflare.com/workers/examples/) and the code that serves this website via Cloudflare Workers, are licensed under the [Apache License, Version 2.0 ↗](https://www.apache.org/licenses/LICENSE-2.0) and [The MIT License ↗](https://opensource.org/licenses/MIT).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/licenses/#page","headline":"Licenses","description":"Review the open-source licenses that apply to Cloudflare documentation content and code contributions.","url":"https://developers.cloudflare.com/fundamentals/reference/policies-compliances/licenses/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Compare Cloudflare redirect options including Single Redirects, Bulk Redirects, Pages Redirects, and Workers.
title: Redirects
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Redirects

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/redirects/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers a variety of ways to perform URL redirects, which tell a visitor's browser that the location of a page has been changed.

Use the following table to determine when to use each option.

| Option | Use when |
| --- | --- |
| [Single redirects](https://developers.cloudflare.com/rules/url-forwarding/single-redirects/) | As a default option. |
| [Bulk redirects](https://developers.cloudflare.com/rules/url-forwarding/bulk-redirects/) | When you have a large number of static redirects. |
| [Pages redirects](https://developers.cloudflare.com/pages/configuration/redirects/) | If you have a Pages project. |
| [Workers redirect](https://developers.cloudflare.com/workers/examples/redirect/) | When the other redirects do not meet your needs. |
| [Page Rules](https://developers.cloudflare.com/rules/page-rules/how-to/url-forwarding/) | If you already rely on Page Rules for other requirements. |

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/redirects/#page","headline":"Redirects","description":"Compare Cloudflare redirect options including Single Redirects, Bulk Redirects, Pages Redirects, and Workers.","url":"https://developers.cloudflare.com/fundamentals/reference/redirects/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to report DMCA issues, phishing, trademark infringement, malware sites, child exploitation material, and more to Cloudflare's Trust and Safety team.
title: Abuse
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Abuse

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/report-abuse/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare offers security and reliability services to millions of websites, helping prevent online abuse and make the Internet more secure.

When it comes to reports of abuse on websites that use our services, our ability to respond depends on the type of Cloudflare service at issue. Most abuse reports we receive pertain to websites that use our pass-through security and content delivery network (CDN) services, while far fewer reports relate to websites using our registrar services or our services to host content at the edge. Because Cloudflare offers a variety of Internet infrastructure services to users, our abuse reporting system is designed with those different services in mind.

## Resources

- [Read abuse policy ↗](https://www.cloudflare.com/trust-hub/abuse-approach/)
- [Review complaint types](https://developers.cloudflare.com/fundamentals/reference/report-abuse/complaint-types/)
- [Providing specific URLs](https://developers.cloudflare.com/fundamentals/reference/report-abuse/provide-specific-urls/)
- [Submit abuse report ↗](https://www.cloudflare.com/abuse/form)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/#page","headline":"Abuse","description":"Learn how to report DMCA issues, phishing, trademark infringement, malware sites, child exploitation material, and more to Cloudflare's Trust and Safety team.","url":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand your obligations when Cloudflare forwards an abuse report for a domain associated with your account.
title: Customer abuse report obligations
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Customer abuse report obligations

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/report-abuse/abuse-report-obligations/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare permits any interested party to submit abuse reports directly to Cloudflare via [abuse.cloudflare.com ↗](https://abuse.cloudflare.com/).

Abuse reports may be submitted for suspected copyright or trademark infringement, illegal, or harmful content (for example, child sex abuse materials), technical abuse (for example, phishing or malware), or other reasons.

You may receive an abuse report from our Trust & Safety team if an abuse report identifies a URL for a domain associated with your Cloudflare account. If you do not provide or monitor an abuse contact, Cloudflare will send abuse reports to your hosting provider.

Our Trust & Safety team sends abuse reports to the domain owner or the abuse point of contact on your account.

To assist with timely resolution and avoid potential service interruptions:

- Confirm that the [abuse contact email address](https://developers.cloudflare.com/fundamentals/account/account-security/abuse-contact/) associated with your account is actively managed and monitored for potential abuse report notifications.
- Consider using a mailing list email address that goes to multiple people or teams within your organization instead of the email address for an individual person.
- Respond to any abuse report notification within 24 hours. In your response, include any information that you believe will be relevant to Cloudflare in its assessment of the abuse report. Failure to respond in a timely manner or to address the concerns in the abuse report may result in the removal or blocking of reported content, websites, or apps and suspension or termination of Cloudflare services for the associated account.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/abuse-report-obligations/#page","headline":"Customer abuse report obligations","description":"Understand your obligations when Cloudflare forwards an abuse report for a domain associated with your account.","url":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/abuse-report-obligations/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Request removal of Trust and Safety content blocks on your domain.
title: Blocked Content
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Blocked Content

Last updated May 1, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/report-abuse/blocked-content/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If your domain has content that has been blocked, Blocked Content on the dashboard gives you the ability to request the Trust and Safety team to remove a block.

To view Blocked Content on the dashboard:

1. In the Cloudflare dashboard, go to the **Blocked Content** page.

[Go to **Blocked content** ↗](https://dash.cloudflare.com/?to=/:account/blocked-content)

Note

You must have Admin, Super Admin, or Trust and Safety [role](https://developers.cloudflare.com/fundamentals/manage-members/roles/) to access Blocked Content.

The Security Center dashboard displays three statuses for blocked content: active, pending, or resolved blocks.

## Active blocks

An active block is a block that is in effect on blocking content.

When you select **Request Review**, the status changes to **In Review**, and the block will be reviewed by the Trust and Safety team.

## Pending blocks

A pending block represents a blocking action Cloudflare will take at the scheduled time.

You can view all your pending blocks by selecting **Pending** on the dashboard. Selecting **Request Review** cancels the pending delayed action. This means that the block will not be placed.

## Resolved blocks

Resolved blocks list your recently resolved blocks. Resolved blocks are limited to 30 days of recently resolved blocks. Resolved blocks require no action. You can only sort and/or filter the list.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/blocked-content/#page","headline":"Blocked Content","description":"Request removal of Trust and Safety content blocks on your domain.","url":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/blocked-content/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-05-01","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Review the types of abuse complaints you can submit to Cloudflare, including DMCA, phishing, trademark, malware, and child exploitation reports.
title: Complaint types
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Complaint types

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/report-abuse/complaint-types/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Use Cloudflare's [online abuse form ↗](https://abuse.cloudflare.com/) to report different types of abuse.

---

## DMCA complaints

Valid [Digital Millennium Copyright Act (DMCA) ↗](https://www.copyright.gov/dmca/) complaints must provide all of the following details:

- A physical or electronic signature (typing your full name is valid) of the copyright owner or a person authorized to act on their behalf.
- Identification of the infringed copyright (for example, a link to your original work or clear description of the materials allegedly infringed upon).
- Identification of the infringing material and information reasonably sufficient to allow Cloudflare to locate the material on the infringing website (for example, a [link to the site](https://developers.cloudflare.com/fundamentals/reference/report-abuse/provide-specific-urls/) where the infringed copyrighted material appears).
- Your contact information, including your address, telephone number, and email address.
- A statement that you believe, in good faith, that the use of the material in the manner asserted is not authorized by the copyright owner, its agent, or the law.
- A statement that the information in the notification is accurate, and, under penalty of perjury, that you are authorized to act on behalf of the copyright owner.

---

## Phishing

Valid phishing reports must provide all of the following details:

- The domain in question.
- The specific link to the phishing page.

After Cloudflare confirms existence of the phishing page, Cloudflare provides a warning page to visitors accessing the phishing link. Cloudflare also notifies the site owner to clean the malicious files from their origin web server.

---

## Trademark infringement

Cloudflare only acknowledges abuse reports from trademark holders or their legally authorized representatives.

For more details about what information is required, refer to [our abuse form ↗](https://abuse.cloudflare.com/).

---

## Malware sites

Legitimate reports of malware URLs are blocked from loading via Cloudflare.

For more details about what information is required, refer to [our abuse form ↗](https://abuse.cloudflare.com/).

---

## Child exploitation material

Cloudflare promptly responds to all valid reports of child exploitation material. When Cloudflare is made aware of a website solely dedicated to the sharing or promotion of child exploitation material, the offending website is immediately removed from our network without notice.

For an expedited review, report child exploitation material via our [abuse form ↗](https://abuse.cloudflare.com/).

Our Trust & Safety team files a complaint with the [National Center for Missing and Exploited Children ↗](http://www.missingkids.com/gethelpnow#onlinechildexploitation) but suggest that you also file a complaint.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/complaint-types/#page","headline":"Complaint types","description":"Review the types of abuse complaints you can submit to Cloudflare, including DMCA, phishing, trademark, malware, and child exploitation reports.","url":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/complaint-types/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn how to provide specific asset URLs when submitting an abuse report.
title: Providing specific URLs
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Providing specific URLs

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/report-abuse/provide-specific-urls/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If you are [submitting an abuse report ↗](https://abuse.cloudflare.com) to Cloudflare because our IP address appears in the WHOIS and DNS records for a website, it is very likely that the website is one of millions of websites that use our pass-through security and content distribution network (CDN) services. Because assets on the same website may be hosted by different providers, it is important that you submit the URL for that specific asset to enable appropriate action. This guide will teach you how to identify URLs for specific video or images on a webpage.

## Get the URL for specific content

To get the URL for a specific piece of content on a webpage:

1. Open your web browser (Google Chrome, Safari, Firefox, Edge).
2. Go to the web page you want to report.
3. Right click on the content you wish to report (often a video or image).
4. Select **Inspect Element**.
5. In the **DevTools** panel, look for the **src** attribute in the selected the image, video, or iFrame. ![Look for the URL in the src attribute of the video or image](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=1268,height=322,format=webp/_astro/identify-url.o_PP6jZ2.png)
6. Copy the URL.

Providing the most specific and helpful URL enables Cloudflare to correctly identify any services it may be providing with respect to that content.

## Submitting the abuse report

Once you have identified the URL for the specific asset, you can [submit an abuse report ↗](https://abuse.cloudflare.com) through Cloudflare's online abuse reporting process.

You can learn more about the process, and what you can expect from Cloudflare in response to such abuse reports, from [our abuse policy ↗](https://www.cloudflare.com/trust-hub/reporting-abuse/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/provide-specific-urls/#page","headline":"Providing specific URLs","description":"Learn how to provide specific asset URLs when submitting an abuse report.","url":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/provide-specific-urls/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Submit abuse reports to Cloudflare via the dashboard, public form, or API, and view reports filed against your account.
title: View and submit reports
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# View and submit reports

Last updated Sep 10, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/report-abuse/submit-report/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Submit reports

Cloudflare provides security, performance, and reliability services to millions of websites. When you report abuse involving a website that uses Cloudflare, Cloudflare's ability to respond depends on the Cloudflare service involved. Many reports involve websites using Cloudflare's pass-through CDN and security services, while others involve domains registered through Cloudflare Registrar or content hosted on Cloudflare's developer platform.

If you find abusive content on a website that uses Cloudflare, you can submit a report in one of three ways:

- **Public form**: Use [Submit an abuse report ↗](https://abuse.cloudflare.com/) to report abuse to Cloudflare. This form is available to anyone on the Internet.
- **Cloudflare dashboard**: Entitled Cloudflare customers can submit abuse reports from the **Abuse reports** page. You must have the **Trust & Safety**, **Admin**, or **Super Admin** role. [Go to **Abuse reports** ↗](https://dash.cloudflare.com/?to=/:account/abuse-reports)
- **Cloudflare API**: Entitled Cloudflare customers can submit abuse reports using the [Abuse Reports API](https://developers.cloudflare.com/api/resources/abuse_reports/). You must have the **Trust & Safety**, **Admin**, or **Super Admin** role.

## View submitted reports

Entitled Cloudflare customers with the **Trust & Safety**, **Admin**, or **Super Admin** role can view abuse reports against content associated with their account.

1. In the Cloudflare dashboard, go to the **Abuse reports** page. [Go to **Abuse reports** ↗](https://dash.cloudflare.com/?to=/:account/abuse-reports)
2. Optionally, filter reports by date, report status, report type, or domain.

If Cloudflare applied a mitigation to your website because of an abuse report, you may be able to request a review of that mitigation in the dashboard or using the [Abuse Report Mitigations API](https://developers.cloudflare.com/api/resources/abuse_reports/subresources/mitigations/). Cloudflare will review the request and may remove the mitigation.

## Receive notifications

You can enable abuse notifications for your account to configure email, webhook, or PagerDuty alerts about new abuse reports against your websites.

For help setting up alerts, refer to [Configure Cloudflare notifications](https://developers.cloudflare.com/notifications/get-started/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/submit-report/#page","headline":"View and submit reports","description":"Submit abuse reports to Cloudflare via the dashboard, public form, or API, and view reports filed against your account.","url":"https://developers.cloudflare.com/fundamentals/reference/report-abuse/submit-report/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-09-10","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand Cloudflare's policy for conducting vulnerability scans and penetration tests on your own zones and assets.
title: Scans and penetration testing policy
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Scans and penetration testing policy

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/scans-penetration/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Customers may conduct scans and penetration tests (with certain restrictions) on application and network-layer aspects of their own assets, such as their [zones](https://developers.cloudflare.com/fundamentals/concepts/accounts-and-zones/#zones) within their Cloudflare accounts, provided they adhere to Cloudflare's policy.

## Permitted targets

All scans or testing must be limited to the following:

- Customer-owned IPs
- Cloudflare's designated public IPs
- The customer's registered DNS entries

Targets like `*.cloudflare.com` or other Cloudflare-owned destinations are only allowed as part of Cloudflare's Public Bug Bounty program. Refer to the [Additional resources](#additional-resources) section for more information.

## Scans

- **Throttling**: Scans should be throttled to a reasonable rate to prevent disruptions and ensure stable system performance.
- **Scope and intent**: Scans should identify the presence of vulnerabilities without attempting to actively exploit any detected weaknesses.
- **Exclusions**: It is recommended to exclude [`/cdn-cgi/` endpoints](https://developers.cloudflare.com/fundamentals/reference/cdn-cgi-endpoint/) from scans to avoid false positives or irrelevant results.
- **Compliance checks**: Customers may conduct [PCI compliance scans](https://developers.cloudflare.com/fundamentals/security/pci-scans/) or verify that [known vulnerabilities](https://developers.cloudflare.com/ssl/reference/compliance-and-vulnerabilities/#known-vulnerabilities-mitigations) have been addressed.

## Penetration tests

Before starting a penetration test on your [zones](https://developers.cloudflare.com/fundamentals/concepts/accounts-and-zones/#zones), set the following application security configurations for each zone you will run the test on:

1. [Deploy the Cloudflare Managed Ruleset](https://developers.cloudflare.com/waf/managed-rules/reference/cloudflare-managed-ruleset/#deploy-in-the-dashboard) and [enable all rules](https://developers.cloudflare.com/waf/managed-rules/reference/cloudflare-managed-ruleset/#ruleset-level-configuration) in the ruleset by setting **Ruleset status** to **Enabled**.
2. [Deploy the Cloudflare OWASP Core Ruleset](https://developers.cloudflare.com/waf/managed-rules/reference/owasp-core-ruleset/configure-dashboard/#deploy-in-the-dashboard) and set the following [ruleset configuration](https://developers.cloudflare.com/waf/managed-rules/reference/owasp-core-ruleset/configure-dashboard/#ruleset-level-configuration):
   - **Paranoia Level**: *PL4*
   - **Score threshold**: *High - 25 and higher*
3. [Create a custom rule](https://developers.cloudflare.com/waf/custom-rules/create-dashboard/) based on the [WAF attack score](https://developers.cloudflare.com/waf/detections/attack-score/) to block requests considered as an attack (WAF attack score between 1 and 20). Refer to the [WAF attack score](https://developers.cloudflare.com/waf/detections/attack-score/#1-create-a-custom-rule) documentation for an example.
4. [Create a custom rule](https://developers.cloudflare.com/waf/custom-rules/create-dashboard/) based on [malicious uploads detection](https://developers.cloudflare.com/waf/detections/malicious-uploads/) to block requests containing content objects considered malicious. Refer to [Example rules](https://developers.cloudflare.com/waf/detections/malicious-uploads/example-rules/#block-requests-to-uri-path-with-a-malicious-content-object) for examples of custom rules used to mitigate this kind of threat.
5. On Pro and Business plans without Bot Management, [enable Super Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/super-bot-fight-mode/#enable-super-bot-fight-mode).  
    Customers with access to Bot Management should make sure that [Bot Management is enabled](https://developers.cloudflare.com/bots/get-started/bot-management/#enable-bot-management-for-enterprise) (it is enabled by default on entitled zones).
6. [Create rate limiting rules](https://developers.cloudflare.com/waf/rate-limiting-rules/create-zone-dashboard/) to protect key endpoints of the zone being tested. Refer to [Rate limiting rule examples](https://developers.cloudflare.com/waf/rate-limiting-rules/use-cases/) and [Rate limiting best practices](https://developers.cloudflare.com/waf/rate-limiting-rules/best-practices/) for example configurations.

Be aware that other Cloudflare security and performance features, configurations, and rules active on your account or zone can influence test results.

After completing the test, it is recommended that you review your security posture and make any necessary adjustments based on the findings.

### Important remarks

- Cloudflare's [anycast network](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/) will report ports other than `80` and `443` as open due to its shared infrastructure and the nature of Cloudflare's proxy. The reporting is expected behavior and does not indicate a vulnerability.
- Tools like Netcat may list [non-standard HTTP ports](https://developers.cloudflare.com/fundamentals/reference/network-ports/) as open; however, these ports are open solely for Cloudflare's routing purposes and do not necessarily indicate that a connection can be established with the customer's origin over those ports.
- **Known false positives**: Any findings related to the [ROBOT vulnerability](https://developers.cloudflare.com/ssl/reference/compliance-and-vulnerabilities/#return-of-bleichenbachers-oracle-threat-robot) are false positives when the customer's assets are behind Cloudflare.

## Denial-of-Service (DoS) tests

For guidelines on required notification and necessary information, refer to [Simulating test DDoS attacks](https://developers.cloudflare.com/ddos-protection/reference/simulate-ddos-attack/). Customers should also familiarize themselves with Cloudflare's [DDoS protection best practices](https://developers.cloudflare.com/ddos-protection/best-practices/).

## Additional resources

- Customers can download the latest Penetration Test Report of Cloudflare via the [dashboard](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/).
- For information about Cloudflare's Public Bug Bounty program, visit [HackerOne ↗](https://hackerone.com/cloudflare).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/scans-penetration/#page","headline":"Scans and penetration testing policy","description":"Understand Cloudflare's policy for conducting vulnerability scans and penetration tests on your own zones and assets.","url":"https://developers.cloudflare.com/fundamentals/reference/scans-penetration/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand Cloudflare's SDK lifecycle stages, supported language runtimes, and ecosystem support commitments.
title: SDK ecosystem support policy
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# SDK ecosystem support policy

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/sdk-ecosystem-support-policy/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

## Lifecycle

Unless otherwise stated in the code repository, Cloudflare only provides active support for the latest major version of a library or tool. The exception to this policy is for critical security fixes, which will be reviewed on a case-by-case basis and take the vulnerability, impact, and mitigation required into consideration.

We provide three primary stages of development: early access, active support, and end of life.

Note

These lifecycle stages may be referred to in different terms across Cloudflare products, but the underlying principles are the same.

### Early access

During this stage, Cloudflare makes SDK changes available that we are seeking feedback on prior to releasing for general usage. Early access will often include warning labels or caveats on functionality that is subject to change without notice. In general, early access SDKs are not suitable for production systems unless explicitly mentioned.

### Active support

During the active support stage, planned changes and support are offered for the library or tool.

### End of life

During the end of life stage, a new major version of the library or tool is released and Cloudflare marks the previous major version as no longer receiving improvements or bug fixes. If you continue to run end of life versions, support will be very limited.

![All lifecycle stages and their relation to one another](https://developers.cloudflare.com/cdn-cgi/image/onerror=redirect,width=2228,height=812,format=webp/_astro/support-policy.ClhHS_PO.png "All lifecycle stages and their relation to one another")

*All lifecycle stages and their relation to one another*

## Previous or end of life versions

While Cloudflare cannot provide support for all older versions of our libraries or tools, we do not remove those versions so they can continued to be used without direct support.

## Versioning

The SDK ecosystem follows semantic versioning, which defines versions as follows:

- MAJOR version when there are backward-incompatible changes made.
- MINOR version when functionality is added in a backward compatible-manner.
- PATCH version for backward-compatible bug fixes (without any improvements).

Caution

As Cloudflare has recently swapped to [automatically generating our libraries using OpenAPI ↗](https://blog.cloudflare.com/lessons-from-building-an-automated-sdk-pipeline), we have relaxed the strict versioning requirements on the libraries (Terraform is not changing). Minor releases *may* contain breaking changes in the forms of method, structure, or type renames as the service owners stabilize their schemas and iterate on usability improvements.

If this is not suitable for your use case, pin to a known good version or use the previous major version of the library.

Depending on your needs, you should ensure your application's package manager versioning is configured correctly. At a minimum, restrict installation to the current major version of the library or tool you are using to prevent any major version upgrades occurring automatically.

## Migration

Where possible, Cloudflare provides an automated approach to performing major version upgrades to limit the disruption using codemods. Review the library or tool-specific release notes for how to use these migration tools.

Alongside the automatic migration approach, we provide documentation on the changes that have taken place in case you need to make the changes manually.

## Related resources

- [Semantic versioning definitions ↗](https://semver.org/)
- [Cloudflare's Terraform documentation](https://developers.cloudflare.com/terraform/)

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/sdk-ecosystem-support-policy/#page","headline":"SDK ecosystem support policy","description":"Understand Cloudflare's SDK lifecycle stages, supported language runtimes, and ecosystem support commitments.","url":"https://developers.cloudflare.com/fundamentals/reference/sdk-ecosystem-support-policy/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Understand how Cloudflare handles TCP connections, keep-alives, and TCP Fast Open between visitors and origin servers.
title: TCP connections
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# TCP connections

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/tcp-connections/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

The following section explains how Cloudflare directs traffic efficiently with anycast routing and serves as an intermediary between users and origin servers. The second part covers TCP connections and keep-alives for performance optimization, and lastly, TCP Fast Open (TFO), a protocol extension that enhances the speed of TCP connections.

## How Cloudflare connects user to origin

Users connect to Cloudflare by sending requests from their devices to Cloudflare's global network. Cloudflare connects to the origin server by acting as an intermediary between the user and the origin.

```
flowchart LR
accTitle: Connections with Cloudflare
A[Visitor] <-- Connection --> B[Cloudflare global network] <-- Connection --> C[Origin server]

```

  

User traffic is routed to the nearest Cloudflare data center based on the shortest [Border Gateway Protocol ↗](https://www.cloudflare.com/learning/security/glossary/what-is-bgp/) (BGP) path, thanks to [anycast ↗](https://www.cloudflare.com/learning/cdn/glossary/anycast-network/) routing. Cloudflare then processes the request. In case a request is not served from Cloudflare’s data centers, Cloudflare will open a connection to the origin server to forward the request.

## TCP connections and keep-alives

HTTP (Hypertext Transfer Protocol) is a [Layer 7 ↗](https://en.wikipedia.org/wiki/OSI_model) application protocol that operates over TCP. By default, HTTP opens a new TCP connection for each request-response cycle, which can lead to performance overhead due to the repeated connection establishment and teardown.

Keep-Alives are a mechanism that bridges TCP and HTTP, and allow a single TCP connection to remain open for multiple HTTP requests and responses. This minimizes the connection overhead and latency associated with establishing new TCP connections for each web resource. Keep-Alives improve the efficiency and responsiveness of web applications by facilitating the reuse of existing connections, reducing network traffic, and enhancing user experience.

TCP connections can persist even after HTTP requests have concluded. However, to manage resources efficiently, idle connections are typically terminated after a certain period of inactivity. To enhance connection reuse and minimize connection overhead, keep-alives are employed. These mechanisms collectively optimize the performance and reliability of web applications while conserving network resources.

If either a user or an origin does not respond to two keep-alives, Cloudflare will sever the connection by sending a TCP Reset (RST) packet.

For connections to users, Cloudflare has a default idle timeout of 400 seconds. After the 400 seconds, Cloudflare will start sending keep-alive probes every 75 seconds. If nine consecutive probes are unanswered, Cloudflare will sever the connection by sending an RST packet.

Note

Be aware that even if there are keep-alives, Cloudflare cannot guarantee to keep a connection, since besides idleness, there are other reasons, like capacity balancing, data center maintenance or node restarts that can cause disconnections. Having this in mind, applications should be structured to handle disconnections gracefully.

TCP connection settings between the user and Cloudflare, and between Cloudflare and Origin can be customized for Enterprise customers. Reach out to your account team for more details.

## TCP Fast Open (TFO)

[TCP Fast Open ↗](https://en.wikipedia.org/wiki/TCP_Fast_Open) (TFO) is a protocol extension that can significantly improve the speed of establishing TCP connections by allowing data to be sent in the initial SYN packet, rather than requiring a separate handshake before data transmission begins. TFO can reduce latency and improve website and application performance, particularly on high-latency networks. Cloudflare supports TFO on user connections.

When a client initiates a connection to a web server protected by Cloudflare, it sends a TCP SYN packet to request a connection. Cloudflare, acting as a reverse proxy, intercepts the SYN packet and responds with a SYN-ACK packet to establish the connection. With TFO enabled, Cloudflare can also send initial data (such as HTTP request data) in the SYN-ACK packet, eliminating the need for an additional round-trip for data transmission. The client receives the SYN-ACK packet with data and acknowledges it with an ACK packet. This fast tracks the connection setup.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/tcp-connections/#page","headline":"TCP connections","description":"Understand how Cloudflare handles TCP connections, keep-alives, and TCP Fast Open between visitors and origin servers.","url":"https://developers.cloudflare.com/fundamentals/reference/tcp-connections/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Resolve common error messages and unexpected behavior when setting up your Cloudflare account and domain.
title: Troubleshooting
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Troubleshooting

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/troubleshooting/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

When you [set up Cloudflare](https://developers.cloudflare.com/fundamentals/account/), you may experience the following issues or error messages.

## Error messages

- [`ERR_TOO_MANY_REDIRECTS`](https://developers.cloudflare.com/ssl/troubleshooting/too-many-redirects/)
- [`525` or `526` errors](https://developers.cloudflare.com/ssl/troubleshooting/too-many-redirects/)
- [Cannot add DNS records with the same name](https://developers.cloudflare.com/dns/manage-dns-records/troubleshooting/records-with-same-name/)
- [`ERR_SSL_VERSION_OR_CIPHER_MISMATCH` or `SSL_ERROR_NO_CYPHER_OVERLAP`](https://developers.cloudflare.com/ssl/troubleshooting/version-cipher-mismatch/)
- [`DNS_PROBE_FINISHED_NXDOMAIN`](https://developers.cloudflare.com/dns/troubleshooting/dns-probe-finished-nxdomain/)
- [Record exposing origin server IP address](https://developers.cloudflare.com/dns/manage-dns-records/troubleshooting/exposed-ip-address/)
- [Mixed content errors](https://developers.cloudflare.com/ssl/troubleshooting/mixed-content-errors/)
- [SSL errors in appear in my browser](https://developers.cloudflare.com/ssl/troubleshooting/general-ssl-errors/)

## Behavior

- [Why are Cloudflare's IPs in my origin web server logs?](https://developers.cloudflare.com/support/troubleshooting/restoring-visitor-ips/restoring-original-visitor-ips/)
- [Is Cloudflare attacking me?](#is-cloudflare-attacking-me)
- [Cannot add domain to Cloudflare](https://developers.cloudflare.com/dns/zone-setups/troubleshooting/cannot-add-domain/)
- [My domain’s email stopped working](https://developers.cloudflare.com/dns/troubleshooting/email-issues/)
- [Why is my site served over HTTP instead of HTTPS?](https://developers.cloudflare.com/ssl/edge-certificates/encrypt-visitor-traffic/)
- [SSL is not working for my second-level subdomain, such as `dev.www.example.com`](https://developers.cloudflare.com/ssl/troubleshooting/general-ssl-errors/#only-some-of-your-subdomains-return-ssl-errors)
- [Why was my domain deleted from Cloudflare?](https://developers.cloudflare.com/dns/zone-setups/troubleshooting/domain-deleted/)

## Cloudflare

- [Gather information to troubleshoot site issues](https://developers.cloudflare.com/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/)
- [Contact Cloudflare support](https://developers.cloudflare.com/support/contacting-cloudflare-support/)
- [Manage email notifications](https://developers.cloudflare.com/fundamentals/user-profiles/customize-account/#notifications)

## General resources

- [DNS FAQ](https://developers.cloudflare.com/dns/faq/)
- [SSL/TLS FAQ](https://developers.cloudflare.com/ssl/faq/)

## Is Cloudflare attacking me

Two common scenarios falsely lead to the perception that Cloudflare is attacking your site:

- Unless you [restore the original visitor IP addresses](https://developers.cloudflare.com/support/troubleshooting/restoring-visitor-ips/restoring-original-visitor-ips/), Cloudflare IP addresses appear in your server logs for all proxied requests.
- The attacker is spoofing Cloudflare's IPs. Cloudflare only [sends traffic to your origin web server over a few specific ports](https://developers.cloudflare.com/fundamentals/reference/network-ports/) unless you use [Cloudflare Spectrum](https://developers.cloudflare.com/spectrum/).

Ideally, because Cloudflare is a reverse proxy, your hosting provider observes attack traffic connecting from [Cloudflare IP addresses ↗](https://www.cloudflare.com/ips/). In contrast, if you notice connections from IP addresses that do not belong to Cloudflare, the attack is direct to your origin web server. Cloudflare cannot stop attacks directly to your origin IP address because the traffic bypasses Cloudflare's network.

Note

If an attacker is directly targeting your origin web server, refer to [Proactive DDoS defense best practices](https://developers.cloudflare.com/ddos-protection/best-practices/proactive-defense/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/troubleshooting/#page","headline":"Troubleshooting","description":"Resolve common error messages and unexpected behavior when setting up your Cloudflare account and domain.","url":"https://developers.cloudflare.com/fundamentals/reference/troubleshooting/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Turn on Cloudflare Under Attack mode to mitigate layer 7 DDoS attacks by challenging suspicious visitors with an interstitial page.
title: Under Attack mode
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Under Attack mode

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/reference/under-attack-mode/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Cloudflare's Under Attack mode performs additional security checks to help mitigate layer 7 DDoS attacks. Validated users access your website and suspicious traffic is blocked. It is designed to be used as one of the last resorts when a zone is under attack (and will temporarily pause access to your site and impact your site analytics).

When enabled, visitors receive an interstitial page.

## Turn on Under Attack mode

Under Attack mode is turned off by default for your zone.

### Globally

To put your entire zone in Under Attack mode:

1. In the Cloudflare dashboard, select your account and zone from the **Account home** page. [Go to **Account home** ↗](https://dash.cloudflare.com/?to=/:account/home)
2. In the zone overview page, turn on **Under Attack Mode** in the **Quick Actions** sidebar.

### Selectively

To enable Under Attack mode for specific pages or sections of your site, use a [configuration rule](https://developers.cloudflare.com/rules/configuration-rules/) to adjust the **Security Level**.

**When incoming requests match**

- **Field:** *URI Path*
- **Operator:** *starts with*
- **Value:** `/admin`

If you are using the Expression Editor, enter the following expression:  
`(starts_with(http.request.uri.path, "/admin"))`

**Then the settings are**

1. For **I'm Under Attack**, select **Add**.
2. Switch the toggle to **On**.

To turn it on for specific ASNs (hosts/ISPs that own IP addresses), countries, or IP ranges, use [IP Access Rules](https://developers.cloudflare.com/waf/tools/ip-access-rules/).

---

## Preview Under Attack mode

To preview what Under Attack mode looks like for your visitors:

1. In the Cloudflare dashboard, go to the **Configurations** page. [Go to **Configurations** ↗](https://dash.cloudflare.com/?to=/:account/configurations)
2. Go to **Custom Pages**.
3. For **Managed Challenge / I'm Under Attack Mode™**, select **Custom Pages** > **View default**.

The `Checking your browser before accessing...` challenge determines whether to block or allow a visitor within five seconds. After passing the challenge, the visitor does not observe another challenge until the duration configured in [Challenge Passage](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/challenge-passage/).

---

## Potential issues

Since the Under Attack mode requires your browser to support JavaScript to display and pass the interstitial page, it is expected to observe impact on third party analytics tools.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/reference/under-attack-mode/#page","headline":"Under Attack mode","description":"Turn on Cloudflare Under Attack mode to mitigate layer 7 DDoS attacks by challenging suspicious visitors with an interstitial page.","url":"https://developers.cloudflare.com/fundamentals/reference/under-attack-mode/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Run PCI compliance scans against your origin server or Cloudflare proxy and interpret the results.
title: Scan for PCI compliance
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Scan for PCI compliance

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/security/pci-scans/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Note

Cloudflare is PCI certified as a Data Processor. Refer to [PCI compliance and vulnerabilities mitigation](https://developers.cloudflare.com/ssl/reference/compliance-and-vulnerabilities) and Cloudflare's PCI DSS Responsibility Matrix for more information.

PCI scanners are tools used to identify security weaknesses. When a business undergoes a compliance audit, PCI scan results are used for compliance verification.

## Initiate a scan

1. Identify which server your scan should target. Are you scanning against your origin server, where your applications are hosted, or at a proxy server sitting in front of your origin, such as Cloudflare?
2. On your scanner tool, enter a public URL or an IP address. If you enter a public website URL, the scanner will resolve the hostname and scan the resulting the IP address. To scan your origin server, be sure to enter your origin server's IP address or a hostname that resolves to the origin server's IP, not a proxy server.
3. Start the scan and analyze the results.
4. (Optional) Run another scan for a different origin server.

### Open ports versus blocked traffic

Cloudflare's anycast network operates in a way that keeps ports other than 80 and 443 open, allowing it to serve traffic for other customers on these ports.

However, customers can easily block all unwanted traffic to these ports by using Cloudflare [WAF Managed Rules](https://developers.cloudflare.com/fundamentals/reference/network-ports/#how-to-block-traffic-on-additional-ports) or [custom rules](https://developers.cloudflare.com/waf/custom-rules/). The PCI scan will show the ports being open, but the traffic will not reach your origin server. This concern is often misunderstood.

## Additional resources

You can find all our public compliance resources in the following pages:

- [Certifications and compliance resources ↗](https://www.cloudflare.com/trust-hub/compliance-resources/)
- [Compliance documentation](https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/)

You can access Compliance documents in the Cloudflare dashboard by selecting your account where you are a Super Administrator and then navigating to **Support** > **Compliance Documents**.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/security/pci-scans/#page","headline":"Scan for PCI compliance","description":"Run PCI compliance scans against your origin server or Cloudflare proxy and interpret the results.","url":"https://developers.cloudflare.com/fundamentals/security/pci-scans/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Prevent and mitigate DDoS attacks on applications.
title: Concepts
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/learning-paths/llms.txt  
> Use this file to discover all available pages before exploring further.

# Concepts

Last updated Apr 23, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/learning-paths/prevent-ddos-attacks/concepts/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Learn the concepts behind DDoS attacks and protection, whether you are using Cloudflare or another provider.

## Objectives

By the end of this module, you will be able to:

- Explain what a DDoS attack is and how it could affect your application.
- List the common ways to prevent DDoS attacks.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/learning-paths/prevent-ddos-attacks/concepts/#page","headline":"Concepts","description":"Prevent and mitigate DDoS attacks on applications.","url":"https://developers.cloudflare.com/learning-paths/prevent-ddos-attacks/concepts/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-23","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Secure your origin server with Cloudflare by hiding its IP address, limiting connections, and monitoring health.
title: Protect your origin server
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Protect your origin server

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/security/protect-your-origin-server/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Your [origin server ↗](https://www.cloudflare.com/learning/cdn/glossary/origin-server) is a physical or virtual machine that is not owned by Cloudflare and hosts your application content (data, webpages, etc.).

Receiving too many requests can be bad for your origin. These requests might increase latency for visitors, incur higher costs — particularly for cloud-based machines — and could knock your application offline.

## Secure origin connections

When you secure origin connections, it prevents attackers from discovering and overloading your origin server with requests.

- **DNS**:
  1. **Proxy records** (when possible): Set up [proxied (orange-clouded) DNS records](https://developers.cloudflare.com/dns/proxy-status/) to hide your origin IP addresses and provide DDoS protection. As part of this, you should [allow Cloudflare IP addresses](https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/) at your origin to prevent requests from being blocked.
  2. **Review DNS-only records**: Audit existing **DNS-only** records ( `SPF`, `TXT`, and more) to make sure they do not contain origin IP information.
  3. **Evaluate mail infrastructure**: If possible, do not host a mail service on the same server as the web resource you want to protect, since emails sent to non-existent addresses get bounced back to the attacker and reveal the mail server IP.
  4. **Rotate origin IPs**: Once [onboarded](https://developers.cloudflare.com/dns/zone-setups/full-setup/setup/#35-verify-changes), rotate your origin IPs, as DNS records are in the public domain. Historical records are kept and would contain IP addresses prior to joining Cloudflare

### Application layer

<details>

<summary>

Cloudflare Tunnel (HTTP / WebSockets)

</summary>

<a href="https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/">Cloudflare Tunnel</a> connects your resources to Cloudflare without a publicly routable IP address, by creating an outbound-only connections to Cloudflare’s global network.

- **Security**: Very secure.
- **Availability**: All customers.
- **Challenges**: Requires installing the <code>cloudflared</code> daemon on origin server or virtual machine.

</details>

<details>

<summary>

HTTP Header Validation

</summary>

Only allow traffic with specific (and secret) HTTP headers.

- **Security**: Moderately secure.
- **Availability**: All customers.
- **Challenges**:
  - Requires more configuration efforts on application- and server-side to accept those headers.
  - Basic authentication is vulnerable to replay attacks. Because basic authentication does not encrypt user credentials, it is important that traffic always be sent over an encrypted SSL session.
  - There might be valid use cases for a mismatch in SNI / Host headers such as through <a href="https://developers.cloudflare.com/rules/origin-rules/features/">Origin or Page Rules</a>, <a href="https://developers.cloudflare.com/load-balancing/additional-options/override-http-host-headers/">Load Balancing</a>, or <a href="https://developers.cloudflare.com/workers/runtime-apis/request/">Workers</a>, which all offer HTTP Host Header overrides.
- **Process**:
  1. Use <a href="https://developers.cloudflare.com/rules/transform/request-header-modification/">Transform rules</a> or <a href="https://developers.cloudflare.com/workers/examples/alter-headers/">Workers</a> to add an HTTP Auth Header.
  2. Configure your origin server to restrict access based on the <a href="https://developers.cloudflare.com/workers/examples/auth-with-headers/">HTTP Auth Header</a> (or perform <a href="https://developers.cloudflare.com/workers/examples/basic-auth/">HTTP Basic Authentication</a>).
  3. Configure your origin server to restrict access based on the <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Host">HTTP Host Header ↗</a>. Specifically, only allow requests which contain expected HTTP Host Header values, and reject all other requests.

</details>

<details>

<summary>

JSON Web Tokens (JWT) Validation

</summary>

Only allow traffic with the appropriate JWT.

- **Security**: Very secure.
- **Availability**: Some customers.
- **Challenges**:
  - Requires either installing incremental software or modifying application code.
  - Lots of manual work.
- **Resources**:
  - <a href="https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/">Validate JWTs for an Access application</a>
  - <a href="https://developers.cloudflare.com/api-shield/security/jwt-validation/">Validate JWTs for an API</a>

</details>

### Transport Layer

<details>

<summary>

Authenticated Origin Pulls

</summary>

<a href="https://developers.cloudflare.com/ssl/origin-configuration/authenticated-origin-pull/">Authenticated Origin Pulls</a> helps ensure requests to your origin server come from the Cloudflare network.

- **Security**: Very secure.
- **Availability**: All customers.
- **Challenges**:
  - Requires <a href="https://developers.cloudflare.com/ssl/origin-configuration/ssl-modes/full/">Full</a> or <a href="https://developers.cloudflare.com/ssl/origin-configuration/ssl-modes/full-strict/">Full (strict)</a> encryption modes.
  - Requires more configuration efforts for application and server, such as uploading a certificate and configuring the server to use it.
  - For more strict security, you should upload your own certificate. Although Cloudflare provides you a certificate for easy configuration, this certificate only guarantees that a request is coming from the Cloudflare network.
  - Not scalable for large numbers of origin servers.

</details>

<details>

<summary>

Cloudflare Tunnel (SSH / RDP)

</summary>

<a href="https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/">Cloudflare Tunnel</a> connects your resources to Cloudflare without a publicly routable IP address, by creating an outbound-only connections to Cloudflare’s global network.

- **Security**: Very secure.
- **Availability**: All customers.
- **Challenges**: Requires installing the <code>cloudflared</code> daemon on origin server or virtual machine.

</details>

### Network Layer

<details>

<summary>

Allowlist Cloudflare IP addresses

</summary>

Explicitly block all traffic that does not come from <a href="https://developers.cloudflare.com/fundamentals/concepts/cloudflare-ip-addresses/">Cloudflare IP addresses</a> (or the IP addresses of your trusted partners, vendors, or applications).

- **Security**: Moderately secure.
- **Availability**: All customers.
- **Challenges**:
  - Requires allowlisting Cloudflare IP ranges at your origin server.
  - Vulnerable to IP spoofing.

</details>

<details>

<summary>

Cloudflare Magic Transit

</summary>

<a href="https://developers.cloudflare.com/magic-transit/">Cloudflare Magic Transit</a> is a network security and performance solution that offers DDoS protection, traffic acceleration, and more for on-premise, cloud-hosted, and hybrid networks.

- **Security**: Very secure.
- **Availability**: Enterprise-only.
- **Challenges**
  - Client's routers must:
    - Support anycast tunneling.
    - Allow configuration of at least one tunnel per Internet service provider (ISP).
    - Support maximum segment size (MSS) clamping.

</details>

<details>

<summary>

Cloudflare Network Interconnect

</summary>

<a href="https://developers.cloudflare.com/network-interconnect/">Cloudflare Network Interconnect</a> allows you to connect your network infrastructure directly with Cloudflare – rather than using the public Internet – for a more reliable and secure experience.

- **Security**: Very secure.
- **Availability**: Enterprise-only.
- **Challenges**
  - Requires some networking knowledge.
  - Only applies to some customer use cases.

</details>

<details>

<summary>

Dedicated CDN Egress IPs

</summary>

<a href="https://developers.cloudflare.com/smart-shield/get-started/#packages-and-availability">Smart Shield Advanced</a> provides dedicated egress IPs (from Cloudflare to your origin) for your layer 7 <a href="https://developers.cloudflare.com/waf/">WAF</a> and CDN services, as well as <a href="https://developers.cloudflare.com/spectrum/">Spectrum</a>. The egress IPs are reserved exclusively for your account so that you can increase your origin security by only allowing a small list of IP addresses through your layer 3 firewall.

- **Security**: Very secure.
- **Availability**: Enterprise-only.
- **Challenges**: Requires network-level firewall policies.

</details>

## Monitor origin health

For passive monitoring, [create notifications](https://developers.cloudflare.com/notifications/get-started/#create-a-notification) for **Origin Error Rate Alerts** to receive alerts when your origin returns 5xx codes above a configurable threshold and **Passive Origin Monitoring** to see when Cloudflare is unable to reach your origin for a few minutes.

For more active monitoring, set up [standalone health checks](https://developers.cloudflare.com/health-checks/) for your origin.

Note

If you have multiple servers and want to proactively prevent origin problems, [set up load balancing](https://developers.cloudflare.com/load-balancing/) as an add-on service.

### Zero Downtime Failover

If you have another `A` or `AAAA` record in your Cloudflare **DNS** or your Cloudflare **Load Balancer** provides another [endpoint](https://developers.cloudflare.com/load-balancing/understand-basics/load-balancing-components/) in the same pool, **Zero-Downtime Failover** automatically retries requests to your origin even before a Load Balancing decision is made.

Zero-downtime failover will trigger a single retry only if there is another healthy endpoint in the pool and a [521, 522, 523, 525 or 526 error code](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/error-521/) is occurring. No other error codes will trigger a zero-downtime failover operation.

  

## Reduce origin traffic

### Block traffic

For more details, refer to [Secure your website](https://developers.cloudflare.com/learning-paths/application-security/account-security/).

### Increase caching

The [cache](https://developers.cloudflare.com/cache/) stores data from your application (webpages, etc.) at Cloudflare data centers around the world, which reduces the number of requests sent to your origin server.

### Distribute traffic

To randomly distribute traffic across multiple servers, [set up multiple DNS records](https://developers.cloudflare.com/dns/manage-dns-records/how-to/round-robin-dns/).

For more fine-grained control over traffic distribution — including automatic failover, intelligent routing, and more — set up our [add-on load balancing service](https://developers.cloudflare.com/load-balancing/).

To protect specific endpoints from being overwhelmed by traffic spikes, [set up a waiting room](https://developers.cloudflare.com/waiting-room/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/security/protect-your-origin-server/#page","headline":"Protect your origin server","description":"Secure your origin server with Cloudflare by hiding its IP address, limiting connections, and monitoring health.","url":"https://developers.cloudflare.com/fundamentals/security/protect-your-origin-server/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Steps to recover your website after a hack and prevent future compromises using Cloudflare security features.
title: Recovering from a hacked site
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Recovering from a hacked site

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/security/recovering-from-hacked-site/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

If your website has been hacked recently, review the recommended steps below to recover a hacked website and prevent future hacks.

## Recovering from an attack

To recover from an attack, reach out to your hosting provider to request:

- Details about the hack, including how they believe the site was hacked.
- That your hosting provider remove any malicious content placed on your website.

Once the hack has been resolved, you should resolve site warnings in [Google Webmaster Tools ↗](https://www.google.com/webmasters/tools) and resubmit your site for Google's review.

---

## Preventing and mitigating the risks of a future hack

To prevent the risk of a hacked site:

- Activate Cloudflare's [WAF managed rules](https://developers.cloudflare.com/waf/managed-rules/) so they can challenge or block known malicious behavior.
- If you use a Content Management System (CMS), make sure you have the most recent version installed (CMS platforms push out updates to address known vulnerabilities).
- If you use plugins, make sure they are updated.
- If you have an admin login page, protect it with Cloudflare's [Rate limiting rules](https://developers.cloudflare.com/waf/rate-limiting-rules/) or a [Cloudflare Access policy](https://developers.cloudflare.com/cloudflare-one/access-controls/policies/).
- Use a backup service so you can avoid losing valid content.

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/security/recovering-from-hacked-site/#page","headline":"Recovering from a hacked site","description":"Steps to recover your website after a hack and prevent future compromises using Cloudflare security features.","url":"https://developers.cloudflare.com/fundamentals/security/recovering-from-hacked-site/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Protect web applications with Cloudflare security products.
title: Account security
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/learning-paths/llms.txt  
> Use this file to discover all available pages before exploring further.

# Account security

Last updated Apr 23, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/learning-paths/application-security/account-security/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

Make sure your account's security basics are configured properly.

## Objectives

By the end of this module, you will be able to:

- Secure your account
- Understand and configure the most common settings for Cloudflare's Application Security Products
- Explore advanced security products such as Bot Management and API Protection

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"WebPage","@id":"https://developers.cloudflare.com/learning-paths/application-security/account-security/#page","headline":"Account security","description":"Protect web applications with Cloudflare security products.","url":"https://developers.cloudflare.com/learning-paths/application-security/account-security/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-23","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```

---

---
description: Learn a few ways to tell if your application is under a DDoS attack.
title: Under a DDoS attack?
image: https://developers.cloudflare.com/og-docs.png
---

[Skip to content](#main-content)

> Documentation Index  
> Fetch the complete documentation index at: https://developers.cloudflare.com/fundamentals/llms.txt  
> Use this file to discover all available pages before exploring further.

# Under a DDoS attack?

Last updated Apr 20, 2026|Copy as Markdown| [View as Markdown](https://developers.cloudflare.com/fundamentals/security/under-ddos-attack/index.md)| [Agent setup](https://developers.cloudflare.com/agent-setup/)

A distributed denial-of-service (DDoS) attack is where a large number of computers or devices, usually controlled by a single attacker, attempt to access a website or online service all at once. This flood of traffic can overwhelm the website's origin servers, causing the site to slow down or even crash.

```
sequenceDiagram;
    participant User;
    participant Website;
    participant Server;
    participant Botnet;
    User->>Website: Requests to access site
    Website->>Origin Server: Processes user requests
    Botnet->>Origin Server: Sends a flood of traffic
    Origin Server-->>Website: Slows down due to traffic overload
    Origin Server-->>User: Unable to respond to user requests

```

  

## Common signs of an attack

Common signs that you are under DDoS attack include:

- Your site is offline or slow to respond to requests.
- Unexpected spikes appear in the graph of **Requests Through Cloudflare** or **Bandwidth** in your Cloudflare **Analytics** app.
- Strange requests appear in your origin web server logs that do not match normal visitor behavior.

Note

If you are currently under DDoS attack, refer to [Proactive DDoS defense best practices](https://developers.cloudflare.com/ddos-protection/best-practices/proactive-defense/).

Was this helpful?

YesNo

## On this page

[![](https://developers.cloudflare.com/_astro/logo.te5VL_aD.svg)Docs](https://developers.cloudflare.com/)

```json
{"@context":"https://schema.org","@type":"TechArticle","@id":"https://developers.cloudflare.com/fundamentals/security/under-ddos-attack/#page","headline":"Under a DDoS attack?","description":"Learn a few ways to tell if your application is under a DDoS attack.","url":"https://developers.cloudflare.com/fundamentals/security/under-ddos-attack/","inLanguage":"en","image":"https://developers.cloudflare.com/og-docs.png","dateModified":"2026-04-20","publisher":{"@type":"Organization","name":"Cloudflare","description":"One platform for your apps, agents, and workforce. Build, secure, and scale without managing infrastructure","url":"https://www.cloudflare.com/","sameAs":["https://github.com/cloudflare","https://www.linkedin.com/company/cloudflare","https://x.com/cloudflare"],"logo":{"@type":"ImageObject","url":"https://developers.cloudflare.com/logo.svg"},"address":{"@type":"PostalAddress","streetAddress":"101 Townsend St","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94107","addressCountry":"US"},"contactPoint":[{"@type":"ContactPoint","contactType":"Customer Support","url":"https://support.cloudflare.com/","availableLanguage":["English"]},{"@type":"ContactPoint","contactType":"Sales","url":"https://www.cloudflare.com/contact/","availableLanguage":["English"]}]},"isPartOf":{"@type":"WebSite","@id":"https://developers.cloudflare.com/#website","name":"Cloudflare Docs","url":"https://developers.cloudflare.com/"}}
```
